Bug #77638 [Ver->Csd]: var_export'ing certain class instances segfaults
| From: | cmb@php.net | Date: | Mon, 25 Nov 2019 14:59:49 +0000 |
| Subject: | Bug #77638 [Ver->Csd]: var_export'ing certain class instances segfaults | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-223886@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=77638&edit=1
ID: 77638
Updated by: cmb@php.net
Reported by: tandre@php.net
Summary: var_export'ing certain class instances segfaults
-Status: Verified
+Status: Closed
Type: Bug
Package: Reproducible crash
Operating System: Linux
PHP Version: Next Minor Version
Assigned To: cmb
Block user comment: N
Private report: N
New Comment:
Automatic comment on behalf of cmbecker69@gmx.de
Revision: http://git.php.net/?p=php-src.git;a=commit;h=23c65a817390d219bbe77f363cf14956c5c7119b
Log: Fix #77638: var_export'ing certain class instances segfaults
Previous Comments:
------------------------------------------------------------------------
[2019-11-25 14:55:08] cmb@php.net
Since COM instances are affected by this very issue as well (as of
PHP 7.3.0), I'm changing the title.
------------------------------------------------------------------------
[2019-10-21 14:08:44] nikic@php.net
Simple fix is to just return NULL instead, but I'd say the proper fix is to use
GC_TRY_(UN)PROTECT_RECURSION macros in var_dump/var_export.
------------------------------------------------------------------------
[2019-10-21 11:53:38] cmb@php.net
The problem is that the get_properties handler returns a pointer
to a const Hashtable[1], which we're trying to modify in
php_var_export_ex().
[1] <https://github.com/php/php-src/blob/d608ac6ee917c1da75868bd9cf40d5029d5e8a18/ext/ffi/ffi.c#L4699>
------------------------------------------------------------------------
[2019-02-18 18:35:27] tandre@php.net
Description:
------------
Whenever var_export() is called on the result of FFI::new(), PHP segfaults.
I think it's related to calling GC_PROTECT_RECURSION, *but the line numbers in my build may be
wrong*
```
553 GC_PROTECT_RECURSION(myht);
(gdb) bt
#0 0x0000000000944811 in php_var_export_ex (struc=0x7fffecc13100, level=1, buf=0x7fffffffbf90) at
/path/to/php-src/ext/standard/var.c:553
#1 0x0000000000944fe3 in zif_var_export (execute_data=0x7fffecc130b0, return_value=0x7fffffffbfe0)
at /path/to/php-src/ext/standard/var.c:622
#2 0x0000000000bb2b63 in ZEND_DO_ICALL_SPEC_RETVAL_UNUSED_HANDLER () at
/path/to/php-src/Zend/zend_vm_execute.h:649
```
Test script:
---------------
```
» php -a
Interactive shell
php > $x = FFI::new('int');
php > echo gettype($x);
object
php > echo get_class($x);
FFI\CData
php > var_dump($x);
object(FFI\CData:int32_t)#1 (1) {
["cdata"]=>
int(0)
}
php > var_export($x);
[1] 2615 segmentation fault php -a
```
Expected result:
----------------
Either dumps the type or throws an Exception/Error for being impossible to dump
Actual result:
--------------
Segfaults
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=77638&edit=1