Bug #77638 [Ver->Csd]: var_export'ing certain class instances segfaults

From: Date: Mon, 25 Nov 2019 14:59:49 +0000
Subject: Bug #77638 [Ver->Csd]: var_export'ing certain class instances segfaults
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-223886@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=77638&edit=1 ID: 77638 Updated by: cmb@php.net Reported by: tandre@php.net Summary: var_export'ing certain class instances segfaults -Status: Verified +Status: Closed Type: Bug Package: Reproducible crash Operating System: Linux PHP Version: Next Minor Version Assigned To: cmb Block user comment: N Private report: N New Comment: Automatic comment on behalf of cmbecker69@gmx.de Revision: http://git.php.net/?p=php-src.git;a=commit;h=23c65a817390d219bbe77f363cf14956c5c7119b Log: Fix #77638: var_export'ing certain class instances segfaults Previous Comments: ------------------------------------------------------------------------ [2019-11-25 14:55:08] cmb@php.net Since COM instances are affected by this very issue as well (as of PHP 7.3.0), I'm changing the title. ------------------------------------------------------------------------ [2019-10-21 14:08:44] nikic@php.net Simple fix is to just return NULL instead, but I'd say the proper fix is to use GC_TRY_(UN)PROTECT_RECURSION macros in var_dump/var_export. ------------------------------------------------------------------------ [2019-10-21 11:53:38] cmb@php.net The problem is that the get_properties handler returns a pointer to a const Hashtable[1], which we're trying to modify in php_var_export_ex(). [1] <https://github.com/php/php-src/blob/d608ac6ee917c1da75868bd9cf40d5029d5e8a18/ext/ffi/ffi.c#L4699> ------------------------------------------------------------------------ [2019-02-18 18:35:27] tandre@php.net Description: ------------ Whenever var_export() is called on the result of FFI::new(), PHP segfaults. I think it's related to calling GC_PROTECT_RECURSION, *but the line numbers in my build may be wrong* ``` 553 GC_PROTECT_RECURSION(myht); (gdb) bt #0 0x0000000000944811 in php_var_export_ex (struc=0x7fffecc13100, level=1, buf=0x7fffffffbf90) at /path/to/php-src/ext/standard/var.c:553 #1 0x0000000000944fe3 in zif_var_export (execute_data=0x7fffecc130b0, return_value=0x7fffffffbfe0) at /path/to/php-src/ext/standard/var.c:622 #2 0x0000000000bb2b63 in ZEND_DO_ICALL_SPEC_RETVAL_UNUSED_HANDLER () at /path/to/php-src/Zend/zend_vm_execute.h:649 ``` Test script: --------------- ``` » php -a Interactive shell php > $x = FFI::new('int'); php > echo gettype($x); object php > echo get_class($x); FFI\CData php > var_dump($x); object(FFI\CData:int32_t)#1 (1) { ["cdata"]=> int(0) } php > var_export($x); [1] 2615 segmentation fault php -a ``` Expected result: ---------------- Either dumps the type or throws an Exception/Error for being impossible to dump Actual result: -------------- Segfaults ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=77638&edit=1

« previous php.bugs (#223886) next »