Bug #78860 [Opn]: Crashes when using ZEND_OP_ARRAY_EXTENSION
| From: | cmb@php.net | Date: | Tue, 26 Nov 2019 10:55:58 +0000 |
| Subject: | Bug #78860 [Opn]: Crashes when using ZEND_OP_ARRAY_EXTENSION | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-223894@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=78860&edit=1
ID: 78860
Updated by: cmb@php.net
Reported by: jtax at newrelic dot com
Summary: Crashes when using ZEND_OP_ARRAY_EXTENSION
Status: Open
Type: Bug
Package: Reproducible crash
Operating System: Linux
PHP Version: 7.4.0RC6
-Assigned To:
+Assigned To: dmitry
Block user comment: N
Private report: N
New Comment:
Dmitry, what do you think?
Previous Comments:
------------------------------------------------------------------------
[2019-11-23 00:58:06] jtax at newrelic dot com
Description:
------------
I'm trying to migrate from using op_array->reserved to ZEND_OP_ARRAY_EXTENSION
in a PHP extension. This is recommended in the UPGRADE.INTERNALS, and I anyway
already ran into problems with op_array reserved pointers in PHP 7.3. I see
various crashes when using ZEND_OP_ARRAY_EXTENSION and I could nail down two
major reasons for those crashes.
1. The run time cache that ZEND_OP_ARRAY_EXTENSION accesses is not always
initialized, and ZEND_OP_ARRAY_EXTENSION does no safety checks around that.
I can mitigate this by calling zend_fetch_function for all functions that I
need to access (zend_fetch_function ensures that the run time cache is
initialized), however there's no similar way to ensure an initialized run
time cache for class methods or callables.
To transition from op_array->reserved to ZEND_OP_ARRAY_EXTENSION, I would
need a way to ensure that the run time cache on the op_array is initialized.
This could be an API function that I can call. There exists a function
init_func_run_time_cache in Zend, but it's static and not part of the public
API.
2. In one cases (namely in zend_get_call_trampoline_func), the run time cache
pointer is set to a dummy value of 0x2. Accessing this op_array with
ZEND_OP_ARRAY_EXTENSION causes a crash.
I'd expect ZEND_OP_ARRAY_EXTENSION to check for this special condition and
handle it accordingly.
The one critical necessary for me (and I think for many others) to transition
from op_array->reserved to ZEND_OP_ARRAY_EXTENSION is a way to ensure an
initialized run time cache on an op_array, like a function
init_func_run_time_cache that I can call. Enhanced safety checks in
ZEND_OP_ARRAY_EXTENSION would be a nice-to-have.
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=78860&edit=1