Bug #78860 [Opn]: Crashes when using ZEND_OP_ARRAY_EXTENSION

From: Date: Tue, 26 Nov 2019 10:55:58 +0000
Subject: Bug #78860 [Opn]: Crashes when using ZEND_OP_ARRAY_EXTENSION
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-223894@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=78860&edit=1 ID: 78860 Updated by: cmb@php.net Reported by: jtax at newrelic dot com Summary: Crashes when using ZEND_OP_ARRAY_EXTENSION Status: Open Type: Bug Package: Reproducible crash Operating System: Linux PHP Version: 7.4.0RC6 -Assigned To: +Assigned To: dmitry Block user comment: N Private report: N New Comment: Dmitry, what do you think? Previous Comments: ------------------------------------------------------------------------ [2019-11-23 00:58:06] jtax at newrelic dot com Description: ------------ I'm trying to migrate from using op_array->reserved to ZEND_OP_ARRAY_EXTENSION in a PHP extension. This is recommended in the UPGRADE.INTERNALS, and I anyway already ran into problems with op_array reserved pointers in PHP 7.3. I see various crashes when using ZEND_OP_ARRAY_EXTENSION and I could nail down two major reasons for those crashes. 1. The run time cache that ZEND_OP_ARRAY_EXTENSION accesses is not always initialized, and ZEND_OP_ARRAY_EXTENSION does no safety checks around that. I can mitigate this by calling zend_fetch_function for all functions that I need to access (zend_fetch_function ensures that the run time cache is initialized), however there's no similar way to ensure an initialized run time cache for class methods or callables. To transition from op_array->reserved to ZEND_OP_ARRAY_EXTENSION, I would need a way to ensure that the run time cache on the op_array is initialized. This could be an API function that I can call. There exists a function init_func_run_time_cache in Zend, but it's static and not part of the public API. 2. In one cases (namely in zend_get_call_trampoline_func), the run time cache pointer is set to a dummy value of 0x2. Accessing this op_array with ZEND_OP_ARRAY_EXTENSION causes a crash. I'd expect ZEND_OP_ARRAY_EXTENSION to check for this special condition and handle it accordingly. The one critical necessary for me (and I think for many others) to transition from op_array->reserved to ZEND_OP_ARRAY_EXTENSION is a way to ensure an initialized run time cache on an op_array, like a function init_func_run_time_cache that I can call. Enhanced safety checks in ZEND_OP_ARRAY_EXTENSION would be a nice-to-have. ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=78860&edit=1

« previous php.bugs (#223894) next »