Bug->Req #78860 [Asn->Fbk]: Crashes when using ZEND_OP_ARRAY_EXTENSION

From: Date: Mon, 09 Dec 2019 13:02:21 +0000
Subject: Bug->Req #78860 [Asn->Fbk]: Crashes when using ZEND_OP_ARRAY_EXTENSION
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-224168@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=78860&edit=1

 ID:                 78860
 Updated by:         dmitry@php.net
 Reported by:        jtax at newrelic dot com
 Summary:            Crashes when using ZEND_OP_ARRAY_EXTENSION
-Status:             Assigned
+Status:             Feedback
-Type:               Bug
+Type:               Feature/Change Request
 Package:            Reproducible crash
 Operating System:   Linux
 PHP Version:        7.4.0RC6
 Assigned To:        dmitry
 Block user comment: N
 Private report:     N

 New Comment:

It's a big question, how you are using op_array extensions.

op_array->run_time_cache is initialized when function is called first time.
If you need to add extended information early, you'll have to initialize run_time_cache
yourself. I added API call at https://github.com/php/php-src/commit/03d1c788ea8d9976f2fcb17d5d1c3d4280dd9570

I'm not sure if additional checks in ZEND_OP_ARRAY_EXTENSION() could help, because they need to
return something anyway. And you'll have to check for trampoline case yourself
(op_array->fn_flags & ZEND_ACC_CALL_VIA_TRAMPOLINE)


Previous Comments:
------------------------------------------------------------------------
[2019-11-26 10:55:58] cmb@php.net

Dmitry, what do you think?

------------------------------------------------------------------------
[2019-11-23 00:58:06] jtax at newrelic dot com

Description:
------------
I'm trying to migrate from using op_array->reserved to ZEND_OP_ARRAY_EXTENSION
in a PHP extension. This is recommended in the UPGRADE.INTERNALS, and I anyway
already ran into problems with op_array reserved pointers in PHP 7.3. I see
various crashes when using ZEND_OP_ARRAY_EXTENSION and I could nail down two
major reasons for those crashes.

1. The run time cache that ZEND_OP_ARRAY_EXTENSION accesses is not always 
   initialized, and ZEND_OP_ARRAY_EXTENSION does no safety checks around that.

   I can mitigate this by calling zend_fetch_function for all functions that I
   need to access (zend_fetch_function ensures that the run time cache is
   initialized), however there's no similar way to ensure an initialized run
   time cache for class methods or callables.

   To transition from op_array->reserved to ZEND_OP_ARRAY_EXTENSION, I would
   need a way to ensure that the run time cache on the op_array is initialized.
   This could be an API function that I can call. There exists a function
   init_func_run_time_cache in Zend, but it's static and not part of the public
   API.

2. In one cases (namely in zend_get_call_trampoline_func), the run time cache
   pointer is set to a dummy value of 0x2. Accessing this op_array with 
   ZEND_OP_ARRAY_EXTENSION causes a crash.

   I'd expect ZEND_OP_ARRAY_EXTENSION to check for this special condition and
   handle it accordingly.

The one critical necessary for me (and I think for many others) to transition
from op_array->reserved to ZEND_OP_ARRAY_EXTENSION is a way to ensure an 
initialized run time cache on an op_array, like a function 
init_func_run_time_cache that I can call. Enhanced safety checks in
ZEND_OP_ARRAY_EXTENSION would be a nice-to-have.




------------------------------------------------------------------------



--
Edit this bug report at https://bugs.php.net/bug.php?id=78860&edit=1


Thread (6 messages)

« previous php.bugs (#224168) next »