Bug #72705 [Opn->Csd]: AddressSanitizer: negative-size-param in zend_compile_stmt

From: Date: Fri, 03 Jan 2020 09:53:04 +0000
Subject: Bug #72705 [Opn->Csd]: AddressSanitizer: negative-size-param in zend_compile_stmt
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-224676@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=72705&edit=1

 ID:                 72705
 Updated by:         nikic@php.net
 Reported by:        pranjal dot jumde at gmail dot com
 Summary:            AddressSanitizer: negative-size-param in
                     zend_compile_stmt
-Status:             Open
+Status:             Closed
 Type:               Bug
 Package:            Reproducible crash
 Operating System:   All
 PHP Version:        7.1Git-2016-07-29 (Git)
-Assigned To:        
+Assigned To:        nikic
 Block user comment: N
 Private report:     N

 New Comment:

I can't repro this either. On a 32-bit build this OOMs when concating the string (thus never
reaching the eval), on a 64-bit build it is clean under asan. I'm assuming this was already
resolved in the meantime.


Previous Comments:
------------------------------------------------------------------------
[2016-10-19 04:39:00] krakjoe@php.net

I'm not able to reproduce (because I don't have a 32bit machine).

I'm not sure that the trace looks like a bug in PHP, compile_stmt doesn't call any
printing functions, so it looks like asan is trying to output some debugging string in compile_stmt,
and it's asan itself is overflowing, possibly.

------------------------------------------------------------------------
[2016-07-29 07:18:18] pranjal dot jumde at gmail dot com

Description:
------------
=38807==ERROR: AddressSanitizer: negative-size-param: (size=-2147483648)
    #0 0x1107632f2 in printf_common(void*, char const*, __va_list_tag*)
(libclang_rt.asan_osx_dynamic.dylib+0x1b2f2)
    #1 0x110763c5b in wrap_vsprintf (libclang_rt.asan_osx_dynamic.dylib+0x1bc5b)
    #2 0x110764956 in wrap_sprintf (libclang_rt.asan_osx_dynamic.dylib+0x1c956)
    #3 0x10f89206f in zend_compile_stmt zend_compile.c:7785
    #4 0x10f8a9a86 in zend_compile_top_stmt zend_compile.c:7691
    #5 0x10f8a9a51 in zend_compile_top_stmt zend_compile.c:7686
    #6 0x10f816a14 in zend_compile zend_language_scanner.l:600
    #7 0x10f818713 in compile_string zend_language_scanner.l:765
    #8 0x10fbb90be in zend_include_or_eval zend_execute.c:2857

Test script:
---------------
 <?php
ini_set('memory_limit', '-1');
$newClassName = str_repeat("a", 2147483647);

eval("class $newClassName {
    function hello() {
        return \"Hello\";
    }
};");
 ?>



------------------------------------------------------------------------



--
Edit this bug report at https://bugs.php.net/bug.php?id=72705&edit=1


Thread (1 message)

  • nikic@php.net
  • Unknown Message
    • nikic@php.net
« previous php.bugs (#224676) next »