Bug #79096 [NEW]: FFI Struct Segfault

From: Date: Fri, 10 Jan 2020 23:02:31 +0000
Subject: Bug #79096 [NEW]: FFI Struct Segfault
Groups: php.bugs 
Request: Send a blank email to php-bugs+get-224839@lists.php.net to get a copy of this message
From: php at tim dot ainfach dot de Operating system: OSX 10.14.6 PHP version: 7.4.1 Package: *Extensibility Functions Bug Type: Bug Bug description:FFI Struct Segfault Description: ------------ Returning a struct with multiple fields larger than an uint64_t segaults. for example when i return a struct with two uint32_t values everything seems to be fine. When i return a struct with three uint32_t members the script segfaults. Works fine: struct Buffer { uint32_t a; uint32_t b; }; Segfault: struct Buffer { uint32_t a; uint64_t b; }; Test script: --------------- // header struct Buffer { uint32_t a; uint64_t b; // with uint32_t it works }; struct Buffer poll(); // php $ffi = \FFI::cdef(file_get_contents(__DIR__ . '/../rlib/rlib.h'), __DIR__ . '/../clib/lib.dylib'); $poll1 = $ffi->poll(); var_dump($poll1); // c #include <stdint.h> #include "../rlib/rlib.h" struct Buffer poll() { struct Buffer b; b.a = 1; b.b = 1; return b; } Expected result: ---------------- object(FFI\CData:struct Buffer)#2 (2) { ["a"]=> int(1) ["b"]=> int(1) } Actual result: -------------- /bin/sh: line 1: 35179 Segmentation fault: 11 php foo.php Thread 3 received signal SIGSEGV, Segmentation fault. ZEND_DO_FCALL_SPEC_RETVAL_USED_HANDLER (execute_data=0x1028160f0) at Zend/zend_vm_execute.h:1743 1743 EG(current_execute_data) = execute_data; (gdb) bt #0 ZEND_DO_FCALL_SPEC_RETVAL_USED_HANDLER (execute_data=0x1028160f0) at Zend/zend_vm_execute.h:1743 #1 0x0000000100363fd8 in execute_ex (ex=0x1) at Zend/zend_vm_execute.h:53379 #2 0x0000000100364199 in zend_execute (op_array=0x1028160f0, return_value=0x0) at Zend/zend_vm_execute.h:57664 #3 0x0000000100318d51 in zend_execute_scripts (type=42033392, retval=0x0, file_count=12405416) at Zend/zend.c:1663 #4 0x00000001002a214c in php_execute_script (primary_file=<optimized out>) at main/main.c:2619 #5 0x00000001003b5ea5 in do_cli (argc=<optimized out>, argv=0x102816020) at sapi/cli/php_cli.c:961 #6 0x00000001003b4d35 in main (argc=42033392, argv=0x102890120) at sapi/cli/php_cli.c:1352 -- Edit bug report at https://bugs.php.net/bug.php?id=79096&edit=1 -- Fix committed: https://bugs.php.net/fix.php?id=79096&r=fixed Fixed in release: https://bugs.php.net/fix.php?id=79096&r=alreadyfixed Need backtrace: https://bugs.php.net/fix.php?id=79096&r=needtrace Need Reproduce Script: https://bugs.php.net/fix.php?id=79096&r=needscript Try newer version: https://bugs.php.net/fix.php?id=79096&r=oldversion Not developer issue: https://bugs.php.net/fix.php?id=79096&r=support Expected behavior: https://bugs.php.net/fix.php?id=79096&r=notwrong Not enough info: https://bugs.php.net/fix.php?id=79096&r=notenoughinfo Submitted twice: https://bugs.php.net/fix.php?id=79096&r=submittedtwice register_globals: https://bugs.php.net/fix.php?id=79096&r=globals PHP version support discontinued: https://bugs.php.net/fix.php?id=79096&r=phptooold Daylight Savings: https://bugs.php.net/fix.php?id=79096&r=dst IIS Stability: https://bugs.php.net/fix.php?id=79096&r=isapi Install GNU Sed: https://bugs.php.net/fix.php?id=79096&r=gnused Floating point limitations: https://bugs.php.net/fix.php?id=79096&r=float No Zend Extensions: https://bugs.php.net/fix.php?id=79096&r=nozend MySQL Configuration Error: https://bugs.php.net/fix.php?id=79096&r=mysqlcfg

« previous php.bugs (#224839) next »