Bug #79096 [PATCH]: FFI Struct Segfault
Edit report at https://bugs.php.net/bug.php?id=79096&edit=1
ID: 79096
Patch added by: cmb@php.net
Reported by: php at tim dot ainfach dot de
Summary: FFI Struct Segfault
Status: Verified
Type: Bug
Package: *Extensibility Functions
Operating System: OSX 10.14.6
PHP Version: 7.4.1
Block user comment: N
Private report: N
New Comment:
The following pull request has been associated:
Patch Name: Fix #79096: FFI Struct Segfault
On GitHub: https://github.com/php/php-src/pull/5079
Patch: https://github.com/php/php-src/pull/5079.patch
Previous Comments:
------------------------------------------------------------------------
[2020-01-11 18:52:59] cmb@php.net
Confirmed. Currently ext/ffi assumes that the size of the return
value is less than or equal to sizeof(ffi_arg), which is basically
sizeof(long).
------------------------------------------------------------------------
[2020-01-10 23:02:31] php at tim dot ainfach dot de
Description:
------------
Returning a struct with multiple fields larger than an uint64_t segaults.
for example when i return a struct with two uint32_t values everything seems to be fine. When i
return a struct with three uint32_t members the script segfaults.
Works fine:
struct Buffer {
uint32_t a;
uint32_t b;
};
Segfault:
struct Buffer {
uint32_t a;
uint64_t b;
};
Test script:
---------------
// header
struct Buffer {
uint32_t a;
uint64_t b; // with uint32_t it works
};
struct Buffer poll();
// php
$ffi = \FFI::cdef(file_get_contents(__DIR__ . '/../rlib/rlib.h'), __DIR__ .
'/../clib/lib.dylib');
$poll1 = $ffi->poll();
var_dump($poll1);
// c
#include <stdint.h>
#include "../rlib/rlib.h"
struct Buffer poll() {
struct Buffer b;
b.a = 1;
b.b = 1;
return b;
}
Expected result:
----------------
object(FFI\CData:struct Buffer)#2 (2) {
["a"]=>
int(1)
["b"]=>
int(1)
}
Actual result:
--------------
/bin/sh: line 1: 35179 Segmentation fault: 11 php foo.php
Thread 3 received signal SIGSEGV, Segmentation fault.
ZEND_DO_FCALL_SPEC_RETVAL_USED_HANDLER (execute_data=0x1028160f0) at Zend/zend_vm_execute.h:1743
1743 EG(current_execute_data) = execute_data;
(gdb) bt
#0 ZEND_DO_FCALL_SPEC_RETVAL_USED_HANDLER (execute_data=0x1028160f0) at Zend/zend_vm_execute.h:1743
#1 0x0000000100363fd8 in execute_ex (ex=0x1) at Zend/zend_vm_execute.h:53379
#2 0x0000000100364199 in zend_execute (op_array=0x1028160f0, return_value=0x0) at
Zend/zend_vm_execute.h:57664
#3 0x0000000100318d51 in zend_execute_scripts (type=42033392, retval=0x0, file_count=12405416) at
Zend/zend.c:1663
#4 0x00000001002a214c in php_execute_script (primary_file=<optimized out>) at
main/main.c:2619
#5 0x00000001003b5ea5 in do_cli (argc=<optimized out>, argv=0x102816020) at
sapi/cli/php_cli.c:961
#6 0x00000001003b4d35 in main (argc=42033392, argv=0x102890120) at sapi/cli/php_cli.c:1352
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=79096&edit=1
Thread (4 messages)