Bug #79125 [Opn->Ver]: FFI lifetime
| From: | cmb@php.net | Date: | Thu, 16 Jan 2020 11:51:49 +0000 |
| Subject: | Bug #79125 [Opn->Ver]: FFI lifetime | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-224930@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=79125&edit=1
ID: 79125
Updated by: cmb@php.net
Reported by: php at tim dot ainfach dot de
Summary: FFI lifetime
-Status: Open
+Status: Verified
Type: Bug
Package: *Extensibility Functions
Operating System: OSX 10.14.6
PHP Version: 7.4.2RC1
Block user comment: N
Private report: N
New Comment:
Indeed, after
::bug79096() has been called, the FFI instance is
destroyed including all its types, although the FFI\Cdata instance
still holds a pointer to the struct bug79096 type. This results
in a use-after-free.
Previous Comments:
------------------------------------------------------------------------
[2020-01-15 19:27:02] php at tim dot ainfach dot de
sorry for the misleading title, seems that i cant change it? "FFI lifetime" would be much
better.
------------------------------------------------------------------------
[2020-01-15 19:11:59] php at tim dot ainfach dot de
Description:
------------
returning and directly using the result of a \FFI::cdef() function ends up in a void pointer.
php-src/ext/ffi/ffi.c:1990: zend_ffi_cdata_get_debug_info: Assertion `0' failed.
https://github.com/php/php-src/blob/9d7e03c325473024e54c864f0379efc1bbf03e72/ext/ffi/ffi.c#L1990
it's easy to reproduct with the same structs used here:
https://github.com/php/php-src/commit/05f3cd23ed61d800a861f2dd057ed56e783ea6f1#diff-3ea95b4dc57e34c882215bcc36f84551
i am not sure if this is a bug or a very consusing api limitation related to the livetime of zvals.
Test script:
---------------
// php code that SEGFAULTS
function ffi()
{
return \FFI::cdef(
file_get_contents(__DIR__ . '/example.h'),
__DIR__ . '/lib.so'
);
}
$res = ffi()->bug79096();
var_dump($res);
// php code that WORKS
// same as above
$ffi = ffi();
$res = $ffi->bug79096();
// c code
struct bug79096 bug79096(void)
{
struct bug79096 b;
b.a = 1;
b.b = 1;
return b;
}
// header
struct bug79096 {
uint64_t a;
uint64_t b;
};
struct bug79096 bug79096(void);
Expected result:
----------------
object(FFI\CData:struct bug79096)#9 (2) {
["a"]=>
int(1)
["b"]=>
int(1)
}
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=79125&edit=1