Bug #79125 [Opn->Ver]: FFI lifetime

From: Date: Thu, 16 Jan 2020 11:51:49 +0000
Subject: Bug #79125 [Opn->Ver]: FFI lifetime
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-224930@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=79125&edit=1 ID: 79125 Updated by: cmb@php.net Reported by: php at tim dot ainfach dot de Summary: FFI lifetime -Status: Open +Status: Verified Type: Bug Package: *Extensibility Functions Operating System: OSX 10.14.6 PHP Version: 7.4.2RC1 Block user comment: N Private report: N New Comment: Indeed, after ::bug79096() has been called, the FFI instance is destroyed including all its types, although the FFI\Cdata instance still holds a pointer to the struct bug79096 type. This results in a use-after-free. Previous Comments: ------------------------------------------------------------------------ [2020-01-15 19:27:02] php at tim dot ainfach dot de sorry for the misleading title, seems that i cant change it? "FFI lifetime" would be much better. ------------------------------------------------------------------------ [2020-01-15 19:11:59] php at tim dot ainfach dot de Description: ------------ returning and directly using the result of a \FFI::cdef() function ends up in a void pointer. php-src/ext/ffi/ffi.c:1990: zend_ffi_cdata_get_debug_info: Assertion `0' failed. https://github.com/php/php-src/blob/9d7e03c325473024e54c864f0379efc1bbf03e72/ext/ffi/ffi.c#L1990 it's easy to reproduct with the same structs used here: https://github.com/php/php-src/commit/05f3cd23ed61d800a861f2dd057ed56e783ea6f1#diff-3ea95b4dc57e34c882215bcc36f84551 i am not sure if this is a bug or a very consusing api limitation related to the livetime of zvals. Test script: --------------- // php code that SEGFAULTS function ffi() { return \FFI::cdef( file_get_contents(__DIR__ . '/example.h'), __DIR__ . '/lib.so' ); } $res = ffi()->bug79096(); var_dump($res); // php code that WORKS // same as above $ffi = ffi(); $res = $ffi->bug79096(); // c code struct bug79096 bug79096(void) { struct bug79096 b; b.a = 1; b.b = 1; return b; } // header struct bug79096 { uint64_t a; uint64_t b; }; struct bug79096 bug79096(void); Expected result: ---------------- object(FFI\CData:struct bug79096)#9 (2) { ["a"]=> int(1) ["b"]=> int(1) } ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=79125&edit=1

« previous php.bugs (#224930) next »