Bug #79571 [NEW]: FFI: calling Win32 LPSTR crashes
| From: | peratx at itxtech dot org | Date: | Thu, 07 May 2020 06:01:39 +0000 |
| Subject: | Bug #79571 [NEW]: FFI: calling Win32 LPSTR crashes | ||
| Groups: | php.bugs | ||
| Request: | Send a blank email to php-bugs+get-226943@lists.php.net to get a copy of this message | ||
From: peratx at itxtech dot org
Operating system: Windows 10 1903
PHP version: 7.4.5
Package: *Extensibility Functions
Bug Type: Bug
Bug description:FFI: calling Win32 LPSTR crashes
Description:
------------
When accessing Windows LPSTR, the whole program crashes.
===========
php -v
PHP 7.3.8 (cli) (built: Jul 30 2019 12:44:06) ( ZTS MSVC15 (Visual C++
2017) x64 )
Copyright (c) 1997-2018 The PHP Group
Zend Engine v3.3.8, Copyright (c) 1998-2018 Zend Technologies
with Zend OPcache v7.3.8, Copyright (c) 1999-2018, by Zend
Technologies
php -m
[PHP Modules]
bcmath
calendar
Core
ctype
curl
date
dom
filter
gd
hash
iconv
json
libxml
mbstring
mysqli
mysqlnd
openssl
pcre
PDO
pdo_mysql
Phar
pthreads
readline
Reflection
runkit7
session
SimpleXML
sockets
sodium
SPL
sqlite3
standard
tokenizer
wddx
xml
xmlreader
xmlwriter
yaml
Zend OPcache
zip
zlib
[Zend Modules]
Zend OPcache
Test script:
---------------
$ffi = \FFI::cdef(<<<EOL
typedef unsigned long DWORD;
typedef int BOOL;
typedef DWORD *LPDWORD;
typedef void *LPVOID;
typedef LPVOID HINTERNET;
typedef char* *LPSTR;
typedef struct {
DWORD dwLowDateTime;
DWORD dwHighDateTime;
} FILETIME, *PFILETIME, *LPFILETIME;
typedef struct {
DWORD dwOption;
union {
DWORD dwValue;
LPSTR pszValue;
FILETIME ftValue;
} Value;
} INTERNET_PER_CONN_OPTIONA, *LPINTERNET_PER_CONN_OPTIONA;
typedef struct {
DWORD dwSize;
LPSTR pszConnection;
DWORD dwOptionCount;
DWORD dwOptionError;
LPINTERNET_PER_CONN_OPTIONA pOptions;
} INTERNET_PER_CONN_OPTION_LISTA, *LPINTERNET_PER_CONN_OPTION_LISTA;
typedef DWORD WINAPI_InternetOption;
BOOL InternetSetOptionA(HINTERNET hInternet, WINAPI_InternetOption
dwOption, LPVOID lpBuffer, DWORD dwBufferLength);
BOOL InternetQueryOptionA(HINTERNET hInternet, WINAPI_InternetOption
dwOption, LPVOID lpBuffer, LPDWORD
lpdwBufferLength);
EOL
, "Wininet.dll");
$list = $ffi->new("INTERNET_PER_CONN_OPTION_LISTA");
$opt = $ffi->new("INTERNET_PER_CONN_OPTIONA");
$str = \FFI::new("char*", "");
$opt->dwOption = 1;
$opt->Value->pszValue = \FFI::addr($str);
$list->dwSize = \FFI::sizeof($list);
$list->pszConnection = null;
$list->dwOptionCount = 1;
$list->dwOptionError = 0;
$list->pOptions = \FFI::addr($opt);
$listptr = \FFI::addr($list);
$int = $ffi->new("DWORD");
$int->cdata = \FFI::sizeof($list) * 2;
$ptr = \FFI::addr($int);
$ffi->InternetQueryOptionA(null, 75, $listptr, $ptr);
var_dump($list);// crashes when it comes to pszValue which is a LPSTR
pointer
Expected result:
----------------
object(FFI\CData:struct <anonymous>)#5 (5) {
["dwSize"]=>
int(32)
["pszConnection"]=>
NULL
["dwOptionCount"]=>
int(1)
["dwOptionError"]=>
int(0)
["pOptions"]=>
object(FFI\CData:struct <anonymous>*)#11 (1) {
[0]=>
object(FFI\CData:struct <anonymous>)#12 (2) {
["dwOption"]=>
int(1)
["Value"]=>
object(FFI\CData:union <anonymous>)#13 (3) {
["dwValue"]=>
int(2)
["pszValue"]=>
string(xxx) "xxxxx"
["value...."]
Actual result:
--------------
object(FFI\CData:struct <anonymous>)#5 (5) {
["dwSize"]=>
int(32)
["pszConnection"]=>
NULL
["dwOptionCount"]=>
int(1)
["dwOptionError"]=>
int(0)
["pOptions"]=>
object(FFI\CData:struct <anonymous>*)#11 (1) {
[0]=>
object(FFI\CData:struct <anonymous>)#12 (2) {
["dwOption"]=>
int(1)
["Value"]=>
object(FFI\CData:union <anonymous>)#13 (3) {
["dwValue"]=>
int(2)
["pszValue"]=> //crashes
--
Edit bug report at https://bugs.php.net/bug.php?id=79571&edit=1
--
Fix committed: https://bugs.php.net/fix.php?id=79571&r=fixed
Fixed in release: https://bugs.php.net/fix.php?id=79571&r=alreadyfixed
Need backtrace: https://bugs.php.net/fix.php?id=79571&r=needtrace
Need Reproduce Script: https://bugs.php.net/fix.php?id=79571&r=needscript
Try newer version: https://bugs.php.net/fix.php?id=79571&r=oldversion
Not developer issue: https://bugs.php.net/fix.php?id=79571&r=support
Expected behavior: https://bugs.php.net/fix.php?id=79571&r=notwrong
Not enough info: https://bugs.php.net/fix.php?id=79571&r=notenoughinfo
Submitted twice: https://bugs.php.net/fix.php?id=79571&r=submittedtwice
register_globals: https://bugs.php.net/fix.php?id=79571&r=globals
PHP version support discontinued: https://bugs.php.net/fix.php?id=79571&r=phptooold
Daylight Savings: https://bugs.php.net/fix.php?id=79571&r=dst
IIS Stability: https://bugs.php.net/fix.php?id=79571&r=isapi
Install GNU Sed: https://bugs.php.net/fix.php?id=79571&r=gnused
Floating point limitations: https://bugs.php.net/fix.php?id=79571&r=float
No Zend Extensions: https://bugs.php.net/fix.php?id=79571&r=nozend
MySQL Configuration Error: https://bugs.php.net/fix.php?id=79571&r=mysqlcfg