Bug #79571 [NEW]: FFI: calling Win32 LPSTR crashes

From: Date: Thu, 07 May 2020 06:01:39 +0000
Subject: Bug #79571 [NEW]: FFI: calling Win32 LPSTR crashes
Groups: php.bugs 
Request: Send a blank email to php-bugs+get-226943@lists.php.net to get a copy of this message
From: peratx at itxtech dot org Operating system: Windows 10 1903 PHP version: 7.4.5 Package: *Extensibility Functions Bug Type: Bug Bug description:FFI: calling Win32 LPSTR crashes Description: ------------ When accessing Windows LPSTR, the whole program crashes. =========== php -v PHP 7.3.8 (cli) (built: Jul 30 2019 12:44:06) ( ZTS MSVC15 (Visual C++ 2017) x64 ) Copyright (c) 1997-2018 The PHP Group Zend Engine v3.3.8, Copyright (c) 1998-2018 Zend Technologies with Zend OPcache v7.3.8, Copyright (c) 1999-2018, by Zend Technologies php -m [PHP Modules] bcmath calendar Core ctype curl date dom filter gd hash iconv json libxml mbstring mysqli mysqlnd openssl pcre PDO pdo_mysql Phar pthreads readline Reflection runkit7 session SimpleXML sockets sodium SPL sqlite3 standard tokenizer wddx xml xmlreader xmlwriter yaml Zend OPcache zip zlib [Zend Modules] Zend OPcache Test script: --------------- $ffi = \FFI::cdef(<<<EOL typedef unsigned long DWORD; typedef int BOOL; typedef DWORD *LPDWORD; typedef void *LPVOID; typedef LPVOID HINTERNET; typedef char* *LPSTR; typedef struct { DWORD dwLowDateTime; DWORD dwHighDateTime; } FILETIME, *PFILETIME, *LPFILETIME; typedef struct { DWORD dwOption; union { DWORD dwValue; LPSTR pszValue; FILETIME ftValue; } Value; } INTERNET_PER_CONN_OPTIONA, *LPINTERNET_PER_CONN_OPTIONA; typedef struct { DWORD dwSize; LPSTR pszConnection; DWORD dwOptionCount; DWORD dwOptionError; LPINTERNET_PER_CONN_OPTIONA pOptions; } INTERNET_PER_CONN_OPTION_LISTA, *LPINTERNET_PER_CONN_OPTION_LISTA; typedef DWORD WINAPI_InternetOption; BOOL InternetSetOptionA(HINTERNET hInternet, WINAPI_InternetOption dwOption, LPVOID lpBuffer, DWORD dwBufferLength); BOOL InternetQueryOptionA(HINTERNET hInternet, WINAPI_InternetOption dwOption, LPVOID lpBuffer, LPDWORD lpdwBufferLength); EOL , "Wininet.dll"); $list = $ffi->new("INTERNET_PER_CONN_OPTION_LISTA"); $opt = $ffi->new("INTERNET_PER_CONN_OPTIONA"); $str = \FFI::new("char*", ""); $opt->dwOption = 1; $opt->Value->pszValue = \FFI::addr($str); $list->dwSize = \FFI::sizeof($list); $list->pszConnection = null; $list->dwOptionCount = 1; $list->dwOptionError = 0; $list->pOptions = \FFI::addr($opt); $listptr = \FFI::addr($list); $int = $ffi->new("DWORD"); $int->cdata = \FFI::sizeof($list) * 2; $ptr = \FFI::addr($int); $ffi->InternetQueryOptionA(null, 75, $listptr, $ptr); var_dump($list);// crashes when it comes to pszValue which is a LPSTR pointer Expected result: ---------------- object(FFI\CData:struct <anonymous>)#5 (5) { ["dwSize"]=> int(32) ["pszConnection"]=> NULL ["dwOptionCount"]=> int(1) ["dwOptionError"]=> int(0) ["pOptions"]=> object(FFI\CData:struct <anonymous>*)#11 (1) { [0]=> object(FFI\CData:struct <anonymous>)#12 (2) { ["dwOption"]=> int(1) ["Value"]=> object(FFI\CData:union <anonymous>)#13 (3) { ["dwValue"]=> int(2) ["pszValue"]=> string(xxx) "xxxxx" ["value...."] Actual result: -------------- object(FFI\CData:struct <anonymous>)#5 (5) { ["dwSize"]=> int(32) ["pszConnection"]=> NULL ["dwOptionCount"]=> int(1) ["dwOptionError"]=> int(0) ["pOptions"]=> object(FFI\CData:struct <anonymous>*)#11 (1) { [0]=> object(FFI\CData:struct <anonymous>)#12 (2) { ["dwOption"]=> int(1) ["Value"]=> object(FFI\CData:union <anonymous>)#13 (3) { ["dwValue"]=> int(2) ["pszValue"]=> //crashes -- Edit bug report at https://bugs.php.net/bug.php?id=79571&edit=1 -- Fix committed: https://bugs.php.net/fix.php?id=79571&r=fixed Fixed in release: https://bugs.php.net/fix.php?id=79571&r=alreadyfixed Need backtrace: https://bugs.php.net/fix.php?id=79571&r=needtrace Need Reproduce Script: https://bugs.php.net/fix.php?id=79571&r=needscript Try newer version: https://bugs.php.net/fix.php?id=79571&r=oldversion Not developer issue: https://bugs.php.net/fix.php?id=79571&r=support Expected behavior: https://bugs.php.net/fix.php?id=79571&r=notwrong Not enough info: https://bugs.php.net/fix.php?id=79571&r=notenoughinfo Submitted twice: https://bugs.php.net/fix.php?id=79571&r=submittedtwice register_globals: https://bugs.php.net/fix.php?id=79571&r=globals PHP version support discontinued: https://bugs.php.net/fix.php?id=79571&r=phptooold Daylight Savings: https://bugs.php.net/fix.php?id=79571&r=dst IIS Stability: https://bugs.php.net/fix.php?id=79571&r=isapi Install GNU Sed: https://bugs.php.net/fix.php?id=79571&r=gnused Floating point limitations: https://bugs.php.net/fix.php?id=79571&r=float No Zend Extensions: https://bugs.php.net/fix.php?id=79571&r=nozend MySQL Configuration Error: https://bugs.php.net/fix.php?id=79571&r=mysqlcfg

« previous php.bugs (#226943) next »