Bug #79571 [Opn->Ver]: FFI: var_dumping unions may segfault

From: Date: Mon, 11 May 2020 13:53:11 +0000
Subject: Bug #79571 [Opn->Ver]: FFI: var_dumping unions may segfault
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-226997@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=79571&edit=1 ID: 79571 Updated by: cmb@php.net Reported by: peratx at itxtech dot org Summary: FFI: var_dumping unions may segfault -Status: Open +Status: Verified Type: Bug Package: *Extensibility Functions Operating System: Windows 10 1903 PHP Version: 7.4.5 -Assigned To: +Assigned To: cmb Block user comment: N Private report: N Previous Comments: ------------------------------------------------------------------------ [2020-05-11 13:52:58] cmb@php.net The following pull request has been associated: Patch Name: Fix #79571: FFI: var_dumping unions may segfault On GitHub: https://github.com/php/php-src/pull/5544 Patch: https://github.com/php/php-src/pull/5544.patch ------------------------------------------------------------------------ [2020-05-07 12:33:02] peratx at itxtech dot org Maybe this issue is related to C Union. ------------------------------------------------------------------------ [2020-05-07 10:39:16] cmb@php.net The following pull request has been associated: Patch Name: Fix #79571: FFI: var_dumping unions may segfault On GitHub: https://github.com/php/php-src/pull/5538 Patch: https://github.com/php/php-src/pull/5538.patch ------------------------------------------------------------------------ [2020-05-07 10:07:40] cmb@php.net Simpler reproducer: <?php $ffi = FFI::cdef(' typedef union { int num; char *str; } my_union; '); $union = $ffi->new('my_union'); $union->num = 17; var_dump($union); ?> The problem is that FFI can't know which member of the union is actually valid, but assumes that all are. ------------------------------------------------------------------------ [2020-05-07 06:11:27] peratx at itxtech dot org Wrong php info, it should be: PHP 7.4.5 (cli) (built: Apr 14 2020 16:17:34) ( ZTS Visual C++ 2017 x64 ) Copyright (c) The PHP Group Zend Engine v3.4.0, Copyright (c) Zend Technologies with Zend OPcache v7.4.5, Copyright (c), by Zend Technologie [PHP Modules] bcmath calendar Core ctype curl date dom FFI filter gd hash iconv json libxml mbstring mysqli mysqlnd openssl pcre PDO pdo_mysql Phar readline Reflection runkit7 session SimpleXML sockets sodium SPL sqlite3 standard tokenizer xml xmlreader xmlwriter yaml Zend OPcache zip zlib [Zend Modules] Zend OPcache ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=79571 -- Edit this bug report at https://bugs.php.net/bug.php?id=79571&edit=1

« previous php.bugs (#226997) next »