Bug #79649 [NEW]: Altering disable_functions from module init corrupts memory
From: video dot ice dot power at seznam dot cz
Operating system: Windows
PHP version: 7.4.6
Package: Reproducible crash
Bug Type: Bug
Bug description:Altering disable_functions from module init corrupts memory
Description:
------------
disable_functions ini directive can be set before the php engine is
initialized here
https://github.com/php/php-src/blob/PHP-7.4.6/main/main.c#L2345
but for some reasons, setting/clearing disable_functions ini directive
causes currently memory corruptions / php crash.
In the example below I post complete source code of the module where the
problem is isolated and it can be produced repeatably by these steps:
1. compile the module
2.a run "php -v" with the module loaded
2.b run https://pastebin.com/NxHCBGmJ with the module
loaded and notice
"B" is not printed. This issue is presented if at least 195 functions
are defined and ini_set() is called. If defined functions count is
reduced or ini_set() is not called, full "AB" is printed, otherwise only
"A" is printed.
Can you reproduce the issue and is the usage of
"zend_alter_ini_entry_chars" function correct? Is there currently a
workaround to clear the disable_functions ini from module init?
Test script:
---------------
problematic line:
zend_alter_ini_entry_chars(ini_name_zend, "", strlen(""),
PHP_INI_SYSTEM, PHP_INI_STAGE_ACTIVATE);
complete mmm.c / module source:
#ifdef HAVE_CONFIG_H
#include "config.h"
#endif
#include "php.h"
PHP_MINIT_FUNCTION(mmm) {
zend_string *ini_name_zend = zend_string_init("disable_functions",
strlen("disable_functions"), 0);
zend_alter_ini_entry_chars(ini_name_zend, "", strlen(""),
PHP_INI_SYSTEM, PHP_INI_STAGE_ACTIVATE);
zend_string_release_ex(ini_name_zend, 0);
return SUCCESS;
}
zend_module_entry mmm_module_entry = {
STANDARD_MODULE_HEADER,
"mmm",
NULL,
PHP_MINIT(mmm),
NULL,
NULL,
NULL,
NULL,
"1.0.0",
STANDARD_MODULE_PROPERTIES
};
ZEND_GET_MODULE(mmm)
Expected result:
----------------
PHP 7.4.5 (cli) (built: Apr 14 2020 16:17:19) ( NTS Visual C++ 2017 x64
)
Copyright (c) The PHP Group
Zend Engine v3.4.0, Copyright (c) Zend Technologies
with Zend OPcache v7.4.5, Copyright (c), by Zend Technologies
Actual result:
--------------
PHP 7.4.5 (cli) (built: Apr 14 2020 16:17:19) ( NTS Visual C++ 2017 x64
)
Copyright (c) The PHP Group
Zend Engine v3.4.0, Copyright (c) Zend Technologies
with Zend OPcache v7.4.5, Copyright (c), by Zend Technologies
zend_mm_heap corrupted
--
Edit bug report at https://bugs.php.net/bug.php?id=79649&edit=1
--
Fix committed: https://bugs.php.net/fix.php?id=79649&r=fixed
Fixed in release: https://bugs.php.net/fix.php?id=79649&r=alreadyfixed
Need backtrace: https://bugs.php.net/fix.php?id=79649&r=needtrace
Need Reproduce Script: https://bugs.php.net/fix.php?id=79649&r=needscript
Try newer version: https://bugs.php.net/fix.php?id=79649&r=oldversion
Not developer issue: https://bugs.php.net/fix.php?id=79649&r=support
Expected behavior: https://bugs.php.net/fix.php?id=79649&r=notwrong
Not enough info: https://bugs.php.net/fix.php?id=79649&r=notenoughinfo
Submitted twice: https://bugs.php.net/fix.php?id=79649&r=submittedtwice
register_globals: https://bugs.php.net/fix.php?id=79649&r=globals
PHP version support discontinued: https://bugs.php.net/fix.php?id=79649&r=phptooold
Daylight Savings: https://bugs.php.net/fix.php?id=79649&r=dst
IIS Stability: https://bugs.php.net/fix.php?id=79649&r=isapi
Install GNU Sed: https://bugs.php.net/fix.php?id=79649&r=gnused
Floating point limitations: https://bugs.php.net/fix.php?id=79649&r=float
No Zend Extensions: https://bugs.php.net/fix.php?id=79649&r=nozend
MySQL Configuration Error: https://bugs.php.net/fix.php?id=79649&r=mysqlcfg
Thread (4 messages)
- video dot ice dot power at seznam dot cz