Bug #79741 [Opn->Ver]: segfault: curl_setopt/CURLOPT_POSTFIELDS using toStringable
| From: | nikic@php.net | Date: | Fri, 26 Jun 2020 10:15:13 +0000 |
| Subject: | Bug #79741 [Opn->Ver]: segfault: curl_setopt/CURLOPT_POSTFIELDS using toStringable | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-227685@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=79741&edit=1
ID: 79741
Updated by: nikic@php.net
Reported by: sjon@php.net
Summary: segfault: curl_setopt/CURLOPT_POSTFIELDS using
toStringable
-Status: Open
+Status: Verified
Type: Bug
Package: cURL related
Operating System: archLinux
PHP Version: 7.4.7
Block user comment: N
Private report: N
New Comment:
Reduced a bit:
<?php
class Test {
private $prop;
public function __toString() {
return "Foobar";
}
}
$ch = curl_init();
curl_setopt($ch, CURLOPT_POSTFIELDS, new Test);
For some reason the property declaration is important.
Previous Comments:
------------------------------------------------------------------------
[2020-06-26 08:45:51] sjon@php.net
Description:
------------
#0 0x00007f9e8c4ba355 raise (libc.so.6 + 0x3c355)
#1 0x00007f9e8c4a3853 abort (libc.so.6 + 0x25853)
#2 0x00007f9e8c4a3727 __assert_fail_base.cold (libc.so.6 + 0x25727)
#3 0x00007f9e8c4b2936 __assert_fail (libc.so.6 + 0x34936)
#4 0x000055e572bcd0d2 __zval_get_string_func (php + 0x64f0d2)
#5 0x000055e572bcd106 zval_get_string_func (php + 0x64f106)
#6 0x00007f9e8a479635 zval_get_tmp_string (curl.so + 0x4635)
#7 0x00007f9e8a482503 build_mime_structure_from_hash (curl.so + 0xd503)
#8 0x00007f9e8a483dfa _php_curl_setopt (curl.so + 0xedfa)
#9 0x00007f9e8a484c4b zif_curl_setopt (curl.so + 0xfc4b)
#10 0x000055e572c4fd71 ZEND_DO_ICALL_SPEC_RETVAL_UNUSED_HANDLER (php + 0x6d1d71)
#11 0x000055e572cb64bc execute_ex (php + 0x7384bc)
#12 0x000055e572cba613 zend_execute (php + 0x73c613)
#13 0x000055e572bdc0e9 zend_execute_scripts (php + 0x65e0e9)
#14 0x000055e572b39fc0 php_execute_script (php + 0x5bbfc0)
#15 0x000055e572cbd1c1 do_cli (php + 0x73f1c1)
#16 0x000055e572cbe3c1 main (php + 0x7403c1)
#17 0x00007f9e8c4a5002 __libc_start_main (libc.so.6 + 0x27002)
#18 0x000055e57277e6ae _start (php + 0x2006ae)
Test script:
---------------
<?php
class x
{
private $_body;
public function __construct(SimpleXMLElement $body)
{
$this->_body = $body;
}
public function __toString()
{
return $this->_body->asXML();
}
}
$body = new x(simplexml_load_string('<?xml version="1.0"
encoding="UTF-8"?>
<Test>
<Id>123</Id>
</Test>'));
$ch = curl_init();
curl_setopt($ch, CURLOPT_POSTFIELDS, $body);
Expected result:
----------------
no segfault - which can be achieved by manually casting to string first eg. curl_setopt($ch,
CURLOPT_POSTFIELDS, (string)$body);
Actual result:
--------------
segfault
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=79741&edit=1