Bug #79741 [Opn->Ver]: segfault: curl_setopt/CURLOPT_POSTFIELDS using toStringable

From: Date: Fri, 26 Jun 2020 10:15:13 +0000
Subject: Bug #79741 [Opn->Ver]: segfault: curl_setopt/CURLOPT_POSTFIELDS using toStringable
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-227685@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=79741&edit=1 ID: 79741 Updated by: nikic@php.net Reported by: sjon@php.net Summary: segfault: curl_setopt/CURLOPT_POSTFIELDS using toStringable -Status: Open +Status: Verified Type: Bug Package: cURL related Operating System: archLinux PHP Version: 7.4.7 Block user comment: N Private report: N New Comment: Reduced a bit: <?php class Test { private $prop; public function __toString() { return "Foobar"; } } $ch = curl_init(); curl_setopt($ch, CURLOPT_POSTFIELDS, new Test); For some reason the property declaration is important. Previous Comments: ------------------------------------------------------------------------ [2020-06-26 08:45:51] sjon@php.net Description: ------------ #0 0x00007f9e8c4ba355 raise (libc.so.6 + 0x3c355) #1 0x00007f9e8c4a3853 abort (libc.so.6 + 0x25853) #2 0x00007f9e8c4a3727 __assert_fail_base.cold (libc.so.6 + 0x25727) #3 0x00007f9e8c4b2936 __assert_fail (libc.so.6 + 0x34936) #4 0x000055e572bcd0d2 __zval_get_string_func (php + 0x64f0d2) #5 0x000055e572bcd106 zval_get_string_func (php + 0x64f106) #6 0x00007f9e8a479635 zval_get_tmp_string (curl.so + 0x4635) #7 0x00007f9e8a482503 build_mime_structure_from_hash (curl.so + 0xd503) #8 0x00007f9e8a483dfa _php_curl_setopt (curl.so + 0xedfa) #9 0x00007f9e8a484c4b zif_curl_setopt (curl.so + 0xfc4b) #10 0x000055e572c4fd71 ZEND_DO_ICALL_SPEC_RETVAL_UNUSED_HANDLER (php + 0x6d1d71) #11 0x000055e572cb64bc execute_ex (php + 0x7384bc) #12 0x000055e572cba613 zend_execute (php + 0x73c613) #13 0x000055e572bdc0e9 zend_execute_scripts (php + 0x65e0e9) #14 0x000055e572b39fc0 php_execute_script (php + 0x5bbfc0) #15 0x000055e572cbd1c1 do_cli (php + 0x73f1c1) #16 0x000055e572cbe3c1 main (php + 0x7403c1) #17 0x00007f9e8c4a5002 __libc_start_main (libc.so.6 + 0x27002) #18 0x000055e57277e6ae _start (php + 0x2006ae) Test script: --------------- <?php class x { private $_body; public function __construct(SimpleXMLElement $body) { $this->_body = $body; } public function __toString() { return $this->_body->asXML(); } } $body = new x(simplexml_load_string('<?xml version="1.0" encoding="UTF-8"?> <Test> <Id>123</Id> </Test>')); $ch = curl_init(); curl_setopt($ch, CURLOPT_POSTFIELDS, $body); Expected result: ---------------- no segfault - which can be achieved by manually casting to string first eg. curl_setopt($ch, CURLOPT_POSTFIELDS, (string)$body); Actual result: -------------- segfault ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=79741&edit=1

« previous php.bugs (#227685) next »