Bug #80186 [Opn]: Segfault when iterating over FFI object

From: Date: Sun, 04 Oct 2020 20:56:56 +0000
Subject: Bug #80186 [Opn]: Segfault when iterating over FFI object
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-229378@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=80186&edit=1

 ID:                 80186
 Updated by:         nikic@php.net
 Reported by:        as@php.net
 Summary:            Segfault when iterating over FFI object
 Status:             Open
 Type:               Bug
 Package:            Reproducible crash
 PHP Version:        8.0Git-2020-10-04 (Git)
 Block user comment: N
 Private report:     N

 New Comment:

zend_empty_array is also used for normal empty arrays [], so it should be possible to make this
work...


Previous Comments:
------------------------------------------------------------------------
[2020-10-04 20:56:27] as@php.net

The following pull request has been associated:

Patch Name: Fix #80186: Prevent segfault when iterating FFI obj props
On GitHub:  https://github.com/php/php-src/pull/6270
Patch:      https://github.com/php/php-src/pull/6270.patch

------------------------------------------------------------------------
[2020-10-04 20:40:56] as@php.net

Description:
------------
Currently zend_fake_get_properties in ext/ffi/ffi.c returns a pointer to
const HashTable zend_empty_array. Attempting to iterate over this array in userland
leads to a segfault because PHP tries to increment zend_empty_array's
nIteratorsCount which is const memory.

The proposed patch allows objects to return NULL for the get_properties handler. In
this case, the VM skips the foreach block.

If this approach is acceptable, there are other extensions and call sites[1][2] to fix where
zend_empty_array leaks into userland.

[1] https://github.com/php/php-src/blob/107962208a19d8b6dc1a190cb25fc37614411e71/ext/com_dotnet/com_handlers.c#L221-L229
[2] https://github.com/protocolbuffers/protobuf/issues/7319


Test script:
---------------
<?php

$ffi = FFI::cdef('');

foreach ($ffi as $_) {
}


Expected result:
----------------
no segfault

Actual result:
--------------
segfault


------------------------------------------------------------------------



--
Edit this bug report at https://bugs.php.net/bug.php?id=80186&edit=1


Thread (4 messages)

« previous php.bugs (#229378) next »