Bug #79643 [Ver->Csd]: PHP with Opcache crashes when a file with specific name is included
| From: | nikic@php.net | Date: | Tue, 20 Oct 2020 10:51:36 +0000 |
| Subject: | Bug #79643 [Ver->Csd]: PHP with Opcache crashes when a file with specific name is included | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-229787@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=79643&edit=1
ID: 79643
Updated by: nikic@php.net
Reported by: pluczkiewicz at wayfair dot com
Summary: PHP with Opcache crashes when a file with specific
name is included
-Status: Verified
+Status: Closed
Type: Bug
Package: opcache
Operating System: Linux
PHP Version: 7.4.6
Block user comment: N
Private report: N
New Comment:
Automatic comment on behalf of twose@qq.com
Revision: http://git.php.net/?p=php-src.git;a=commit;h=d134c0ac05b6f8969463ff1cf5dd7b6332bf5ab4
Log: Fix bug #79643: Invalid memory read when opcache.interned_strings_buffer is 0
Previous Comments:
------------------------------------------------------------------------
[2020-05-29 13:17:59] adbrvn at gmail dot com
Same behaviour.
One more example for reproduce https://github.com/adbrvn/php-sefgault
Tested on 7.4.4
------------------------------------------------------------------------
[2020-05-27 14:23:31] sjon@php.net
can confirm - but it requires the first file to actually exist
------------------------------------------------------------------------
[2020-05-27 13:21:53] pluczkiewicz at wayfair dot com
Description:
------------
PHP segfaults when a file with a very specific name is included, followed by another file (the first
path must be exactly as it is in the test script, for the second one I had more luck with random
values).
I have tested 7.3.0, 7.4.3 and 7.4.6, all of them are segfaulting.
opcache.interned_strings_buffer=0 seems to be required to get the segfault.
Test script:
---------------
Opcache config:
```
opcache.enable=On
opcache.enable_cli=On
opcache.interned_strings_buffer=0
opcache.max_accelerated_files=4000
```
Script itself:
```
<?php
require_once '/wayfair/data/codebase/php/includes/filesystem/temporary_local_storage.php';
require_once 'rNSSDJBm2jVwL899rn2rA4g0PdC8Pb0S4mrd5Xfsqq00qdaaOW2PkZDOelKbI26iE64oYvrk7l';
echo 'NO CRASH';
```
Code on GitHub: https://github.com/Agares/opcache-bug-repro
(run with docker build -t opcache_crash . && docker run opcache_crash)
Actual result:
--------------
Segfault
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=79643&edit=1