Bug #81430 [NEW]: Attribute instantiation leaves dangling execute_data pointer

From: Date: Fri, 10 Sep 2021 16:22:53 +0000
Subject: Bug #81430 [NEW]: Attribute instantiation leaves dangling execute_data pointer
Groups: php.bugs 
Request: Send a blank email to php-bugs+get-236528@lists.php.net to get a copy of this message
From: bwoebi Operating system: MacOS 11 PHP version: 8.0.10 Package: Reproducible crash Bug Type: Bug Bug description:Attribute instantiation leaves dangling execute_data pointer Description: ------------ I found sporadic crashes in my application upon max_time_limit exhaustion. They were all somewhere within zend_observer_fcall_end_all. The crashes are all related to invalid contents within current_observed_frame. In this specific reproducer I found, the issue is related to attributes, which use a stack allocated dummy frame (notably with ex->func being non-NULL, which is unlike the generator dummy frames). Test script: --------------- Using zend_test with INI: zend_test.observer.enabled=1 zend_test.observer.observe_all=1 <?php namespace X; // avoid cuf() being optimized away ini_set("memory_limit", "20M"); #[\Attribute] class A { public function __construct() {} } #[A] function B() {} $r = new \ReflectionFunction("X\\B"); var_dump(call_user_func([$r->getAttributes(A::class)[0], 'newInstance'])); array_map("str_repeat", ["\xFF"], [100000000]); // cause a bailout Expected result: ---------------- No crash. Actual result: -------------- * thread #1, queue = 'com.apple.main-thread', stop reason = EXC_BAD_ACCESS (code=EXC_I386_GPFLT) * frame #0: 0x0000000100722f16 php`zend_observer_fcall_end(execute_data=0x00007ffeefbfde70, return_value=0x0000000000000000) at zend_observer.c:211:42 frame #1: 0x00000001007230a3 php`zend_observer_fcall_end_all at zend_observer.c:243:4 frame #2: 0x00000001004fd7c5 php`php_request_shutdown(dummy=0x0000000000000000) at main.c:1783:3 frame #3: 0x00000001007a44d1 php`do_cli(argc=4, argv=0x00007ffeefbff930) at php_cli.c:1135:3 (lldb) p execute_data (zend_execute_data *) $0 = 0x00007ffeefbfde70 // stack memory -- Edit bug report at https://bugs.php.net/bug.php?id=81430&edit=1 -- Fix committed: https://bugs.php.net/fix.php?id=81430&r=fixed Fixed in release: https://bugs.php.net/fix.php?id=81430&r=alreadyfixed Need backtrace: https://bugs.php.net/fix.php?id=81430&r=needtrace Need Reproduce Script: https://bugs.php.net/fix.php?id=81430&r=needscript Try newer version: https://bugs.php.net/fix.php?id=81430&r=oldversion Not developer issue: https://bugs.php.net/fix.php?id=81430&r=support Expected behavior: https://bugs.php.net/fix.php?id=81430&r=notwrong Not enough info: https://bugs.php.net/fix.php?id=81430&r=notenoughinfo Submitted twice: https://bugs.php.net/fix.php?id=81430&r=submittedtwice register_globals: https://bugs.php.net/fix.php?id=81430&r=globals PHP version support discontinued: https://bugs.php.net/fix.php?id=81430&r=phptooold Daylight Savings: https://bugs.php.net/fix.php?id=81430&r=dst IIS Stability: https://bugs.php.net/fix.php?id=81430&r=isapi Install GNU Sed: https://bugs.php.net/fix.php?id=81430&r=gnused Floating point limitations: https://bugs.php.net/fix.php?id=81430&r=float No Zend Extensions: https://bugs.php.net/fix.php?id=81430&r=nozend MySQL Configuration Error: https://bugs.php.net/fix.php?id=81430&r=mysqlcfg

« previous php.bugs (#236528) next »