Bug #81430 [NEW]: Attribute instantiation leaves dangling execute_data pointer
| From: | bwoebi@php.net | Date: | Fri, 10 Sep 2021 16:22:53 +0000 |
| Subject: | Bug #81430 [NEW]: Attribute instantiation leaves dangling execute_data pointer | ||
| Groups: | php.bugs | ||
| Request: | Send a blank email to php-bugs+get-236528@lists.php.net to get a copy of this message | ||
From: bwoebi
Operating system: MacOS 11
PHP version: 8.0.10
Package: Reproducible crash
Bug Type: Bug
Bug description:Attribute instantiation leaves dangling execute_data pointer
Description:
------------
I found sporadic crashes in my application upon max_time_limit
exhaustion. They were all somewhere within zend_observer_fcall_end_all.
The crashes are all related to invalid contents within
current_observed_frame.
In this specific reproducer I found, the issue is related to attributes,
which use a stack allocated dummy frame (notably with ex->func being
non-NULL, which is unlike the generator dummy frames).
Test script:
---------------
Using zend_test with INI:
zend_test.observer.enabled=1
zend_test.observer.observe_all=1
<?php
namespace X; // avoid cuf() being optimized away
ini_set("memory_limit", "20M");
#[\Attribute]
class A {
public function __construct() {}
}
#[A]
function B() {}
$r = new \ReflectionFunction("X\\B");
var_dump(call_user_func([$r->getAttributes(A::class)[0],
'newInstance']));
array_map("str_repeat", ["\xFF"], [100000000]); // cause a bailout
Expected result:
----------------
No crash.
Actual result:
--------------
* thread #1, queue = 'com.apple.main-thread', stop reason =
EXC_BAD_ACCESS (code=EXC_I386_GPFLT)
* frame #0: 0x0000000100722f16
php`zend_observer_fcall_end(execute_data=0x00007ffeefbfde70,
return_value=0x0000000000000000) at zend_observer.c:211:42
frame #1: 0x00000001007230a3 php`zend_observer_fcall_end_all at
zend_observer.c:243:4
frame #2: 0x00000001004fd7c5
php`php_request_shutdown(dummy=0x0000000000000000) at main.c:1783:3
frame #3: 0x00000001007a44d1 php`do_cli(argc=4,
argv=0x00007ffeefbff930) at php_cli.c:1135:3
(lldb) p execute_data
(zend_execute_data *) $0 = 0x00007ffeefbfde70 // stack memory
--
Edit bug report at https://bugs.php.net/bug.php?id=81430&edit=1
--
Fix committed: https://bugs.php.net/fix.php?id=81430&r=fixed
Fixed in release: https://bugs.php.net/fix.php?id=81430&r=alreadyfixed
Need backtrace: https://bugs.php.net/fix.php?id=81430&r=needtrace
Need Reproduce Script: https://bugs.php.net/fix.php?id=81430&r=needscript
Try newer version: https://bugs.php.net/fix.php?id=81430&r=oldversion
Not developer issue: https://bugs.php.net/fix.php?id=81430&r=support
Expected behavior: https://bugs.php.net/fix.php?id=81430&r=notwrong
Not enough info: https://bugs.php.net/fix.php?id=81430&r=notenoughinfo
Submitted twice: https://bugs.php.net/fix.php?id=81430&r=submittedtwice
register_globals: https://bugs.php.net/fix.php?id=81430&r=globals
PHP version support discontinued: https://bugs.php.net/fix.php?id=81430&r=phptooold
Daylight Savings: https://bugs.php.net/fix.php?id=81430&r=dst
IIS Stability: https://bugs.php.net/fix.php?id=81430&r=isapi
Install GNU Sed: https://bugs.php.net/fix.php?id=81430&r=gnused
Floating point limitations: https://bugs.php.net/fix.php?id=81430&r=float
No Zend Extensions: https://bugs.php.net/fix.php?id=81430&r=nozend
MySQL Configuration Error: https://bugs.php.net/fix.php?id=81430&r=mysqlcfg