Bug #81610 [Opn->Dup]: Interrupt on jump leads to dangling pointer

From: Date: Thu, 11 Nov 2021 08:08:41 +0000
Subject: Bug #81610 [Opn->Dup]: Interrupt on jump leads to dangling pointer
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-237681@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=81610&edit=1 ID: 81610 Updated by: nikic@php.net Reported by: tstarling@php.net Summary: Interrupt on jump leads to dangling pointer -Status: Open +Status: Duplicate Type: Bug Package: Reproducible crash PHP Version: 8.1Git-2021-11-11 (Git) Block user comment: N Private report: N Previous Comments: ------------------------------------------------------------------------ [2021-11-11 08:08:34] nikic@php.net Duplicate of bug #81577. ------------------------------------------------------------------------ [2021-11-11 07:09:49] tstarling@php.net Originally discussed at https://phabricator.wikimedia.org/T293568 ------------------------------------------------------------------------ [2021-11-11 06:44:05] tstarling@php.net Description: ------------ Handlers of jump-like opcodes update the opline to point to the jump target before checking EG(vm_interrupt) and calling the interrupt handler. If an exception is thrown by the interrupt handler, the ZEND_HANDLE_EXCEPTION handler will free the return value of the target opline, even though it has had no opportunity to run yet. There will be a PR. Test script: --------------- <?php /* Run with opcache.enable_cli=1 and send SIGUSR1 several times */ class C { public static $cond = 1; public static $a; } C::$a = [ C::$cond ]; // make countable zval function go() { while ( true ) { $cond = C::$cond; // T1 = FETCH_STATIC_PROP_R string("a") string("C") C::$a; // FREE T1 // JMPZ CV0($cond) 0000 if ( $cond ) // T1 = FETCH_STATIC_PROP_R string("a") string("C") // (not executed but T1 freed) C::$a; } } pcntl_async_signals( true ); pcntl_signal( SIGUSR1, function () { throw new Exception( 'ping' ); } ); while ( true ) { try { go(); } catch ( Exception $e ) {} } Actual result: -------------- It crashes after receiving about 4 SIGUSR1 signals. ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=81610&edit=1

« previous php.bugs (#237681) next »