Bug #81610 [Opn->Dup]: Interrupt on jump leads to dangling pointer
| From: | nikic@php.net | Date: | Thu, 11 Nov 2021 08:08:41 +0000 |
| Subject: | Bug #81610 [Opn->Dup]: Interrupt on jump leads to dangling pointer | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-237681@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=81610&edit=1
ID: 81610
Updated by: nikic@php.net
Reported by: tstarling@php.net
Summary: Interrupt on jump leads to dangling pointer
-Status: Open
+Status: Duplicate
Type: Bug
Package: Reproducible crash
PHP Version: 8.1Git-2021-11-11 (Git)
Block user comment: N
Private report: N
Previous Comments:
------------------------------------------------------------------------
[2021-11-11 08:08:34] nikic@php.net
Duplicate of bug #81577.
------------------------------------------------------------------------
[2021-11-11 07:09:49] tstarling@php.net
Originally discussed at https://phabricator.wikimedia.org/T293568
------------------------------------------------------------------------
[2021-11-11 06:44:05] tstarling@php.net
Description:
------------
Handlers of jump-like opcodes update the opline to point to the jump target before checking
EG(vm_interrupt) and calling the interrupt handler. If an exception is thrown by the interrupt
handler, the ZEND_HANDLE_EXCEPTION handler will free the return value of the target opline, even
though it has had no opportunity to run yet.
There will be a PR.
Test script:
---------------
<?php
/* Run with opcache.enable_cli=1 and send SIGUSR1 several times */
class C {
public static $cond = 1;
public static $a;
}
C::$a = [ C::$cond ]; // make countable zval
function go() {
while ( true ) {
$cond = C::$cond;
// T1 = FETCH_STATIC_PROP_R string("a") string("C")
C::$a;
// FREE T1
// JMPZ CV0($cond) 0000
if ( $cond )
// T1 = FETCH_STATIC_PROP_R string("a") string("C")
// (not executed but T1 freed)
C::$a;
}
}
pcntl_async_signals( true );
pcntl_signal( SIGUSR1, function () {
throw new Exception( 'ping' );
} );
while ( true ) {
try {
go();
} catch ( Exception $e ) {}
}
Actual result:
--------------
It crashes after receiving about 4 SIGUSR1 signals.
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=81610&edit=1