Bug #81577 [Ver]: Segfault when signal handler raising a fatal error interrupts sleep+negation

From: Date: Thu, 11 Nov 2021 18:28:44 +0000
Subject: Bug #81577 [Ver]: Segfault when signal handler raising a fatal error interrupts sleep+negation
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-237700@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=81577&edit=1

 ID:                 81577
 Updated by:         dmitry@php.net
 Reported by:        abecker at mailbox dot org
 Summary:            Segfault when signal handler raising a fatal error
                     interrupts sleep+negation
 Status:             Verified
 Type:               Bug
 Package:            PCNTL related
 Operating System:   Linux
 PHP Version:        8.0.12
 Block user comment: N
 Private report:     N

 New Comment:

The bug is partially fixed in PHP-8.0 and above by the following commits:

https://github.com/php/php-src/commit/fa0b84a06b03a1c2a2bcadd647232a8a4a90aa05
https://github.com/php/php-src/commit/5380b415a243e538240fbbb92bf020a3719ab927


Previous Comments:
------------------------------------------------------------------------
[2021-11-11 08:08:34] nikic@php.net

Related To: Bug #81610

------------------------------------------------------------------------
[2021-11-04 14:08:51] nikic@php.net

The following pull request has been associated:

Patch Name: Fix bug #81577: Execute interrupt handler on original opline
On GitHub:  https://github.com/php/php-src/pull/7624
Patch:      https://github.com/php/php-src/pull/7624.patch

------------------------------------------------------------------------
[2021-11-04 11:13:22] nikic@php.net

Confirmed under valgrind:

^C==185861== Conditional jump or move depends on uninitialised value(s)
==185861==    at 0xA256BE: zval_ptr_dtor_nogc (zend_variables.h:34)
==185861==    by 0xA3B359: ZEND_HANDLE_EXCEPTION_SPEC_HANDLER (zend_vm_execute.h:2978)
==185861==    by 0xAA6D96: execute_ex (zend_vm_execute.h:54284)
==185861==    by 0xAAC367: zend_execute (zend_vm_execute.h:58523)
==185861==    by 0x9FCCCE: zend_execute_scripts (zend.c:1680)
==185861==    by 0x95E7C2: php_execute_script (main.c:2539)
==185861==    by 0xAED57D: do_cli (php_cli.c:949)
==185861==    by 0xAEE5CA: main (php_cli.c:1337)
==185861==

------------------------------------------------------------------------
[2021-10-31 08:42:52] abecker at mailbox dot org

Description:
------------
Run the test script on the command line and press Ctrl+C. The program will crash.

A crash will occur if sleep is interrupted by the faulty signal handler and
a negation of any variable with any value follows immediately. Negation of
a constant will not result in a crash.

Test script:
---------------
pcntl_async_signals(true);
pcntl_signal(SIGINT, function() { 0/0; });
sleep(10);
! $anyVariableWithAnyValue;




------------------------------------------------------------------------



--
Edit this bug report at https://bugs.php.net/bug.php?id=81577&edit=1


Thread (6 messages)

« previous php.bugs (#237700) next »