Bug #81430 [Opn->Csd]: Attribute instantiation leaves dangling execute_data pointer
| From: | git@php.net | Date: | Mon, 10 Jan 2022 11:43:38 +0000 |
| Subject: | Bug #81430 [Opn->Csd]: Attribute instantiation leaves dangling execute_data pointer | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-238933@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=81430&edit=1
ID: 81430
Updated by: git@php.net
Reported by: bwoebi@php.net
Summary: Attribute instantiation leaves dangling execute_data
pointer
-Status: Open
+Status: Closed
Type: Bug
Package: Reproducible crash
Operating System: MacOS 11
PHP Version: 8.0.10
Block user comment: N
Private report: N
New Comment:
Automatic comment on behalf of beberlei (author) and cmb69 (committer)
Revision: https://github.com/php/php-src/commit/2f6a06ccb0ef78e6122bb9e67f9b8b1ad07776e1
Log: Fix #81430: Attribute instantiation leaves dangling pointer
Previous Comments:
------------------------------------------------------------------------
[2021-11-29 10:02:40] beberlei@php.net
A workaround on PHP extension level is to not register an observer for attribute constructor
functions.
We have an example for this in our open-source extension in this PR: https://github.com/tideways/php-xhprof-extension/pull/109/files
------------------------------------------------------------------------
[2021-11-24 14:23:41] nikic@php.net
Related To: Bug #81648
------------------------------------------------------------------------
[2021-11-18 15:23:03] f dot sowade at r9e dot de
The following pull request has been associated:
Patch Name: Fixed bug #81430 Check if runtime cache pointer is NULL before dereferencing
On GitHub: https://github.com/php/php-src/pull/7665
Patch: https://github.com/php/php-src/pull/7665.patch
------------------------------------------------------------------------
[2021-11-12 15:07:37] f dot sowade at r9e dot de
The problem seems to be that func->op_array->run_time_cache__ptr is NULL in the reflection
dummy frame. I added a patch that checks for a null pointer before accessing the run_time_cache.
This fixes the crash for me.
An alternative solution would be to initialize the run_time_cache in the dummy frame as well. I
think this fix would have to be done in the call_attribute_constructor() in
ext/reflection/php_reflection.c.
Not sure which of these fixes makes more sense.
------------------------------------------------------------------------
[2021-11-12 15:01:29] f dot sowade at r9e dot de
The following patch has been added/updated:
Patch Name: fix81430.patch
Revision: 1636729289
URL: https://bugs.php.net/patch-display.php?bug=81430&patch=fix81430.patch&revision=1636729289
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=81430
--
Edit this bug report at https://bugs.php.net/bug.php?id=81430&edit=1