Bug #81280 [Com]: cli.prompt leads to segmentation fault

From: Date: Tue, 08 Feb 2022 13:34:52 +0000
Subject: Bug #81280 [Com]: cli.prompt leads to segmentation fault
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-239556@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=81280&edit=1

 ID:                 81280
 Comment by:         pardon at vimp dot com
 Reported by:        easteregg at verfriemelt dot org
 Summary:            cli.prompt leads to segmentation fault
 Status:             Closed
 Type:               Bug
 Package:            *General Issues
 Operating System:   Debian GNU/Linux 11 (bullseye)
 PHP Version:        8.0.8
 Block user comment: N
 Private report:     N

 New Comment:

I can reproduce this error within interactive PHP shell:

$ php -a
Interactive mode enabled

php > $gitName = shell_exec('git config user.name');
php > echo $gitName;
Christoph René Pardon
php > echo readline('confirm ' . $gitName) . PHP_EOL;
[1]    1306364 segmentation fault  php -a


Previous Comments:
------------------------------------------------------------------------
[2021-08-11 08:35:13] git@php.net

Automatic comment on behalf of krakjoe
Revision: https://github.com/php/php-src/commit/a2e051921a325fb0368afe0909f469a8d20dbb44
Log: Fix bug #81280 refuse to allow unicode chars in prompts

------------------------------------------------------------------------
[2021-07-30 15:21:02] cmb@php.net

The segfault has already been reported as bug #76989.

------------------------------------------------------------------------
[2021-07-23 15:15:40] easteregg at verfriemelt dot org

i tried to play around with this issue some more, and noticed, i am not even able to input
"»" in the interactive mode.

some other cli tools, like for example psql ( postgresql client ) uses readline aswell, and i know
for a fact, that those handle » just fine on windows and linux.

------------------------------------------------------------------------
[2021-07-23 13:51:40] cmb@php.net

FWIW, this works on Windows (except that setting the option via
command line causes a assertion violation, because isalnum expects
a number in range -1 to 255[1] while by default char gets promoted
to int as if from type signed char[2]).

And well, the documentation is meager; it does not even mention
the meaning of the escape characters[3].

[1] <https://github.com/php/php-src/blob/php-7.4.21/sapi/cli/php_cli.c#L1252>
[2] <https://docs.microsoft.com/en-us/cpp/cpp/char-wchar-t-char16-t-char32-t?view=msvc-160>
[3] <https://github.com/php/php-src/blob/php-7.4.21/ext/readline/readline_cli.c#L143-L181>

------------------------------------------------------------------------
[2021-07-23 08:31:01] easteregg at verfriemelt dot org

with -n it does not segfault but shows no prompt at all.

gdb trace:

Reading symbols from /usr/bin/php...
Reading symbols from /usr/lib/debug/.build-id/b5/86e7d17af20d6d58923a72e13bcd4d4c2c9295.debug...
(gdb) r
Starting program: /usr/bin/php -d cli.prompt=» -a
[Thread debugging using libthread_db enabled]
Using host libthread_db library "/lib/x86_64-linux-gnu/libthread_db.so.1".
Interactive mode enabled


Program received signal SIGSEGV, Segmentation fault.
0x00007ffff2fb66e5 in ?? () from /lib/x86_64-linux-gnu/libedit.so.2
(gdb) bt
#0  0x00007ffff2fb66e5 in ?? () from /lib/x86_64-linux-gnu/libedit.so.2
#1  0x00007ffff2fb78db in ?? () from /lib/x86_64-linux-gnu/libedit.so.2
#2  0x00007ffff2fb6e57 in ?? () from /lib/x86_64-linux-gnu/libedit.so.2
#3  0x00007ffff2fb7258 in el_wgets () from /lib/x86_64-linux-gnu/libedit.so.2
#4  0x00007ffff2fb1d63 in el_gets () from /lib/x86_64-linux-gnu/libedit.so.2
#5  0x00007ffff2fc5486 in readline () from /lib/x86_64-linux-gnu/libedit.so.2
#6  0x00007ffff31528e4 in readline_shell_run () at ./ext/readline/readline_cli.c:624
#7  0x00005555558a25dd in do_cli (argc=4, argv=0x555555a35ed0) at ./sapi/cli/php_cli.c:947
#8  0x000055555566767b in main (argc=4, argv=0x555555a35ed0) at ./sapi/cli/php_cli.c:1336
(gdb)

------------------------------------------------------------------------


The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at

    https://bugs.php.net/bug.php?id=81280


--
Edit this bug report at https://bugs.php.net/bug.php?id=81280&edit=1


Thread (10 messages)

« previous php.bugs (#239556) next »