[php-src] Issue #10471: SIGSEGV in zend_Call_function.
Issue: https://github.com/php/php-src/issues/10471
Author: HeenaBansal2009
### Description
I am getting segmentation fault in zend_call_function() and I am not sure what is wrong with my
code. If I comment zend_call_function() core dump doesn't happen.
This function is basically responsible for mapping user functions defined in user code or if not
defined check in EG scope .
```
#if PHP_VERSION_ID >= 70000
static zend_always_inline zval *tracing_call_user_method_va(zval *object, const char *name,
size_t name_len, zval **retval_ptr_ptr TSRMLS_DC, uint32_t params_count, va_list passed_params)
{
int result;
uint32_t i;
zend_fcall_info fci;
zend_fcall_info_cache fcc;
zend_class_entry *obj_ce;
HashTable *function_table;
zend_string *lc_name;
zval retval, *params = NULL, **orig_params;
zval *retval_ptr = *retval_ptr_ptr;
ALLOCA_FLAG(use_heap0);
ALLOCA_FLAG(use_heap1);
if (params_count) {
params = (zval*)do_alloca(sizeof(zval)*params_count, use_heap0);
orig_params = (zval **)do_alloca(sizeof(zval*)*params_count, use_heap1);
for (i = 0; i < params_count; i++) {
zval *val = va_arg(passed_params, zval*);
orig_params[i] = val;
ZVAL_COPY(¶ms[i], val);
}
}
fci.params = params;
fci.object = (object && Z_TYPE_P(object) == IS_OBJECT) ? Z_OBJ_P(object) : NULL;
fci.retval = retval_ptr ? retval_ptr : &retval;
fci.size = sizeof(fci);
#if PHP_VERSION_ID < 70100
fci.symbol_table = NULL;
fci.function_table = NULL;
#endif
fci.param_count = params_count;
#if PHP_VERSION_ID < 80000
fci.no_separation = 1;
#endif
#if PHP_VERSION_ID >= 80000
fci.named_params = NULL;
#endif
obj_ce = object ? Z_OBJCE_P(object) : NULL;
if (obj_ce) {
function_table = &obj_ce->function_table;
} else {
function_table = EG(function_table);
}
lc_name = zend_string_alloc(name_len, 0);
zend_str_tolower_copy(ZSTR_VAL(lc_name), name, name_len);
if (UNEXPECTED((fcc.function_handler = zend_hash_find_ptr(function_table, lc_name)) ==
NULL)) {
ZVAL_STRINGL(&fci.function_name, name, name_len);
result = zend_call_function(&fci, NULL);
zval_ptr_dtor(&fci.function_name);
} else {
#if PHP_VERSION_ID < 70300
fcc.initialized = 1;
#endif
fcc.calling_scope = obj_ce;
if (object) {
fcc.called_scope = Z_OBJCE_P(object);
} else {
zend_class_entry *called_scope = zend_get_called_scope(EG(current_execute_data));
if (obj_ce &&
(!called_scope ||
!instanceof_function(called_scope, obj_ce))) {
fcc.called_scope = obj_ce;
} else {
fcc.called_scope = called_scope;
}
}
fcc.object = object ? Z_OBJ_P(object) : NULL;
result = zend_call_function(&fci, &fcc TSRMLS_CC);
}
zend_string_release(lc_name);
if (result == FAILURE) {
if (!EG(exception)) {
php_error_docref(NULL, E_WARNING, "Couldn't trace method %s%s%s", obj_ce ?
ZSTR_VAL(obj_ce->name) : "", obj_ce ? "::" : "", name);
}
}
for (i = 0; i < params_count; i++) {
if (Z_ISREF(params[i]) && !Z_ISREF_P(orig_params[i])) {
ZVAL_COPY_VALUE(orig_params[i], ¶ms[i]);
}
zval_ptr_dtor(¶ms[i]);
}
if (params_count) {
free_alloca(orig_params, use_heap0);
free_alloca(params, use_heap1);
}
if (!retval_ptr) {
zval_ptr_dtor(&retval);
return NULL;
}
return retval_ptr;
}
```
Resulted in this output:
019+ **Crash Report**
024+ # 1: /lib64/libc.so.6(+0x36400) [0x7f0bdc2f2400]
025+ # 2: /usr/local/bin/php() [0xe35a17]
026+ # 3: /usr/local/bin/php() [0xe35ee3]
027+ # 4: /usr/local/bin/php(zval_ptr_dtor+0x36) [0xe36394]
028+ # 5: /usr/local/bin/php() [0xc1054d]
029+ # 6: /usr/local/bin/php(zend_call_function+0xee5) [0xe16044]
But I expected this output instead:
NO Segmentation fault.
### PHP Version
PHP 7.3.29 and above
### Operating System
_No response_
Thread (1 message)
- HeenaBansal2009