[php-src] Issue #10471: SIGSEGV in zend_Call_function.

From: Date: Mon, 30 Jan 2023 04:24:41 +0000
Subject: [php-src] Issue #10471: SIGSEGV in zend_Call_function.
Groups: php.bugs 
Request: Send a blank email to php-bugs+get-243590@lists.php.net to get a copy of this message
Issue: https://github.com/php/php-src/issues/10471
Author: HeenaBansal2009

### Description

I am getting segmentation fault in zend_call_function() and I am not sure what is wrong with my
code. If I comment zend_call_function() core dump doesn't happen.

This function is basically responsible for mapping user functions defined in user code or if not
defined check in EG scope .

```
#if PHP_VERSION_ID >= 70000
static zend_always_inline zval *tracing_call_user_method_va(zval     *object, const char *name,
size_t name_len, zval **retval_ptr_ptr TSRMLS_DC, uint32_t params_count, va_list passed_params)
{
   int result;
   uint32_t i;
   zend_fcall_info fci;
   zend_fcall_info_cache fcc;
   zend_class_entry *obj_ce;
   HashTable *function_table;
   zend_string *lc_name;
   zval retval, *params = NULL, **orig_params;
   zval *retval_ptr = *retval_ptr_ptr;
   ALLOCA_FLAG(use_heap0);
   ALLOCA_FLAG(use_heap1);

   if (params_count) {
     params = (zval*)do_alloca(sizeof(zval)*params_count, use_heap0);
     orig_params = (zval **)do_alloca(sizeof(zval*)*params_count, use_heap1);

     for (i = 0; i < params_count; i++) {
        zval *val = va_arg(passed_params, zval*);
        orig_params[i] = val;
        ZVAL_COPY(&params[i], val);
     }
  }
  fci.params = params;
  fci.object = (object && Z_TYPE_P(object) == IS_OBJECT) ? Z_OBJ_P(object) : NULL;
  fci.retval = retval_ptr ? retval_ptr : &retval;

  fci.size = sizeof(fci);

  #if PHP_VERSION_ID < 70100
  
  fci.symbol_table = NULL;
  fci.function_table = NULL;
  #endif
  
  fci.param_count = params_count;
  
  #if PHP_VERSION_ID < 80000
  fci.no_separation = 1; 
  #endif
  
  #if PHP_VERSION_ID >= 80000
  fci.named_params = NULL;
  #endif

  obj_ce = object ? Z_OBJCE_P(object) : NULL;
  if (obj_ce) {
     function_table = &obj_ce->function_table;
  } else {
    function_table = EG(function_table);
  }

  lc_name = zend_string_alloc(name_len, 0);
  zend_str_tolower_copy(ZSTR_VAL(lc_name), name, name_len);
  if (UNEXPECTED((fcc.function_handler =       zend_hash_find_ptr(function_table, lc_name)) ==
NULL)) {
    ZVAL_STRINGL(&fci.function_name, name, name_len);
    result = zend_call_function(&fci, NULL);
    zval_ptr_dtor(&fci.function_name);
  } else {
  #if PHP_VERSION_ID < 70300
    fcc.initialized = 1;
  #endif
    fcc.calling_scope = obj_ce;
    if (object) {
        fcc.called_scope = Z_OBJCE_P(object);
    } else {
        zend_class_entry *called_scope =      zend_get_called_scope(EG(current_execute_data));

        if (obj_ce &&
            (!called_scope ||
            !instanceof_function(called_scope, obj_ce))) {
            fcc.called_scope = obj_ce;
        } else {
            fcc.called_scope = called_scope;
        }
    }
    fcc.object = object ? Z_OBJ_P(object) : NULL;
    result = zend_call_function(&fci, &fcc TSRMLS_CC);
}
zend_string_release(lc_name);


if (result == FAILURE) {
    if (!EG(exception)) {
        php_error_docref(NULL, E_WARNING, "Couldn't trace method %s%s%s", obj_ce ?
ZSTR_VAL(obj_ce->name) : "", obj_ce ? "::" : "", name);
    }
}

for (i = 0; i < params_count; i++) {
    if (Z_ISREF(params[i]) && !Z_ISREF_P(orig_params[i])) {
        ZVAL_COPY_VALUE(orig_params[i], &params[i]);
    }
    zval_ptr_dtor(&params[i]);
}
if (params_count) {
    free_alloca(orig_params, use_heap0);
    free_alloca(params, use_heap1);
}

if (!retval_ptr) {
    zval_ptr_dtor(&retval);
    return NULL;
}

return retval_ptr;
}
```

Resulted in this output:
019+ **Crash Report**

024+ # 1: /lib64/libc.so.6(+0x36400) [0x7f0bdc2f2400]
025+ # 2: /usr/local/bin/php() [0xe35a17]
026+ # 3: /usr/local/bin/php() [0xe35ee3]
027+ # 4: /usr/local/bin/php(zval_ptr_dtor+0x36) [0xe36394]
028+ # 5: /usr/local/bin/php() [0xc1054d]
029+ # 6: /usr/local/bin/php(zend_call_function+0xee5) [0xe16044]

But I expected this output instead:
NO Segmentation fault.


### PHP Version

PHP 7.3.29 and above

### Operating System

_No response_


Thread (1 message)

  • HeenaBansal2009
« previous php.bugs (#243590) next »