Re: alloca() problem

From: Date: Mon, 14 Jun 2004 16:05:51 +0000
Subject: Re: alloca() problem
References: 1  Groups: php.internals 
Request: Send a blank email to internals+get-10442@lists.php.net to get a copy of this message
Ilia Alshanetsky wrote:
There is a rather nasty crash possible in PHP due to the usage of the alloca() function as can be demonstrated by bug #28064. Simpler bug replication case: php -r ' $a = str_repeat("a", 1024 * 1024 * 6); defined($a); '
The following two fragments will lead to virtually identical code:
    void foo()
    {
        char bar[2048];
        ...
    }
and
    void foo()
    {
        char *bar = alloca(2048);
        ....
They both start out by moving the stack pointer down 2k to leave enough room for bar, and they will both crash in a similar way if the stack doesn't have enough room available. I think that not alloca() itself but its improper use is the problem here. Any function will cause a crash if you call it when your stack is full. Just be sensible about when (not to) use it. -- Ard

« previous php.internals (#10442) next »