| 
        php.net | support | documentation | report a bug | advanced search | search howto | statistics | random bug | login | 
  [2010-05-07 00:13 UTC] russell dot tempero at rightnow dot com
 Description:
------------
When running PHP through Purify, I am seeing Invalid Pointer Read (IPR) errors such as the following:
IPR: Invalid pointer read:
  * This is occurring while in thread 8075:
    lex_scan       [zend_language_scanner.c:3174]
    zendlex        [zend_compile.c:4950]
    zendparse      [zend_language_parser.c:3280]
    compile_file   [zend_language_scanner.l:343]
    rnt_compile_file [rnt_opcode_cache.c:1008]
    compile_filename [zend_language_scanner.l:386]
  * Reading 1 byte from 0xf735f332 between the heap and the stack.
It appears that script files are memory mapped and then a cursor pointer is used to iterate over the mapped memory. The problem is that the cursor pointer is not properly checked when reaching the end of the file and memory values are read that are not part of the mapped memory. I manually fixed one case of this (see attached diff). However, there are others.
It looks like this file is generated (using flex?) so this is probably not actually a PHP issue. However, I thought I would start here. Let me know if this needs to be submitted to somebody else.
Patchesscanner_ipr.diff (last revision 2010-05-06 22:13 UTC by russell dot tempero at rightnow dot com)Pull RequestsHistoryAllCommentsChangesGit/SVN commits             
             | 
    |||||||||||||||||||||||||||||||||
            
                 
                Copyright © 2001-2025 The PHP GroupAll rights reserved.  | 
        Last updated: Tue Nov 04 00:00:01 2025 UTC | 
Here is some useful debug information if you wish to trace exactly where the IPRs are happening: . . . state: 476 char: ? addr: 0xf1c7885e state: 140 char: ? addr: 0xf1c7885e state: 121 char: ? addr: 0xf1c7885e state: -1 char: ? addr: 0xffce705b state: 166 char: ? addr: 0xf1c7885e state: 201 char: > addr: 0xf1c7885f state: 203 char: addr: 0xf1c78860 RUSSELL: YYCURSOR: 0xf1c78860 YYLIMIT: 0xf1c78861 state: 202 char: state: 0 char: state: 4 char: state: 3 char: RUSSELL: returning 0 in yy3