|
php.net | support | documentation | report a bug | advanced search | search howto | statistics | random bug | login |
[2015-11-05 12:06 UTC] a dot cobest at gmail dot com
Description: ------------ Short description: Broken pointer may appear due to the fact that there is no checking that the memory has been "freed". Long description: Rewriting the extension to php7 often get a Segmentation fault. it turned out that if somewhere I release the memory I get SIGSEGV in an unexpected place. The memory manager does not have a check that the memory has already been freed earlier (example attached). This problem will produce strange and hard-to-diagnose bugs Like this (also like this https://bugs.php.net/bug.php?id=70249 or this https://bugs.php.net/bug.php?id=70033 or this https://bugs.php.net/bug.php?id=70017 etc): php -v: PHP 7.0.0RC6 (cli) (built: Nov 2 2015 10:24:35) ( NTS DEBUG ) Copyright (c) 1997-2015 The PHP Group Zend Engine v3.0.0-dev, Copyright (c) 1998-2015 Zend Technologies uname -a: Darwin shadow 14.5.0 Darwin Kernel Version 14.5.0: Wed Jul 29 02:26:53 PDT 2015; root:xnu-2782.40.9~1/RELEASE_X86_64 x86_64 OS: MacOS 10.10.5 gdb backtrace: Program received signal SIGSEGV, Segmentation fault. 0x00000001003cd013 in zend_mm_alloc_small (heap=0x101200040, size=72, bin_num=8, __zend_filename=0x10090b633 "Zend/zend_string.h", __zend_lineno=121, __zend_orig_filename=0x0, __zend_orig_lineno=0) at Zend/zend_alloc.c:1291 1291 heap->free_slot[bin_num] = p->next_free_slot; Thread 1 (Thread 0xf03 of process 97454): #0 0x00000001003cd013 in zend_mm_alloc_small (heap=0x101200040, size=72, bin_num=8, __zend_filename=0x10090b633 "Zend/zend_string.h", __zend_lineno=121, __zend_orig_filename=0x0, __zend_orig_lineno=0) at Zend/zend_alloc.c:1291 #1 0x00000001003ca38e in zend_mm_alloc_heap (heap=0x101200040, size=72, __zend_filename=0x10090b633 "Zend/zend_string.h", __zend_lineno=121, __zend_orig_filename=0x0, __zend_orig_lineno=0) at Zend/zend_alloc.c:1358 #2 0x00000001003cb4bf in _emalloc (size=40, __zend_filename=0x10090b633 "Zend/zend_string.h", __zend_lineno=121, __zend_orig_filename=0x0, __zend_orig_lineno=0) at Zend/zend_alloc.c:2442 #3 0x00000001004282ca in zend_string_alloc (len=8, persistent=0) at Zend/zend_string.h:121 #4 0x0000000100421b5f in zend_string_init (str=0x1008d2b73 "function", len=8, persistent=0) at Zend/zend_string.h:157 #5 0x0000000100421c8f in _zend_hash_str_update (ht=0x102beb120, str=0x1008d2b73 "function", len=8, pData=0x7fff5fbfdd68, __zend_filename=0x10090ed84 "Zend/zend_hash.h", __zend_lineno=393) at Zend/zend_hash.c:598 #6 0x0000000100410db0 in zend_symtable_str_update (ht=0x102beb120, str=0x1008d2b73 "function", len=8, pData=0x7fff5fbfdd68) at Zend/zend_hash.h:393 #7 0x0000000100410ff3 in add_assoc_str_ex (arg=0x7fff5fbfdea0, key=0x1008d2b73 "function", key_len=8, str=0x102b748c0) at Zend/zend_API.c:1361 #8 0x000000010042a211 in zend_fetch_debug_backtrace (return_value=0x7fff5fbfdf58, skip_last=0, options=0, limit=0) at Zend/zend_builtin_functions.c:2595 #9 0x0000000100442da6 in zend_default_exception_new_ex (class_type=0x103805db8, skip_top_traces=0) at Zend/zend_exceptions.c:201 #10 0x0000000100441af7 in zend_default_exception_new (class_type=0x103805db8) at Zend/zend_exceptions.c:224 #11 0x0000000100410c13 in _object_and_properties_init (arg=0x7fff5fbfe098, class_type=0x103805db8, properties=0x0, __zend_filename=0x1009158a4 "Zend/zend_vm_execute.h", __zend_lineno=3356) at Zend/zend_API.c:1288 #12 0x0000000100410c76 in _object_init_ex (arg=0x7fff5fbfe098, class_type=0x103805db8, __zend_filename=0x1009158a4 "Zend/zend_vm_execute.h", __zend_lineno=3356) at Zend/zend_API.c:1296 #13 0x000000010049dea1 in ZEND_NEW_SPEC_CONST_HANDLER (execute_data=0x10121c350) at Zend/zend_vm_execute.h:3356 #14 0x00000001004712f4 in execute_ex (ex=0x10121bd00) at Zend/zend_vm_execute.h:417 #15 0x00000001003ed59e in zend_call_function (fci=0x7fff5fbfe3d0, fci_cache=0x7fff5fbfe3a8) at Zend/zend_execute_API.c:854 #16 0x0000000100165bcb in zim_reflection_method_invokeArgs (execute_data=0x10121bc80, return_value=0x10121b950) at ext/reflection/php_reflection.c:3370 #17 0x000000010049c267 in ZEND_DO_FCALL_SPEC_HANDLER (execute_data=0x10121b750) at Zend/zend_vm_execute.h:842 #18 0x00000001004712f4 in execute_ex (ex=0x101217030) at Zend/zend_vm_execute.h:417 #19 0x0000000100471460 in zend_execute (op_array=0x101273300, return_value=0x0) at Zend/zend_vm_execute.h:458 #20 0x000000010040b583 in zend_execute_scripts (type=8, retval=0x0, file_count=3) at Zend/zend.c:1428 #21 0x000000010035abc6 in php_execute_script (primary_file=0x7fff5fbff308) at main/main.c:2471 #22 0x00000001005047b3 in do_cli (argc=6, argv=0x7fff5fbffa28) at sapi/cli/php_cli.c:974 #23 0x00000001005035de in main (argc=6, argv=0x7fff5fbffa28) at sapi/cli/php_cli.c:1345 Test script: --------------- PHP_FUNCTION(double_free) { char * tmp = emalloc(sizeof(char)*7); memcpy(tmp, "alloc1", sizeof("alloc1")+1); efree(tmp); efree(tmp); char * tmp1 = emalloc(sizeof(char)*4); memcpy(tmp1, "all2", sizeof("all2")+1); char * tmp2 = emalloc(sizeof(char)*4); memcpy(tmp2, "all3", sizeof("all3")+1); // tmp1 has string "all3" } PatchesPull RequestsHistoryAllCommentsChangesGit/SVN commits
|
|||||||||||||||||||||||||||
Copyright © 2001-2026 The PHP GroupAll rights reserved. |
Last updated: Tue Oct 06 05:00:01 2026 UTC |
Typo in test: --------------- PHP_FUNCTION(double_free) { char * tmp = emalloc(sizeof(char)*7); memcpy(tmp, "alloc1", sizeof("alloc1")); efree(tmp); efree(tmp); char * tmp1 = emalloc(sizeof(char)*4); memcpy(tmp1, "all2", sizeof("all2")); char * tmp2 = emalloc(sizeof(char)*4); memcpy(tmp2, "all3", sizeof("all3")); // tmp1 has string "all3" }