php.net |  support |  documentation |  report a bug |  advanced search |  search howto |  statistics |  random bug |  login
Bug #70860 Broken pointer in the memory heap.
Submitted: 2015-11-05 12:06 UTC Modified: 2015-11-06 08:41 UTC
From: a dot cobest at gmail dot com Assigned: laruence (profile)
Status: Closed Package: Scripting Engine problem
PHP Version: 7.0.0RC6 OS: any
Private report: No CVE-ID: None
Welcome back! If you're the original bug submitter, here's where you can edit the bug or add additional notes.
If you forgot your password, you can retrieve your password here.
Password:
Status:
Package:
Bug Type:
Summary:
From: a dot cobest at gmail dot com
New email:
PHP Version: OS:

 

 [2015-11-05 12:06 UTC] a dot cobest at gmail dot com
Description:
------------
Short description: Broken pointer may appear due to the fact that there is no checking that the memory has been "freed".
Long description: Rewriting the extension to php7 often get a Segmentation fault. it turned out that if somewhere I release the memory I get SIGSEGV in an unexpected place. 
The memory manager does not have a check that the memory has already been freed earlier (example attached). This problem will produce strange and hard-to-diagnose bugs

Like this (also like this https://bugs.php.net/bug.php?id=70249 or this https://bugs.php.net/bug.php?id=70033 or this https://bugs.php.net/bug.php?id=70017 etc):

php -v:
PHP 7.0.0RC6 (cli) (built: Nov  2 2015 10:24:35) ( NTS DEBUG )
Copyright (c) 1997-2015 The PHP Group
Zend Engine v3.0.0-dev, Copyright (c) 1998-2015 Zend Technologies

uname -a:
Darwin shadow 14.5.0 Darwin Kernel Version 14.5.0: Wed Jul 29 02:26:53 PDT 2015; root:xnu-2782.40.9~1/RELEASE_X86_64 x86_64

OS:
MacOS 10.10.5

gdb backtrace:
Program received signal SIGSEGV, Segmentation fault.
0x00000001003cd013 in zend_mm_alloc_small (heap=0x101200040, size=72, bin_num=8, __zend_filename=0x10090b633 "Zend/zend_string.h", __zend_lineno=121, __zend_orig_filename=0x0, __zend_orig_lineno=0) at Zend/zend_alloc.c:1291
1291			heap->free_slot[bin_num] = p->next_free_slot;

Thread 1 (Thread 0xf03 of process 97454):
#0  0x00000001003cd013 in zend_mm_alloc_small (heap=0x101200040, size=72, bin_num=8, __zend_filename=0x10090b633 "Zend/zend_string.h", __zend_lineno=121, __zend_orig_filename=0x0, __zend_orig_lineno=0) at Zend/zend_alloc.c:1291
#1  0x00000001003ca38e in zend_mm_alloc_heap (heap=0x101200040, size=72, __zend_filename=0x10090b633 "Zend/zend_string.h", __zend_lineno=121, __zend_orig_filename=0x0, __zend_orig_lineno=0) at Zend/zend_alloc.c:1358
#2  0x00000001003cb4bf in _emalloc (size=40, __zend_filename=0x10090b633 "Zend/zend_string.h", __zend_lineno=121, __zend_orig_filename=0x0, __zend_orig_lineno=0) at Zend/zend_alloc.c:2442
#3  0x00000001004282ca in zend_string_alloc (len=8, persistent=0) at Zend/zend_string.h:121
#4  0x0000000100421b5f in zend_string_init (str=0x1008d2b73 "function", len=8, persistent=0) at Zend/zend_string.h:157
#5  0x0000000100421c8f in _zend_hash_str_update (ht=0x102beb120, str=0x1008d2b73 "function", len=8, pData=0x7fff5fbfdd68, __zend_filename=0x10090ed84 "Zend/zend_hash.h", __zend_lineno=393) at Zend/zend_hash.c:598
#6  0x0000000100410db0 in zend_symtable_str_update (ht=0x102beb120, str=0x1008d2b73 "function", len=8, pData=0x7fff5fbfdd68) at Zend/zend_hash.h:393
#7  0x0000000100410ff3 in add_assoc_str_ex (arg=0x7fff5fbfdea0, key=0x1008d2b73 "function", key_len=8, str=0x102b748c0) at Zend/zend_API.c:1361
#8  0x000000010042a211 in zend_fetch_debug_backtrace (return_value=0x7fff5fbfdf58, skip_last=0, options=0, limit=0) at Zend/zend_builtin_functions.c:2595
#9  0x0000000100442da6 in zend_default_exception_new_ex (class_type=0x103805db8, skip_top_traces=0) at Zend/zend_exceptions.c:201
#10 0x0000000100441af7 in zend_default_exception_new (class_type=0x103805db8) at Zend/zend_exceptions.c:224
#11 0x0000000100410c13 in _object_and_properties_init (arg=0x7fff5fbfe098, class_type=0x103805db8, properties=0x0, __zend_filename=0x1009158a4 "Zend/zend_vm_execute.h", __zend_lineno=3356) at Zend/zend_API.c:1288
#12 0x0000000100410c76 in _object_init_ex (arg=0x7fff5fbfe098, class_type=0x103805db8, __zend_filename=0x1009158a4 "Zend/zend_vm_execute.h", __zend_lineno=3356) at Zend/zend_API.c:1296
#13 0x000000010049dea1 in ZEND_NEW_SPEC_CONST_HANDLER (execute_data=0x10121c350) at Zend/zend_vm_execute.h:3356
#14 0x00000001004712f4 in execute_ex (ex=0x10121bd00) at Zend/zend_vm_execute.h:417
#15 0x00000001003ed59e in zend_call_function (fci=0x7fff5fbfe3d0, fci_cache=0x7fff5fbfe3a8) at Zend/zend_execute_API.c:854
#16 0x0000000100165bcb in zim_reflection_method_invokeArgs (execute_data=0x10121bc80, return_value=0x10121b950) at ext/reflection/php_reflection.c:3370
#17 0x000000010049c267 in ZEND_DO_FCALL_SPEC_HANDLER (execute_data=0x10121b750) at Zend/zend_vm_execute.h:842
#18 0x00000001004712f4 in execute_ex (ex=0x101217030) at Zend/zend_vm_execute.h:417
#19 0x0000000100471460 in zend_execute (op_array=0x101273300, return_value=0x0) at Zend/zend_vm_execute.h:458
#20 0x000000010040b583 in zend_execute_scripts (type=8, retval=0x0, file_count=3) at Zend/zend.c:1428
#21 0x000000010035abc6 in php_execute_script (primary_file=0x7fff5fbff308) at main/main.c:2471
#22 0x00000001005047b3 in do_cli (argc=6, argv=0x7fff5fbffa28) at sapi/cli/php_cli.c:974
#23 0x00000001005035de in main (argc=6, argv=0x7fff5fbffa28) at sapi/cli/php_cli.c:1345

Test script:
---------------
PHP_FUNCTION(double_free) {
    char * tmp = emalloc(sizeof(char)*7);
    memcpy(tmp, "alloc1", sizeof("alloc1")+1);
    efree(tmp);
    efree(tmp);
    char * tmp1 = emalloc(sizeof(char)*4);
    memcpy(tmp1, "all2", sizeof("all2")+1);
    char * tmp2 = emalloc(sizeof(char)*4);
    memcpy(tmp2, "all3", sizeof("all3")+1); // tmp1 has string "all3"
}


Patches

Pull Requests

History

AllCommentsChangesGit/SVN commitsRelated reports
 [2015-11-05 12:07 UTC] a dot cobest at gmail dot com
-Summary: Broken pointer in the heap memory. +Summary: Broken pointer in the memory heap.
 [2015-11-05 12:07 UTC] a dot cobest at gmail dot com
typo
 [2015-11-05 12:19 UTC] a dot cobest at gmail dot com
Typo in test:
---------------
PHP_FUNCTION(double_free) {
    char * tmp = emalloc(sizeof(char)*7);
    memcpy(tmp, "alloc1", sizeof("alloc1"));
    efree(tmp);
    efree(tmp);
    char * tmp1 = emalloc(sizeof(char)*4);
    memcpy(tmp1, "all2", sizeof("all2"));
    char * tmp2 = emalloc(sizeof(char)*4);
    memcpy(tmp2, "all3", sizeof("all3")); // tmp1 has string "all3"
}
 [2015-11-05 14:30 UTC] nikic@php.net
If you want to debug memory management issues run USE_ZEND_ALLOC=0 valgrind php. The ZMM only helps you with memory leaks, not with other kinds of memory problems.
 [2015-11-05 17:52 UTC] a dot cobest at gmail dot com
Thank you, it's works. It is what we need!
 [2015-11-06 08:41 UTC] laruence@php.net
-Status: Open +Status: Closed -Assigned To: +Assigned To: laruence
 
PHP Copyright © 2001-2026 The PHP Group
All rights reserved.
Last updated: Tue Oct 06 05:00:01 2026 UTC