php / php/php-src

stack overflow in jit

Offen
#23,119 0 Kommentare 0 Reaktionen 0 zugewiesene Personen Auf GitHub ansehen

Dieses Issue hat noch niemand übernommen.

Bug Category: JIT Status: Verified
Vorherrschende Sprache
C
Sterne
40.4k
Forks
8.1k
Ø Merge
2 T. 13 Std.
Gemergte PRs (30 T.)
96

Beschreibung

Description

The following code:

<?php
$a=[]; $b=[];
for($i=0;$i<1000000;$i++){ $a=[$a]; $b=[$b]; }
var_dump($a === $b);

Resulted in this output:

    #359 0x55b2f4f448f1 in zend_hash_compare_impl /home/php-src/Zend/zend_hash.c:3204
    #360 0x55b2f4f448f1 in zend_hash_compare /home/php-src/Zend/zend_hash.c:3234
    #361 0x55b2f5037f64 in zend_is_identical /home/php-src/Zend/zend_operators.c:2495
    #362 0x55b2f5038254 in fast_is_not_identical_function /home/php-src/Zend/zend_operators.h:963
    #363 0x55b2f5038254 in hash_zval_identical_function /home/php-src/Zend/zend_operators.c:2471
    #364 0x55b2f4f448f1 in zend_hash_compare_impl /home/php-src/Zend/zend_hash.c:3204
    #365 0x55b2f4f448f1 in zend_hash_compare /home/php-src/Zend/zend_hash.c:3234
    #366 0x55b2f5037f64 in zend_is_identical /home/php-src/Zend/zend_operators.c:2495
    #367 0x55b2f5038254 in fast_is_not_identical_function /home/php-src/Zend/zend_operators.h:963
    #368 0x55b2f5038254 in hash_zval_identical_function /home/php-src/Zend/zend_operators.c:2471
    #369 0x55b2f4f448f1 in zend_hash_compare_impl /home/php-src/Zend/zend_hash.c:3204
    #370 0x55b2f4f448f1 in zend_hash_compare /home/php-src/Zend/zend_hash.c:3234
    #371 0x55b2f5037f64 in zend_is_identical /home/php-src/Zend/zend_operators.c:2495
    #372 0x55b2f5038254 in fast_is_not_identical_function /home/php-src/Zend/zend_operators.h:963
    #373 0x55b2f5038254 in hash_zval_identical_function /home/php-src/Zend/zend_operators.c:2471
    #374 0x55b2f4f448f1 in zend_hash_compare_impl /home/php-src/Zend/zend_hash.c:3204
    #375 0x55b2f4f448f1 in zend_hash_compare /home/php-src/Zend/zend_hash.c:3234
    #376 0x55b2f5037f64 in zend_is_identical /home/php-src/Zend/zend_operators.c:2495
    #377 0x55b2f5038254 in fast_is_not_identical_function /home/php-src/Zend/zend_operators.h:963
    #378 0x55b2f5038254 in hash_zval_identical_function /home/php-src/Zend/zend_operators.c:2471
    #379 0x55b2f4f448f1 in zend_hash_compare_impl /home/php-src/Zend/zend_hash.c:3204
    #380 0x55b2f4f448f1 in zend_hash_compare /home/php-src/Zend/zend_hash.c:3234
    #381 0x55b2f5037f64 in zend_is_identical /home/php-src/Zend/zend_operators.c:2495
    #382 0x55b2f5038254 in fast_is_not_identical_function /home/php-src/Zend/zend_operators.h:963
    #383 0x55b2f5038254 in hash_zval_identical_function /home/php-src/Zend/zend_operators.c:2471
    #384 0x55b2f4f448f1 in zend_hash_compare_impl /home/php-src/Zend/zend_hash.c:3204
    #385 0x55b2f4f448f1 in zend_hash_compare /home/php-src/Zend/zend_hash.c:3234
    #386 0x55b2f5037f64 in zend_is_identical /home/php-src/Zend/zend_operators.c:2495
    #387 0x55b2f5038254 in fast_is_not_identical_function /home/php-src/Zend/zend_operators.h:963
    #388 0x55b2f5038254 in hash_zval_identical_function /home/php-src/Zend/zend_operators.c:2471
    #389 0x55b2f4f448f1 in zend_hash_compare_impl /home/php-src/Zend/zend_hash.c:3204
    #390 0x55b2f4f448f1 in zend_hash_compare /home/php-src/Zend/zend_hash.c:3234
    #391 0x55b2f5037f64 in zend_is_identical /home/php-src/Zend/zend_operators.c:2495
    #392 0x55b2f5038254 in fast_is_not_identical_function /home/php-src/Zend/zend_operators.h:963
    #393 0x55b2f5038254 in hash_zval_identical_function /home/php-src/Zend/zend_operators.c:2471
    #394 0x55b2f4f448f1 in zend_hash_compare_impl /home/php-src/Zend/zend_hash.c:3204
    #395 0x55b2f4f448f1 in zend_hash_compare /home/php-src/Zend/zend_hash.c:3234
    #396 0x55b2f5037f64 in zend_is_identical /home/php-src/Zend/zend_operators.c:2495
    #397 0x55b2f5038254 in fast_is_not_identical_function /home/php-src/Zend/zend_operators.h:963
    #398 0x55b2f5038254 in hash_zval_identical_function /home/php-src/Zend/zend_operators.c:2471
    #399 0x55b2f4f448f1 in zend_hash_compare_impl /home/php-src/Zend/zend_hash.c:3204
    #400 0x55b2f4f448f1 in zend_hash_compare /home/php-src/Zend/zend_hash.c:3234
    #401 0x55b2f5037f64 in zend_is_identical /home/php-src/Zend/zend_operators.c:2495
    #402 0x55b2f5038254 in fast_is_not_identical_function /home/php-src/Zend/zend_operators.h:963
    #403 0x55b2f5038254 in hash_zval_identical_function /home/php-src/Zend/zend_operators.c:2471
    #404 0x55b2f4f448f1 in zend_hash_compare_impl /home/php-src/Zend/zend_hash.c:3204
    #405 0x55b2f4f448f1 in zend_hash_compare /home/php-src/Zend/zend_hash.c:3234
    #406 0x55b2f5037f64 in zend_is_identical /home/php-src/Zend/zend_operators.c:2495
    #407 0x55b2f5038254 in fast_is_not_identical_function /home/php-src/Zend/zend_operators.h:963
    #408 0x55b2f5038254 in hash_zval_identical_function /home/php-src/Zend/zend_operators.c:2471
    #409 0x55b2f4f448f1 in zend_hash_compare_impl /home/php-src/Zend/zend_hash.c:3204
    #410 0x55b2f4f448f1 in zend_hash_compare /home/php-src/Zend/zend_hash.c:3234
    #411 0x55b2f5037f64 in zend_is_identical /home/php-src/Zend/zend_operators.c:2495
    #412 0x55b2f5038254 in fast_is_not_identical_function /home/php-src/Zend/zend_operators.h:963
    #413 0x55b2f5038254 in hash_zval_identical_function /home/php-src/Zend/zend_operators.c:2471

SUMMARY: AddressSanitizer: stack-overflow /home/php-src/Zend/zend_hash.c:3215 in zend_hash_compare
==50==ABORTING
USE_ZEND_ALLOC=0 ./php-src/sapi/cli/php -d "opcache.enable=1" -d "opcache.enable_cli=1" -d "opcache.jit=tracing" -d "opcache.jit_hot_loop=1" -d "opcache.jit_hot_func=1" poc.php
PHP Version
8.6.0
Operating System

ubuntu 22.04

Beitragsleitfaden

Beitragsleitfaden öffnen

Erste Schritte

  1. Lies das ganze Issue und danach den Beitragsleitfaden des Projekts.
  2. Schreib ins Issue, dass du es übernimmst — das erspart doppelte Arbeit.
  3. Forke das Repository und arbeite in einem Branch.
  4. Öffne einen Pull Request, der die Issue-Nummer nennt.

Rechercherichtung

Reproduziere den Fehler mit dem bereitgestellten CLI-Befehl und poc.php und untersuche anschließend die rekursiven Vergleichspfade in Zend/zend_hash.c, Zend/zend_operators.c und Zend/zend_operators.h rund um die gemeldeten Stackframes. Erledigt ist die Aufgabe, wenn der Reproducer nicht mehr mit einem Stacküberlauf abbricht und dabei das erwartete Vergleichsverhalten erhalten bleibt.

Vom Indexierungsmodell aus dem Issue-Text verfasst.

Bewertung

Tech-Stack
c, php
Bereich
compilers
Issue-Typ
Bug
Schwierigkeit
5/5
Geschätzter Aufwand
Über eine Woche
Aktivitätsstatus
Ruhig
Klarheit
Größtenteils klar
Anfängerfreundlichkeit
35/100

Neue Issues direkt in Ihr Postfach

Eine kurze Übersicht über anfängerfreundliche GitHub-Issues.