-
Couldn't load subscription status.
- Fork 8k
Fix GH-15210: phpdbg_print_changed_zvals working on a real copy instead. #15229
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Changes from 1 commit
File filter
Filter by extension
Conversations
Jump to
Diff view
Diff view
There are no files selected for viewing
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,40 @@ | ||
| --TEST-- | ||
| GH-15210 use after free after continue | ||
| --CREDITS-- | ||
| YuanchengJiang | ||
|
||
| --PHPDBG-- | ||
| b 4 | ||
| r | ||
| w $a[0] | ||
| w r $b | ||
| c | ||
| q | ||
| --FILE-- | ||
| <?php | ||
| header_register_callback(function() { echo "sent";}); | ||
| $a = [0]; | ||
| $a[0] = 1; | ||
| $b = &$a; | ||
| $a[0] = 2; | ||
| $a[1] = 3; | ||
| $c = [1]; | ||
| $b = &$c; | ||
| ?> | ||
| --EXPECTF-- | ||
| [Successful compilation of %s] | ||
| prompt> [Breakpoint #0 added at %s:%d] | ||
| prompt> [Breakpoint #0 at %s:%d, hits: 1] | ||
| >00004: $a[0] = 1; | ||
| 00005: $b = &$a; | ||
| 00006: $a[0] = 2; | ||
| prompt> [Added watchpoint #0 for $a[0]] | ||
| prompt> [Added recursive watchpoint #1 for $b] | ||
| prompt> [Breaking on watchpoint $a[0]] | ||
| Old value: [Breaking on watchpoint $a[0]] | ||
| Old value: 0 | ||
| New value: 1 | ||
| >00002: header_register_callback(function() { echo "sent";}); | ||
| 00003: $a = [0]; | ||
| 00004: $a[0] = 1; | ||
| prompt> [$a[0] has been removed, removing watchpoint] | ||
| [$b has been removed, removing watchpoint recursively] | ||
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
I don't totally understand why we need to duplicate the memory? Is it because the HashTable might be allocated with ZMM?
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
in fact is to avoid the hashtable corruption of the original watchpoint list, working on a copy then copy back once all is done. it fixed the issue for me.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Would increasing the refcounter on the HashTable also fix it or not?
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
seems to work if I allow cow violation.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
That would be wrong, we need a temporary hash table so that resizes don't cause problems. Increasing the refcount won't protect you against that and only papers over the real issue.