Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 2 additions & 0 deletions NEWS
Original file line number Diff line number Diff line change
Expand Up @@ -78,6 +78,8 @@ PHP NEWS
nested arrays). (Lazizbek Ergashev)
. Fixed bug GH-23115 (Stack overflow in compact() with deeply nested
arrays). (Lazizbek Ergashev)
. Fixed stack overflow in count() with COUNT_RECURSIVE and deeply nested
arrays. (Lazizbek Ergashev)

- Streams:
. Fixed bug GH-15836 (Use-after-free when a user stream filter accesses
Expand Down
6 changes: 5 additions & 1 deletion ext/spl/spl_observer.c
Original file line number Diff line number Diff line change
Expand Up @@ -679,7 +679,11 @@ PHP_METHOD(SplObjectStorage, count)
}

if (mode == PHP_COUNT_RECURSIVE) {
RETURN_LONG(php_count_recursive(&intern->storage));
zend_long count = php_count_recursive(&intern->storage);
if (UNEXPECTED(count < 0)) {
RETURN_THROWS();
}
RETURN_LONG(count);
}

RETURN_LONG(zend_hash_num_elements(&intern->storage));
Expand Down
20 changes: 18 additions & 2 deletions ext/standard/array.c
Original file line number Diff line number Diff line change
Expand Up @@ -611,10 +611,18 @@ PHPAPI zend_long php_count_recursive(HashTable *ht) /* {{{ */
zend_long cnt = 0;
zval *element;

#ifdef ZEND_CHECK_STACK_LIMIT
if (UNEXPECTED(zend_call_stack_overflowed(EG(stack_limit)))) {
zend_call_stack_size_error();
return -1;
}
#endif

if (!(GC_FLAGS(ht) & GC_IMMUTABLE)) {
if (GC_IS_RECURSIVE(ht)) {
php_error_docref(NULL, E_WARNING, "Recursion detected");
return 0;
/* A user error handler may have thrown. */
return EG(exception) ? -1 : 0;
}
GC_PROTECT_RECURSION(ht);
}
Expand All @@ -623,7 +631,12 @@ PHPAPI zend_long php_count_recursive(HashTable *ht) /* {{{ */
ZEND_HASH_FOREACH_VAL(ht, element) {
ZVAL_DEREF(element);
if (Z_TYPE_P(element) == IS_ARRAY) {
cnt += php_count_recursive(Z_ARRVAL_P(element));
zend_long sub_cnt = php_count_recursive(Z_ARRVAL_P(element));
if (UNEXPECTED(sub_cnt < 0)) {
cnt = -1;
break;
}
cnt += sub_cnt;
}
} ZEND_HASH_FOREACH_END();

Expand Down Expand Up @@ -656,6 +669,9 @@ PHP_FUNCTION(count)
cnt = zend_hash_num_elements(Z_ARRVAL_P(array));
} else {
cnt = php_count_recursive(Z_ARRVAL_P(array));
if (UNEXPECTED(cnt < 0)) {
RETURN_THROWS();
}
}
RETURN_LONG(cnt);
break;
Expand Down
1 change: 1 addition & 0 deletions ext/standard/php_array.h
Original file line number Diff line number Diff line change
Expand Up @@ -29,6 +29,7 @@ PHPAPI int php_array_merge(HashTable *dest, HashTable *src);
PHPAPI int php_array_merge_recursive(HashTable *dest, HashTable *src);
PHPAPI int php_array_replace_recursive(HashTable *dest, HashTable *src);
PHPAPI int php_multisort_compare(const void *a, const void *b);
/* Returns -1 and throws if the array is nested too deeply. */
PHPAPI zend_long php_count_recursive(HashTable *ht);

PHPAPI bool php_array_data_shuffle(php_random_algo_with_state engine, zval *array);
Expand Down
32 changes: 32 additions & 0 deletions ext/standard/tests/array/count_recursive_stack_limit.phpt
Original file line number Diff line number Diff line change
@@ -0,0 +1,32 @@
--TEST--
Stack overflow in count() with COUNT_RECURSIVE and deeply nested arrays
--SKIPIF--
<?php
if (ini_get('zend.max_allowed_stack_size') === false) {
die('skip No stack limit support');
}
if (getenv('SKIP_ASAN')) {
die('skip ASAN needs different stack limit setting due to more stack space usage');
}
?>
--INI--
zend.max_allowed_stack_size=256K
--FILE--
<?php
/* Two elements per nesting level: the sibling must not be visited once the
* stack limit error has been thrown, so only one Error is thrown. */
$a = [];
for ($i = 0; $i < 30000; $i++) {
$a = [$a, []];
}

try {
count($a, COUNT_RECURSIVE);
} catch (Throwable $e) {
echo $e::class, ": ", $e->getMessage(), "\n";
var_dump($e->getPrevious());
}
?>
--EXPECTF--
Error: Maximum call stack size of %d bytes (zend.max_allowed_stack_size - zend.reserved_stack_size) reached. Infinite recursion?
NULL
Loading