Perl / perl5

🐪 The Perl programming language
https://dev.perl.org/perl5/
Other
1.91k stars 542 forks source link

Assertion failure in Perl_newATTRSUB_x (op.c:10342) #16868

Open p5pRT opened 5 years ago

p5pRT commented 5 years ago

Migrated from rt.perl.org#133887 (status was 'new')

Searchable as RT133887$

p5pRT commented 5 years ago

From @dur-randir

Created by @dur-randir

While fuzzing perl v5.29.8-21-gde59f38ed9 built with afl and run under libdislocator\, I found the following program

use strict;END{{{{}}}}{END}END{e}

to cause an assertion failure​:

perl​: op.c​:10342​: CV *Perl_newATTRSUB_x(I32\, OP *\, OP *\, OP *\, OP *\, _Bool)​: Assertion `!cv || evanescent || SvREFCNT((SV*)cv) != 0' failed.

GDB stack trace is following​:

#0 __GI_raise (sig=sig@​entry=6) at ../sysdeps/unix/sysv/linux/raise.c​:50 #1 0x00007ffff7c25535 in __GI_abort () at abort.c​:79 #2 0x00007ffff7c2540f in __assert_fail_base (fmt=0x7ffff7d87ee0 "%s%s%s​:%u​: %s%sAssertion `%s' failed.\n%n"\,   assertion=0x555555914b58 "!cv || evanescent || SvREFCNT((SV*)cv) != 0"\, file=0x55555590f7ae "op.c"\, line=10342\, function=\<optimized out>) at assert.c​:92 #3 0x00007ffff7c330f2 in __GI___assert_fail (assertion=0x555555914b58 "!cv || evanescent || SvREFCNT((SV*)cv) != 0"\, file=0x55555590f7ae "op.c"\,   line=10342\, function=0x555555917750 \<__PRETTY_FUNCTION__.21155> "Perl_newATTRSUB_x") at assert.c​:101 #4 0x00005555555b981c in Perl_newATTRSUB_x (floor=49\, o=0x555555b51af8\, proto=0x0\, attrs=0x0\, block=0x555555b51ce8\, o_is_gv=false) at op.c​:10342 #5 0x0000555555659cd8 in Perl_yyparse (gramtype=258) at perly.y​:289 #6 0x00005555555d92ea in S_parse_body (env=0x0\, xsinit=0x55555558e1d8 \<xs_init>) at perl.c​:2507 #7 0x00005555555d75bc in perl_parse (my_perl=0x555555b24260\, xsinit=0x55555558e1d8 \<xs_init>\, argc=4\, argv=0x7fffffffe1a8\, env=0x0) at perl.c​:1798 #8 0x000055555558e11b in main (argc=4\, argv=0x7fffffffe1a8\, env=0x7fffffffe1d0) at perlmain.c​:126

This is a regression between 5.20 and 5.22\, bisect points to

commit a70f21d0d169a526a6bafd2465e01e1ca8d16234 Author​: Father Chrysostomos \sprout@&#8203;cpan\.org Date​: Mon Dec 8 21​:59​:22 2014 -0800

  Fix OUTSIDE for named subs inside predeclared subs

Perl Info ``` Flags: category=core severity=low Site configuration information for perl 5.29.9: Configured by dur-randir at Wed Feb 27 14:51:01 MSK 2019. Summary of my perl5 (revision 5 version 29 subversion 9) configuration: Commit id: c1e47bad34ce1d9c84ed57c9b8978bcbd5a02e98 Platform: osname=darwin osvers=13.4.0 archname=darwin-thread-multi-2level uname='darwin isengard.local 13.4.0 darwin kernel version 13.4.0: mon jan 11 18:17:34 pst 2016; root:xnu-2422.115.15~1release_x86_64 x86_64 ' config_args='-de -Dusedevel -DDEBUGGING -Dusethreads' hint=recommended useposix=true d_sigaction=define useithreads=define usemultiplicity=define use64bitint=define use64bitall=define uselongdouble=undef usemymalloc=n default_inc_excludes_dot=define bincompat5005=undef Compiler: cc='cc' ccflags ='-fno-common -DPERL_DARWIN -mmacosx-version-min=10.9 -DDEBUGGING -fno-strict-aliasing -pipe -fstack-protector -I/usr/local/include -DPERL_USE_SAFE_PUTENV' optimize='-O3 -g' cppflags='-fno-common -DPERL_DARWIN -mmacosx-version-min=10.9 -DDEBUGGING -fno-strict-aliasing -pipe -fstack-protector -I/usr/local/include' ccversion='' gccversion='4.2.1 Compatible Apple LLVM 6.0 (clang-600.0.56)' gccosandvers='' intsize=4 longsize=8 ptrsize=8 doublesize=8 byteorder=12345678 doublekind=3 d_longlong=define longlongsize=8 d_longdbl=define longdblsize=16 longdblkind=3 ivtype='long' ivsize=8 nvtype='double' nvsize=8 Off_t='off_t' lseeksize=8 alignbytes=8 prototype=define Linker and Libraries: ld='cc' ldflags =' -mmacosx-version-min=10.9 -fstack-protector -L/usr/local/lib' libpth=/usr/local/lib /Applications/Xcode.app/Contents/Developer/Toolchains/XcodeDefault.xctoolchain/usr/bin/../lib/clang/6.0/lib /Applications/Xcode.app/Contents/Developer/Toolchains/XcodeDefault.xctoolchain/usr/lib /usr/lib libs=-lpthread -lgdbm -ldbm -ldl -lm -lutil -lc perllibs=-lpthread -ldl -lm -lutil -lc libc= so=dylib useshrplib=false libperl=libperl.a gnulibc_version='' Dynamic Linking: dlsrc=dl_dlopen.xs dlext=bundle d_dlsymun=undef ccdlflags=' ' cccdlflags=' ' lddlflags=' -mmacosx-version-min=10.9 -bundle -undefined dynamic_lookup -L/usr/local/lib -fstack-protector' @INC for perl 5.29.9: lib /usr/local/lib/perl5/site_perl/5.29.9/darwin-thread-multi-2level /usr/local/lib/perl5/site_perl/5.29.9 /usr/local/lib/perl5/5.29.9/darwin-thread-multi-2level /usr/local/lib/perl5/5.29.9 Environment for perl 5.29.9: DYLD_LIBRARY_PATH (unset) HOME=/Users/dur-randir LANG=en_US.UTF-8 LANGUAGE (unset) LD_LIBRARY_PATH (unset) LOGDIR (unset) PATH=/Users/dur-randir/perlbrew/bin:/Users/dur-randir/perlbrew/perls/perl-5.22.1/bin:/usr/local/bin:/usr/local/sbin:/usr/bin:/bin:/usr/sbin:/sbin:/usr/texbin PERLBREW_HOME=/Users/dur-randir/.perlbrew PERLBREW_MANPATH=/Users/dur-randir/perlbrew/perls/perl-5.22.1/man PERLBREW_PATH=/Users/dur-randir/perlbrew/bin:/Users/dur-randir/perlbrew/perls/perl-5.22.1/bin PERLBREW_PERL=perl-5.22.1 PERLBREW_ROOT=/Users/dur-randir/perlbrew PERLBREW_SHELLRC_VERSION=0.84 PERLBREW_VERSION=0.84 PERL_BADLANG (unset) SHELL=/usr/local/bin/zsh ```