#39576 [Opn->Fbk]: Segfault on array_intersect
| From: | johannes@php.net | Date: | Wed, 22 Nov 2006 01:00:59 +0000 |
| Subject: | #39576 [Opn->Fbk]: Segfault on array_intersect | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-105276@lists.php.net to get a copy of this message | ||
ID: 39576
Updated by: johannes@php.net
Reported By: php at seven dot net dot nz
-Status: Open
+Status: Feedback
Bug Type: Reproducible crash
Operating System: Linux
PHP Version: 5.2.0
New Comment:
Not enough information was provided for us to be able
to handle this bug. Please re-read the instructions at
http://bugs.php.net/how-to-report.php
If you can provide more information, feel free to add it
to this bug and change the status back to "Open".
Thank you for your interest in PHP.
We really need a proper reproduce case showing the bug.
Previous Comments:
------------------------------------------------------------------------
[2006-11-22 00:26:43] php at seven dot net dot nz
Description:
------------
When intersecting 2 arrays, PHP segfaults.
The first array is the contents of get_object_vars ($this), the second
is a key => object pair.
This does not reproduce the bug, but this is what the code looks like.
Setting up the environment to reproduce it will take some time (objects
returned by a database etc), so I'll only do it if necessary
Reproduce code:
---------------
<?php
class Test {
function run () {
$c = array_intersect_key (
get_object_vars ($this),
$this->columns
);
print_r ($c);
}
}
class Test2 {}
$test = new Test;
$test->columns = array ('id' => new Test2);
$test->id = '1';
$test->run ();
?>
Expected result:
----------------
Array ( [id] => 1 )
Actual result:
--------------
Program received signal SIGSEGV, Segmentation fault.
[Switching to Thread -1215007056 (LWP 21112)]
0xb765ab06 in zend_hash_del_key_or_index (ht=0xb6c47e44,
arKey=0xb6c7e828 "", nKeyLength=1, h=3445614760, flag=0) at
/root/php-5.2.0/Zend/zend_hash.c:462
462 p = ht->arBuckets[nIndex];
(gdb) bt
#0 0xb765ab06 in zend_hash_del_key_or_index (ht=0xb6c47e44,
arKey=0xb6c7e828 "", nKeyLength=1, h=3445614760, flag=0)
at /root/php-5.2.0/Zend/zend_hash.c:462
#1 0xb759b96c in php_array_intersect (ht=2, return_value=0xb6c7ee74,
return_value_ptr=<value optimized out>, this_ptr=0x0,
return_value_used=1,
behavior=<value optimized out>, data_compare_type=0,
key_compare_type=0) at /root/php-5.2.0/ext/standard/array.c:3135
#2 0xb766b6b3 in zend_do_fcall_common_helper_SPEC
(execute_data=0xbfd50820) at
/root/php-5.2.0/Zend/zend_vm_execute.h:200
#3 0xb76697cb in execute (op_array=0xb6c56bec) at
/root/php-5.2.0/Zend/zend_vm_execute.h:92
#4 0xb766b236 in zend_do_fcall_common_helper_SPEC
(execute_data=0xbfd509a0) at
/root/php-5.2.0/Zend/zend_vm_execute.h:234
#5 0xb76697cb in execute (op_array=0xb6c1a474) at
/root/php-5.2.0/Zend/zend_vm_execute.h:92
#6 0xb766b236 in zend_do_fcall_common_helper_SPEC
(execute_data=0xbfd50ed0) at
/root/php-5.2.0/Zend/zend_vm_execute.h:234
#7 0xb76697cb in execute (op_array=0xb6c8144c) at
/root/php-5.2.0/Zend/zend_vm_execute.h:92
#8 0xb766ecdd in ZEND_INCLUDE_OR_EVAL_SPEC_TMP_HANDLER
(execute_data=0xbfd527a0) at
/root/php-5.2.0/Zend/zend_vm_execute.h:4572
#9 0xb76697cb in execute (op_array=0xb6c71574) at
/root/php-5.2.0/Zend/zend_vm_execute.h:92
#10 0xb76510af in zend_execute_scripts (type=8, retval=0x80,
file_count=3) at /root/php-5.2.0/Zend/zend.c:1097
#11 0xb7615afa in php_execute_script (primary_file=0xbfd54ac8) at
/root/php-5.2.0/main/main.c:1758
#12 0xb76d2711 in php_handler (r=0x84ab238) at
/root/php-5.2.0/sapi/apache2handler/sapi_apache2.c:592
#13 0x08078709 in ap_run_handler ()
#14 0x0807b8b1 in ap_invoke_handler ()
#15 0x0806a42c in ap_internal_redirect ()
#16 0xb79433c5 in ?? () from /usr/lib/apache2/modules/mod_rewrite.so
#17 0x084ab228 in ?? ()
#18 0x084a2978 in ?? ()
#19 0xb7944da7 in ?? () from /usr/lib/apache2/modules/mod_rewrite.so
#20 0x084a36c8 in ?? ()
#21 0x00000000 in ?? ()
------------------------------------------------------------------------
--
Edit this bug report at http://bugs.php.net/?id=39576&edit=1