#43175 [Ver]: __destruct() with __call() causes segfault
| From: | jani@php.net | Date: | Thu, 01 Nov 2007 17:26:02 +0000 |
| Subject: | #43175 [Ver]: __destruct() with __call() causes segfault | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-119220@lists.php.net to get a copy of this message | ||
ID: 43175
Updated by: jani@php.net
Reported By: development at domain51 dot com
Status: Verified
-Bug Type: *General Issues
+Bug Type: Scripting Engine problem
Operating System: *
PHP Version: 5CVS,6CVS (2007-11-01)
New Comment:
Simplest script to reproduce:
<?php
class foobar {
public function __destruct() {
throw new Exception();
}
public function __call($m, $a) {
return $this;
}
public static function factory() {
return new foobar();
}
}
function foobar() {
return new foobar();
}
try {
foobar::factory()->unknown();
} catch (Exception $e) {
echo "__call via traditional factory should be caught\n";
}
?>
Program received signal SIGSEGV, Segmentation fault.
0x082fe66d in add_assoc_string_ex (arg=0x95f0484, key=0x85d8db2
"function", key_len=9, str=0x7 <Address 0x7 out of bounds>,
duplicate=1)
at /home/jani/src/php-5.3/Zend/zend_API.c:1147
1147 ZVAL_STRING(tmp, str, duplicate);
(gdb) bt
#0 0x082fe66d in add_assoc_string_ex (arg=0x95f0484, key=0x85d8db2
"function", key_len=9, str=0x7 <Address 0x7 out of bounds>,
duplicate=1)
at /home/jani/src/php-5.3/Zend/zend_API.c:1147
#1 0x08310cb1 in zend_fetch_debug_backtrace (return_value=0x95f21a4,
skip_last=-1, provide_object=0)
at /home/jani/src/php-5.3/Zend/zend_builtin_functions.c:2026
.
.
Previous Comments:
------------------------------------------------------------------------
[2007-11-01 17:17:41] jani@php.net
I noticed you try to throw in destructor and that's not supposed to
work. See page: http://docs.php.net/manual/en/language.oop5.decon.php
"Note: Attempting to throw an exception from a destructor (called in
the time of script termination) causes a fatal error. "
Of course it shouldn't cause any crash though. :)
------------------------------------------------------------------------
[2007-11-01 15:27:51] development at domain51 dot com
Description:
------------
If __destruct() throws an exception on an object that was not assigned
to a variable, but had __call() invoked, it will segfault
Reproduce code:
---------------
Full test case available at:
http://plumb.domain51.com/sandbox/__destruct-bug/bug.phpt
http://plumb.domain51.com/sandbox/__destruct-bug/bug.phps
(syntax
highlighted)
Simplified sample:
foobar::factory()>unknown();
foobar()->unknown(); // where foobar is a function wrapping new foobar
Expected result:
----------------
Exception to be thrown in foobar::__destruct()
Actual result:
--------------
Segfault on Linux
Bus error on Mac OSX
I'll get a backtrace added later as time allows
------------------------------------------------------------------------
--
Edit this bug report at http://bugs.php.net/?id=43175&edit=1