#43121 [Csd]: gdImageFill with IMG_COLOR_TILED crashes httpd

From: Date: Mon, 05 Nov 2007 11:56:24 +0000
Subject: #43121 [Csd]: gdImageFill with IMG_COLOR_TILED crashes httpd
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-119282@lists.php.net to get a copy of this message
ID: 43121 User updated by: carlosp at ravenna dot com Reported By: carlosp at ravenna dot com Status: Closed Bug Type: GD related Operating System: FreeBSD 6.2 PHP Version: 5.2.5RC1 Assigned To: mattias New Comment: I confirmed the bug fix in 5.2-dev snapshot. Thank you! Previous Comments: ------------------------------------------------------------------------ [2007-11-04 23:58:44] mattias@php.net This bug has been fixed in CVS. Snapshots of the sources are packaged every three hours; this change will be in the next snapshot. You can grab the snapshot at http://snaps.php.net/. Thank you for the report, and for helping us make PHP better. ------------------------------------------------------------------------ [2007-10-29 02:13:32] carlosp at ravenna dot com For what it's worth, I first experienced a similar segfault on my Mac OS X version (5.2.4 Liyanage/Entropy package). I moved my script to my FreeBSD box running older 5.1.4 and the problem went away. I was ready to dismiss it until it manifested itself on another server with the fresh 5.2.4 install. Further troubleshooting revealed it was still failing on 5.2.5RC1 but not 5.2.3. If necessary, I'll figure out how to test a CVS version, let me know. ------------------------------------------------------------------------ [2007-10-28 22:57:11] scottmac@php.net [Switching to Thread -1208927680 (LWP 19371)] 0x0814d151 in php_gd__gdImageFillTiled (im=0xa3efeec, x=0, y=16843101, nc=2) at /usr/local/src/php5.2-200710150630/ext/gd/libgd/gd.c:2083 2083 for (x=x1; x>=0 && (!pts[y + x*wx2] && gdImageGetPixel(im,x,y)==oc); x--) { (gdb) bt full #0 0x0814d151 in php_gd__gdImageFillTiled (im=0xa3efeec, x=0, y=16843101, nc=2) at /usr/local/src/php5.2-200710150630/ext/gd/libgd/gd.c:2083 l = 102 x1 = 0 x2 = 99 dy = 1 oc = 0 tiled = 1 wx2 = 200 wy2 = 100 stack = (struct seg *) 0xa4080d4 sp = (struct seg *) 0xa408294 pts = 0xa403284 '\001' <repeats 13 times> #1 0x0814ca2e in php_gd_gdImageFill (im=0xa3efeec, x=0, y=0, nc=-5) at /usr/local/src/php5.2-200710150630/ext/gd/libgd/gd.c:1972 l = 0 x1 = 84 x2 = 84 dy = 20 oc = 171900652 wx2 = -1076818088 wy2 = 9 alphablending_bak = 0 stack = (struct seg *) 0x0 sp = (struct seg *) 0x4 #2 0x08141f69 in zif_imagefill (ht=4, return_value=0xa3fd9d0, return_value_ptr=0x0, this_ptr=0x0, return_value_used=0, tsrm_ls=0xa254050) at /usr/local/src/php5.2-200710150630/ext/gd/gd.c:3612 IM = (zval **) 0xa3e2ea8 x = (zval **) 0xa3e2eac y = (zval **) 0xa3e2eb0 col = (zval **) 0xa3e2eb4 im = (gdImagePtr) 0xa3efeec From a build last week that I had, I can't reproduce on 2.1.0 here. ------------------------------------------------------------------------ [2007-10-28 22:34:00] pajoye@php.net Assign to Mattias, he will take a look at what I broke since 5.2.3 :) ------------------------------------------------------------------------ [2007-10-28 22:08:55] pajoye@php.net It is weird, nothing in the imagefill code changed between 5.2.4 and 5.2.5RC. Can you provide a backtrace please? ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at http://bugs.php.net/43121 -- Edit this bug report at http://bugs.php.net/?id=43121&edit=1

« previous php.bugs (#119282) next »