Bug #55130 [Opn->Fbk]: Php engine crash on $node = clone (($condition) ? $oneNode : $theOtherNode);
| From: | felipe@php.net | Date: | Mon, 04 Jul 2011 23:12:27 +0000 |
| Subject: | Bug #55130 [Opn->Fbk]: Php engine crash on $node = clone (($condition) ? $oneNode : $theOtherNode); | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-161585@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=55130&edit=1
ID: 55130
Updated by: felipe@php.net
Reported by: ghostwik at gmail dot com
Summary: Php engine crash on $node = clone (($condition) ?
$oneNode : $theOtherNode);
-Status: Open
+Status: Feedback
Type: Bug
Package: Scripting Engine problem
Operating System: Linux 2.6.39-ARCH x86_64
PHP Version: 5.3.6
Block user comment: N
Private report: N
New Comment:
Thank you for this bug report. To properly diagnose the problem, we
need a short but complete example script to be able to reproduce
this bug ourselves.
A proper reproducing script starts with <?php and ends with ?>,
is max. 10-20 lines long and does not require any external
resources such as databases, etc. If the script requires a
database to demonstrate the issue, please make sure it creates
all necessary tables, stored procedures etc.
Please avoid embedding huge scripts into the report.
Previous Comments:
------------------------------------------------------------------------
[2011-07-04 12:52:58] ghostwik at gmail dot com
Description:
------------
PHP caused Segmentation fault probably on code
$node = clone ($condition ? $DOMElement1 : $DOMElement2);
Test script:
---------------
// This piece of code actually loads some XML elements via xPath
$firstNode = $domElement->getElementsByTagName( 'div')->item(0);
$secondNode = $domElement->getElementsByTagName( 'div')->item(1);
// The problematic line
$node = clone ((rand()%2) ? $firstNode : $secondNode);
// // After retyping code to:
// $node = ((rand()%2) ? clone $firstNode : clone $secondNode);
// // All started working just fine (maybe it's coincidence)
Expected result:
----------------
One node is domElement for "thumb up" and the other node is domElement for "thumb
down" (for product rating in e-shop), I've tried to create new html based on xml
templates.
Actual result:
--------------
Mos of the time I got error 302 from server and proxy error or "Empty result"
In log always repeated this:
[Mon Jul 04 18:20:39 2011] [notice] child pid 5825 exit signal Segmentation
fault (11)
Sometimes:
[Mon Jul 04 18:20:39 2011] [notice] child pid 5825 exit signal Segmentation
fault (11)
*** glibc detected *** /usr/sbin/httpd: double free or corruption (!prev):
0x0000000001980e20 ***
======= Backtrace: =========
/lib/libc.so.6(+0x7366a)[0x7f819f69166a]
/lib/libc.so.6(cfree+0x6c)[0x7f819f69554c]
/etc/httpd/modules/libphp5.so(php_libxml_node_decrement_resource+0x80)
[0x7f8194c9b590]
/etc/httpd/modules/libphp5.so(+0xf2c6f)[0x7f8194ca3c6f]
/etc/httpd/modules/libphp5.so(zend_objects_store_del_ref_by_handle_ex+0x257)
[0x7f8194e65167]
/etc/httpd/modules/libphp5.so(zend_objects_store_del_ref+0x13)[0x7f8194e65183]
/etc/httpd/modules/libphp5.so(_zval_ptr_dtor+0x41)[0x7f8194e32681]
/etc/httpd/modules/libphp5.so(zend_hash_destroy+0x40)[0x7f8194e4dda0]
/etc/httpd/modules/libphp5.so(_zval_dtor_func+0x7f)[0x7f8194e4009f]
/etc/httpd/modules/libphp5.so(_zval_ptr_dtor+0x41)[0x7f8194e32681]
/etc/httpd/modules/libphp5.so(+0xf2b7e)[0x7f8194ca3b7e]
/etc/httpd/modules/libphp5.so(zend_objects_store_del_ref_by_handle_ex+0x23f)
[0x7f8194e6514f]
/etc/httpd/modules/libphp5.so(zend_objects_store_del_ref+0x13)[0x7f8194e65183]
/etc/httpd/modules/libphp5.so(_zval_ptr_dtor+0x41)[0x7f8194e32681]
/etc/httpd/modules/libphp5.so(+0x29b70e)[0x7f8194e4c70e]
/etc/httpd/modules/libphp5.so(zend_hash_reverse_apply+0x71)[0x7f8194e4e241]
/etc/httpd/modules/libphp5.so(+0x281a31)[0x7f8194e32a31]
/etc/httpd/modules/libphp5.so(+0x28fd17)[0x7f8194e40d17]
/etc/httpd/modules/libphp5.so(php_request_shutdown+0x33d)[0x7f8194deefcd]
/etc/httpd/modules/libphp5.so(+0x323367)[0x7f8194ed4367]
/usr/sbin/httpd(ap_run_handler+0x48)[0x438ad8]
/usr/sbin/httpd(ap_invoke_handler+0xce)[0x438f3e]
/usr/sbin/httpd(ap_process_request+0x190)[0x445d60]
/usr/sbin/httpd[0x442d70]
/usr/sbin/httpd(ap_run_process_connection+0x48)[0x43f0f8]
/usr/sbin/httpd[0x44a22f]
/usr/sbin/httpd[0x44a94c]
/usr/sbin/httpd(ap_mpm_run+0x9d2)[0x44b4a2]
/usr/sbin/httpd(main+0xb44)[0x424554]
/lib/libc.so.6(__libc_start_main+0xed)[0x7f819f63f17d]
/usr/sbin/httpd[0x424601]
======= Memory map: ========
00400000-00460000 r-xp 00000000 fe:01 861362
/usr/sbin/httpd
0065f000-00664000 rw-p 0005f000 fe:01 861362
/usr/sbin/httpd
00664000-00667000 rw-p 00000000 00:00 0
01571000-04298000 rw-p 00000000 00:00 0 [heap]
7f818c000000-7f818c021000 rw-p 00000000 00:00 0
7f818c021000-7f8190000000 ---p 00000000 00:00 0
7f81914b1000-7f81914c6000 r-xp 00000000 fe:01 631049
/usr/lib/libgcc_s.so.1
...
And few hundreds of similar lines.
On ArchLinux:
extra/php 5.3.6-4 [installed]
With:
extension=gd.so
extension=gettext.so
extension=iconv.so
extension=json.so
extension=ldap.so
extension=mcrypt.so
extension=mysql.so
extension=pdo_mysql.so
extension=soap.so
extension=sockets.so
extension=tidy.so
extension=xmlrpc.so
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=55130&edit=1