Bug #55130 [Opn->Fbk]: Php engine crash on $node = clone (($condition) ? $oneNode : $theOtherNode);

From: Date: Mon, 04 Jul 2011 23:12:27 +0000
Subject: Bug #55130 [Opn->Fbk]: Php engine crash on $node = clone (($condition) ? $oneNode : $theOtherNode);
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-161585@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=55130&edit=1 ID: 55130 Updated by: felipe@php.net Reported by: ghostwik at gmail dot com Summary: Php engine crash on $node = clone (($condition) ? $oneNode : $theOtherNode); -Status: Open +Status: Feedback Type: Bug Package: Scripting Engine problem Operating System: Linux 2.6.39-ARCH x86_64 PHP Version: 5.3.6 Block user comment: N Private report: N New Comment: Thank you for this bug report. To properly diagnose the problem, we need a short but complete example script to be able to reproduce this bug ourselves. A proper reproducing script starts with <?php and ends with ?>, is max. 10-20 lines long and does not require any external resources such as databases, etc. If the script requires a database to demonstrate the issue, please make sure it creates all necessary tables, stored procedures etc. Please avoid embedding huge scripts into the report. Previous Comments: ------------------------------------------------------------------------ [2011-07-04 12:52:58] ghostwik at gmail dot com Description: ------------ PHP caused Segmentation fault probably on code $node = clone ($condition ? $DOMElement1 : $DOMElement2); Test script: --------------- // This piece of code actually loads some XML elements via xPath $firstNode = $domElement->getElementsByTagName( 'div')->item(0); $secondNode = $domElement->getElementsByTagName( 'div')->item(1); // The problematic line $node = clone ((rand()%2) ? $firstNode : $secondNode); // // After retyping code to: // $node = ((rand()%2) ? clone $firstNode : clone $secondNode); // // All started working just fine (maybe it's coincidence) Expected result: ---------------- One node is domElement for "thumb up" and the other node is domElement for "thumb down" (for product rating in e-shop), I've tried to create new html based on xml templates. Actual result: -------------- Mos of the time I got error 302 from server and proxy error or "Empty result" In log always repeated this: [Mon Jul 04 18:20:39 2011] [notice] child pid 5825 exit signal Segmentation fault (11) Sometimes: [Mon Jul 04 18:20:39 2011] [notice] child pid 5825 exit signal Segmentation fault (11) *** glibc detected *** /usr/sbin/httpd: double free or corruption (!prev): 0x0000000001980e20 *** ======= Backtrace: ========= /lib/libc.so.6(+0x7366a)[0x7f819f69166a] /lib/libc.so.6(cfree+0x6c)[0x7f819f69554c] /etc/httpd/modules/libphp5.so(php_libxml_node_decrement_resource+0x80) [0x7f8194c9b590] /etc/httpd/modules/libphp5.so(+0xf2c6f)[0x7f8194ca3c6f] /etc/httpd/modules/libphp5.so(zend_objects_store_del_ref_by_handle_ex+0x257) [0x7f8194e65167] /etc/httpd/modules/libphp5.so(zend_objects_store_del_ref+0x13)[0x7f8194e65183] /etc/httpd/modules/libphp5.so(_zval_ptr_dtor+0x41)[0x7f8194e32681] /etc/httpd/modules/libphp5.so(zend_hash_destroy+0x40)[0x7f8194e4dda0] /etc/httpd/modules/libphp5.so(_zval_dtor_func+0x7f)[0x7f8194e4009f] /etc/httpd/modules/libphp5.so(_zval_ptr_dtor+0x41)[0x7f8194e32681] /etc/httpd/modules/libphp5.so(+0xf2b7e)[0x7f8194ca3b7e] /etc/httpd/modules/libphp5.so(zend_objects_store_del_ref_by_handle_ex+0x23f) [0x7f8194e6514f] /etc/httpd/modules/libphp5.so(zend_objects_store_del_ref+0x13)[0x7f8194e65183] /etc/httpd/modules/libphp5.so(_zval_ptr_dtor+0x41)[0x7f8194e32681] /etc/httpd/modules/libphp5.so(+0x29b70e)[0x7f8194e4c70e] /etc/httpd/modules/libphp5.so(zend_hash_reverse_apply+0x71)[0x7f8194e4e241] /etc/httpd/modules/libphp5.so(+0x281a31)[0x7f8194e32a31] /etc/httpd/modules/libphp5.so(+0x28fd17)[0x7f8194e40d17] /etc/httpd/modules/libphp5.so(php_request_shutdown+0x33d)[0x7f8194deefcd] /etc/httpd/modules/libphp5.so(+0x323367)[0x7f8194ed4367] /usr/sbin/httpd(ap_run_handler+0x48)[0x438ad8] /usr/sbin/httpd(ap_invoke_handler+0xce)[0x438f3e] /usr/sbin/httpd(ap_process_request+0x190)[0x445d60] /usr/sbin/httpd[0x442d70] /usr/sbin/httpd(ap_run_process_connection+0x48)[0x43f0f8] /usr/sbin/httpd[0x44a22f] /usr/sbin/httpd[0x44a94c] /usr/sbin/httpd(ap_mpm_run+0x9d2)[0x44b4a2] /usr/sbin/httpd(main+0xb44)[0x424554] /lib/libc.so.6(__libc_start_main+0xed)[0x7f819f63f17d] /usr/sbin/httpd[0x424601] ======= Memory map: ======== 00400000-00460000 r-xp 00000000 fe:01 861362 /usr/sbin/httpd 0065f000-00664000 rw-p 0005f000 fe:01 861362 /usr/sbin/httpd 00664000-00667000 rw-p 00000000 00:00 0 01571000-04298000 rw-p 00000000 00:00 0 [heap] 7f818c000000-7f818c021000 rw-p 00000000 00:00 0 7f818c021000-7f8190000000 ---p 00000000 00:00 0 7f81914b1000-7f81914c6000 r-xp 00000000 fe:01 631049 /usr/lib/libgcc_s.so.1 ... And few hundreds of similar lines. On ArchLinux: extra/php 5.3.6-4 [installed] With: extension=gd.so extension=gettext.so extension=iconv.so extension=json.so extension=ldap.so extension=mcrypt.so extension=mysql.so extension=pdo_mysql.so extension=soap.so extension=sockets.so extension=tidy.so extension=xmlrpc.so ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=55130&edit=1

« previous php.bugs (#161585) next »