Bug #65969 [PATCH]: Chain assignment with T_LIST failure

From: Date: Wed, 27 Nov 2013 06:32:02 +0000
Subject: Bug #65969 [PATCH]: Chain assignment with T_LIST failure
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-182957@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=65969&edit=1 ID: 65969 Patch added by: laruence@php.net Reported by: mwelinder at gmail dot com Summary: Chain assignment with T_LIST failure Status: Verified Type: Bug Package: Variables related Operating System: linux mint 15 PHP Version: 5.4.21 Assigned To: dmitry Block user comment: N Private report: N New Comment: The following patch has been added/updated: Patch Name: bug65969.patch Revision: 1385533921 URL: https://bugs.php.net/patch-display.php?bug=65969&patch=bug65969.patch&revision=1385533921 Previous Comments: ------------------------------------------------------------------------ [2013-11-27 05:39:37] laruence@php.net The following patch has been added/updated: Patch Name: bug65969.phpt Revision: 1385530777 URL: https://bugs.php.net/patch-display.php?bug=65969&patch=bug65969.phpt&revision=1385530777 ------------------------------------------------------------------------ [2013-11-27 05:36:13] laruence@php.net Dmitry, could you please look into the patch I attached? thanks ------------------------------------------------------------------------ [2013-11-27 05:35:49] laruence@php.net The following patch has been added/updated: Patch Name: bug65969.patch Revision: 1385530548 URL: https://bugs.php.net/patch-display.php?bug=65969&patch=bug65969.patch&revision=1385530548 ------------------------------------------------------------------------ [2013-11-26 19:09:10] requinix@php.net Related To: Bug #66181 ------------------------------------------------------------------------ [2013-10-29 20:17:25] nikic@php.net Reduced testcase: <?php $obj = new stdClass; list($a) = $obj->prop = [1]; Valgrind output with ZMM=0: ==7793== Conditional jump or move depends on uninitialised value(s) ==7793== at 0x826493D: _get_zval_ptr_ptr_var (zend_execute.c:378) ==7793== by 0x8283546: ZEND_FETCH_DIM_R_SPEC_VAR_CONST_HANDLER (zend_vm_execute.h:12886) ==7793== by 0x8267F96: execute (zend_vm_execute.h:410) ==7793== by 0x8234E54: zend_execute_scripts (zend.c:1319) ==7793== by 0x81B9E8E: php_execute_script (main.c:2502) ==7793== by 0x82C773C: do_cli (php_cli.c:989) ==7793== by 0x82C8998: main (php_cli.c:1365) ==7793== ==7793== Use of uninitialised value of size 4 ==7793== at 0x82673A5: zend_fetch_dimension_address_read (zend_execute.c:1253) ==7793== by 0x8283580: ZEND_FETCH_DIM_R_SPEC_VAR_CONST_HANDLER (zend_vm_execute.h:12887) ==7793== by 0x8267F96: execute (zend_vm_execute.h:410) ==7793== by 0x8234E54: zend_execute_scripts (zend.c:1319) ==7793== by 0x81B9E8E: php_execute_script (main.c:2502) ==7793== by 0x82C773C: do_cli (php_cli.c:989) ==7793== by 0x82C8998: main (php_cli.c:1365) ==7793== ==7793== Invalid read of size 4 ==7793== at 0x82673A5: zend_fetch_dimension_address_read (zend_execute.c:1253) ==7793== by 0x8283580: ZEND_FETCH_DIM_R_SPEC_VAR_CONST_HANDLER (zend_vm_execute.h:12887) ==7793== by 0x8267F96: execute (zend_vm_execute.h:410) ==7793== by 0x8234E54: zend_execute_scripts (zend.c:1319) ==7793== by 0x81B9E8E: php_execute_script (main.c:2502) ==7793== by 0x82C773C: do_cli (php_cli.c:989) ==7793== by 0x82C8998: main (php_cli.c:1365) ==7793== Address 0x0 is not stack'd, malloc'd or (recently) free'd ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=65969 -- Edit this bug report at https://bugs.php.net/bug.php?id=65969&edit=1

« previous php.bugs (#182957) next »