Bug #65969 [PATCH]: Chain assignment with T_LIST failure
| From: | laruence@php.net | Date: | Wed, 27 Nov 2013 06:32:02 +0000 |
| Subject: | Bug #65969 [PATCH]: Chain assignment with T_LIST failure | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-182957@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=65969&edit=1
ID: 65969
Patch added by: laruence@php.net
Reported by: mwelinder at gmail dot com
Summary: Chain assignment with T_LIST failure
Status: Verified
Type: Bug
Package: Variables related
Operating System: linux mint 15
PHP Version: 5.4.21
Assigned To: dmitry
Block user comment: N
Private report: N
New Comment:
The following patch has been added/updated:
Patch Name: bug65969.patch
Revision: 1385533921
URL: https://bugs.php.net/patch-display.php?bug=65969&patch=bug65969.patch&revision=1385533921
Previous Comments:
------------------------------------------------------------------------
[2013-11-27 05:39:37] laruence@php.net
The following patch has been added/updated:
Patch Name: bug65969.phpt
Revision: 1385530777
URL: https://bugs.php.net/patch-display.php?bug=65969&patch=bug65969.phpt&revision=1385530777
------------------------------------------------------------------------
[2013-11-27 05:36:13] laruence@php.net
Dmitry, could you please look into the patch I attached? thanks
------------------------------------------------------------------------
[2013-11-27 05:35:49] laruence@php.net
The following patch has been added/updated:
Patch Name: bug65969.patch
Revision: 1385530548
URL: https://bugs.php.net/patch-display.php?bug=65969&patch=bug65969.patch&revision=1385530548
------------------------------------------------------------------------
[2013-11-26 19:09:10] requinix@php.net
Related To: Bug #66181
------------------------------------------------------------------------
[2013-10-29 20:17:25] nikic@php.net
Reduced testcase:
<?php
$obj = new stdClass;
list($a) = $obj->prop = [1];
Valgrind output with ZMM=0:
==7793== Conditional jump or move depends on uninitialised value(s)
==7793== at 0x826493D: _get_zval_ptr_ptr_var (zend_execute.c:378)
==7793== by 0x8283546: ZEND_FETCH_DIM_R_SPEC_VAR_CONST_HANDLER (zend_vm_execute.h:12886)
==7793== by 0x8267F96: execute (zend_vm_execute.h:410)
==7793== by 0x8234E54: zend_execute_scripts (zend.c:1319)
==7793== by 0x81B9E8E: php_execute_script (main.c:2502)
==7793== by 0x82C773C: do_cli (php_cli.c:989)
==7793== by 0x82C8998: main (php_cli.c:1365)
==7793==
==7793== Use of uninitialised value of size 4
==7793== at 0x82673A5: zend_fetch_dimension_address_read (zend_execute.c:1253)
==7793== by 0x8283580: ZEND_FETCH_DIM_R_SPEC_VAR_CONST_HANDLER (zend_vm_execute.h:12887)
==7793== by 0x8267F96: execute (zend_vm_execute.h:410)
==7793== by 0x8234E54: zend_execute_scripts (zend.c:1319)
==7793== by 0x81B9E8E: php_execute_script (main.c:2502)
==7793== by 0x82C773C: do_cli (php_cli.c:989)
==7793== by 0x82C8998: main (php_cli.c:1365)
==7793==
==7793== Invalid read of size 4
==7793== at 0x82673A5: zend_fetch_dimension_address_read (zend_execute.c:1253)
==7793== by 0x8283580: ZEND_FETCH_DIM_R_SPEC_VAR_CONST_HANDLER (zend_vm_execute.h:12887)
==7793== by 0x8267F96: execute (zend_vm_execute.h:410)
==7793== by 0x8234E54: zend_execute_scripts (zend.c:1319)
==7793== by 0x81B9E8E: php_execute_script (main.c:2502)
==7793== by 0x82C773C: do_cli (php_cli.c:989)
==7793== by 0x82C8998: main (php_cli.c:1365)
==7793== Address 0x0 is not stack'd, malloc'd or (recently) free'd
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=65969
--
Edit this bug report at https://bugs.php.net/bug.php?id=65969&edit=1