Bug #61046 [Com]: Segfault when memory limit is hit while copying hash table

From: Date: Wed, 08 Jan 2014 15:20:02 +0000
Subject: Bug #61046 [Com]: Segfault when memory limit is hit while copying hash table
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-183647@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=61046&edit=1

 ID:                 61046
 Comment by:         info at ihead dot ru
 Reported by:        nikic@php.net
 Summary:            Segfault when memory limit is hit while copying hash
                     table
 Status:             No Feedback
 Type:               Bug
 Package:            Reproducible crash
 PHP Version:        5.4.0RC7
 Assigned To:        laruence
 Block user comment: N
 Private report:     N

 New Comment:

The patch https://bugs.php.net/patch-display.php?bug=61046&patch=bug61046.patch&revision=1356016047
makes the segfault disappear.


Previous Comments:
------------------------------------------------------------------------
[2014-01-08 13:43:11] info at ihead dot ru

The bug is reproducable on
PHP version 5.4.23, 5.3.28
OS: FreeBSD 9.2 amd64
memory_limit=32M

function byRef(&$ref) {}

$array = array_fill(0, 200000, '*');
$ref = $array;

byRef($array);

------------------------------------------------------------------------
[2013-02-18 00:35:40] php-bugs at lists dot php dot net

No feedback was provided. The bug is being suspended because
we assume that you are no longer experiencing the problem.
If this is not the case and you are able to provide the
information that was requested earlier, please do so and
change the status of the bug back to "Open". Thank you.

------------------------------------------------------------------------
[2012-12-20 15:28:22] laruence@php.net

another way to fix this is promote the ht point assignment in ctor(list blow), 
but there is still a chance that alloc failed when try to alloc memory for ht.

so I still think the fix I attached is the better one.

diff --git a/Zend/zend_variables.c b/Zend/zend_variables.c
index 25a66a1..bb6927a 100644
--- a/Zend/zend_variables.c
+++ b/Zend/zend_variables.c
@@ -134,9 +134,9 @@ ZEND_API void _zval_copy_ctor_func(zval *zvalue 
ZEND_FILE_LINE_DC)
 					return; /* do nothing */
 				}
 				ALLOC_HASHTABLE_REL(tmp_ht);
+				zvalue->value.ht = tmp_ht;
 				zend_hash_init(tmp_ht, 
zend_hash_num_elements(original_ht), NULL, ZVAL_PTR_DTOR, 0);
 				zend_hash_copy(tmp_ht, original_ht, 
(copy_ctor_func_t) zval_add_ref, (void *) &tmp, sizeof(zval *));
-				zvalue->value.ht = tmp_ht;
 			}
 			break;
 		case IS_OBJECT:

------------------------------------------------------------------------
[2012-12-20 15:08:30] laruence@php.net

quick fix attached, could you please verify it?

------------------------------------------------------------------------
[2012-12-20 15:07:27] laruence@php.net

The following patch has been added/updated:

Patch Name: bug61046.patch
Revision:   1356016047
URL:        https://bugs.php.net/patch-display.php?bug=61046&patch=bug61046.patch&revision=1356016047

------------------------------------------------------------------------


The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at

    https://bugs.php.net/bug.php?id=61046


-- 
Edit this bug report at https://bugs.php.net/bug.php?id=61046&edit=1


Thread (13 messages)

« previous php.bugs (#183647) next »