Edit report at https://bugs.php.net/bug.php?id=61046&edit=1
ID: 61046
Comment by: info at ihead dot ru
Reported by: nikic@php.net
Summary: Segfault when memory limit is hit while copying hash
table
Status: No Feedback
Type: Bug
Package: Reproducible crash
PHP Version: 5.4.0RC7
Assigned To: laruence
Block user comment: N
Private report: N
New Comment:
The patch https://bugs.php.net/patch-display.php?bug=61046&patch=bug61046.patch&revision=1356016047
makes the segfault disappear.
Previous Comments:
------------------------------------------------------------------------
[2014-01-08 13:43:11] info at ihead dot ru
The bug is reproducable on
PHP version 5.4.23, 5.3.28
OS: FreeBSD 9.2 amd64
memory_limit=32M
function byRef(&$ref) {}
$array = array_fill(0, 200000, '*');
$ref = $array;
byRef($array);
------------------------------------------------------------------------
[2013-02-18 00:35:40] php-bugs at lists dot php dot net
No feedback was provided. The bug is being suspended because
we assume that you are no longer experiencing the problem.
If this is not the case and you are able to provide the
information that was requested earlier, please do so and
change the status of the bug back to "Open". Thank you.
------------------------------------------------------------------------
[2012-12-20 15:28:22] laruence@php.net
another way to fix this is promote the ht point assignment in ctor(list blow),
but there is still a chance that alloc failed when try to alloc memory for ht.
so I still think the fix I attached is the better one.
diff --git a/Zend/zend_variables.c b/Zend/zend_variables.c
index 25a66a1..bb6927a 100644
--- a/Zend/zend_variables.c
+++ b/Zend/zend_variables.c
@@ -134,9 +134,9 @@ ZEND_API void _zval_copy_ctor_func(zval *zvalue
ZEND_FILE_LINE_DC)
return; /* do nothing */
}
ALLOC_HASHTABLE_REL(tmp_ht);
+ zvalue->value.ht = tmp_ht;
zend_hash_init(tmp_ht,
zend_hash_num_elements(original_ht), NULL, ZVAL_PTR_DTOR, 0);
zend_hash_copy(tmp_ht, original_ht,
(copy_ctor_func_t) zval_add_ref, (void *) &tmp, sizeof(zval *));
- zvalue->value.ht = tmp_ht;
}
break;
case IS_OBJECT:
------------------------------------------------------------------------
[2012-12-20 15:08:30] laruence@php.net
quick fix attached, could you please verify it?
------------------------------------------------------------------------
[2012-12-20 15:07:27] laruence@php.net
The following patch has been added/updated:
Patch Name: bug61046.patch
Revision: 1356016047
URL: https://bugs.php.net/patch-display.php?bug=61046&patch=bug61046.patch&revision=1356016047
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=61046
--
Edit this bug report at https://bugs.php.net/bug.php?id=61046&edit=1