Bug #66751 [Com]: php_strip_whitespace causes segmentation fault

From: Date: Wed, 05 Mar 2014 01:07:11 +0000
Subject: Bug #66751 [Com]: php_strip_whitespace causes segmentation fault
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-184522@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=66751&edit=1 ID: 66751 Comment by: cidsphere at gmail dot com Reported by: yu at hoaxster dot net Summary: php_strip_whitespace causes segmentation fault Status: Open Type: Bug Package: *General Issues Operating System: OS X Mavericks PHP Version: 5.6.0alpha2 Block user comment: N Private report: N New Comment: I can reproduce this bug in php-5.6.0alpha3 on Ubuntu 13.10 with PHP compiled from source. The function php_strip_whitespace is used in Composer to generate autoload file. I find it impossible to use Composer because of this bug. Previous Comments: ------------------------------------------------------------------------ [2014-02-24 19:54:36] krakjoe@php.net This is a bit strange ... diff --git a/Zend/zend_highlight.c b/Zend/zend_highlight.c index e4f8d02..b961104 100644 --- a/Zend/zend_highlight.c +++ b/Zend/zend_highlight.c @@ -211,7 +211,8 @@ ZEND_API void zend_strip(TSRMLS_D) break; default: - efree(token.value.str.val); + if (token.value.str.len) + efree(token.value.str.val); break; } } You wouldn't think this is necessary, so I won't submit this as a patch ... Just a note really, I couldn't make this segfault but there is a call to efree an invalid pointer. /me leaves this for someone else who has more of a clue ... ------------------------------------------------------------------------ [2014-02-21 12:01:16] yu at hoaxster dot net Description: ------------ php_strip_whitespace causes segmentation fault while parsing __CLASS__. Test script: --------------- # cat test.php <?php __CLASS__ ?> # php -r 'php_strip_whitespace(getcwd()."/test.php");' Actual result: -------------- [Fri Feb 21 20:57:50 2014] Script: '-' --------------------------------------- /var/tmp/php-build/source/5.6.0alpha2/Zend/zend_highlight.c(214) : Block 0x10781c048 status: Invalid pointer: ((size=0x0002b5a5) != (next.prev=0x444d4f4400000001)) Invalid pointer: ((prev=0x00000001) != (prev.size=0x0002b5a5)) ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=66751&edit=1

« previous php.bugs (#184522) next »