Bug #66127 [Asn->Csd]: Segmentation fault with ArrayObject unset
| From: | stas@php.net | Date: | Wed, 11 Jun 2014 06:21:44 +0000 |
| Subject: | Bug #66127 [Asn->Csd]: Segmentation fault with ArrayObject unset | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-186150@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=66127&edit=1
ID: 66127
Updated by: stas@php.net
Reported by: webm4st0r at gmail dot com
Summary: Segmentation fault with ArrayObject unset
-Status: Assigned
+Status: Closed
Type: Bug
Package: Reproducible crash
Operating System: CentOS confirmed
PHP Version: 5.5.6
Assigned To: stas
Block user comment: N
Private report: N
New Comment:
Automatic comment on behalf of stas
Revision: http://git.php.net/?p=php-src.git;a=commit;h=317bcb96d01a1dade28f2875bdd9bbbf73a40160
Log: Fix bug #66127 (Segmentation fault with ArrayObject unset)
Previous Comments:
------------------------------------------------------------------------
[2014-06-10 19:29:41] arjen at react dot com
Your patch fixes the reported issue, however it introduces a regression in
ext/spl/tests/iterator_035.phpt
--TEST--
SPL: ArrayIterator and values assigned by reference
--FILE--
<?php
$tmp = 1;
$a = new ArrayIterator();
$a[] = $tmp;
$a[] = &$tmp;
echo "Done\n";
?>
--EXPECTF--
Fatal error: Cannot assign by reference to overloaded object in %s on line %d
The expected fatal error isn't triggered.
------------------------------------------------------------------------
[2014-06-08 22:41:33] stas@php.net
Proposed fix:
diff --git a/ext/spl/spl_array.c b/ext/spl/spl_array.c
index 34f3a38..758947a 100644
--- a/ext/spl/spl_array.c
+++ b/ext/spl/spl_array.c
@@ -402,7 +402,7 @@ static zval *spl_array_read_dimension_ex(int check_inherited, zval *object, zval
/* When in a write context,
* ZE has to be fooled into thinking this is in a reference set
* by separating (if necessary) and returning as an is_ref=1 zval (even if refcount == 1) */
- if ((type == BP_VAR_W || type == BP_VAR_RW || type == BP_VAR_UNSET) &&
!Z_ISREF_PP(ret)) {
+ if ((type == BP_VAR_W || type == BP_VAR_RW || type == BP_VAR_UNSET) &&
!Z_ISREF_PP(ret) && ret != &EG(uninitialized_zval_ptr)) {
if (Z_REFCOUNT_PP(ret) > 1) {
zval *newval;
Please check if it works for you.
------------------------------------------------------------------------
[2014-06-08 00:16:43] rasmus@php.net
Here is the Valgrind memcheck output for this:
https://gist.github.com/anonymous/3d813b987629d0eb6022
This is from a PHP-5.6-dev checkout from today.
Basically we are accessing memory that has already been free'ed here.
------------------------------------------------------------------------
[2014-06-05 11:15:49] arjen at react dot com
Still crashes: 5.4.13 - 5.6.0beta3
http://3v4l.org/j4GdO
------------------------------------------------------------------------
[2013-11-22 04:54:20] laruence@php.net
@Stas, could you please look into this?
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=66127
--
Edit this bug report at https://bugs.php.net/bug.php?id=66127&edit=1