Bug #66127 [Asn->Csd]: Segmentation fault with ArrayObject unset

From: Date: Wed, 11 Jun 2014 06:21:44 +0000
Subject: Bug #66127 [Asn->Csd]: Segmentation fault with ArrayObject unset
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-186150@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=66127&edit=1 ID: 66127 Updated by: stas@php.net Reported by: webm4st0r at gmail dot com Summary: Segmentation fault with ArrayObject unset -Status: Assigned +Status: Closed Type: Bug Package: Reproducible crash Operating System: CentOS confirmed PHP Version: 5.5.6 Assigned To: stas Block user comment: N Private report: N New Comment: Automatic comment on behalf of stas Revision: http://git.php.net/?p=php-src.git;a=commit;h=317bcb96d01a1dade28f2875bdd9bbbf73a40160 Log: Fix bug #66127 (Segmentation fault with ArrayObject unset) Previous Comments: ------------------------------------------------------------------------ [2014-06-10 19:29:41] arjen at react dot com Your patch fixes the reported issue, however it introduces a regression in ext/spl/tests/iterator_035.phpt --TEST-- SPL: ArrayIterator and values assigned by reference --FILE-- <?php $tmp = 1; $a = new ArrayIterator(); $a[] = $tmp; $a[] = &$tmp; echo "Done\n"; ?> --EXPECTF-- Fatal error: Cannot assign by reference to overloaded object in %s on line %d The expected fatal error isn't triggered. ------------------------------------------------------------------------ [2014-06-08 22:41:33] stas@php.net Proposed fix: diff --git a/ext/spl/spl_array.c b/ext/spl/spl_array.c index 34f3a38..758947a 100644 --- a/ext/spl/spl_array.c +++ b/ext/spl/spl_array.c @@ -402,7 +402,7 @@ static zval *spl_array_read_dimension_ex(int check_inherited, zval *object, zval /* When in a write context, * ZE has to be fooled into thinking this is in a reference set * by separating (if necessary) and returning as an is_ref=1 zval (even if refcount == 1) */ - if ((type == BP_VAR_W || type == BP_VAR_RW || type == BP_VAR_UNSET) && !Z_ISREF_PP(ret)) { + if ((type == BP_VAR_W || type == BP_VAR_RW || type == BP_VAR_UNSET) && !Z_ISREF_PP(ret) && ret != &EG(uninitialized_zval_ptr)) { if (Z_REFCOUNT_PP(ret) > 1) { zval *newval; Please check if it works for you. ------------------------------------------------------------------------ [2014-06-08 00:16:43] rasmus@php.net Here is the Valgrind memcheck output for this: https://gist.github.com/anonymous/3d813b987629d0eb6022 This is from a PHP-5.6-dev checkout from today. Basically we are accessing memory that has already been free'ed here. ------------------------------------------------------------------------ [2014-06-05 11:15:49] arjen at react dot com Still crashes: 5.4.13 - 5.6.0beta3 http://3v4l.org/j4GdO ------------------------------------------------------------------------ [2013-11-22 04:54:20] laruence@php.net @Stas, could you please look into this? ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=66127 -- Edit this bug report at https://bugs.php.net/bug.php?id=66127&edit=1

« previous php.bugs (#186150) next »