#14582 [Opn->Csd]: Array key -1 can crash PHP
| From: | stas@php.net | Date: | Mon, 09 Sep 2002 14:42:11 +0000 |
| Subject: | #14582 [Opn->Csd]: Array key -1 can crash PHP | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-18796@lists.php.net to get a copy of this message | ||
ID: 14582
Updated by: stas@php.net
-Summary: initializing with NULL reference
-Reported By: zork@clan.pl
+Reported By: carl@thep.lu.se
-Status: Open
+Status: Closed
Bug Type: Scripting Engine problem
-Operating System: slackware linux 8.0
+Operating System: Linux
-PHP Version: 4.1.0
+PHP Version: 4.3.0-dev
New Comment:
This bug has been fixed in CVS.
In case this was a PHP problem, snapshots of the sources are packaged
every three hours; this change will be in the next snapshot. You can
grab the snapshot at http://snaps.php.net/.
In case this was a documentation problem, the fix will show up soon at
http://www.php.net/manual/.
In case this was a PHP.net website problem, the change will show
up on the PHP.net site and on the mirror sites in short time.
Thank you for the report, and for helping us make PHP better.
Though the leak is still there, but the bug itself (new returning NULL)
is gone.
Previous Comments:
------------------------------------------------------------------------
[2001-12-18 11:21:30] mfischer@php.net
Seems we've a leak here:
$ php -f 14582.php
NULL
object(cinput_select)(3) {
["values"]=>
array(0) {
}
["name"]=>
&array(0) {
}
["options"]=>
&array(0) {
}
}
./zend_execute.c(425) : Freeing 0x082FC964 (2 bytes),
script=14582.php
zend_variables.c(107) : Actual location (location was relayed)
I remember seeing another BR leeking at the same place when trying to
access arrays with constants but can't find it right now.
------------------------------------------------------------------------
[2001-12-18 11:11:07] zork@clan.pl
I've encountered stack problem. Here is simplest code, that reproduces
this:
<?php
class CForm {
var $inputs;
function Cform() {
$this -> inputs = array();
}
function &get_input($name) {
return($this -> inputs[$name]);
}
};
class Cinput_select {
var $values;
var $name;
function Cinput_select($t) {
$this -> name = $t;
$this -> options = array();
}
function add_value($value) {
$this -> values[] = $value;
}
};
$form = new CForm();
//coment next two lines and new returns NULL
$sel = new CInput_select("b");
$sel -> add_value("a");
$a =& $form -> get_input("a");
var_dump($a);
$sel = new CInput_select("test");
var_dump($sel);
$sel -> add_value("a");
?>
After call to CForm::get_input() $a is not a registered variable. Later
new returns corrupted structure.
If you comment out first two lines of program new returns NULL.
In my original source code even when I created object using diffrient
name after assigning NULL reference to variable new still corupts some
of my variables. I think its becouse $a doesn't have storage on stack
but interpreter thinks that it has.
I think that returning NULL reference should initialize variable to
false. This is code is not good programming pracitce and could be
easily ommited, but taht doesn't change the fact that this is a bug.
regards
Lukasz Michalski
------------------------------------------------------------------------
--
Edit this bug report at http://bugs.php.net/?id=14582&edit=1