Bug #68252 [Opn]: segfault in Zend/zend_hash.c in function _zend_hash_del_el

From: Date: Wed, 22 Oct 2014 08:58:54 +0000
Subject: Bug #68252 [Opn]: segfault in Zend/zend_hash.c in function _zend_hash_del_el
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-188258@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=68252&edit=1 ID: 68252 Updated by: laruence@php.net Reported by: bugs at milos dot nz Summary: segfault in Zend/zend_hash.c in function _zend_hash_del_el Status: Open Type: Bug Package: Reproducible crash Operating System: Linux 3.16 (Gentoo) PHP Version: master-Git-2014-10-17 (Git) Block user comment: N Private report: N New Comment: great, thanks, a temporary access is enough :) Previous Comments: ------------------------------------------------------------------------ [2014-10-22 07:21:58] bugs at milos dot nz Yes, that is fine. I will contact you sometime tomorrow or the day after. Thank you for your interest in this bug. ------------------------------------------------------------------------ [2014-10-22 06:17:01] laruence@php.net is that possible, you can grant me a remote access to your box ? if yes, please send to me via mail :) thanks ------------------------------------------------------------------------ [2014-10-22 06:16:59] laruence@php.net is that possible, you can grant me a remote access to your box ? if yes, please send to me via mail :) thanks ------------------------------------------------------------------------ [2014-10-22 03:55:50] laruence@php.net the i is IVALID_IDX here..... now the problem is how it became that... ------------------------------------------------------------------------ [2014-10-21 10:19:51] bugs at milos dot nz The latest master PHP branch recompiled sans optimisation (-O0) results in the following gdb backtrace: (gdb) bt full #0 0x0000000000974b73 in _zend_hash_del_el (p=0x7fffeff117b0, idx=1725, ht=0x129c880) at /root/tmp/php-src/Zend/zend_hash.c:658 nIndex = 643 i = 4294967295 prev = 0x801feff03ff0 #1 zend_hash_apply_deleter (ht=0x129c880, idx=1725, p=0x7fffeff117b0) at /root/tmp/php-src/Zend/zend_hash.c:973 No locals. #2 0x00000000009753c7 in zend_hash_reverse_apply (ht=0x129c880, apply_func=0x93313a <clean_non_persistent_function>) at /root/tmp/php-src/Zend/zend_hash.c:1133 idx = 1725 p = 0x7fffeff117b0 result = 1 #3 0x0000000000933da1 in shutdown_executor () at /root/tmp/php-src/Zend/zend_execute_API.c:347 __orig_bailout = 0x7fffffffddf0 __bailout = {{__jmpbuf = {0, -8375293845698859549, 4721632, 140737488347248, 0, 0, -8375293845684179485, 8375292634278702563}, __mask_was_saved = 0, __saved_mask = {__val = {140737226576512, 9343290, 19498944, 140737488345520, 18446744073447799296, 140737488345520, 9772479, 0, 139646304518208, 9343290, 19498944, 140737226211328, 19498944, 140737488345552, 9343543, 140737226604240}}}} func = 0x129c830 ce = 0x176eee0 #4 0x0000000000954b71 in zend_deactivate () at /root/tmp/php-src/Zend/zend.c:883 No locals. #5 0x00000000008ab3d6 in php_request_shutdown (dummy=0x0) at /root/tmp/php-src/main/main.c:1859 report_memleaks = 1 '\001' #6 0x0000000000ad5df5 in main (argc=2, argv=0x7fffffffe078) at /root/tmp/php-src/sapi/cgi/cgi_main.c:2515 __orig_bailout = 0x0 __bailout = {{__jmpbuf = {0, -8375293845908574749, 4721632, 140737488347248, 0, 0, -8375293845814202909, 8375292580019351011}, __mask_was_saved = 0, __saved_mask = {__val = {4478074, 140737229643112, 4277064, 4294967296, 4294969391, 140737229617936, 140737353971192, 140737488347072, 140737354130592, 140737488347112, 140737354129736, 1, 140737351931677, 0, 140737353971192, 1}}}} free_query_string = 1 exit_status = 0 cgi = 0 c = -1 i = 2 len = 54 file_handle = {handle = {fd = -261734144, fp = 0x7ffff0664100, stream = {handle = 0x7ffff0664100, isatty = 0, mmap = {len = 418, pos = 0, map = 0x0, buf = 0x7ffff7ff6000 "", old_handle = 0x0, old_closer = 0x0}, reader = 0x8cb19a <_php_stream_read>, fsizer = 0x8aa26b <php_zend_stream_fsizer>, closer = 0x8aa245 <php_zend_stream_mmap_closer>}}, filename = 0x7ffff0602000 " \rh\360\377\177", opened_path = 0x0, type = ZEND_HANDLE_MAPPED, free_filename = 0 '\000'} s = 0x13c77f0 "/home/simon/theibguide.com/www/public_html/index.php" behavior = 1 no_headers = 0 orig_optind = 1 orig_optarg = 0x0 script_file = 0x0 ini_entries_len = 0 max_requests = 500 requests = 0 fastcgi = 0 bindpath = 0x0 fcgi_fd = 0 request = 0x0 warmup_repeats = 0 repeats = 1 benchmark = 0 start = {tv_sec = 140737229643112, tv_usec = 140737314262832} end = {tv_sec = 1, tv_usec = 140737354129736} status = 0 query_string = 0x0 decoded_query_string = 0x7ffff7de5594 <do_lookup_x+2324> "H\205\300L\213L$\030L\213\\$(D\213D$0\017\205\216\370\377\377H\213T$\020\213\n\353\203ff.\017\037\204" skip_getopt = 0 ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=68252 -- Edit this bug report at https://bugs.php.net/bug.php?id=68252&edit=1

« previous php.bugs (#188258) next »