Bug #68539 [NEW]: Crash with simple script that contains __debugInfo method

From: Date: Wed, 03 Dec 2014 09:14:31 +0000
Subject: Bug #68539 [NEW]: Crash with simple script that contains __debugInfo method
Groups: php.bugs 
Request: Send a blank email to php-bugs+get-188893@lists.php.net to get a copy of this message
From: eran at zend dot com Operating system: Linux PHP version: 5.6.3 Package: *General Issues Bug Type: Bug Bug description:Crash with simple script that contains __debugInfo method Description: ------------ Hello, Running the below Test Script results in segfault. I compiled PHP with debug info + OPcache with debug info and ran PHP under valgrind like this (more useful than gdb in this case): valgrind --log-file=/tmp/vg.log /usr/sbin/apache2 -X Shows consistent 'Invalid free/delete' error messages here is sample from valgrind output: ==14364== Invalid free() / delete / delete[] / realloc() ==14364== at 0x4C2BDEC: free (in /usr/lib/valgrind/vgpreload_memcheck-amd64-linux.so) ==14364== by 0x8E08625: _efree (zend_alloc.c:2437) ==14364== by 0x8E2FEB7: destroy_op_array (zend_opcode.c:361) ==14364== by 0x8E2F4B5: destroy_zend_function (zend_opcode.c:116) ==14364== by 0x8E2F4D2: zend_function_dtor (zend_opcode.c:128) ==14364== by 0x8E51F67: zend_hash_destroy (zend_hash.c:548) ==14364== by 0x8E2FC20: destroy_zend_class (zend_opcode.c:300) ==14364== by 0x8E5073B: zend_hash_bucket_delete (zend_hash.c:182) ==14364== by 0x8E52628: zend_hash_reverse_apply (zend_hash.c:733) ==14364== by 0x8E294C6: shutdown_executor (zend_execute_API.c:303) ==14364== by 0x8E3FDB6: zend_deactivate (zend.c:949) ==14364== by 0x8DAEE2A: php_request_shutdown (main.c:1884) ==14364== Address 0x1dae38f0 is 0 bytes inside a block of size 16 free'd ==14364== at 0x4C2BDEC: free (in /usr/lib/valgrind/vgpreload_memcheck-amd64-linux.so) ==14364== by 0x8E08625: _efree (zend_alloc.c:2437) ==14364== by 0x8E2FEB7: destroy_op_array (zend_opcode.c:361) ==14364== by 0x8E2F4B5: destroy_zend_function (zend_opcode.c:116) ==14364== by 0x8E2F4D2: zend_function_dtor (zend_opcode.c:128) ==14364== by 0x8E51F67: zend_hash_destroy (zend_hash.c:548) ==14364== by 0x8E2FC20: destroy_zend_class (zend_opcode.c:300) ==14364== by 0x8E5073B: zend_hash_bucket_delete (zend_hash.c:182) ==14364== by 0x8E52628: zend_hash_reverse_apply (zend_hash.c:733) ==14364== by 0x8E294C6: shutdown_executor (zend_execute_API.c:303) ==14364== by 0x8E3FDB6: zend_deactivate (zend.c:949) ==14364== by 0x8DAEE2A: php_request_shutdown (main.c:1884) everything was tested on Linux Mint 17, 64 bit Using PHP 5.6.3. Test script: --------------- <?php class C { public $val; public function __debugInfo() { return $this->val; } public function __construct($val) { $this->val = $val; } } $c = new C(0); var_dump($c); Expected result: ---------------- No crash Actual result: -------------- Segmentation fault -- Edit bug report at https://bugs.php.net/bug.php?id=68539&edit=1 -- Try a snapshot (PHP 5.4): https://bugs.php.net/fix.php?id=68539&r=trysnapshot54 Try a snapshot (PHP 5.5): https://bugs.php.net/fix.php?id=68539&r=trysnapshot55 Try a snapshot (trunk): https://bugs.php.net/fix.php?id=68539&r=trysnapshottrunk Fixed in SVN: https://bugs.php.net/fix.php?id=68539&r=fixed Fixed in release: https://bugs.php.net/fix.php?id=68539&r=alreadyfixed Need backtrace: https://bugs.php.net/fix.php?id=68539&r=needtrace Need Reproduce Script: https://bugs.php.net/fix.php?id=68539&r=needscript Try newer version: https://bugs.php.net/fix.php?id=68539&r=oldversion Not developer issue: https://bugs.php.net/fix.php?id=68539&r=support Expected behavior: https://bugs.php.net/fix.php?id=68539&r=notwrong Not enough info: https://bugs.php.net/fix.php?id=68539&r=notenoughinfo Submitted twice: https://bugs.php.net/fix.php?id=68539&r=submittedtwice register_globals: https://bugs.php.net/fix.php?id=68539&r=globals PHP 4 support discontinued: https://bugs.php.net/fix.php?id=68539&r=php4 Daylight Savings: https://bugs.php.net/fix.php?id=68539&r=dst IIS Stability: https://bugs.php.net/fix.php?id=68539&r=isapi Install GNU Sed: https://bugs.php.net/fix.php?id=68539&r=gnused Floating point limitations: https://bugs.php.net/fix.php?id=68539&r=float No Zend Extensions: https://bugs.php.net/fix.php?id=68539&r=nozend MySQL Configuration Error: https://bugs.php.net/fix.php?id=68539&r=mysqlcfg

« previous php.bugs (#188893) next »