Bug #68539 [Opn->Csd]: Crash with simple script that contains __debugInfo method
| From: | dmitry@php.net | Date: | Wed, 03 Dec 2014 09:19:48 +0000 |
| Subject: | Bug #68539 [Opn->Csd]: Crash with simple script that contains __debugInfo method | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-188894@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=68539&edit=1
ID: 68539
Updated by: dmitry@php.net
Reported by: eran at zend dot com
Summary: Crash with simple script that contains __debugInfo
method
-Status: Open
+Status: Closed
Type: Bug
Package: *General Issues
Operating System: Linux
PHP Version: 5.6.3
-Assigned To:
+Assigned To: dmitry
Block user comment: N
Private report: N
New Comment:
Must be fixed by http://git.php.net/?p=php-src.git;a=commitdiff;h=cd68c4b1d2fd7d2852881c98ca4cf8de351961d5
Previous Comments:
------------------------------------------------------------------------
[2014-12-03 09:14:30] eran at zend dot com
Description:
------------
Hello,
Running the below Test Script results in segfault.
I compiled PHP with debug info + OPcache with debug info and ran PHP under valgrind like this (more
useful than gdb in this case):
valgrind --log-file=/tmp/vg.log /usr/sbin/apache2 -X
Shows consistent 'Invalid free/delete' error messages
here is sample from valgrind output:
==14364== Invalid free() / delete / delete[] / realloc()
==14364== at 0x4C2BDEC: free (in /usr/lib/valgrind/vgpreload_memcheck-amd64-linux.so)
==14364== by 0x8E08625: _efree (zend_alloc.c:2437)
==14364== by 0x8E2FEB7: destroy_op_array (zend_opcode.c:361)
==14364== by 0x8E2F4B5: destroy_zend_function (zend_opcode.c:116)
==14364== by 0x8E2F4D2: zend_function_dtor (zend_opcode.c:128)
==14364== by 0x8E51F67: zend_hash_destroy (zend_hash.c:548)
==14364== by 0x8E2FC20: destroy_zend_class (zend_opcode.c:300)
==14364== by 0x8E5073B: zend_hash_bucket_delete (zend_hash.c:182)
==14364== by 0x8E52628: zend_hash_reverse_apply (zend_hash.c:733)
==14364== by 0x8E294C6: shutdown_executor (zend_execute_API.c:303)
==14364== by 0x8E3FDB6: zend_deactivate (zend.c:949)
==14364== by 0x8DAEE2A: php_request_shutdown (main.c:1884)
==14364== Address 0x1dae38f0 is 0 bytes inside a block of size 16 free'd
==14364== at 0x4C2BDEC: free (in /usr/lib/valgrind/vgpreload_memcheck-amd64-linux.so)
==14364== by 0x8E08625: _efree (zend_alloc.c:2437)
==14364== by 0x8E2FEB7: destroy_op_array (zend_opcode.c:361)
==14364== by 0x8E2F4B5: destroy_zend_function (zend_opcode.c:116)
==14364== by 0x8E2F4D2: zend_function_dtor (zend_opcode.c:128)
==14364== by 0x8E51F67: zend_hash_destroy (zend_hash.c:548)
==14364== by 0x8E2FC20: destroy_zend_class (zend_opcode.c:300)
==14364== by 0x8E5073B: zend_hash_bucket_delete (zend_hash.c:182)
==14364== by 0x8E52628: zend_hash_reverse_apply (zend_hash.c:733)
==14364== by 0x8E294C6: shutdown_executor (zend_execute_API.c:303)
==14364== by 0x8E3FDB6: zend_deactivate (zend.c:949)
==14364== by 0x8DAEE2A: php_request_shutdown (main.c:1884)
everything was tested on Linux Mint 17, 64 bit
Using PHP 5.6.3.
Test script:
---------------
<?php
class C {
public $val;
public function __debugInfo() {
return $this->val;
}
public function __construct($val) {
$this->val = $val;
}
}
$c = new C(0);
var_dump($c);
Expected result:
----------------
No crash
Actual result:
--------------
Segmentation fault
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=68539&edit=1