Bug #68896 [NEW]: Changing ArrayObject value cause Segment Fault
| From: | jrbasso at gmail dot com | Date: | Sat, 24 Jan 2015 04:53:19 +0000 |
| Subject: | Bug #68896 [NEW]: Changing ArrayObject value cause Segment Fault | ||
| Groups: | php.bugs | ||
| Request: | Send a blank email to php-bugs+get-190168@lists.php.net to get a copy of this message | ||
From: jrbasso at gmail dot com
Operating system: Linux
PHP version: master-Git-2015-01-24 (Git)
Package: SPL related
Bug Type: Bug
Bug description:Changing ArrayObject value cause Segment Fault
Description:
------------
On PHP 7 (git master rev. be5337421680f059f7b23dd530645e070b15715a) when
execute the code below it causes a segment fault.
You can also see the error on http://3v4l.org/lV2FT
Test script:
---------------
<?php
$obj = new ArrayObject(["a" => 1]);
$obj["a"] .= "test";
var_dump($obj["a"]);
Expected result:
----------------
string(5) "1test"
Actual result:
--------------
$ ./sapi/cli/php -r '$obj = new ArrayObject(["a" => 1]); $obj["a"] .=
"test"; var_dump($obj["a"]);'
php: /root/php-src-dbg/Zend/zend_hash.c:284: _zend_hash_add_or_update_i:
Assertion `&p->val != pData' failed.
Aborted
(gdb) bt
#0 0x00007ffff61840d5 in raise () from /lib/x86_64-linux-gnu/libc.so.6
#1 0x00007ffff618783b in abort () from /lib/x86_64-linux-gnu/libc.so.6
#2 0x00007ffff617cd9e in ?? () from /lib/x86_64-linux-gnu/libc.so.6
#3 0x00007ffff617ce42 in __assert_fail () from
/lib/x86_64-linux-gnu/libc.so.6
#4 0x00000000008f27d4 in _zend_hash_add_or_update_i (ht=0x7ffff48583c8,
key=0x7ffff48579c0, pData=0x7ffff485e8c0, flag=5,
__zend_filename=0xe0fe68 "/.../php-src-dbg/Zend/zend_hash.h",
__zend_lineno=317) at /.../php-src-dbg/Zend/zend_hash.c:284
#5 0x00000000008f2b06 in _zend_hash_update_ind (ht=0x7ffff48583c8,
key=0x7ffff48579c0, pData=0x7ffff485e8c0, __zend_filename=0xe0fe68
"/.../php-src-dbg/Zend/zend_hash.h", __zend_lineno=317)
at /.../php-src-dbg/Zend/zend_hash.c:338
#6 0x0000000000778904 in zend_symtable_update_ind (ht=0x7ffff48583c8,
key=0x7ffff48579c0, pData=0x7ffff485e8c0) at
/.../php-src-dbg/Zend/zend_hash.h:317
#7 0x000000000077a27d in spl_array_write_dimension_ex
(check_inherited=1, object=0x7ffff4813090, offset=0x7ffff48750d0,
value=0x7ffff485e8c0) at /.../php-src-dbg/ext/spl/spl_array.c:493
#8 0x000000000077a3c2 in spl_array_write_dimension
(object=0x7ffff4813090, offset=0x7ffff48750d0, value=0x7ffff485e8c0) at
/.../php-src-dbg/ext/spl/spl_array.c:533
#9 0x000000000092cca8 in zend_binary_assign_op_obj_dim
(object=0x7ffff4813090, property=0x7ffff48750d0, value=0x7ffff48750e0,
retval=0x0, binary_op=0x8d8b83 <concat_function>)
at /.../php-src-dbg/Zend/zend_execute.c:945
#10 0x0000000000968fda in zend_binary_assign_op_dim_helper_SPEC_CV_CONST
(binary_op=0x8d8b83 <concat_function>, execute_data=0x7ffff4813030) at
/.../php-src-dbg/Zend/zend_vm_execute.h:24794
#11 0x0000000000969879 in ZEND_ASSIGN_CONCAT_SPEC_CV_CONST_HANDLER
(execute_data=0x7ffff4813030) at
/.../php-src-dbg/Zend/zend_vm_execute.h:25018
#12 0x000000000092f72c in execute_ex (execute_data=0x7ffff4813030) at
/.../php-src-dbg/Zend/zend_vm_execute.h:352
#13 0x000000000092f87e in zend_execute (op_array=0x7ffff4880000,
return_value=0x7fffffffcf70) at
/.../php-src-dbg/Zend/zend_vm_execute.h:381
#14 0x00000000008caf30 in zend_eval_stringl (str=0x11b2a10 "$obj = new
ArrayObject([\"a\" => 1]); $obj[\"a\"] .= \"test\";
var_dump($obj[\"a\"]);", str_len=77, retval_ptr=0x0,
string_name=0xe51e34 "Command line code") at
/.../php-src-dbg/Zend/zend_execute_API.c:1074
#15 0x00000000008cb110 in zend_eval_stringl_ex (str=0x11b2a10 "$obj =
new ArrayObject([\"a\" => 1]); $obj[\"a\"] .= \"test\";
var_dump($obj[\"a\"]);", str_len=77, retval_ptr=0x0,
string_name=0xe51e34 "Command line code", handle_exceptions=1) at
/.../php-src-dbg/Zend/zend_execute_API.c:1115
#16 0x00000000008cb1ab in zend_eval_string_ex (str=0x11b2a10 "$obj = new
ArrayObject([\"a\" => 1]); $obj[\"a\"] .= \"test\";
var_dump($obj[\"a\"]);", retval_ptr=0x0,
string_name=0xe51e34 "Command line code", handle_exceptions=1) at
/.../php-src-dbg/Zend/zend_execute_API.c:1126
#17 0x0000000000985a8e in do_cli (argc=3, argv=0x11b2990) at
/.../php-src-dbg/sapi/cli/php_cli.c:1022
#18 0x0000000000986ace in main (argc=3, argv=0x11b2990) at
/.../php-src-dbg/sapi/cli/php_cli.c:1361
--
Edit bug report at https://bugs.php.net/bug.php?id=68896&edit=1
--
Try a snapshot (PHP 5.4): https://bugs.php.net/fix.php?id=68896&r=trysnapshot54
Try a snapshot (PHP 5.5): https://bugs.php.net/fix.php?id=68896&r=trysnapshot55
Try a snapshot (trunk): https://bugs.php.net/fix.php?id=68896&r=trysnapshottrunk
Fixed in SVN: https://bugs.php.net/fix.php?id=68896&r=fixed
Fixed in release: https://bugs.php.net/fix.php?id=68896&r=alreadyfixed
Need backtrace: https://bugs.php.net/fix.php?id=68896&r=needtrace
Need Reproduce Script: https://bugs.php.net/fix.php?id=68896&r=needscript
Try newer version: https://bugs.php.net/fix.php?id=68896&r=oldversion
Not developer issue: https://bugs.php.net/fix.php?id=68896&r=support
Expected behavior: https://bugs.php.net/fix.php?id=68896&r=notwrong
Not enough info: https://bugs.php.net/fix.php?id=68896&r=notenoughinfo
Submitted twice: https://bugs.php.net/fix.php?id=68896&r=submittedtwice
register_globals: https://bugs.php.net/fix.php?id=68896&r=globals
PHP 4 support discontinued: https://bugs.php.net/fix.php?id=68896&r=php4
Daylight Savings: https://bugs.php.net/fix.php?id=68896&r=dst
IIS Stability: https://bugs.php.net/fix.php?id=68896&r=isapi
Install GNU Sed: https://bugs.php.net/fix.php?id=68896&r=gnused
Floating point limitations: https://bugs.php.net/fix.php?id=68896&r=float
No Zend Extensions: https://bugs.php.net/fix.php?id=68896&r=nozend
MySQL Configuration Error: https://bugs.php.net/fix.php?id=68896&r=mysqlcfg