Bug #68896 [NEW]: Changing ArrayObject value cause Segment Fault

From: Date: Sat, 24 Jan 2015 04:53:19 +0000
Subject: Bug #68896 [NEW]: Changing ArrayObject value cause Segment Fault
Groups: php.bugs 
Request: Send a blank email to php-bugs+get-190168@lists.php.net to get a copy of this message
From: jrbasso at gmail dot com Operating system: Linux PHP version: master-Git-2015-01-24 (Git) Package: SPL related Bug Type: Bug Bug description:Changing ArrayObject value cause Segment Fault Description: ------------ On PHP 7 (git master rev. be5337421680f059f7b23dd530645e070b15715a) when execute the code below it causes a segment fault. You can also see the error on http://3v4l.org/lV2FT Test script: --------------- <?php $obj = new ArrayObject(["a" => 1]); $obj["a"] .= "test"; var_dump($obj["a"]); Expected result: ---------------- string(5) "1test" Actual result: -------------- $ ./sapi/cli/php -r '$obj = new ArrayObject(["a" => 1]); $obj["a"] .= "test"; var_dump($obj["a"]);' php: /root/php-src-dbg/Zend/zend_hash.c:284: _zend_hash_add_or_update_i: Assertion `&p->val != pData' failed. Aborted (gdb) bt #0 0x00007ffff61840d5 in raise () from /lib/x86_64-linux-gnu/libc.so.6 #1 0x00007ffff618783b in abort () from /lib/x86_64-linux-gnu/libc.so.6 #2 0x00007ffff617cd9e in ?? () from /lib/x86_64-linux-gnu/libc.so.6 #3 0x00007ffff617ce42 in __assert_fail () from /lib/x86_64-linux-gnu/libc.so.6 #4 0x00000000008f27d4 in _zend_hash_add_or_update_i (ht=0x7ffff48583c8, key=0x7ffff48579c0, pData=0x7ffff485e8c0, flag=5, __zend_filename=0xe0fe68 "/.../php-src-dbg/Zend/zend_hash.h", __zend_lineno=317) at /.../php-src-dbg/Zend/zend_hash.c:284 #5 0x00000000008f2b06 in _zend_hash_update_ind (ht=0x7ffff48583c8, key=0x7ffff48579c0, pData=0x7ffff485e8c0, __zend_filename=0xe0fe68 "/.../php-src-dbg/Zend/zend_hash.h", __zend_lineno=317) at /.../php-src-dbg/Zend/zend_hash.c:338 #6 0x0000000000778904 in zend_symtable_update_ind (ht=0x7ffff48583c8, key=0x7ffff48579c0, pData=0x7ffff485e8c0) at /.../php-src-dbg/Zend/zend_hash.h:317 #7 0x000000000077a27d in spl_array_write_dimension_ex (check_inherited=1, object=0x7ffff4813090, offset=0x7ffff48750d0, value=0x7ffff485e8c0) at /.../php-src-dbg/ext/spl/spl_array.c:493 #8 0x000000000077a3c2 in spl_array_write_dimension (object=0x7ffff4813090, offset=0x7ffff48750d0, value=0x7ffff485e8c0) at /.../php-src-dbg/ext/spl/spl_array.c:533 #9 0x000000000092cca8 in zend_binary_assign_op_obj_dim (object=0x7ffff4813090, property=0x7ffff48750d0, value=0x7ffff48750e0, retval=0x0, binary_op=0x8d8b83 <concat_function>) at /.../php-src-dbg/Zend/zend_execute.c:945 #10 0x0000000000968fda in zend_binary_assign_op_dim_helper_SPEC_CV_CONST (binary_op=0x8d8b83 <concat_function>, execute_data=0x7ffff4813030) at /.../php-src-dbg/Zend/zend_vm_execute.h:24794 #11 0x0000000000969879 in ZEND_ASSIGN_CONCAT_SPEC_CV_CONST_HANDLER (execute_data=0x7ffff4813030) at /.../php-src-dbg/Zend/zend_vm_execute.h:25018 #12 0x000000000092f72c in execute_ex (execute_data=0x7ffff4813030) at /.../php-src-dbg/Zend/zend_vm_execute.h:352 #13 0x000000000092f87e in zend_execute (op_array=0x7ffff4880000, return_value=0x7fffffffcf70) at /.../php-src-dbg/Zend/zend_vm_execute.h:381 #14 0x00000000008caf30 in zend_eval_stringl (str=0x11b2a10 "$obj = new ArrayObject([\"a\" => 1]); $obj[\"a\"] .= \"test\"; var_dump($obj[\"a\"]);", str_len=77, retval_ptr=0x0, string_name=0xe51e34 "Command line code") at /.../php-src-dbg/Zend/zend_execute_API.c:1074 #15 0x00000000008cb110 in zend_eval_stringl_ex (str=0x11b2a10 "$obj = new ArrayObject([\"a\" => 1]); $obj[\"a\"] .= \"test\"; var_dump($obj[\"a\"]);", str_len=77, retval_ptr=0x0, string_name=0xe51e34 "Command line code", handle_exceptions=1) at /.../php-src-dbg/Zend/zend_execute_API.c:1115 #16 0x00000000008cb1ab in zend_eval_string_ex (str=0x11b2a10 "$obj = new ArrayObject([\"a\" => 1]); $obj[\"a\"] .= \"test\"; var_dump($obj[\"a\"]);", retval_ptr=0x0, string_name=0xe51e34 "Command line code", handle_exceptions=1) at /.../php-src-dbg/Zend/zend_execute_API.c:1126 #17 0x0000000000985a8e in do_cli (argc=3, argv=0x11b2990) at /.../php-src-dbg/sapi/cli/php_cli.c:1022 #18 0x0000000000986ace in main (argc=3, argv=0x11b2990) at /.../php-src-dbg/sapi/cli/php_cli.c:1361 -- Edit bug report at https://bugs.php.net/bug.php?id=68896&edit=1 -- Try a snapshot (PHP 5.4): https://bugs.php.net/fix.php?id=68896&r=trysnapshot54 Try a snapshot (PHP 5.5): https://bugs.php.net/fix.php?id=68896&r=trysnapshot55 Try a snapshot (trunk): https://bugs.php.net/fix.php?id=68896&r=trysnapshottrunk Fixed in SVN: https://bugs.php.net/fix.php?id=68896&r=fixed Fixed in release: https://bugs.php.net/fix.php?id=68896&r=alreadyfixed Need backtrace: https://bugs.php.net/fix.php?id=68896&r=needtrace Need Reproduce Script: https://bugs.php.net/fix.php?id=68896&r=needscript Try newer version: https://bugs.php.net/fix.php?id=68896&r=oldversion Not developer issue: https://bugs.php.net/fix.php?id=68896&r=support Expected behavior: https://bugs.php.net/fix.php?id=68896&r=notwrong Not enough info: https://bugs.php.net/fix.php?id=68896&r=notenoughinfo Submitted twice: https://bugs.php.net/fix.php?id=68896&r=submittedtwice register_globals: https://bugs.php.net/fix.php?id=68896&r=globals PHP 4 support discontinued: https://bugs.php.net/fix.php?id=68896&r=php4 Daylight Savings: https://bugs.php.net/fix.php?id=68896&r=dst IIS Stability: https://bugs.php.net/fix.php?id=68896&r=isapi Install GNU Sed: https://bugs.php.net/fix.php?id=68896&r=gnused Floating point limitations: https://bugs.php.net/fix.php?id=68896&r=float No Zend Extensions: https://bugs.php.net/fix.php?id=68896&r=nozend MySQL Configuration Error: https://bugs.php.net/fix.php?id=68896&r=mysqlcfg

« previous php.bugs (#190168) next »