Bug #69038 [Com]: switch(SOMECONSTANT) misbehaves

From: Date: Thu, 12 Feb 2015 11:41:13 +0000
Subject: Bug #69038 [Com]: switch(SOMECONSTANT) misbehaves
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-190623@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=69038&edit=1 ID: 69038 Comment by: php at bof dot de Reported by: php at bof dot de Summary: switch(SOMECONSTANT) misbehaves Status: Open Type: Bug Package: opcache Operating System: Linux PHP Version: 5.6.5 Block user comment: N Private report: N New Comment: Two more tests: issue exists in PHP-5.6.6RC1 issue does NOT exist in current MASTER Previous Comments: ------------------------------------------------------------------------ [2015-02-12 10:03:10] php at bof dot de Final words, for now: the issue also exists for the 5.6.2 and 5.6.4 builds I still have lying around. It does NOT exist for my last 5.5 build, version 5.5.18 ! ------------------------------------------------------------------------ [2015-02-12 09:57:11] php at bof dot de Playing around with the ordering of the cases: - leaving out default: altogether does not remove the issue - ordering the problematic case 'foo': behind the default does not remove the issue - putting the default: as the first thing does not remove the issue AND changes valgrind output a bit (two instead of three blocks of backtraces) This gives me a more minimal reproducer: define('OK', 'ok'); function badswitch() { switch(OK) { default: return 'bad'; case 'ok': return 'ok'; } } var_dump(badswitch()); with valgrind output Thu Feb 12 10:55:44 2015 (6761): Debug Loading blacklist file: '/opt/php/ini.d/opcache.blacklist' Thu Feb 12 10:55:44 2015 (6761): Message Cached script '/home/patrick/webdev/switch_const_myconst.php' ==6761== Conditional jump or move depends on uninitialised value(s) ==6761== at 0xA8A33C: compare_function (zend_operators.c:1602) ==6761== by 0xA8BE21: is_equal_function (zend_operators.c:1837) ==6761== by 0xAEA4E1: ZEND_CASE_SPEC_TMP_CONST_HANDLER (zend_vm_execute.h:9364) ==6761== by 0xAD67D9: execute_ex (zend_vm_execute.h:363) ==6761== by 0xAD685E: zend_execute (zend_vm_execute.h:388) ==6761== by 0xA91EB9: zend_execute_scripts (zend.c:1341) ==6761== by 0x9FBC55: php_execute_script (main.c:2584) ==6761== by 0xB4618E: do_cli (php_cli.c:994) ==6761== by 0xB47239: main (php_cli.c:1378) ==6761== ==6761== Use of uninitialised value of size 8 ==6761== at 0xA8A353: compare_function (zend_operators.c:1602) ==6761== by 0xA8BE21: is_equal_function (zend_operators.c:1837) ==6761== by 0xAEA4E1: ZEND_CASE_SPEC_TMP_CONST_HANDLER (zend_vm_execute.h:9364) ==6761== by 0xAD67D9: execute_ex (zend_vm_execute.h:363) ==6761== by 0xAD685E: zend_execute (zend_vm_execute.h:388) ==6761== by 0xA91EB9: zend_execute_scripts (zend.c:1341) ==6761== by 0x9FBC55: php_execute_script (main.c:2584) ==6761== by 0xB4618E: do_cli (php_cli.c:994) ==6761== by 0xB47239: main (php_cli.c:1378) ==6761== string(3) "bad" ------------------------------------------------------------------------ [2015-02-12 09:46:43] php at bof dot de The issue remains when I change the case "label" from a constant string to a variable; the valgrind output is slightly different then: Code: define('MYCONST', 'foo'); function goodswitch() { $foo = 'foo'; switch(MYCONST) { case $foo: return 'foo'; case 'bar': return 'bar'; default: return 'default'; } } function badswitch() { $foo = 'foo'; switch(MYCONST) { case 'bar': return 'bar'; case $foo: return 'foo'; default: return 'default'; } } var_dump(goodswitch()); var_dump(badswitch()); Valgrind: Thu Feb 12 10:44:21 2015 (4062): Debug Loading blacklist file: '/opt/php/ini.d/opcache.blacklist' Thu Feb 12 10:44:21 2015 (4062): Message Cached script '/home/patrick/webdev/switch_const_myconst.php' string(3) "foo" ==4062== Conditional jump or move depends on uninitialised value(s) ==4062== at 0xA8A33C: compare_function (zend_operators.c:1602) ==4062== by 0xA8BE21: is_equal_function (zend_operators.c:1837) ==4062== by 0xAF1508: ZEND_CASE_SPEC_TMP_CV_HANDLER (zend_vm_execute.h:12541) ==4062== by 0xAD67D9: execute_ex (zend_vm_execute.h:363) ==4062== by 0xAD685E: zend_execute (zend_vm_execute.h:388) ==4062== by 0xA91EB9: zend_execute_scripts (zend.c:1341) ==4062== by 0x9FBC55: php_execute_script (main.c:2584) ==4062== by 0xB4618E: do_cli (php_cli.c:994) ==4062== by 0xB47239: main (php_cli.c:1378) ==4062== ==4062== Use of uninitialised value of size 8 ==4062== at 0xA8A353: compare_function (zend_operators.c:1602) ==4062== by 0xA8BE21: is_equal_function (zend_operators.c:1837) ==4062== by 0xAF1508: ZEND_CASE_SPEC_TMP_CV_HANDLER (zend_vm_execute.h:12541) ==4062== by 0xAD67D9: execute_ex (zend_vm_execute.h:363) ==4062== by 0xAD685E: zend_execute (zend_vm_execute.h:388) ==4062== by 0xA91EB9: zend_execute_scripts (zend.c:1341) ==4062== by 0x9FBC55: php_execute_script (main.c:2584) ==4062== by 0xB4618E: do_cli (php_cli.c:994) ==4062== by 0xB47239: main (php_cli.c:1378) ==4062== ==4062== Conditional jump or move depends on uninitialised value(s) ==4062== at 0xAD0D9C: _zval_dtor (zend_variables.h:32) ==4062== by 0xAE6F4E: ZEND_FREE_SPEC_TMP_HANDLER (zend_vm_execute.h:7956) ==4062== by 0xAD67D9: execute_ex (zend_vm_execute.h:363) ==4062== by 0xAD685E: zend_execute (zend_vm_execute.h:388) ==4062== by 0xA91EB9: zend_execute_scripts (zend.c:1341) ==4062== by 0x9FBC55: php_execute_script (main.c:2584) ==4062== by 0xB4618E: do_cli (php_cli.c:994) ==4062== by 0xB47239: main (php_cli.c:1378) ==4062== string(7) "default" ------------------------------------------------------------------------ [2015-02-12 09:29:48] php at bof dot de BTW, same valgrind result (a bit shorter backtrace) after disabling xdebug and any extension other than opcache. Disabling opcache also, removes the issue, shows foo+foo and no valgrind noise. ------------------------------------------------------------------------ [2015-02-12 09:23:35] php at bof dot de valgrind has something to say on the issue! patrick@dev0:{dbg-5.6.5}> valgrind php -d opcache.enable_cli=1 ~/webdev/switch_const_myconst.php ==30622== Memcheck, a memory error detector ==30622== Copyright (C) 2002-2010, and GNU GPL'd, by Julian Seward et al. ==30622== Using Valgrind-3.6.1 and LibVEX; rerun with -h for copyright info ==30622== Command: php -d opcache.enable_cli=1 /home/patrick/webdev/switch_const_myconst.php ==30622== Thu Feb 12 10:22:35 2015 (30622): Debug Loading blacklist file: '/opt/php/ini.d/opcache.blacklist' Thu Feb 12 10:22:35 2015 (30622): Message Cached script '/home/patrick/webdev/switch_const_myconst.php' string(3) "foo" ==30622== Conditional jump or move depends on uninitialised value(s) ==30622== at 0xA8A33C: compare_function (zend_operators.c:1602) ==30622== by 0xA8BE21: is_equal_function (zend_operators.c:1837) ==30622== by 0xAEA4E1: ZEND_CASE_SPEC_TMP_CONST_HANDLER (zend_vm_execute.h:9364) ==30622== by 0xAD67D9: execute_ex (zend_vm_execute.h:363) ==30622== by 0xCC31BE3: xdebug_execute_ex (xdebug.c:1437) ==30622== by 0xAD685E: zend_execute (zend_vm_execute.h:388) ==30622== by 0xAD7390: zend_do_fcall_common_helper_SPEC (zend_vm_execute.h:592) ==30622== by 0xADCB02: ZEND_DO_FCALL_SPEC_CONST_HANDLER (zend_vm_execute.h:2595) ==30622== by 0xAD67D9: execute_ex (zend_vm_execute.h:363) ==30622== by 0xCC31BE3: xdebug_execute_ex (xdebug.c:1437) ==30622== by 0xAD685E: zend_execute (zend_vm_execute.h:388) ==30622== by 0xA91EB9: zend_execute_scripts (zend.c:1341) ==30622== ==30622== Use of uninitialised value of size 8 ==30622== at 0xA8A353: compare_function (zend_operators.c:1602) ==30622== by 0xA8BE21: is_equal_function (zend_operators.c:1837) ==30622== by 0xAEA4E1: ZEND_CASE_SPEC_TMP_CONST_HANDLER (zend_vm_execute.h:9364) ==30622== by 0xAD67D9: execute_ex (zend_vm_execute.h:363) ==30622== by 0xCC31BE3: xdebug_execute_ex (xdebug.c:1437) ==30622== by 0xAD685E: zend_execute (zend_vm_execute.h:388) ==30622== by 0xAD7390: zend_do_fcall_common_helper_SPEC (zend_vm_execute.h:592) ==30622== by 0xADCB02: ZEND_DO_FCALL_SPEC_CONST_HANDLER (zend_vm_execute.h:2595) ==30622== by 0xAD67D9: execute_ex (zend_vm_execute.h:363) ==30622== by 0xCC31BE3: xdebug_execute_ex (xdebug.c:1437) ==30622== by 0xAD685E: zend_execute (zend_vm_execute.h:388) ==30622== by 0xA91EB9: zend_execute_scripts (zend.c:1341) ==30622== ==30622== Conditional jump or move depends on uninitialised value(s) ==30622== at 0xAD0D9C: _zval_dtor (zend_variables.h:32) ==30622== by 0xAE6F4E: ZEND_FREE_SPEC_TMP_HANDLER (zend_vm_execute.h:7956) ==30622== by 0xAD67D9: execute_ex (zend_vm_execute.h:363) ==30622== by 0xCC31BE3: xdebug_execute_ex (xdebug.c:1437) ==30622== by 0xAD685E: zend_execute (zend_vm_execute.h:388) ==30622== by 0xAD7390: zend_do_fcall_common_helper_SPEC (zend_vm_execute.h:592) ==30622== by 0xADCB02: ZEND_DO_FCALL_SPEC_CONST_HANDLER (zend_vm_execute.h:2595) ==30622== by 0xAD67D9: execute_ex (zend_vm_execute.h:363) ==30622== by 0xCC31BE3: xdebug_execute_ex (xdebug.c:1437) ==30622== by 0xAD685E: zend_execute (zend_vm_execute.h:388) ==30622== by 0xA91EB9: zend_execute_scripts (zend.c:1341) ==30622== by 0x9FBC55: php_execute_script (main.c:2584) ==30622== string(7) "default" ==30622== ==30622== HEAP SUMMARY: ==30622== in use at exit: 5,556 bytes in 45 blocks ==30622== total heap usage: 34,708 allocs, 34,663 frees, 5,475,889 bytes allocated ==30622== ==30622== LEAK SUMMARY: ==30622== definitely lost: 733 bytes in 26 blocks ==30622== indirectly lost: 0 bytes in 0 blocks ==30622== possibly lost: 0 bytes in 0 blocks ==30622== still reachable: 4,823 bytes in 19 blocks ==30622== suppressed: 0 bytes in 0 blocks ==30622== Rerun with --leak-check=full to see details of leaked memory ==30622== ==30622== For counts of detected and suppressed errors, rerun with: -v ==30622== Use --track-origins=yes to see where uninitialised values come from ==30622== ERROR SUMMARY: 3 errors from 3 contexts (suppressed: 6 from 6) ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=69038 -- Edit this bug report at https://bugs.php.net/bug.php?id=69038&edit=1

« previous php.bugs (#190623) next »