Bug #69038 [Asn]: switch(SOMECONSTANT) misbehaves
| From: | laruence@php.net | Date: | Sun, 15 Feb 2015 03:36:25 +0000 |
| Subject: | Bug #69038 [Asn]: switch(SOMECONSTANT) misbehaves | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-190689@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=69038&edit=1
ID: 69038
Updated by: laruence@php.net
Reported by: php at bof dot de
Summary: switch(SOMECONSTANT) misbehaves
Status: Assigned
Type: Bug
Package: opcache
Operating System: Linux
PHP Version: 5.6.5
Assigned To: laruence
Block user comment: N
Private report: N
New Comment:
a fix could be https://gist.github.com/laruence/14a5c7388a50ff716ada
anyway, I needs verify it carefully
Previous Comments:
------------------------------------------------------------------------
[2015-02-12 11:41:12] php at bof dot de
Two more tests:
issue exists in PHP-5.6.6RC1
issue does NOT exist in current MASTER
------------------------------------------------------------------------
[2015-02-12 10:03:10] php at bof dot de
Final words, for now:
the issue also exists for the 5.6.2 and 5.6.4 builds I still have lying around.
It does NOT exist for my last 5.5 build, version 5.5.18 !
------------------------------------------------------------------------
[2015-02-12 09:57:11] php at bof dot de
Playing around with the ordering of the cases:
- leaving out default: altogether does not remove the issue
- ordering the problematic case 'foo': behind the default does not remove the issue
- putting the default: as the first thing does not remove the issue AND changes valgrind output a
bit (two instead of three blocks of backtraces)
This gives me a more minimal reproducer:
define('OK', 'ok');
function badswitch() {
switch(OK) {
default: return 'bad';
case 'ok': return 'ok';
}
}
var_dump(badswitch());
with valgrind output
Thu Feb 12 10:55:44 2015 (6761): Debug Loading blacklist file:
'/opt/php/ini.d/opcache.blacklist'
Thu Feb 12 10:55:44 2015 (6761): Message Cached script
'/home/patrick/webdev/switch_const_myconst.php'
==6761== Conditional jump or move depends on uninitialised value(s)
==6761== at 0xA8A33C: compare_function (zend_operators.c:1602)
==6761== by 0xA8BE21: is_equal_function (zend_operators.c:1837)
==6761== by 0xAEA4E1: ZEND_CASE_SPEC_TMP_CONST_HANDLER (zend_vm_execute.h:9364)
==6761== by 0xAD67D9: execute_ex (zend_vm_execute.h:363)
==6761== by 0xAD685E: zend_execute (zend_vm_execute.h:388)
==6761== by 0xA91EB9: zend_execute_scripts (zend.c:1341)
==6761== by 0x9FBC55: php_execute_script (main.c:2584)
==6761== by 0xB4618E: do_cli (php_cli.c:994)
==6761== by 0xB47239: main (php_cli.c:1378)
==6761==
==6761== Use of uninitialised value of size 8
==6761== at 0xA8A353: compare_function (zend_operators.c:1602)
==6761== by 0xA8BE21: is_equal_function (zend_operators.c:1837)
==6761== by 0xAEA4E1: ZEND_CASE_SPEC_TMP_CONST_HANDLER (zend_vm_execute.h:9364)
==6761== by 0xAD67D9: execute_ex (zend_vm_execute.h:363)
==6761== by 0xAD685E: zend_execute (zend_vm_execute.h:388)
==6761== by 0xA91EB9: zend_execute_scripts (zend.c:1341)
==6761== by 0x9FBC55: php_execute_script (main.c:2584)
==6761== by 0xB4618E: do_cli (php_cli.c:994)
==6761== by 0xB47239: main (php_cli.c:1378)
==6761==
string(3) "bad"
------------------------------------------------------------------------
[2015-02-12 09:46:43] php at bof dot de
The issue remains when I change the case "label" from a constant string to a variable; the
valgrind output is slightly different then:
Code:
define('MYCONST', 'foo');
function goodswitch() {
$foo = 'foo';
switch(MYCONST) {
case $foo: return 'foo';
case 'bar': return 'bar';
default: return 'default';
}
}
function badswitch() {
$foo = 'foo';
switch(MYCONST) {
case 'bar': return 'bar';
case $foo: return 'foo';
default: return 'default';
}
}
var_dump(goodswitch());
var_dump(badswitch());
Valgrind:
Thu Feb 12 10:44:21 2015 (4062): Debug Loading blacklist file:
'/opt/php/ini.d/opcache.blacklist'
Thu Feb 12 10:44:21 2015 (4062): Message Cached script
'/home/patrick/webdev/switch_const_myconst.php'
string(3) "foo"
==4062== Conditional jump or move depends on uninitialised value(s)
==4062== at 0xA8A33C: compare_function (zend_operators.c:1602)
==4062== by 0xA8BE21: is_equal_function (zend_operators.c:1837)
==4062== by 0xAF1508: ZEND_CASE_SPEC_TMP_CV_HANDLER (zend_vm_execute.h:12541)
==4062== by 0xAD67D9: execute_ex (zend_vm_execute.h:363)
==4062== by 0xAD685E: zend_execute (zend_vm_execute.h:388)
==4062== by 0xA91EB9: zend_execute_scripts (zend.c:1341)
==4062== by 0x9FBC55: php_execute_script (main.c:2584)
==4062== by 0xB4618E: do_cli (php_cli.c:994)
==4062== by 0xB47239: main (php_cli.c:1378)
==4062==
==4062== Use of uninitialised value of size 8
==4062== at 0xA8A353: compare_function (zend_operators.c:1602)
==4062== by 0xA8BE21: is_equal_function (zend_operators.c:1837)
==4062== by 0xAF1508: ZEND_CASE_SPEC_TMP_CV_HANDLER (zend_vm_execute.h:12541)
==4062== by 0xAD67D9: execute_ex (zend_vm_execute.h:363)
==4062== by 0xAD685E: zend_execute (zend_vm_execute.h:388)
==4062== by 0xA91EB9: zend_execute_scripts (zend.c:1341)
==4062== by 0x9FBC55: php_execute_script (main.c:2584)
==4062== by 0xB4618E: do_cli (php_cli.c:994)
==4062== by 0xB47239: main (php_cli.c:1378)
==4062==
==4062== Conditional jump or move depends on uninitialised value(s)
==4062== at 0xAD0D9C: _zval_dtor (zend_variables.h:32)
==4062== by 0xAE6F4E: ZEND_FREE_SPEC_TMP_HANDLER (zend_vm_execute.h:7956)
==4062== by 0xAD67D9: execute_ex (zend_vm_execute.h:363)
==4062== by 0xAD685E: zend_execute (zend_vm_execute.h:388)
==4062== by 0xA91EB9: zend_execute_scripts (zend.c:1341)
==4062== by 0x9FBC55: php_execute_script (main.c:2584)
==4062== by 0xB4618E: do_cli (php_cli.c:994)
==4062== by 0xB47239: main (php_cli.c:1378)
==4062==
string(7) "default"
------------------------------------------------------------------------
[2015-02-12 09:29:48] php at bof dot de
BTW, same valgrind result (a bit shorter backtrace) after disabling xdebug and any extension other
than opcache.
Disabling opcache also, removes the issue, shows foo+foo and no valgrind noise.
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=69038
--
Edit this bug report at https://bugs.php.net/bug.php?id=69038&edit=1