Bug #69373 [NEW]: References to deleted XPath query results
| From: | ttoohey@php.net | Date: | Sat, 04 Apr 2015 01:42:13 +0000 |
| Subject: | Bug #69373 [NEW]: References to deleted XPath query results | ||
| Groups: | php.bugs | ||
| Request: | Send a blank email to php-bugs+get-191812@lists.php.net to get a copy of this message | ||
From: ttoohey@php.net
Operating system: Linux
PHP version: master-Git-2015-04-04 (Git)
Package: DOM XML related
Bug Type: Bug
Bug description:References to deleted XPath query results
Description:
------------
Creating a node list using the DOMXPath query() or evaluate() functions,
then removing the nodes from the document by writing to nodeValue of an
ancestor occasionally results in "double free or corruption" or
"Segmentation fault". It can also result in the nodeValue text content
being cropped.
Test script:
---------------
$doc = new DOMDocument();
for( $i=0; $i<20; $i++ ) {
$doc->loadXML("<parent><child /><child /></parent>");
$xpath = new DOMXpath($doc);
$all = $xpath->query('//*');
$doc->firstChild->nodeValue = '';
}
Actual result:
--------------
#0 0x00007ffff698e107 in __GI_raise (sig=sig@entry=6) at
../nptl/sysdeps/unix/sysv/linux/raise.c:56
#1 0x00007ffff698f4e8 in __GI_abort () at abort.c:89
#2 0x00007ffff69cc204 in __libc_message (do_abort=do_abort@entry=1,
fmt=fmt@entry=0x7ffff6abefe0 "*** Error in `%s': %s: 0x%s ***\n")
at ../sysdeps/posix/libc_fatal.c:175
#3 0x00007ffff69d19de in malloc_printerr (action=1, str=0x7ffff6abb09e
"free(): invalid pointer", ptr=<optimized out>) at malloc.c:4996
#4 0x00007ffff69d26e6 in _int_free (av=<optimized out>, p=<optimized
out>, have_lock=0) at malloc.c:3840
#5 0x0000000000454bc8 in php_libxml_node_decrement_resource
(object=0x68f1) at /tmp/php-src/ext/libxml/libxml.c:1330
#6 0x000000000052e785 in dom_objects_free_storage
(object=0x7ffff606d218) at /tmp/php-src/ext/dom/php_dom.c:1045
#7 0x0000000000702992 in zend_objects_store_del (object=0x68f1) at
/tmp/php-src/Zend/zend_objects_API.c:181
#8 0x00000000006d818b in i_zval_ptr_dtor (zval_ptr=0x7ffff605e908) at
/tmp/php-src/Zend/zend_variables.h:57
#9 zend_array_destroy (ht=0x7ffff6057268) at
/tmp/php-src/Zend/zend_hash.c:1179
#10 0x000000000052df71 in dom_nnodemap_object_dtor
(object=0x7ffff606d1d8) at /tmp/php-src/ext/dom/php_dom.c:1136
#11 0x00000000007029ac in zend_objects_store_del (object=0x68f1) at
/tmp/php-src/Zend/zend_objects_API.c:163
#12 0x0000000000719b63 in zend_assign_to_variable (value_type=4 '\004',
value=0x7ffff6014150, variable_ptr=0x7ffff60140c0)
at /tmp/php-src/Zend/zend_execute.h:102
#13 ZEND_ASSIGN_SPEC_CV_VAR_HANDLER () at
/tmp/php-src/Zend/zend_vm_execute.h:31935
#14 0x0000000000707a1b in execute_ex (ex=<optimized out>) at
/tmp/php-src/Zend/zend_vm_execute.h:394
#15 0x00000000006c73d5 in zend_execute_scripts (type=26865,
type@entry=8, retval=0x68f1, retval@entry=0x0, file_count=6,
file_count@entry=3)
at /tmp/php-src/Zend/zend.c:1364
#16 0x000000000066cf68 in php_execute_script
(primary_file=0x7fffffffcf20) at /tmp/php-src/main/main.c:2481
#17 0x000000000075f2da in do_cli (argc=26865, argv=0x68f1) at
/tmp/php-src/sapi/cli/php_cli.c:967
#18 0x0000000000426c47 in main (argc=26865, argv=0x68f1) at
/tmp/php-src/sapi/cli/php_cli.c:1334
--
Edit bug report at https://bugs.php.net/bug.php?id=69373&edit=1
--
Try a snapshot (PHP 5.4): https://bugs.php.net/fix.php?id=69373&r=trysnapshot54
Try a snapshot (PHP 5.5): https://bugs.php.net/fix.php?id=69373&r=trysnapshot55
Try a snapshot (trunk): https://bugs.php.net/fix.php?id=69373&r=trysnapshottrunk
Fixed in SVN: https://bugs.php.net/fix.php?id=69373&r=fixed
Fixed in release: https://bugs.php.net/fix.php?id=69373&r=alreadyfixed
Need backtrace: https://bugs.php.net/fix.php?id=69373&r=needtrace
Need Reproduce Script: https://bugs.php.net/fix.php?id=69373&r=needscript
Try newer version: https://bugs.php.net/fix.php?id=69373&r=oldversion
Not developer issue: https://bugs.php.net/fix.php?id=69373&r=support
Expected behavior: https://bugs.php.net/fix.php?id=69373&r=notwrong
Not enough info: https://bugs.php.net/fix.php?id=69373&r=notenoughinfo
Submitted twice: https://bugs.php.net/fix.php?id=69373&r=submittedtwice
register_globals: https://bugs.php.net/fix.php?id=69373&r=globals
PHP 4 support discontinued: https://bugs.php.net/fix.php?id=69373&r=php4
Daylight Savings: https://bugs.php.net/fix.php?id=69373&r=dst
IIS Stability: https://bugs.php.net/fix.php?id=69373&r=isapi
Install GNU Sed: https://bugs.php.net/fix.php?id=69373&r=gnused
Floating point limitations: https://bugs.php.net/fix.php?id=69373&r=float
No Zend Extensions: https://bugs.php.net/fix.php?id=69373&r=nozend
MySQL Configuration Error: https://bugs.php.net/fix.php?id=69373&r=mysqlcfg