Bug #69846 [Opn]: Segmenation fault (access violation) when iterating over DOMNodeList

From: Date: Tue, 16 Jun 2015 12:34:46 +0000
Subject: Bug #69846 [Opn]: Segmenation fault (access violation) when iterating over DOMNodeList
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-193560@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=69846&edit=1

 ID:                 69846
 User updated by:    jan dot slabon at setasign dot com
 Reported by:        jan dot slabon at setasign dot com
 Summary:            Segmenation fault (access violation) when iterating
                     over DOMNodeList
 Status:             Open
 Type:               Bug
 Package:            Reproducible crash
 Operating System:   Windows 7 Pro (x64)
 PHP Version:        7.0.0alpha1
 Block user comment: N
 Private report:     N

 New Comment:

I just send a reproduce case to ab@php.net.


Previous Comments:
------------------------------------------------------------------------
[2015-06-16 10:47:53] jan dot slabon at setasign dot com

While I am trying to reproduce it, its behaviour becomes much more strange: Yesterday evening the
crash was reproducible with a test item no 13. Today it's 10...

I am going to clean-up the whole package so I only left the files which are needed to reproduce this
issue. Anyhow I would please you to confirm that these files are not being used further or made
public, because they are part of proprietary products. I can send it to ab@php.net?

------------------------------------------------------------------------
[2015-06-16 10:03:49] ab@php.net

Thanks for the dump. Maybe it'll help if i say that the crash happens in
SetaPDF_FormFiller_XfaTest, maybe it needs some more stress for a reproduce. But i'll dig
further in the meanwhile.

Thanks.

------------------------------------------------------------------------
[2015-06-16 07:53:34] jan dot slabon at setasign dot com

Here's the log and dump:
https://www.setasign.com/files/php.net/69846/php__PID__8788__Date__06_15_2015__Time_11_06_27PM__48__Log.txt
https://www.setasign.com/files/php.net/69846/php__PID__8788__Date__06_15_2015__Time_11_06_29PM__945__Second_Chance_Exception_C0000005.dmp

I am going to investigate further to see if we have a chance to extract a reproduce case. As it
seems to be a memory problem it simply relies on other (absolutely independent) code. Running the
test alone works. Running two tests in a folder will crash...

------------------------------------------------------------------------
[2015-06-16 07:38:45] ab@php.net

Thanks for the report. Yep, a dump were useful.

Also an idea - if it is only reproduceable with phpunit, maybe it could make sense to create a suite
with just that one unit test as a reproduce case (of course if it does repro then)?

Thanks.

------------------------------------------------------------------------
[2015-06-16 07:04:59] jan dot slabon at setasign dot com

Description:
------------
I'm using the "VC14 x64 Thread Safe" version with following extensions enabled:
extension=php_mbstring.dll
extension=php_openssl.dll
extension=php_pdo_mysql.dll
extension=php_pdo_sqlite.dll
extension=php_soap.dll
extension=php_sqlite3.dll

I encounter a problem when iterating over a DOMNodeList object while overwriting the $value:

foreach ($dataNodes AS $node) {
    $node = $datasetDom->importNode($node, true);
    // ...
}

Actually I'm not able to reproduce this separated from our unit tests but at least I have a
backtrace (that's what I get, if I follow this guide: https://bugs.php.net/bugs-generating-backtrace-win32.php)
- see actual result.

I can provide the full dump if necessary.

The behaviour is very strange because it can be manipulated/suppressed by simply removing an entry
from another array in another scope which will never be used. Or by simply running the test wihout
another which are absolutely independed from each other.

Actual result:
--------------
Thread report

Thread 0 - System ID 8580

Entry point
  php!mainCRTStartup
Create time
  15.06.2015 23:06:26

Time spent in user mode
  0 Days 00:00:00.093

Time spent in kernel mode
  0 Days 00:00:00.312


Function
php7ts!php_dom_create_object+36
php7ts!php_dom_iterator_move_forward+154
php7ts!ZEND_FE_FETCH_R_SPEC_VAR_HANDLER+206
php7ts!execute_ex+38
php7ts!zend_call_function+367bd3
php7ts!zim_reflection_method_invokeArgs+363
php7ts!ZEND_DO_FCALL_SPEC_HANDLER+10a
php7ts!execute_ex+38
php7ts!zend_execute+1db
php7ts!zend_execute_scripts+13e
php7ts!php_execute_script+521
php!do_cli+73c
php!main+400
php!__scrt_common_main_seh+124
kernel32!BaseThreadInitThunk+d
ntdll!RtlUserThreadStart+1d

Exception Information

PHP7TS!PHP_DOM_CREATE_OBJECT+36In
php__PID__8788__Date__06_15_2015__Time_11_06_29PM__945__Second_Chance_Exception_C0000005.dmp the
assembly instruction at php7ts!php_dom_create_object+36 in C:\php 7.0.0alpha1\php7ts.dll from The
PHP Group has caused an access violation exception (0xC0000005) when trying to read from memory
location 0x00000000 on thread 0


------------------------------------------------------------------------



--
Edit this bug report at https://bugs.php.net/bug.php?id=69846&edit=1


Thread (13 messages)

« previous php.bugs (#193560) next »