Bug #69955 [Asn->Csd]: Segfault when trying to combine [] and assign-op on ArrayAccess object

From: Date: Mon, 29 Jun 2015 08:18:23 +0000
Subject: Bug #69955 [Asn->Csd]: Segfault when trying to combine [] and assign-op on ArrayAccess object
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-193981@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=69955&edit=1 ID: 69955 Updated by: dmitry@php.net Reported by: stas@php.net Summary: Segfault when trying to combine [] and assign-op on ArrayAccess object -Status: Assigned +Status: Closed Type: Bug Package: Reproducible crash Operating System: * PHP Version: 7.0Git-2015-06-28 (Git) Assigned To: dmitry Block user comment: N Private report: N New Comment: Automatic comment on behalf of dmitry@zend.com Revision: http://git.php.net/?p=php-src.git;a=commit;h=8e923197b48a200eb7cdb0f07d5e7d1a6533b12d Log: Fixed bug #69955 (Segfault when trying to combine [] and assign-op on ArrayAccess object). (Laruence) Previous Comments: ------------------------------------------------------------------------ [2015-06-28 11:04:37] laruence@php.net seems we should always have this: diff --git a/Zend/zend_vm_def.h b/Zend/zend_vm_def.h index 933be83..be9b012 100644 --- a/Zend/zend_vm_def.h +++ b/Zend/zend_vm_def.h @@ -804,13 +804,11 @@ ZEND_VM_HELPER_EX(zend_binary_assign_op_dim_helper, VAR|UNUSED|CV, CONST|TMPVAR| if (OP1_TYPE != IS_UNUSED) { ZVAL_DEREF(container); } -#if !defined(ZEND_VM_SPEC) || (OP2_TYPE != IS_UNUSED) if (OP1_TYPE == IS_UNUSED || EXPECTED(Z_TYPE_P(container) == IS_OBJECT)) { value = get_zval_ptr((opline+1)->op1_type, (opline+1)->op1, execute_data, &free_op_data1 , BP_VAR_R); zend_binary_assign_op_obj_dim(container, dim, value, UNEXPECTED(RETURN_VALUE_USED(opline )) ? EX_VAR(opline->result.var) : NULL, binary_op); break; } -#endif } thanks ------------------------------------------------------------------------ [2015-06-28 09:17:43] laruence@php.net what I get is: Inside C10::offsetGet PHP Notice: Undefined variable: offset in /tmp/1.php on line 10 Notice: Undefined variable: offset in /tmp/1.php on line 10 NULL PHP Notice: Indirect modification of overloaded element of C10 has no effect in /tmp/1.php on line 24 Notice: Indirect modification of overloaded element of C10 has no effect in /tmp/1.php on line 24 php: /home/huixinchen/opensource/trunk/Zend/zend_vm_execute.h:34205: zend_binary_assign_op_dim_helper_SPEC_CV_UNUSED: Assertion `zval_get_type(&(rv)) == 15' failed. Aborted (core dumped) and zend_fetch_dimension_address_RW may really don't return a IS_INDRECT value. thanks ------------------------------------------------------------------------ [2015-06-28 05:20:30] stas@php.net Description: ------------ When applying assign-operator (like +=) to result of $a[] when $a is an object implementing ArrayAccess, segfault happens. Test script: --------------- <?php class C10 implements ArrayAccess { function offsetExists($offset) { echo "\nInside " . __METHOD__ . "\n"; var_dump($offset); } function offsetGet($offset) { echo "\nInside " . __METHOD__ . "\n"; var_dump($offset); return 100; } function offsetSet($offset, $value) { echo "\nInside " . __METHOD__ . "\n"; var_dump($offset); var_dump($value); } function offsetUnset($offset) { echo "\nInside " . __METHOD__ . "\n"; var_dump($offset); } } $c10 = new C10; var_dump($c10[] += 5); Expected result: ---------------- No segfault Actual result: -------------- Inside C10::offsetGet NULL Segmentation fault: 11 ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=69955&edit=1

« previous php.bugs (#193981) next »