Bug #69955 [Asn->Csd]: Segfault when trying to combine [] and assign-op on ArrayAccess object
| From: | dmitry@php.net | Date: | Mon, 29 Jun 2015 08:18:23 +0000 |
| Subject: | Bug #69955 [Asn->Csd]: Segfault when trying to combine [] and assign-op on ArrayAccess object | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-193981@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=69955&edit=1
ID: 69955
Updated by: dmitry@php.net
Reported by: stas@php.net
Summary: Segfault when trying to combine [] and assign-op on
ArrayAccess object
-Status: Assigned
+Status: Closed
Type: Bug
Package: Reproducible crash
Operating System: *
PHP Version: 7.0Git-2015-06-28 (Git)
Assigned To: dmitry
Block user comment: N
Private report: N
New Comment:
Automatic comment on behalf of dmitry@zend.com
Revision: http://git.php.net/?p=php-src.git;a=commit;h=8e923197b48a200eb7cdb0f07d5e7d1a6533b12d
Log: Fixed bug #69955 (Segfault when trying to combine [] and assign-op on ArrayAccess object).
(Laruence)
Previous Comments:
------------------------------------------------------------------------
[2015-06-28 11:04:37] laruence@php.net
seems we should always have this:
diff --git a/Zend/zend_vm_def.h b/Zend/zend_vm_def.h
index 933be83..be9b012 100644
--- a/Zend/zend_vm_def.h
+++ b/Zend/zend_vm_def.h
@@ -804,13 +804,11 @@ ZEND_VM_HELPER_EX(zend_binary_assign_op_dim_helper, VAR|UNUSED|CV,
CONST|TMPVAR|
if (OP1_TYPE != IS_UNUSED) {
ZVAL_DEREF(container);
}
-#if !defined(ZEND_VM_SPEC) || (OP2_TYPE != IS_UNUSED)
if (OP1_TYPE == IS_UNUSED || EXPECTED(Z_TYPE_P(container) == IS_OBJECT)) {
value = get_zval_ptr((opline+1)->op1_type, (opline+1)->op1, execute_data,
&free_op_data1
, BP_VAR_R);
zend_binary_assign_op_obj_dim(container, dim, value, UNEXPECTED(RETURN_VALUE_USED(opline
)) ? EX_VAR(opline->result.var) : NULL, binary_op);
break;
}
-#endif
}
thanks
------------------------------------------------------------------------
[2015-06-28 09:17:43] laruence@php.net
what I get is:
Inside C10::offsetGet
PHP Notice: Undefined variable: offset in /tmp/1.php on line 10
Notice: Undefined variable: offset in /tmp/1.php on line 10
NULL
PHP Notice: Indirect modification of overloaded element of C10 has no effect in /tmp/1.php on line
24
Notice: Indirect modification of overloaded element of C10 has no effect in /tmp/1.php on line 24
php: /home/huixinchen/opensource/trunk/Zend/zend_vm_execute.h:34205:
zend_binary_assign_op_dim_helper_SPEC_CV_UNUSED: Assertion `zval_get_type(&(rv)) == 15'
failed.
Aborted (core dumped)
and zend_fetch_dimension_address_RW may really don't return a IS_INDRECT value.
thanks
------------------------------------------------------------------------
[2015-06-28 05:20:30] stas@php.net
Description:
------------
When applying assign-operator (like +=) to result of $a[] when $a is an object implementing
ArrayAccess, segfault happens.
Test script:
---------------
<?php
class C10 implements ArrayAccess
{
function offsetExists($offset)
{
echo "\nInside " . __METHOD__ . "\n"; var_dump($offset);
}
function offsetGet($offset)
{
echo "\nInside " . __METHOD__ . "\n"; var_dump($offset); return
100;
}
function offsetSet($offset, $value)
{
echo "\nInside " . __METHOD__ . "\n"; var_dump($offset);
var_dump($value);
}
function offsetUnset($offset)
{
echo "\nInside " . __METHOD__ . "\n"; var_dump($offset);
}
}
$c10 = new C10;
var_dump($c10[] += 5);
Expected result:
----------------
No segfault
Actual result:
--------------
Inside C10::offsetGet
NULL
Segmentation fault: 11
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=69955&edit=1