Bug #70111 [NEW]: Segfault when a function uses both an explicit return type and an explicit cast
| From: | malte dot skoruppa at gmail dot com | Date: | Wed, 22 Jul 2015 10:31:28 +0000 |
| Subject: | Bug #70111 [NEW]: Segfault when a function uses both an explicit return type and an explicit cast | ||
| Groups: | php.bugs | ||
| Request: | Send a blank email to php-bugs+get-194610@lists.php.net to get a copy of this message | ||
From: malte dot skoruppa at gmail dot com
Operating system: Ubuntu 14.04 LTS
PHP version: 7.0Git-2015-07-22 (Git)
Package: Reproducible crash
Bug Type: Bug
Bug description:Segfault when a function uses both an explicit return type and an explicit cast
Description:
------------
When a function both
* specifies an explicit return type
* AND uses an explicit cast of the return value,
then the PHP interpreter segfaults non-deterministically with high
probability.
To reproduce, execute the following script with the PHP interpreter
several times in a row. Sometimes it works, sometimes it segfaults.
Test script:
---------------
<?php
foo();
function foo() : string {
return (string) 42;
}
Expected result:
----------------
PHP interpreter should not crash, no matter how many times the script is
run.
Actual result:
--------------
The PHP interpreter segfaults when running this script. Not always, but
very often:
$ php crash.php
Segmentation fault (core dumped)
gdb backtrace:
Core was generated by `php crash.php'.
Program terminated with signal SIGSEGV, Segmentation fault.
#0 0x0000000000000000 in ?? ()
(gdb) bt
#0 0x0000000000000000 in ?? ()
#1 0x0000000000888c20 in execute_ex (ex=0x7fa8daa14030) at
/home/malte/php7/php-src/Zend/zend_vm_execute.h:406
#2 0x0000000000888d32 in zend_execute (op_array=0x7fa8daa75100,
return_value=0x0) at
/home/malte/php7/php-src/Zend/zend_vm_execute.h:450
#3 0x000000000082ee86 in zend_execute_scripts (type=8, retval=0x0,
file_count=3) at /home/malte/php7/php-src/Zend/zend.c:1399
#4 0x000000000079aefc in php_execute_script
(primary_file=0x7ffdb976c850) at
/home/malte/php7/php-src/main/main.c:2475
#5 0x00000000008ec6ac in do_cli (argc=2, argv=0x2f6b0e0) at
/home/malte/php7/php-src/sapi/cli/php_cli.c:971
#6 0x00000000008ed870 in main (argc=2, argv=0x2f6b0e0) at
/home/malte/php7/php-src/sapi/cli/php_cli.c:1338
--
Edit bug report at https://bugs.php.net/bug.php?id=70111&edit=1
--
Try a snapshot (PHP 5.4): https://bugs.php.net/fix.php?id=70111&r=trysnapshot54
Try a snapshot (PHP 5.5): https://bugs.php.net/fix.php?id=70111&r=trysnapshot55
Try a snapshot (trunk): https://bugs.php.net/fix.php?id=70111&r=trysnapshottrunk
Fixed in SVN: https://bugs.php.net/fix.php?id=70111&r=fixed
Fixed in release: https://bugs.php.net/fix.php?id=70111&r=alreadyfixed
Need backtrace: https://bugs.php.net/fix.php?id=70111&r=needtrace
Need Reproduce Script: https://bugs.php.net/fix.php?id=70111&r=needscript
Try newer version: https://bugs.php.net/fix.php?id=70111&r=oldversion
Not developer issue: https://bugs.php.net/fix.php?id=70111&r=support
Expected behavior: https://bugs.php.net/fix.php?id=70111&r=notwrong
Not enough info: https://bugs.php.net/fix.php?id=70111&r=notenoughinfo
Submitted twice: https://bugs.php.net/fix.php?id=70111&r=submittedtwice
register_globals: https://bugs.php.net/fix.php?id=70111&r=globals
PHP 4 support discontinued: https://bugs.php.net/fix.php?id=70111&r=php4
Daylight Savings: https://bugs.php.net/fix.php?id=70111&r=dst
IIS Stability: https://bugs.php.net/fix.php?id=70111&r=isapi
Install GNU Sed: https://bugs.php.net/fix.php?id=70111&r=gnused
Floating point limitations: https://bugs.php.net/fix.php?id=70111&r=float
No Zend Extensions: https://bugs.php.net/fix.php?id=70111&r=nozend
MySQL Configuration Error: https://bugs.php.net/fix.php?id=70111&r=mysqlcfg