Bug #70111 [Asn->Csd]: Segfault when a function uses both an explicit return type and an explicit cast

From: Date: Wed, 22 Jul 2015 14:48:34 +0000
Subject: Bug #70111 [Asn->Csd]: Segfault when a function uses both an explicit return type and an explicit cast
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-194632@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=70111&edit=1

 ID:                 70111
 Updated by:         laruence@php.net
 Reported by:        malte dot skoruppa at gmail dot com
 Summary:            Segfault when a function uses both an explicit
                     return type and an explicit cast
-Status:             Assigned
+Status:             Closed
 Type:               Bug
 Package:            Reproducible crash
 Operating System:   Ubuntu 14.04 LTS
 PHP Version:        7.0Git-2015-07-22 (Git)
 Assigned To:        laruence
 Block user comment: N
 Private report:     N

 New Comment:

Automatic comment on behalf of laruence
Revision: http://git.php.net/?p=php-src.git;a=commit;h=3e479ef424b2193f41a28fda18bde076a79ea71e
Log: Fixed bug #70111 (Segfault when a function uses both an explicit return type and an explicit
cast)


Previous Comments:
------------------------------------------------------------------------
[2015-07-22 11:30:21] laruence@php.net

this is an opcache issue...

------------------------------------------------------------------------
[2015-07-22 10:31:27] malte dot skoruppa at gmail dot com

Description:
------------
When a function both
* specifies an explicit return type
* AND uses an explicit cast of the return value,
then the PHP interpreter segfaults non-deterministically with high probability.

To reproduce, execute the following script with the PHP interpreter several times in a row.
Sometimes it works, sometimes it segfaults.


Test script:
---------------
<?php

foo();

function foo() : string {
  return (string) 42;
}


Expected result:
----------------
PHP interpreter should not crash, no matter how many times the script is run.


Actual result:
--------------
The PHP interpreter segfaults when running this script. Not always, but very often:

$ php crash.php
Segmentation fault (core dumped)


gdb backtrace:

Core was generated by `php crash.php'.
Program terminated with signal SIGSEGV, Segmentation fault.
#0  0x0000000000000000 in ?? ()
(gdb) bt
#0  0x0000000000000000 in ?? ()
#1  0x0000000000888c20 in execute_ex (ex=0x7fa8daa14030) at
/home/malte/php7/php-src/Zend/zend_vm_execute.h:406
#2  0x0000000000888d32 in zend_execute (op_array=0x7fa8daa75100, return_value=0x0) at
/home/malte/php7/php-src/Zend/zend_vm_execute.h:450
#3  0x000000000082ee86 in zend_execute_scripts (type=8, retval=0x0, file_count=3) at
/home/malte/php7/php-src/Zend/zend.c:1399
#4  0x000000000079aefc in php_execute_script (primary_file=0x7ffdb976c850) at
/home/malte/php7/php-src/main/main.c:2475
#5  0x00000000008ec6ac in do_cli (argc=2, argv=0x2f6b0e0) at
/home/malte/php7/php-src/sapi/cli/php_cli.c:971
#6  0x00000000008ed870 in main (argc=2, argv=0x2f6b0e0) at
/home/malte/php7/php-src/sapi/cli/php_cli.c:1338



------------------------------------------------------------------------



--
Edit this bug report at https://bugs.php.net/bug.php?id=70111&edit=1


Thread (4 messages)

« previous php.bugs (#194632) next »