Bug #69674 [Opn->Ver]: SIGSEGV array.c:953
| From: | cmb@php.net | Date: | Tue, 28 Jul 2015 21:10:20 +0000 |
| Subject: | Bug #69674 [Opn->Ver]: SIGSEGV array.c:953 | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-194791@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=69674&edit=1
ID: 69674
Updated by: cmb@php.net
Reported by: opitz dot alexander at googlemail dot com
Summary: SIGSEGV array.c:953
-Status: Open
+Status: Verified
Type: Bug
Package: *General Issues
-Operating System: Linux
+Operating System: *
PHP Version: 7.0.0beta2
-Assigned To:
+Assigned To: laruence
Block user comment: N
Private report: N
New Comment:
Thanks for the reproduce script. I can confirm the segfault on
Windows and Linux.
For some reason when current() is called the second time,
array->htInternalPointer == 0 for the empty array (instead of
0xffffffff), so zend_hash_get_current_data() returns an
uninitialized entry instead of NULL.
Laruence, could you please have a look at this issue.
Previous Comments:
------------------------------------------------------------------------
[2015-07-28 11:43:46] opitz dot alexander at googlemail dot com
This issue still exists with beta2.
What is needed to get this fixed?
------------------------------------------------------------------------
[2015-06-23 14:30:33] opitz dot alexander at googlemail dot com
Output of other PHP versions:
http://3v4l.org/UO3aI
------------------------------------------------------------------------
[2015-06-23 13:38:33] opitz dot alexander at googlemail dot com
Snippet to crash PHP7.
Without the unset, $var isn't changed and returns same content as before.
If array is empty in the first assignment you get a notice that $var is an uninitialized var.
<?php
$configuration = array(
'controllerConfiguration' => array(
'TheFirstController' => array(
),
)
);
$var = current(array_keys($configuration['controllerConfiguration']));
var_dump($var);
unset($configuration['controllerConfiguration']['TheFirstController']);
$configuration['controllerConfiguration'] = array();
$var = current(array_keys($configuration['controllerConfiguration']));
var_dump($var);
------------------------------------------------------------------------
[2015-06-23 13:26:19] opitz dot alexander at googlemail dot com
Dragged this down a bit further.
The crash happens on following line:
https://github.com/TYPO3/TYPO3.CMS/blob/master/typo3/sysext/extbase/Classes/Mvc/Web/RequestBuilder.php#L110
$this->defaultControllerName =
current(array_keys($configuration['controllerConfiguration']));
in the crashing test, this is an empty array. But trying this in a 10 lines test doesn't fail.
------------------------------------------------------------------------
[2015-06-05 12:18:20] opitz dot alexander at googlemail dot com
Example of output for running the tests.
https://travis-ci.org/TYPO3/TYPO3.CMS/jobs/65556246
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=69674
--
Edit this bug report at https://bugs.php.net/bug.php?id=69674&edit=1