Bug #69674 [PATCH]: SIGSEGV array.c:953

From: Date: Tue, 28 Jul 2015 21:49:14 +0000
Subject: Bug #69674 [PATCH]: SIGSEGV array.c:953
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-194792@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=69674&edit=1

 ID:                 69674
 Patch added by:     cmb@php.net
 Reported by:        opitz dot alexander at googlemail dot com
 Summary:            SIGSEGV array.c:953
 Status:             Verified
 Type:               Bug
 Package:            *General Issues
 Operating System:   *
 PHP Version:        7.0.0beta2
 Assigned To:        laruence
 Block user comment: N
 Private report:     N

 New Comment:

The following patch has been added/updated:

Patch Name: ZEND_HASH_FILL_END
Revision:   1438120153
URL:        https://bugs.php.net/patch-display.php?bug=69674&patch=ZEND_HASH_FILL_END&revision=1438120153


Previous Comments:
------------------------------------------------------------------------
[2015-07-28 21:10:20] cmb@php.net

Thanks for the reproduce script. I can confirm the segfault on
Windows and Linux.

For some reason when current() is called the second time,
array->htInternalPointer == 0 for the empty array (instead of
0xffffffff), so zend_hash_get_current_data() returns an
uninitialized entry instead of NULL.

Laruence, could you please have a look at this issue.

------------------------------------------------------------------------
[2015-07-28 11:43:46] opitz dot alexander at googlemail dot com

This issue still exists with beta2.
What is needed to get this fixed?

------------------------------------------------------------------------
[2015-06-23 14:30:33] opitz dot alexander at googlemail dot com

Output of other PHP versions:

http://3v4l.org/UO3aI

------------------------------------------------------------------------
[2015-06-23 13:38:33] opitz dot alexander at googlemail dot com

Snippet to crash PHP7.

Without the unset, $var isn't changed and returns same content as before.
If array is empty in the first assignment you get a notice that $var is an uninitialized var.

<?php
    $configuration = array(
        'controllerConfiguration' => array(
            'TheFirstController' => array(
            ),
        )
    );
    $var = current(array_keys($configuration['controllerConfiguration']));
    var_dump($var);

    unset($configuration['controllerConfiguration']['TheFirstController']);

    $configuration['controllerConfiguration'] = array();
    $var = current(array_keys($configuration['controllerConfiguration']));
    var_dump($var);

------------------------------------------------------------------------
[2015-06-23 13:26:19] opitz dot alexander at googlemail dot com

Dragged this down a bit further.

The crash happens on following line:
https://github.com/TYPO3/TYPO3.CMS/blob/master/typo3/sysext/extbase/Classes/Mvc/Web/RequestBuilder.php#L110

$this->defaultControllerName =
current(array_keys($configuration['controllerConfiguration']));

in the crashing test, this is an empty array. But trying this in a 10 lines test doesn't fail.

------------------------------------------------------------------------


The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at

    https://bugs.php.net/bug.php?id=69674


--
Edit this bug report at https://bugs.php.net/bug.php?id=69674&edit=1


Thread (16 messages)

« previous php.bugs (#194792) next »