Bug #69674 [Csd]: SIGSEGV array.c:953

From: Date: Wed, 29 Jul 2015 08:09:49 +0000
Subject: Bug #69674 [Csd]: SIGSEGV array.c:953
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-194805@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=69674&edit=1

 ID:                 69674
 User updated by:    opitz dot alexander at googlemail dot com
 Reported by:        opitz dot alexander at googlemail dot com
 Summary:            SIGSEGV array.c:953
 Status:             Closed
 Type:               Bug
 Package:            *General Issues
 Operating System:   *
 PHP Version:        7.0.0beta2
 Assigned To:        laruence
 Block user comment: N
 Private report:     N

 New Comment:

Verified, works now. Many Thanks.


Previous Comments:
------------------------------------------------------------------------
[2015-07-29 02:59:50] laruence@php.net

@cmb, thanks the patch looks fine. I committed it here: https://github.com/php/php-src/commit/7d5fb7bbf3c27017fa3bed462474aaa8d4746e72

------------------------------------------------------------------------
[2015-07-29 02:55:38] laruence@php.net

Automatic comment on behalf of laruence
Revision: http://git.php.net/?p=php-src.git;a=commit;h=7d5fb7bbf3c27017fa3bed462474aaa8d4746e72
Log: Fixed bug #69674 (SIGSEGV array.c:953)

------------------------------------------------------------------------
[2015-07-28 21:51:21] cmb@php.net

It seems that's a general issue in ZEND_HASH_FILL_END[1], where
nInternalPointer is always set to zero, instead of 0xffffffff for
empty arrays (see the attached patch "ZEND_HASH_FILL_END").

[1] <https://github.com/php/php-src/blob/php-7.0.0beta2/Zend/zend_hash.h#L887>

------------------------------------------------------------------------
[2015-07-28 21:49:13] cmb@php.net

The following patch has been added/updated:

Patch Name: ZEND_HASH_FILL_END
Revision:   1438120153
URL:        https://bugs.php.net/patch-display.php?bug=69674&patch=ZEND_HASH_FILL_END&revision=1438120153

------------------------------------------------------------------------
[2015-07-28 21:10:20] cmb@php.net

Thanks for the reproduce script. I can confirm the segfault on
Windows and Linux.

For some reason when current() is called the second time,
array->htInternalPointer == 0 for the empty array (instead of
0xffffffff), so zend_hash_get_current_data() returns an
uninitialized entry instead of NULL.

Laruence, could you please have a look at this issue.

------------------------------------------------------------------------


The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at

    https://bugs.php.net/bug.php?id=69674


--
Edit this bug report at https://bugs.php.net/bug.php?id=69674&edit=1


Thread (16 messages)

« previous php.bugs (#194805) next »