Edit report at https://bugs.php.net/bug.php?id=69674&edit=1
ID: 69674
Updated by: laruence@php.net
Reported by: opitz dot alexander at googlemail dot com
Summary: SIGSEGV array.c:953
-Status: Verified
+Status: Closed
Type: Bug
Package: *General Issues
Operating System: *
PHP Version: 7.0.0beta2
Assigned To: laruence
Block user comment: N
Private report: N
New Comment:
Automatic comment on behalf of laruence
Revision: http://git.php.net/?p=php-src.git;a=commit;h=7d5fb7bbf3c27017fa3bed462474aaa8d4746e72
Log: Fixed bug #69674 (SIGSEGV array.c:953)
Previous Comments:
------------------------------------------------------------------------
[2015-07-28 21:51:21] cmb@php.net
It seems that's a general issue in ZEND_HASH_FILL_END[1], where
nInternalPointer is always set to zero, instead of 0xffffffff for
empty arrays (see the attached patch "ZEND_HASH_FILL_END").
[1] <https://github.com/php/php-src/blob/php-7.0.0beta2/Zend/zend_hash.h#L887>
------------------------------------------------------------------------
[2015-07-28 21:49:13] cmb@php.net
The following patch has been added/updated:
Patch Name: ZEND_HASH_FILL_END
Revision: 1438120153
URL: https://bugs.php.net/patch-display.php?bug=69674&patch=ZEND_HASH_FILL_END&revision=1438120153
------------------------------------------------------------------------
[2015-07-28 21:10:20] cmb@php.net
Thanks for the reproduce script. I can confirm the segfault on
Windows and Linux.
For some reason when current() is called the second time,
array->htInternalPointer == 0 for the empty array (instead of
0xffffffff), so zend_hash_get_current_data() returns an
uninitialized entry instead of NULL.
Laruence, could you please have a look at this issue.
------------------------------------------------------------------------
[2015-07-28 11:43:46] opitz dot alexander at googlemail dot com
This issue still exists with beta2.
What is needed to get this fixed?
------------------------------------------------------------------------
[2015-06-23 14:30:33] opitz dot alexander at googlemail dot com
Output of other PHP versions:
http://3v4l.org/UO3aI
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=69674
--
Edit this bug report at https://bugs.php.net/bug.php?id=69674&edit=1