Bug #70262 [Com]: Accessing array crashes PHP 7.0beta3
Edit report at https://bugs.php.net/bug.php?id=70262&edit=1
ID: 70262
Comment by: bugs dot php dot net at majkl578 dot cz
Reported by: pavel dot kouril at hotmail dot com
Summary: Accessing array crashes PHP 7.0beta3
Status: Closed
Type: Bug
Package: Reproducible crash
Operating System: Windows, Linux
PHP Version: 7.0.0beta3
Assigned To: laruence
Block user comment: N
Private report: N
New Comment:
Hi,
I'm afraid the original issue has not been fixed by ce89fd9758.
I recompiled master with this commit and I am not seeing crashes with Laruence's code, but I am
still getting segfaults in zend_hash_index_find_bucket with the original repro script
(https://github.com/pavelkouril/php7-sigsegv). :(
Previous Comments:
------------------------------------------------------------------------
[2015-08-17 09:58:41] dmitry@php.net
Automatic comment on behalf of dmitry@zend.com
Revision: http://git.php.net/?p=php-src.git;a=commit;h=ce89fd9758fffd6c4bffca130829734ac3fca8ec
Log: Fixed bug #70262 (Accessing array crashes PHP 7.0beta3)
------------------------------------------------------------------------
[2015-08-16 07:02:06] laruence@php.net
yes, they behavior different result(double free result undefined behavior), but they have the both
same root cause.. ;)
I need find out the root cause first, then can according to that made a simpler reproduce case..
------------------------------------------------------------------------
[2015-08-15 15:37:05] bugs dot php dot net at majkl578 dot cz
Hi laruence,
the original repro script (the php7-sigsegv repo) crashed with a regular sigsegv while your repro
script ends prematurely for me (7.0.0beta3 DEBUG without your patch) with the following assert:
php: Zend/zend_gc.c:226: void gc_possible_root(zend_refcounted *): Assertion
`((zend_refcounted*)(ref))->u.v.type == 7 || ((zend_refcounted*)(ref))->u.v.type == 8'
failed.
Anyway, your patch fixed both. :)
Thanks for your awesome work, these issues are always PITA...
------------------------------------------------------------------------
[2015-08-15 15:25:13] pavel dot kouril at hotmail dot com
I compiled PHP on Windows with your change and the application now works - thanks a lot!
------------------------------------------------------------------------
[2015-08-15 11:26:34] laruence@php.net
This was really a tough one to figure out the root cause :<
after all, I finally get the reason, and made a simple reproduce case:
<?php
class C {
public $arguments;
public function __construct($arg) {
$this->arguments = $arg;
}
}
function & a(&$arg) {
$c = new C($arg);
$arg[] = $c;
return $c;
}
function c($arr) {
a($arr)->arguments[0] = "bad";
}
$arr = array();
$arr[] = "foo";
$arr[] = "bar";
c($arr);
var_dump($arr);
?>
and a fix might be: https://gist.github.com/laruence/848e69d0a43846b61d26
all tests is passed....
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=70262
--
Edit this bug report at https://bugs.php.net/bug.php?id=70262&edit=1
Thread (8 messages)