Bug #70616 [NEW]: SIGSEGV while lex_scan-ning

From: Date: Thu, 01 Oct 2015 18:56:00 +0000
Subject: Bug #70616 [NEW]: SIGSEGV while lex_scan-ning
Groups: php.bugs 
Request: Send a blank email to php-bugs+get-196334@lists.php.net to get a copy of this message
From:             roctom at gmail dot com
Operating system: Windows 7
PHP version:      5.6.13
Package:          Reproducible crash
Bug Type:         Bug
Bug description:SIGSEGV while lex_scan-ning

Description:
------------
Under cygwin:

PHP 5.6.13 (cli) (built: Sep  4 2015 12:40:08)
Copyright (c) 1997-2015 The PHP Group
Zend Engine v2.6.0, Copyright (c) 1998-2015 Zend Technologies

I get the following reproducible SIGSEGV after installing the
phpunit/phpunit package.



Test script:
---------------
In a composer.json file

{
	"require": {
		"phpunit/phpunit": "~4"
	}
}

Then run php composer.phar install. It should segfault just after you
can read "Generating autoload files".

Expected result:
----------------
No "Program received signal SIGSEGV, Segmentation fault.".

The program completes without crashing.

Actual result:
--------------
Here is a backtrace in gdb:

Program received signal SIGSEGV, Segmentation fault.
lex_scan (zendlval=zendlval@entry=0x228cd0) at
Zend/zend_language_scanner.c:2636
2636    Zend/zend_language_scanner.c: No such file or directory.
(gdb) bt
#0  lex_scan (zendlval=zendlval@entry=0x228cd0) at
Zend/zend_language_scanner.c:2636
#1  0x00000003f689a69c in zend_strip () at
/usr/src/debug/php-5.6.13-1/Zend/zend_highlight.c:174
#2  0x00000003f67c056a in zif_php_strip_whitespace (ht=<optimized out>,
return_value=0x6fffeff2798, return_value_ptr=<optimized out>,
this_ptr=<optimized out>, return_value_used=1)
    at /usr/src/debug/php-5.6.13-1/ext/standard/basic_functions.c:5241
#3  0x00000003f694c66c in zend_do_fcall_common_helper_SPEC
(execute_data=<optimized out>) at
/usr/src/debug/php-5.6.13-1/Zend/zend_vm_execute.h:558
#4  0x00000003f68dcb58 in execute_ex (execute_data=0x6fffffbe2f0) at
/usr/src/debug/php-5.6.13-1/Zend/zend_vm_execute.h:363
#5  0x00000003f68a80ed in zend_execute_scripts (type=8, retval=0x0,
file_count=3) at /usr/src/debug/php-5.6.13-1/Zend/zend.c:1341
#6  0x00000003f6845c8a in php_execute_script (primary_file=0x22b858) at
/usr/src/debug/php-5.6.13-1/main/main.c:2597
#7  0x0000000100402729 in do_cli (argc=3, argv=0x22cb10) at
/usr/src/debug/php-5.6.13-1/sapi/cli/php_cli.c:994
#8  0x000000010040b6fb in main (argc=3, argv=0x22cb10) at
/usr/src/debug/php-5.6.13-1/sapi/cli/php_cli.c:1378

The zval given to lex_scan:

(gdb) p *(zval *) 0x228cd0
$1 = {value = {lval = 7696551907325, dval = 3.802601888843204e-311, str
= {val = 0x6fffe3e0ffd "\n}\n"<error: Cannot access memory at address
0x6fffe3e1000>, len = 1}, ht = 0x6fffe3e0ffd,
    obj = {handle = 4265480189, handlers = 0x1}, ast = 0x6fffe3e0ffd},
refcount__gc = 4278048360, type = 0 '\000', is_ref__gc = 6 '\006'}


-- 
Edit bug report at https://bugs.php.net/bug.php?id=70616&edit=1
-- 
Try a snapshot (PHP 5.4):   https://bugs.php.net/fix.php?id=70616&r=trysnapshot54
Try a snapshot (PHP 5.5):   https://bugs.php.net/fix.php?id=70616&r=trysnapshot55
Try a snapshot (trunk):     https://bugs.php.net/fix.php?id=70616&r=trysnapshottrunk
Fixed in SVN:               https://bugs.php.net/fix.php?id=70616&r=fixed
Fixed in release:           https://bugs.php.net/fix.php?id=70616&r=alreadyfixed
Need backtrace:             https://bugs.php.net/fix.php?id=70616&r=needtrace
Need Reproduce Script:      https://bugs.php.net/fix.php?id=70616&r=needscript
Try newer version:          https://bugs.php.net/fix.php?id=70616&r=oldversion
Not developer issue:        https://bugs.php.net/fix.php?id=70616&r=support
Expected behavior:          https://bugs.php.net/fix.php?id=70616&r=notwrong
Not enough info:            https://bugs.php.net/fix.php?id=70616&r=notenoughinfo
Submitted twice:            https://bugs.php.net/fix.php?id=70616&r=submittedtwice
register_globals:           https://bugs.php.net/fix.php?id=70616&r=globals
PHP 4 support discontinued: https://bugs.php.net/fix.php?id=70616&r=php4
Daylight Savings:           https://bugs.php.net/fix.php?id=70616&r=dst
IIS Stability:              https://bugs.php.net/fix.php?id=70616&r=isapi
Install GNU Sed:            https://bugs.php.net/fix.php?id=70616&r=gnused
Floating point limitations: https://bugs.php.net/fix.php?id=70616&r=float
No Zend Extensions:         https://bugs.php.net/fix.php?id=70616&r=nozend
MySQL Configuration Error:  https://bugs.php.net/fix.php?id=70616&r=mysqlcfg



Thread (5 messages)

« previous php.bugs (#196334) next »