Bug #71337 [NEW]: zend_call_function will object and long function name make some strange problem

From: Date: Mon, 11 Jan 2016 14:35:12 +0000
Subject: Bug #71337 [NEW]: zend_call_function will object and long function name make some strange problem
Groups: php.bugs 
Request: Send a blank email to php-bugs+get-198569@lists.php.net to get a copy of this message
From:             hi at youmingdot dot com
Operating system: Ubuntu 14.04
PHP version:      7.0.2
Package:          Unknown/Other Function
Bug Type:         Bug
Bug description:zend_call_function will object and long function name make some strange problem

Description:
------------
When I use zend_call_function or other related function like
zend_call_method with a object to call object's method, I wrote code
like below. 
The function is defined in php script, and running goes fun, result of
the function is right. But at request stop with debug
zend_mm_check_leaks called, cause some exceptions (backtraces at
below).
I try to find the cause of it. And strange is it may be caused by the
name of function. When I call function with the length of it's name less
then 8 (like 'anyfunc'), everything is Ok, and none exception occurred.
Otherwise when the length of it's name more then 8 (like 'anyfunction'),
this error occur and make php stop with code 255.

Test script:
---------------
{
    zval *this = getThis();
    zend_string *class_name;

    ZEND_PARSE_PARAMETERS_START(1, 1)
        Z_PARAM_STR(class_name)
    ZEND_PARSE_PARAMETERS_END_EX(RETURN_FALSE);

    zval params[1], retval;
    int result;

    ZVAL_STR(&params[0], class_name);

    zend_call_method(this, Z_OBJCE_P(this), NULL,
ZEND_STRL("anyfunction"), &retval, 1, &params[0], NULL);

    zval_ptr_dtor(&retval);
    zval_ptr_dtor(&params[0]);

    if (result == FAILURE) {
        RETURN_FALSE;
    }

    RETURN_TRUE;
}

Actual result:
--------------
#0  0x00007ffff657faea in strlen () from
/lib/x86_64-linux-gnu/libc.so.6
#1  0x000000000081d1fa in format_converter (odp=0x7fffffffb4b0,
fmt=0xf27e29 "s(%d) :  Freeing 0x%.8lX (%zu bytes), script=%s\n",
ap=0x7fffffffb4f8) at
/home/youmingdot/Source/php-7.0.2/main/snprintf.c:993
#2  0x000000000081dc81 in strx_printv (ccp=0x7fffffffb4f4,
buf=0x7fffffffb860 "[Mon Jan 11 22:20:32 2016]  Script: 
'/home/youmingdot/Code/Beaver/beaver.php'\n", len=512, format=0xf27e28
"%s(%d) :  Freeing 0x%.8lX (%zu bytes), script=%s\n", ap=0x7fffffffb4f8)
at /home/youmingdot/Source/php-7.0.2/main/snprintf.c:1248
#3  0x000000000081deb9 in ap_php_snprintf (buf=0x7fffffffb860 "[Mon Jan
11 22:20:32 2016]  Script: 
'/home/youmingdot/Code/Beaver/beaver.php'\n", len=512, format=0xf27e28
"%s(%d) :  Freeing 0x%.8lX (%zu bytes), script=%s\n") at
/home/youmingdot/Source/php-7.0.2/main/snprintf.c:1293
#4  0x0000000000818738 in php_message_handler_for_zend (message=4,
data=0x7fffffffc910) at
/home/youmingdot/Source/php-7.0.2/main/main.c:1431
#5  0x00000000008ac189 in zend_message_dispatcher (message=4,
data=0x7fffffffc910) at
/home/youmingdot/Source/php-7.0.2/Zend/zend.c:998
#6  0x00000000008792e4 in zend_mm_check_leaks (heap=0x7ffff5600040) at
/home/youmingdot/Source/php-7.0.2/Zend/zend_alloc.c:2121
#7  0x0000000000879620 in zend_mm_shutdown (heap=0x7ffff5600040, full=0,
silent=0) at /home/youmingdot/Source/php-7.0.2/Zend/zend_alloc.c:2193
#8  0x000000000087a48f in shutdown_memory_manager (silent=0,
full_shutdown=0) at
/home/youmingdot/Source/php-7.0.2/Zend/zend_alloc.c:2629
#9  0x000000000081960f in php_request_shutdown (dummy=0x0) at
/home/youmingdot/Source/php-7.0.2/main/main.c:1833
#10 0x000000000096d116 in do_cli (argc=3, argv=0x1351210) at
/home/youmingdot/Source/php-7.0.2/sapi/cli/php_cli.c:1142
#11 0x000000000096d98b in main (argc=3, argv=0x1351210) at
/home/youmingdot/Source/php-7.0.2/sapi/cli/php_cli.c:1345

-- 
Edit bug report at https://bugs.php.net/bug.php?id=71337&edit=1
-- 
Try a snapshot (PHP 5.4):   https://bugs.php.net/fix.php?id=71337&r=trysnapshot54
Try a snapshot (PHP 5.5):   https://bugs.php.net/fix.php?id=71337&r=trysnapshot55
Try a snapshot (trunk):     https://bugs.php.net/fix.php?id=71337&r=trysnapshottrunk
Fixed in SVN:               https://bugs.php.net/fix.php?id=71337&r=fixed
Fixed in release:           https://bugs.php.net/fix.php?id=71337&r=alreadyfixed
Need backtrace:             https://bugs.php.net/fix.php?id=71337&r=needtrace
Need Reproduce Script:      https://bugs.php.net/fix.php?id=71337&r=needscript
Try newer version:          https://bugs.php.net/fix.php?id=71337&r=oldversion
Not developer issue:        https://bugs.php.net/fix.php?id=71337&r=support
Expected behavior:          https://bugs.php.net/fix.php?id=71337&r=notwrong
Not enough info:            https://bugs.php.net/fix.php?id=71337&r=notenoughinfo
Submitted twice:            https://bugs.php.net/fix.php?id=71337&r=submittedtwice
register_globals:           https://bugs.php.net/fix.php?id=71337&r=globals
PHP 4 support discontinued: https://bugs.php.net/fix.php?id=71337&r=php4
Daylight Savings:           https://bugs.php.net/fix.php?id=71337&r=dst
IIS Stability:              https://bugs.php.net/fix.php?id=71337&r=isapi
Install GNU Sed:            https://bugs.php.net/fix.php?id=71337&r=gnused
Floating point limitations: https://bugs.php.net/fix.php?id=71337&r=float
No Zend Extensions:         https://bugs.php.net/fix.php?id=71337&r=nozend
MySQL Configuration Error:  https://bugs.php.net/fix.php?id=71337&r=mysqlcfg



Thread (2 messages)

« previous php.bugs (#198569) next »