Bug #71539 [NEW]: Memory error on $arr[$a] =& $arr[$b] if RHS rehashes
From: nikic
Operating system:
PHP version: 7.0.3
Package: Scripting Engine problem
Bug Type: Bug
Bug description:Memory error on $arr[$a] =& $arr[$b] if RHS rehashes
Description:
------------
Reproduce code:
$array = [];
$array[0] =& $array[''];
The $array[''] is used to force a packed-to-hash conversion.
Output:
[Sat Feb 6 16:53:58 2016] Script: '/home/nikic/php-src/t203.php'
/home/nikic/php-src/Zend/zend_execute.c(577) : Freeing 0x7FEE3D6010E0
(24 bytes), script=/home/nikic/php-src/t203.php
=== Total 1 memory leaks detected ===
First valgrind:
==30433== Invalid read of size 1
==30433== at 0xB7EAAD: zval_get_type (zend_types.h:330)
==30433== by 0xBB80A5: ZEND_ASSIGN_REF_SPEC_VAR_VAR_HANDLER
(zend_vm_execute.h:19702)
==30433== by 0xB88A6F: execute_ex (zend_vm_execute.h:422)
==30433== by 0xB88C71: zend_execute (zend_vm_execute.h:466)
==30433== by 0xB247EC: zend_execute_scripts (zend.c:1427)
==30433== by 0xA630F9: php_execute_script (main.c:2484)
==30433== by 0xC0783C: do_cli (php_cli.c:974)
==30433== by 0xC08CD1: main (php_cli.c:1345)
==30433== Address 0xf47b680 is 16 bytes inside a block of size 264
free'd
==30433== at 0x4C2BDEC: free (in
/usr/lib/valgrind/vgpreload_memcheck-amd64-linux.so)
==30433== by 0xAE4EAD: _efree (zend_alloc.c:2453)
==30433== by 0xB379A8: zend_hash_packed_to_hash (zend_hash.c:220)
==30433== by 0xB3915C: _zend_hash_add_or_update_i (zend_hash.c:566)
==30433== by 0xB3951C: _zend_hash_add_new (zend_hash.c:640)
==30433== by 0xB852E5: zend_fetch_dimension_address_inner
(zend_execute.c:1466)
==30433== by 0xB85AB4: zend_fetch_dimension_address
(zend_execute.c:1681)
==30433== by 0xB861AE: zend_fetch_dimension_address_W
(zend_execute.c:1772)
==30433== by 0xBDAB96: ZEND_FETCH_DIM_W_SPEC_CV_CONST_HANDLER
(zend_vm_execute.h:36832)
==30433== by 0xB88A6F: execute_ex (zend_vm_execute.h:422)
==30433== by 0xB88C71: zend_execute (zend_vm_execute.h:466)
==30433== by 0xB247EC: zend_execute_scripts (zend.c:1427)
The cause is the opcode sequence:
@1 = FETCH_DIM_W $array 0
@2 = FETCH_DIM_W $array ""
ASSIGN_REF @1 @2
Where the second FETCH_DIM_W will reallocate the backing array while @1
still holds a pointer into it.
--
Edit bug report at https://bugs.php.net/bug.php?id=71539&edit=1
--
Try a snapshot (PHP 5.4): https://bugs.php.net/fix.php?id=71539&r=trysnapshot54
Try a snapshot (PHP 5.5): https://bugs.php.net/fix.php?id=71539&r=trysnapshot55
Try a snapshot (trunk): https://bugs.php.net/fix.php?id=71539&r=trysnapshottrunk
Fixed in SVN: https://bugs.php.net/fix.php?id=71539&r=fixed
Fixed in release: https://bugs.php.net/fix.php?id=71539&r=alreadyfixed
Need backtrace: https://bugs.php.net/fix.php?id=71539&r=needtrace
Need Reproduce Script: https://bugs.php.net/fix.php?id=71539&r=needscript
Try newer version: https://bugs.php.net/fix.php?id=71539&r=oldversion
Not developer issue: https://bugs.php.net/fix.php?id=71539&r=support
Expected behavior: https://bugs.php.net/fix.php?id=71539&r=notwrong
Not enough info: https://bugs.php.net/fix.php?id=71539&r=notenoughinfo
Submitted twice: https://bugs.php.net/fix.php?id=71539&r=submittedtwice
register_globals: https://bugs.php.net/fix.php?id=71539&r=globals
PHP 4 support discontinued: https://bugs.php.net/fix.php?id=71539&r=php4
Daylight Savings: https://bugs.php.net/fix.php?id=71539&r=dst
IIS Stability: https://bugs.php.net/fix.php?id=71539&r=isapi
Install GNU Sed: https://bugs.php.net/fix.php?id=71539&r=gnused
Floating point limitations: https://bugs.php.net/fix.php?id=71539&r=float
No Zend Extensions: https://bugs.php.net/fix.php?id=71539&r=nozend
MySQL Configuration Error: https://bugs.php.net/fix.php?id=71539&r=mysqlcfg
Thread (9 messages)
- nikic@php.net