Bug #72411 [NEW]: PHP segfaults when there are too many elements added to a linked list

From: Date: Wed, 15 Jun 2016 11:31:13 +0000
Subject: Bug #72411 [NEW]: PHP segfaults when there are too many elements added to a linked list
Groups: php.bugs 
Request: Send a blank email to php-bugs+get-201643@lists.php.net to get a copy of this message
From: pwmosquito at gmail dot com Operating system: All PHP version: Irrelevant Package: Reproducible crash Bug Type: Bug Bug description:PHP segfaults when there are too many elements added to a linked list Description: ------------ OSes: OSX (version 10.11.5), Ubuntu 14.04.3 LTS, CentOS release 6.5 (Final) PHP versions: 5.5, 5.6, 7.0 When implementing a simple singly linked list in PHP I get a segfault if I try to add too many items to the list. To define too many: the sample code attached could cope with 29,000 items on my machine but segfaults with 30,000 items. The interesting part is that if I first remove the items from the list, eg. with $this->head = $this->head->getNext() (method excluded from the sample code for brevity) then everything works as expected and I can add items to the list till it fill up and I get "Fatal error: Uncaught RuntimeException: Stack overflow.", which is expected. If I add __destruct() { $this->head = null; } to LinkedList and set a breakpoint there it will segfault when I execute that line. Test script: --------------- <?php class Node { private $next; public function setNext(Node $node = null) { $this->next = $node; return $this; } } class LinkedList { private $head; public function addNode() { $this->head = (new Node())->setNext($this->head); } } $ll = new LinkedList(); for ($i = 0; $i < 100000; $i++) { $ll->addNode(); } Expected result: ---------------- no output Actual result: -------------- 'php test.php' terminated by signal SIGSEGV (Address boundary error) -- Edit bug report at https://bugs.php.net/bug.php?id=72411&edit=1 -- Try a snapshot (PHP 5.4): https://bugs.php.net/fix.php?id=72411&r=trysnapshot54 Try a snapshot (PHP 5.5): https://bugs.php.net/fix.php?id=72411&r=trysnapshot55 Try a snapshot (trunk): https://bugs.php.net/fix.php?id=72411&r=trysnapshottrunk Fixed in SVN: https://bugs.php.net/fix.php?id=72411&r=fixed Fixed in release: https://bugs.php.net/fix.php?id=72411&r=alreadyfixed Need backtrace: https://bugs.php.net/fix.php?id=72411&r=needtrace Need Reproduce Script: https://bugs.php.net/fix.php?id=72411&r=needscript Try newer version: https://bugs.php.net/fix.php?id=72411&r=oldversion Not developer issue: https://bugs.php.net/fix.php?id=72411&r=support Expected behavior: https://bugs.php.net/fix.php?id=72411&r=notwrong Not enough info: https://bugs.php.net/fix.php?id=72411&r=notenoughinfo Submitted twice: https://bugs.php.net/fix.php?id=72411&r=submittedtwice register_globals: https://bugs.php.net/fix.php?id=72411&r=globals PHP 4 support discontinued: https://bugs.php.net/fix.php?id=72411&r=php4 Daylight Savings: https://bugs.php.net/fix.php?id=72411&r=dst IIS Stability: https://bugs.php.net/fix.php?id=72411&r=isapi Install GNU Sed: https://bugs.php.net/fix.php?id=72411&r=gnused Floating point limitations: https://bugs.php.net/fix.php?id=72411&r=float No Zend Extensions: https://bugs.php.net/fix.php?id=72411&r=nozend MySQL Configuration Error: https://bugs.php.net/fix.php?id=72411&r=mysqlcfg

« previous php.bugs (#201643) next »