Bug #72411 [Opn->Dup]: PHP segfaults when there are too many elements added to a linked list

From: Date: Wed, 15 Jun 2016 13:42:44 +0000
Subject: Bug #72411 [Opn->Dup]: PHP segfaults when there are too many elements added to a linked list
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-201651@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=72411&edit=1 ID: 72411 Updated by: nikic@php.net Reported by: pwmosquito at gmail dot com Summary: PHP segfaults when there are too many elements added to a linked list -Status: Open +Status: Duplicate Type: Bug Package: Reproducible crash Operating System: All PHP Version: Irrelevant Block user comment: N Private report: N New Comment: Duplicate of bug #68606. Previous Comments: ------------------------------------------------------------------------ [2016-06-15 11:31:10] pwmosquito at gmail dot com Description: ------------ OSes: OSX (version 10.11.5), Ubuntu 14.04.3 LTS, CentOS release 6.5 (Final) PHP versions: 5.5, 5.6, 7.0 When implementing a simple singly linked list in PHP I get a segfault if I try to add too many items to the list. To define too many: the sample code attached could cope with 29,000 items on my machine but segfaults with 30,000 items. The interesting part is that if I first remove the items from the list, eg. with $this->head = $this->head->getNext() (method excluded from the sample code for brevity) then everything works as expected and I can add items to the list till it fill up and I get "Fatal error: Uncaught RuntimeException: Stack overflow.", which is expected. If I add __destruct() { $this->head = null; } to LinkedList and set a breakpoint there it will segfault when I execute that line. Test script: --------------- <?php class Node { private $next; public function setNext(Node $node = null) { $this->next = $node; return $this; } } class LinkedList { private $head; public function addNode() { $this->head = (new Node())->setNext($this->head); } } $ll = new LinkedList(); for ($i = 0; $i < 100000; $i++) { $ll->addNode(); } Expected result: ---------------- no output Actual result: -------------- 'php test.php' terminated by signal SIGSEGV (Address boundary error) ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=72411&edit=1

« previous php.bugs (#201651) next »