Bug #72794 [NEW]: Corrupted or nulled, pointers to zvals arrval (HT)

From: Date: Tue, 09 Aug 2016 11:08:03 +0000
Subject: Bug #72794 [NEW]: Corrupted or nulled, pointers to zvals arrval (HT)
Groups: php.bugs 
Request: Send a blank email to php-bugs+get-203107@lists.php.net to get a copy of this message
From: shlomi at sbz dot co dot il Operating system: centOS 7 x64 PHP version: 7.0.9 Package: hash related Bug Type: Bug Bug description:Corrupted or nulled, pointers to zvals arrval (HT) Description: ------------ Hi, I'm trying to add zvals to parent zval (creating associative array), and hold pointers to each entry. Then fill the entries. The process fails with segmentation fault when adding (int)indexed array, or corrupts the hash when adding acct array. There is an example under: Test script. I'll try to debug this issue but I need a clue what the problem might be. Thanks. Shlomi Test script: --------------- PHP_METHOD(__some_class__, foo){ zval *data, *data_a, *data_b, *data_c, *data_d, *data_e, *data_f, *data_g, *data_h, *data_i, *data_j; array_init(return_value); zval tmp; array_init(&tmp); data = zend_hash_str_add(Z_ARRVAL_P(return_value), "data", strlen("data"), &tmp); array_init(&tmp); data_a = zend_hash_str_add(Z_ARRVAL_P(data), "index_a", strlen("index_a"), &tmp); array_init(&tmp); data_b = zend_hash_str_add(Z_ARRVAL_P(data), "index_b", strlen("index_b"), &tmp); array_init(&tmp); data_c = zend_hash_str_add(Z_ARRVAL_P(data), "index_c", strlen("index_c"), &tmp); array_init(&tmp); data_d = zend_hash_str_add(Z_ARRVAL_P(data), "index_d", strlen("index_d"), &tmp); array_init(&tmp); data_e = zend_hash_str_add(Z_ARRVAL_P(data), "index_e", strlen("index_e"), &tmp); array_init(&tmp); data_f = zend_hash_str_add(Z_ARRVAL_P(data), "index_f", strlen("index_f"), &tmp); array_init(&tmp); data_g = zend_hash_str_add(Z_ARRVAL_P(data), "index_g", strlen("index_g"), &tmp); array_init(&tmp); data_h = zend_hash_str_add(Z_ARRVAL_P(data), "index_h", strlen("index_h"), &tmp); array_init(&tmp); data_i = zend_hash_str_add(Z_ARRVAL_P(data), "index_i", strlen("index_i"), &tmp); array_init(&tmp); data_j = zend_hash_str_add(Z_ARRVAL_P(data), "index_j", strlen("index_j"), &tmp); int i, j; char str[6]; for(i=0; i<30; i++){ zval *__z; zend_string *key; zval *carr = data_h; // change this for testing [data_a - data_j]. // when set to data_i or data_j it works as expected. /** / __z = zend_hash_index_find(Z_ARRVAL_P(carr), i); if(!__z) { zval __tmp; array_init(&__tmp); __z = zend_hash_index_add_new(Z_ARRVAL_P(carr), i, &__tmp); } // seg fault the HT is nulled /**/ snprintf(str, 6, "_%d", i); key = zend_string_init(str, strlen(str), 0); __z = zend_hash_find(Z_ARRVAL_P(carr), key); if(!__z) { zval __tmp; array_init(&__tmp); __z = zend_hash_add_new(Z_ARRVAL_P(carr), key, &__tmp); } zend_string_release(key); // hash corrupted /**/ add_assoc_string(__z, "hello", "world!"); } } -- Edit bug report at https://bugs.php.net/bug.php?id=72794&edit=1 -- Try a snapshot (PHP 5.4): https://bugs.php.net/fix.php?id=72794&r=trysnapshot54 Try a snapshot (PHP 5.5): https://bugs.php.net/fix.php?id=72794&r=trysnapshot55 Try a snapshot (trunk): https://bugs.php.net/fix.php?id=72794&r=trysnapshottrunk Fixed in SVN: https://bugs.php.net/fix.php?id=72794&r=fixed Fixed in release: https://bugs.php.net/fix.php?id=72794&r=alreadyfixed Need backtrace: https://bugs.php.net/fix.php?id=72794&r=needtrace Need Reproduce Script: https://bugs.php.net/fix.php?id=72794&r=needscript Try newer version: https://bugs.php.net/fix.php?id=72794&r=oldversion Not developer issue: https://bugs.php.net/fix.php?id=72794&r=support Expected behavior: https://bugs.php.net/fix.php?id=72794&r=notwrong Not enough info: https://bugs.php.net/fix.php?id=72794&r=notenoughinfo Submitted twice: https://bugs.php.net/fix.php?id=72794&r=submittedtwice register_globals: https://bugs.php.net/fix.php?id=72794&r=globals PHP 4 support discontinued: https://bugs.php.net/fix.php?id=72794&r=php4 Daylight Savings: https://bugs.php.net/fix.php?id=72794&r=dst IIS Stability: https://bugs.php.net/fix.php?id=72794&r=isapi Install GNU Sed: https://bugs.php.net/fix.php?id=72794&r=gnused Floating point limitations: https://bugs.php.net/fix.php?id=72794&r=float No Zend Extensions: https://bugs.php.net/fix.php?id=72794&r=nozend MySQL Configuration Error: https://bugs.php.net/fix.php?id=72794&r=mysqlcfg

« previous php.bugs (#203107) next »