Bug #72854 [Opn]: PHP Crashes on duplicate destructor call
| From: | nikic@php.net | Date: | Tue, 16 Aug 2016 15:40:49 +0000 |
| Subject: | Bug #72854 [Opn]: PHP Crashes on duplicate destructor call | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-203317@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=72854&edit=1
ID: 72854
Updated by: nikic@php.net
Reported by: php at abiusx dot com
Summary: PHP Crashes on duplicate destructor call
Status: Open
Type: Bug
Package: Class/Object related
Operating System: Mac OS X, Linux
PHP Version: 7.0.9
Block user comment: N
Private report: N
New Comment:
Thanks, I'm seeing a segfault now. GDB backtrace:
#0 0x0000000000b58b5a in zend_mm_alloc_small (heap=0x7fffeda00040, size=56, bin_num=6,
__zend_filename=0x1254a20 "/home/nikic/php-src/Zend/zend_vm_execute.h",
__zend_lineno=16726,
__zend_orig_filename=0x0, __zend_orig_lineno=0) at /home/nikic/php-src/Zend/zend_alloc.c:1250
#1 0x0000000000b58dfd in zend_mm_alloc_heap (heap=0x7fffeda00040, size=56,
__zend_filename=0x1254a20 "/home/nikic/php-src/Zend/zend_vm_execute.h",
__zend_lineno=16726,
__zend_orig_filename=0x0, __zend_orig_lineno=0) at /home/nikic/php-src/Zend/zend_alloc.c:1321
#2 0x0000000000b5b92c in _emalloc (size=24,
__zend_filename=0x1254a20 "/home/nikic/php-src/Zend/zend_vm_execute.h",
__zend_lineno=16726,
__zend_orig_filename=0x0, __zend_orig_lineno=0) at /home/nikic/php-src/Zend/zend_alloc.c:2406
#3 0x0000000000c35e13 in ZEND_FE_FETCH_RW_SPEC_VAR_HANDLER ()
at /home/nikic/php-src/Zend/zend_vm_execute.h:16726
#4 0x0000000000c0bcd1 in execute_ex (ex=0x7fffeda36ac0)
at /home/nikic/php-src/Zend/zend_vm_execute.h:429
#5 0x0000000000b83567 in zend_call_function (fci=0x7fffffff9d00, fci_cache=0x7fffffff9cd0)
at /home/nikic/php-src/Zend/zend_execute_API.c:837
#6 0x0000000000bcb264 in zend_call_method (object=0x7fffffff9de0, obj_ce=0x7fffeda04820,
fn_proxy=0x7fffffff9db0, function_name=0x1251fbe "__destruct", function_name_len=10,
retval_ptr=0x0, param_count=0, arg1=0x0, arg2=0x0)
at /home/nikic/php-src/Zend/zend_interfaces.c:102
#7 0x0000000000bf21df in zend_objects_destroy_object (object=0x7fffea6ff000)
at /home/nikic/php-src/Zend/zend_objects.c:156
#8 0x0000000000bf98d8 in zend_objects_store_del (object=0x7fffea6ff000)
at /home/nikic/php-src/Zend/zend_objects_API.c:160
#9 0x0000000000b990f7 in _zval_dtor_func (p=0x7fffea6ff000,
__zend_filename=0x12538e0 "/home/nikic/php-src/Zend/zend_execute.c",
__zend_lineno=579)
at /home/nikic/php-src/Zend/zend_variables.c:56
#10 0x0000000000b98fd6 in i_zval_ptr_dtor (zval_ptr=0x7fffec388698,
__zend_filename=0x12538e0 "/home/nikic/php-src/Zend/zend_execute.c",
__zend_lineno=579)
at /home/nikic/php-src/Zend/zend_variables.h:48
#11 0x0000000000b99131 in _zval_dtor_func (p=0x7fffec388690,
__zend_filename=0x12538e0 "/home/nikic/php-src/Zend/zend_execute.c",
__zend_lineno=579)
at /home/nikic/php-src/Zend/zend_variables.c:69
#12 0x0000000000c01735 in i_zval_ptr_dtor (zval_ptr=0x7fffeda6bc18,
__zend_filename=0x12538e0 "/home/nikic/php-src/Zend/zend_execute.c",
__zend_lineno=579)
at /home/nikic/php-src/Zend/zend_variables.h:48
#13 0x0000000000c03e89 in zend_assign_to_variable_reference (variable_ptr=0x7fffeda6bc18,
value_ptr=0x7fffeda36a90) at /home/nikic/php-src/Zend/zend_execute.c:579
#14 0x0000000000c40168 in ZEND_ASSIGN_REF_SPEC_VAR_VAR_HANDLER ()
at /home/nikic/php-src/Zend/zend_vm_execute.h:20438
#15 0x0000000000c0bcd1 in execute_ex (ex=0x7fffeda14030)
at /home/nikic/php-src/Zend/zend_vm_execute.h:429
#16 0x0000000000c0bed2 in zend_execute (op_array=0x7fffeda9a200, return_value=0x0)
at /home/nikic/php-src/Zend/zend_vm_execute.h:474
#17 0x0000000000b9e93c in zend_execute_scripts (type=8, retval=0x0, file_count=3)
#18 0x0000000000ad63ee in php_execute_script (primary_file=0x7fffffffc8b0)
at /home/nikic/php-src/main/main.c:2537
#19 0x0000000000c99e71 in do_cli (argc=8, argv=0x1642cf0)
at /home/nikic/php-src/sapi/cli/php_cli.c:990
#20 0x0000000000c9b319 in main (argc=8, argv=0x1642cf0)
at /home/nikic/php-src/sapi/cli/php_cli.c:1378
Warnings under USE_ZEND_ALLOC=0 valgrind:
==30704== Invalid read of size 4
==30704== at 0xC01075: zval_delref_p (zend_types.h:834)
==30704== by 0xC01717: i_zval_ptr_dtor (zend_variables.h:47)
==30704== by 0xC03E88: zend_assign_to_variable_reference (zend_execute.c:579)
==30704== by 0xC48C8B: ZEND_ASSIGN_REF_SPEC_VAR_CV_HANDLER (zend_vm_execute.h:24278)
==30704== by 0xC0BCD0: execute_ex (zend_vm_execute.h:429)
==30704== by 0xB83566: zend_call_function (zend_execute_API.c:837)
==30704== by 0xBCB263: zend_call_method (zend_interfaces.c:102)
==30704== by 0xBF21DE: zend_objects_destroy_object (zend_objects.c:156)
==30704== by 0xBF98D7: zend_objects_store_del (zend_objects_API.c:160)
==30704== by 0xB990F6: _zval_dtor_func (zend_variables.c:56)
==30704== by 0xB98FD5: i_zval_ptr_dtor (zend_variables.h:48)
==30704== by 0xB99130: _zval_dtor_func (zend_variables.c:69)
==30704== Address 0x112b18b0 is 0 bytes inside a block of size 24 free'd
==30704== at 0x4C2EDEB: free (in /usr/lib/valgrind/vgpreload_memcheck-amd64-linux.so)
==30704== by 0xB5BA53: _efree (zend_alloc.c:2417)
==30704== by 0xB99153: _zval_dtor_func (zend_variables.c:70)
==30704== by 0xC016E3: _zval_ptr_dtor_nogc (zend_variables.h:40)
==30704== by 0xC7698E: ZEND_ASSIGN_OBJ_SPEC_CV_CV_OP_DATA_VAR_HANDLER (zend_vm_execute.h:45393)
==30704== by 0xC0BCD0: execute_ex (zend_vm_execute.h:429)
==30704== by 0xB83566: zend_call_function (zend_execute_API.c:837)
==30704== by 0xBCB263: zend_call_method (zend_interfaces.c:102)
==30704== by 0xBF21DE: zend_objects_destroy_object (zend_objects.c:156)
==30704== by 0xBF98D7: zend_objects_store_del (zend_objects_API.c:160)
==30704== by 0xB990F6: _zval_dtor_func (zend_variables.c:56)
==30704== by 0xB98FD5: i_zval_ptr_dtor (zend_variables.h:48)
==30704== Block was alloc'd at
==30704== at 0x4C2DB8F: malloc (in /usr/lib/valgrind/vgpreload_memcheck-amd64-linux.so)
==30704== by 0xB5B8D8: _emalloc (zend_alloc.c:2402)
==30704== by 0xC35E12: ZEND_FE_FETCH_RW_SPEC_VAR_HANDLER (zend_vm_execute.h:16726)
==30704== by 0xC0BCD0: execute_ex (zend_vm_execute.h:429)
==30704== by 0xC0BED1: zend_execute (zend_vm_execute.h:474)
==30704== by 0xB9E93B: zend_execute_scripts (zend.c:1447)
==30704== by 0xAD63ED: php_execute_script (main.c:2537)
==30704== by 0xC99E70: do_cli (php_cli.c:990)
==30704== by 0xC9B318: main (php_cli.c:1378)
==30704==
==30704== Invalid write of size 4
==30704== at 0xC0107A: zval_delref_p (zend_types.h:834)
==30704== by 0xC01717: i_zval_ptr_dtor (zend_variables.h:47)
==30704== by 0xC03E88: zend_assign_to_variable_reference (zend_execute.c:579)
==30704== by 0xC48C8B: ZEND_ASSIGN_REF_SPEC_VAR_CV_HANDLER (zend_vm_execute.h:24278)
==30704== by 0xC0BCD0: execute_ex (zend_vm_execute.h:429)
==30704== by 0xB83566: zend_call_function (zend_execute_API.c:837)
==30704== by 0xBCB263: zend_call_method (zend_interfaces.c:102)
==30704== by 0xBF21DE: zend_objects_destroy_object (zend_objects.c:156)
==30704== by 0xBF98D7: zend_objects_store_del (zend_objects_API.c:160)
==30704== by 0xB990F6: _zval_dtor_func (zend_variables.c:56)
==30704== by 0xB98FD5: i_zval_ptr_dtor (zend_variables.h:48)
==30704== by 0xB99130: _zval_dtor_func (zend_variables.c:69)
==30704== Address 0x112b18b0 is 0 bytes inside a block of size 24 free'd
==30704== at 0x4C2EDEB: free (in /usr/lib/valgrind/vgpreload_memcheck-amd64-linux.so)
==30704== by 0xB5BA53: _efree (zend_alloc.c:2417)
==30704== by 0xB99153: _zval_dtor_func (zend_variables.c:70)
==30704== by 0xC016E3: _zval_ptr_dtor_nogc (zend_variables.h:40)
==30704== by 0xC7698E: ZEND_ASSIGN_OBJ_SPEC_CV_CV_OP_DATA_VAR_HANDLER (zend_vm_execute.h:45393)
==30704== by 0xC0BCD0: execute_ex (zend_vm_execute.h:429)
==30704== by 0xB83566: zend_call_function (zend_execute_API.c:837)
==30704== by 0xBCB263: zend_call_method (zend_interfaces.c:102)
==30704== by 0xBF21DE: zend_objects_destroy_object (zend_objects.c:156)
==30704== by 0xBF98D7: zend_objects_store_del (zend_objects_API.c:160)
==30704== by 0xB990F6: _zval_dtor_func (zend_variables.c:56)
==30704== by 0xB98FD5: i_zval_ptr_dtor (zend_variables.h:48)
==30704== Block was alloc'd at
==30704== at 0x4C2DB8F: malloc (in /usr/lib/valgrind/vgpreload_memcheck-amd64-linux.so)
==30704== by 0xB5B8D8: _emalloc (zend_alloc.c:2402)
==30704== by 0xC35E12: ZEND_FE_FETCH_RW_SPEC_VAR_HANDLER (zend_vm_execute.h:16726)
==30704== by 0xC0BCD0: execute_ex (zend_vm_execute.h:429)
==30704== by 0xC0BED1: zend_execute (zend_vm_execute.h:474)
==30704== by 0xB9E93B: zend_execute_scripts (zend.c:1447)
==30704== by 0xAD63ED: php_execute_script (main.c:2537)
==30704== by 0xC99E70: do_cli (php_cli.c:990)
==30704== by 0xC9B318: main (php_cli.c:1378)
==30704==
==30704== Invalid read of size 4
==30704== at 0xC0107C: zval_delref_p (zend_types.h:834)
==30704== by 0xC01717: i_zval_ptr_dtor (zend_variables.h:47)
==30704== by 0xC03E88: zend_assign_to_variable_reference (zend_execute.c:579)
==30704== by 0xC48C8B: ZEND_ASSIGN_REF_SPEC_VAR_CV_HANDLER (zend_vm_execute.h:24278)
==30704== by 0xC0BCD0: execute_ex (zend_vm_execute.h:429)
==30704== by 0xB83566: zend_call_function (zend_execute_API.c:837)
==30704== by 0xBCB263: zend_call_method (zend_interfaces.c:102)
==30704== by 0xBF21DE: zend_objects_destroy_object (zend_objects.c:156)
==30704== by 0xBF98D7: zend_objects_store_del (zend_objects_API.c:160)
==30704== by 0xB990F6: _zval_dtor_func (zend_variables.c:56)
==30704== by 0xB98FD5: i_zval_ptr_dtor (zend_variables.h:48)
==30704== by 0xB99130: _zval_dtor_func (zend_variables.c:69)
==30704== Address 0x112b18b0 is 0 bytes inside a block of size 24 free'd
==30704== at 0x4C2EDEB: free (in /usr/lib/valgrind/vgpreload_memcheck-amd64-linux.so)
==30704== by 0xB5BA53: _efree (zend_alloc.c:2417)
==30704== by 0xB99153: _zval_dtor_func (zend_variables.c:70)
==30704== by 0xC016E3: _zval_ptr_dtor_nogc (zend_variables.h:40)
==30704== by 0xC7698E: ZEND_ASSIGN_OBJ_SPEC_CV_CV_OP_DATA_VAR_HANDLER (zend_vm_execute.h:45393)
==30704== by 0xC0BCD0: execute_ex (zend_vm_execute.h:429)
==30704== by 0xB83566: zend_call_function (zend_execute_API.c:837)
==30704== by 0xBCB263: zend_call_method (zend_interfaces.c:102)
==30704== by 0xBF21DE: zend_objects_destroy_object (zend_objects.c:156)
==30704== by 0xBF98D7: zend_objects_store_del (zend_objects_API.c:160)
==30704== by 0xB990F6: _zval_dtor_func (zend_variables.c:56)
==30704== by 0xB98FD5: i_zval_ptr_dtor (zend_variables.h:48)
==30704== Block was alloc'd at
==30704== at 0x4C2DB8F: malloc (in /usr/lib/valgrind/vgpreload_memcheck-amd64-linux.so)
==30704== by 0xB5B8D8: _emalloc (zend_alloc.c:2402)
==30704== by 0xC35E12: ZEND_FE_FETCH_RW_SPEC_VAR_HANDLER (zend_vm_execute.h:16726)
==30704== by 0xC0BCD0: execute_ex (zend_vm_execute.h:429)
==30704== by 0xC0BED1: zend_execute (zend_vm_execute.h:474)
==30704== by 0xB9E93B: zend_execute_scripts (zend.c:1447)
==30704== by 0xAD63ED: php_execute_script (main.c:2537)
==30704== by 0xC99E70: do_cli (php_cli.c:990)
==30704== by 0xC9B318: main (php_cli.c:1378)
==30704==
==30704== Invalid read of size 1
==30704== at 0xC0165D: gc_check_possible_root (zend_gc.h:135)
==30704== by 0xC01742: i_zval_ptr_dtor (zend_variables.h:50)
==30704== by 0xC03E88: zend_assign_to_variable_reference (zend_execute.c:579)
==30704== by 0xC48C8B: ZEND_ASSIGN_REF_SPEC_VAR_CV_HANDLER (zend_vm_execute.h:24278)
==30704== by 0xC0BCD0: execute_ex (zend_vm_execute.h:429)
==30704== by 0xB83566: zend_call_function (zend_execute_API.c:837)
==30704== by 0xBCB263: zend_call_method (zend_interfaces.c:102)
==30704== by 0xBF21DE: zend_objects_destroy_object (zend_objects.c:156)
==30704== by 0xBF98D7: zend_objects_store_del (zend_objects_API.c:160)
==30704== by 0xB990F6: _zval_dtor_func (zend_variables.c:56)
==30704== by 0xB98FD5: i_zval_ptr_dtor (zend_variables.h:48)
==30704== by 0xB99130: _zval_dtor_func (zend_variables.c:69)
==30704== Address 0x112b18c1 is 17 bytes inside a block of size 24 free'd
==30704== at 0x4C2EDEB: free (in /usr/lib/valgrind/vgpreload_memcheck-amd64-linux.so)
==30704== by 0xB5BA53: _efree (zend_alloc.c:2417)
==30704== by 0xB99153: _zval_dtor_func (zend_variables.c:70)
==30704== by 0xC016E3: _zval_ptr_dtor_nogc (zend_variables.h:40)
==30704== by 0xC7698E: ZEND_ASSIGN_OBJ_SPEC_CV_CV_OP_DATA_VAR_HANDLER (zend_vm_execute.h:45393)
==30704== by 0xC0BCD0: execute_ex (zend_vm_execute.h:429)
==30704== by 0xB83566: zend_call_function (zend_execute_API.c:837)
==30704== by 0xBCB263: zend_call_method (zend_interfaces.c:102)
==30704== by 0xBF21DE: zend_objects_destroy_object (zend_objects.c:156)
==30704== by 0xBF98D7: zend_objects_store_del (zend_objects_API.c:160)
==30704== by 0xB990F6: _zval_dtor_func (zend_variables.c:56)
==30704== by 0xB98FD5: i_zval_ptr_dtor (zend_variables.h:48)
==30704== Block was alloc'd at
==30704== at 0x4C2DB8F: malloc (in /usr/lib/valgrind/vgpreload_memcheck-amd64-linux.so)
==30704== by 0xB5B8D8: _emalloc (zend_alloc.c:2402)
==30704== by 0xC35E12: ZEND_FE_FETCH_RW_SPEC_VAR_HANDLER (zend_vm_execute.h:16726)
==30704== by 0xC0BCD0: execute_ex (zend_vm_execute.h:429)
==30704== by 0xC0BED1: zend_execute (zend_vm_execute.h:474)
==30704== by 0xB9E93B: zend_execute_scripts (zend.c:1447)
==30704== by 0xAD63ED: php_execute_script (main.c:2537)
==30704== by 0xC99E70: do_cli (php_cli.c:990)
==30704== by 0xC9B318: main (php_cli.c:1378)
==30704==
==30704== Invalid read of size 8
==30704== at 0xC0166F: gc_check_possible_root (zend_gc.h:135)
==30704== by 0xC01742: i_zval_ptr_dtor (zend_variables.h:50)
==30704== by 0xC03E88: zend_assign_to_variable_reference (zend_execute.c:579)
==30704== by 0xC48C8B: ZEND_ASSIGN_REF_SPEC_VAR_CV_HANDLER (zend_vm_execute.h:24278)
==30704== by 0xC0BCD0: execute_ex (zend_vm_execute.h:429)
==30704== by 0xB83566: zend_call_function (zend_execute_API.c:837)
==30704== by 0xBCB263: zend_call_method (zend_interfaces.c:102)
==30704== by 0xBF21DE: zend_objects_destroy_object (zend_objects.c:156)
==30704== by 0xBF98D7: zend_objects_store_del (zend_objects_API.c:160)
==30704== by 0xB990F6: _zval_dtor_func (zend_variables.c:56)
==30704== by 0xB98FD5: i_zval_ptr_dtor (zend_variables.h:48)
==30704== by 0xB99130: _zval_dtor_func (zend_variables.c:69)
==30704== Address 0x112b18b8 is 8 bytes inside a block of size 24 free'd
==30704== at 0x4C2EDEB: free (in /usr/lib/valgrind/vgpreload_memcheck-amd64-linux.so)
==30704== by 0xB5BA53: _efree (zend_alloc.c:2417)
==30704== by 0xB99153: _zval_dtor_func (zend_variables.c:70)
==30704== by 0xC016E3: _zval_ptr_dtor_nogc (zend_variables.h:40)
==30704== by 0xC7698E: ZEND_ASSIGN_OBJ_SPEC_CV_CV_OP_DATA_VAR_HANDLER (zend_vm_execute.h:45393)
==30704== by 0xC0BCD0: execute_ex (zend_vm_execute.h:429)
==30704== by 0xB83566: zend_call_function (zend_execute_API.c:837)
==30704== by 0xBCB263: zend_call_method (zend_interfaces.c:102)
==30704== by 0xBF21DE: zend_objects_destroy_object (zend_objects.c:156)
==30704== by 0xBF98D7: zend_objects_store_del (zend_objects_API.c:160)
==30704== by 0xB990F6: _zval_dtor_func (zend_variables.c:56)
==30704== by 0xB98FD5: i_zval_ptr_dtor (zend_variables.h:48)
==30704== Block was alloc'd at
==30704== at 0x4C2DB8F: malloc (in /usr/lib/valgrind/vgpreload_memcheck-amd64-linux.so)
==30704== by 0xB5B8D8: _emalloc (zend_alloc.c:2402)
==30704== by 0xC35E12: ZEND_FE_FETCH_RW_SPEC_VAR_HANDLER (zend_vm_execute.h:16726)
==30704== by 0xC0BCD0: execute_ex (zend_vm_execute.h:429)
==30704== by 0xC0BED1: zend_execute (zend_vm_execute.h:474)
==30704== by 0xB9E93B: zend_execute_scripts (zend.c:1447)
==30704== by 0xAD63ED: php_execute_script (main.c:2537)
==30704== by 0xC99E70: do_cli (php_cli.c:990)
==30704== by 0xC9B318: main (php_cli.c:1378)
==30704==
--------- (19.6.2) > â /wp-includes/wp-db.php:623
==30704== Invalid free() / delete / delete[] / realloc()
==30704== at 0x4C2EDEB: free (in /usr/lib/valgrind/vgpreload_memcheck-amd64-linux.so)
==30704== by 0xB5BA53: _efree (zend_alloc.c:2417)
==30704== by 0xB99153: _zval_dtor_func (zend_variables.c:70)
==30704== by 0xC01734: i_zval_ptr_dtor (zend_variables.h:48)
==30704== by 0xC03E88: zend_assign_to_variable_reference (zend_execute.c:579)
==30704== by 0xC40167: ZEND_ASSIGN_REF_SPEC_VAR_VAR_HANDLER (zend_vm_execute.h:20438)
==30704== by 0xC0BCD0: execute_ex (zend_vm_execute.h:429)
==30704== by 0xC0BED1: zend_execute (zend_vm_execute.h:474)
==30704== by 0xB9E93B: zend_execute_scripts (zend.c:1447)
==30704== by 0xAD63ED: php_execute_script (main.c:2537)
==30704== by 0xC99E70: do_cli (php_cli.c:990)
==30704== by 0xC9B318: main (php_cli.c:1378)
==30704== Address 0x112b18b0 is 0 bytes inside a block of size 24 free'd
==30704== at 0x4C2EDEB: free (in /usr/lib/valgrind/vgpreload_memcheck-amd64-linux.so)
==30704== by 0xB5BA53: _efree (zend_alloc.c:2417)
==30704== by 0xB99153: _zval_dtor_func (zend_variables.c:70)
==30704== by 0xC016E3: _zval_ptr_dtor_nogc (zend_variables.h:40)
==30704== by 0xC7698E: ZEND_ASSIGN_OBJ_SPEC_CV_CV_OP_DATA_VAR_HANDLER (zend_vm_execute.h:45393)
==30704== by 0xC0BCD0: execute_ex (zend_vm_execute.h:429)
==30704== by 0xB83566: zend_call_function (zend_execute_API.c:837)
==30704== by 0xBCB263: zend_call_method (zend_interfaces.c:102)
==30704== by 0xBF21DE: zend_objects_destroy_object (zend_objects.c:156)
==30704== by 0xBF98D7: zend_objects_store_del (zend_objects_API.c:160)
==30704== by 0xB990F6: _zval_dtor_func (zend_variables.c:56)
==30704== by 0xB98FD5: i_zval_ptr_dtor (zend_variables.h:48)
==30704== Block was alloc'd at
==30704== at 0x4C2DB8F: malloc (in /usr/lib/valgrind/vgpreload_memcheck-amd64-linux.so)
==30704== by 0xB5B8D8: _emalloc (zend_alloc.c:2402)
==30704== by 0xC35E12: ZEND_FE_FETCH_RW_SPEC_VAR_HANDLER (zend_vm_execute.h:16726)
==30704== by 0xC0BCD0: execute_ex (zend_vm_execute.h:429)
==30704== by 0xC0BED1: zend_execute (zend_vm_execute.h:474)
==30704== by 0xB9E93B: zend_execute_scripts (zend.c:1447)
==30704== by 0xAD63ED: php_execute_script (main.c:2537)
==30704== by 0xC99E70: do_cli (php_cli.c:990)
==30704== by 0xC9B318: main (php_cli.c:1378)
==30704==
Previous Comments:
------------------------------------------------------------------------
[2016-08-16 15:16:56] php at abiusx dot com
It needs to run on concolic mode, I gave you access to the private Github repo, please give the
analyzer a try.
Use the following:
php main.php -f wordpress/index.php --concolic --strict -v 10
------------------------------------------------------------------------
[2016-08-16 15:12:48] nikic@php.net
I tried running the command from the README
php main.php -f wordpress/index.php -v 10 --strict && cat output.txt
on wordpress-4.1 and I do not observe a crash.
------------------------------------------------------------------------
[2016-08-16 15:12:34] php at abiusx dot com
I am aware of what you said, and I plan on doing a thorough investigation on this issue. I have
faced it over and over in my line of work, both on OS X and on Ubuntu.
The backtrace is 600mb, which is not very useful. Plus, it ends up in system malloc, which is
another useless clue.
I have made several attempts at making a short example that reproduces the crash, but have been
unable to do so.
At this point, this bug just serves as an entry point for myself to do further research and find the
problem.
------------------------------------------------------------------------
[2016-08-16 15:09:58] requinix@php.net
Running that php-emul stuff is a bit much for us to do. Some short repro code would be great - may
be hard for you to come up with though. I know you said you haven't been able to run it though
a debug version yet, but without the code then we'll need a backtrace (see http://bugs.php.net/bugs-generating-backtrace.php).
------------------------------------------------------------------------
[2016-08-16 14:47:39] php at abiusx dot com
Description:
------------
I have a very complicated code that runs for 4 minutes. The important thing the code does, is it
makes deep copies of data structures in PHP, does something, and discards the deep copy.
Many times when this happens, PHP segfaults (typically with memory violation) when the destructor of
a deep copied object is called, and a resource is involved in that object.
Examples are wp-db and phpmailer classes in Wordpress, both of which segfault PHP on their
destructor.
I still haven't had the chance to run PHP's debug version on it to figure out the details,
but now I'm sure the bug is there (and has been since PHP 7.0.0, also tested on PHP 5.4 and it
persists).
Test script:
---------------
github.com/abiusx/php-emul concolic mode on Wordpress and Joomla causes the crash.
The crash is not stack related, it is also deterministic.
Expected result:
----------------
No crash
Actual result:
--------------
Segfault (memory violation)
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=72854&edit=1