Bug #73423 [Com]: Reproducible crash with GDB backtrace

From: Date: Sun, 30 Oct 2016 23:49:38 +0000
Subject: Bug #73423 [Com]: Reproducible crash with GDB backtrace
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-205083@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=73423&edit=1 ID: 73423 Comment by: love at sickpeople dot se Reported by: love at sickpeople dot se Summary: Reproducible crash with GDB backtrace Status: Open Type: Bug Package: Reproducible crash Operating System: Linux PHP Version: 7.1.0RC5 Block user comment: N Private report: N New Comment: Please note that there are other circumstances for this crash. I've seen several variants. Eg calling a method on the class in "z.php" with no argument crashes if the method has a required argument. It seems that (more or less) errors caused with the destructor in the stack leads to SEGV (always) at Zend/zend_objects_API.c:149. I have not however reproduced this without a file inclusion and never with a short path to the file. Previous Comments: ------------------------------------------------------------------------ [2016-10-30 22:35:44] love at sickpeople dot se Description: ------------ These are the elements involved 1. I use the RecursiveFilterIterator 2. I include a file from the destructor 3. The file has a long filename/path (IMPORTANT) 4. The file contains a class that extends a class 5. The parent class does not exist If all above is applied, this crashes. NOTE: 3) above is crucial for reproduce. In my case I have "/tmp/uu/abcdefghi/abcdefghi/abcdefghi/abcdefghi/z.php". Moving/changing the "z.php" to "/tmp/uu/z.php" does NOT cause a crash. ==== GDB backtrace Core was generated by `/usr/local/php7.1-RC5/bin/php -f b.php'. Program terminated with signal SIGSEGV, Segmentation fault. #0 zend_objects_store_del (object=0x7f1143075150) at /home/le/Downloads/php-7.1.0RC5/Zend/zend_objects_API.c:149 149 if (EG(objects_store).object_buckets && (gdb) bt #0 zend_objects_store_del (object=0x7f1143075150) at /home/le/Downloads/php-7.1.0RC5/Zend/zend_objects_API.c:149 #1 0x000000000084ac05 in zend_iterator_dtor (iter=<optimized out>) at /home/le/Downloads/php-7.1.0RC5/Zend/zend_iterators.c:88 #2 0x000000000070c4b7 in spl_recursive_it_dtor (_iter=0x7f114306a0c0) at /home/le/Downloads/php-7.1.0RC5/ext/spl/spl_iterators.c:179 #3 0x000000000086b441 in zend_objects_store_free_object_storage (objects=objects@entry=0x11cabd8 <executor_globals+824>) at /home/le/Downloads/php-7.1.0RC5/Zend/zend_objects_API.c:99 #4 0x000000000081c9e3 in shutdown_executor () at /home/le/Downloads/php-7.1.0RC5/Zend/zend_execute_API.c:359 #5 0x000000000082ca4b in zend_deactivate () at /home/le/Downloads/php-7.1.0RC5/Zend/zend.c:987 #6 0x00000000007c8dc2 in php_request_shutdown (dummy=dummy@entry=0x0) at /home/le/Downloads/php-7.1.0RC5/main/main.c:1873 #7 0x00000000008d26cc in do_cli (argc=3, argv=0x1e76ef0) at /home/le/Downloads/php-7.1.0RC5/sapi/cli/php_cli.c:1157 #8 0x000000000044b831 in main (argc=3, argv=0x1e76ef0) at /home/le/Downloads/php-7.1.0RC5/sapi/cli/php_cli.c:1378 Test script: --------------- ==== z.php (the file to be included) class Crash extends Nonexistent { } ==== b.php class foo implements \RecursiveIterator { public $foo = []; public Function current () { return current ($this->foo); } public Function key () { return key ($this->foo); } public Function next () { next ($this->foo); } public Function rewind () { reset ($this->foo); } public Function valid () { return current ($this->foo) !== false; } public Function getChildren () { return current ($this->foo); } public Function hasChildren () { return (bool) count ($this->foo); } } class fooIterator extends \RecursiveFilterIterator { public Function __destruct () { require_once ("./abcdefghi/abcdefghi/abcdefghi/abcdefghi/z.php"); /* CRASH */ } public Function accept () { return true; } } $foo = new foo (); $foo->foo[] = new foo (); foreach (new \RecursiveIteratorIterator (new fooIterator ($foo)) as $bar) ; ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=73423&edit=1

« previous php.bugs (#205083) next »