Bug #73423 [Com]: Reproducible crash with GDB backtrace
| From: | love at sickpeople dot se | Date: | Sun, 30 Oct 2016 23:49:38 +0000 |
| Subject: | Bug #73423 [Com]: Reproducible crash with GDB backtrace | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-205083@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=73423&edit=1
ID: 73423
Comment by: love at sickpeople dot se
Reported by: love at sickpeople dot se
Summary: Reproducible crash with GDB backtrace
Status: Open
Type: Bug
Package: Reproducible crash
Operating System: Linux
PHP Version: 7.1.0RC5
Block user comment: N
Private report: N
New Comment:
Please note that there are other circumstances for this crash. I've seen several variants. Eg
calling a method on the class in "z.php" with no argument crashes if the method has a
required argument.
It seems that (more or less) errors caused with the destructor in the stack leads to SEGV (always)
at Zend/zend_objects_API.c:149.
I have not however reproduced this without a file inclusion and never with a short path to the file.
Previous Comments:
------------------------------------------------------------------------
[2016-10-30 22:35:44] love at sickpeople dot se
Description:
------------
These are the elements involved
1. I use the RecursiveFilterIterator
2. I include a file from the destructor
3. The file has a long filename/path (IMPORTANT)
4. The file contains a class that extends a class
5. The parent class does not exist
If all above is applied, this crashes.
NOTE: 3) above is crucial for reproduce. In my case I have
"/tmp/uu/abcdefghi/abcdefghi/abcdefghi/abcdefghi/z.php". Moving/changing the
"z.php" to "/tmp/uu/z.php" does NOT cause a crash.
====
GDB backtrace
Core was generated by `/usr/local/php7.1-RC5/bin/php -f b.php'.
Program terminated with signal SIGSEGV, Segmentation fault.
#0 zend_objects_store_del (object=0x7f1143075150) at
/home/le/Downloads/php-7.1.0RC5/Zend/zend_objects_API.c:149
149 if (EG(objects_store).object_buckets &&
(gdb) bt
#0 zend_objects_store_del (object=0x7f1143075150) at
/home/le/Downloads/php-7.1.0RC5/Zend/zend_objects_API.c:149
#1 0x000000000084ac05 in zend_iterator_dtor (iter=<optimized out>) at
/home/le/Downloads/php-7.1.0RC5/Zend/zend_iterators.c:88
#2 0x000000000070c4b7 in spl_recursive_it_dtor (_iter=0x7f114306a0c0)
at /home/le/Downloads/php-7.1.0RC5/ext/spl/spl_iterators.c:179
#3 0x000000000086b441 in zend_objects_store_free_object_storage (objects=objects@entry=0x11cabd8
<executor_globals+824>)
at /home/le/Downloads/php-7.1.0RC5/Zend/zend_objects_API.c:99
#4 0x000000000081c9e3 in shutdown_executor () at
/home/le/Downloads/php-7.1.0RC5/Zend/zend_execute_API.c:359
#5 0x000000000082ca4b in zend_deactivate () at /home/le/Downloads/php-7.1.0RC5/Zend/zend.c:987
#6 0x00000000007c8dc2 in php_request_shutdown (dummy=dummy@entry=0x0) at
/home/le/Downloads/php-7.1.0RC5/main/main.c:1873
#7 0x00000000008d26cc in do_cli (argc=3, argv=0x1e76ef0) at
/home/le/Downloads/php-7.1.0RC5/sapi/cli/php_cli.c:1157
#8 0x000000000044b831 in main (argc=3, argv=0x1e76ef0) at
/home/le/Downloads/php-7.1.0RC5/sapi/cli/php_cli.c:1378
Test script:
---------------
====
z.php (the file to be included)
class Crash extends Nonexistent { }
====
b.php
class foo implements \RecursiveIterator
{
public $foo = [];
public Function current ()
{
return current ($this->foo);
}
public Function key ()
{
return key ($this->foo);
}
public Function next ()
{
next ($this->foo);
}
public Function rewind ()
{
reset ($this->foo);
}
public Function valid ()
{
return current ($this->foo) !== false;
}
public Function getChildren ()
{
return current ($this->foo);
}
public Function hasChildren ()
{
return (bool) count ($this->foo);
}
}
class fooIterator extends \RecursiveFilterIterator
{
public Function __destruct ()
{
require_once ("./abcdefghi/abcdefghi/abcdefghi/abcdefghi/z.php");
/* CRASH */
}
public Function accept ()
{
return true;
}
}
$foo = new foo ();
$foo->foo[] = new foo ();
foreach (new \RecursiveIteratorIterator (new fooIterator ($foo)) as $bar) ;
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=73423&edit=1