Bug #73684 [Com]: Can be segmentation fault

From: Date: Thu, 08 Dec 2016 14:38:40 +0000
Subject: Bug #73684 [Com]: Can be segmentation fault
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-205852@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=73684&edit=1 ID: 73684 Comment by: thisisabug at server dot com Reported by: deepvavar at mail dot ru Summary: Can be segmentation fault Status: Duplicate Type: Bug Package: Scripting Engine problem Operating System: All PHP Version: Irrelevant Block user comment: N Private report: N New Comment: I don't want introduce recursion limits. This code: public static function bar($b, $i = 0) { if ($i == 15396) { return; } $b->b = self::$a->getNewB(); self::bar($b->b, ++$i); } Says about memory limit problem. This is last good value. For $i == 15397 I get segfault. php doesn't check for availability of the memory (what return malloc/calloc/realloc) or (position) pointer? I don't believe. Ok. What I can for fix or check it? I just want expected behaviour. Previous Comments: ------------------------------------------------------------------------ [2016-12-08 14:11:59] nikic@php.net This is a well-known issue, we probably have 100s of duplicates about this. E.g. #72568 for interaction with pthreads, but there's many others around for specific cases. This usually occurs either with magic methods or if you have extensions loaded that hook into the function call process. We know this issue exists and there is no concrete plan to fix it. We don't want to introduce recursion limits (though if someone is sufficiently interested in this, an RFC might convince people about this) and more direct means of detecting stack overflows are heavily system dependent. We may want to improve our support for fcall hooks to enable more extensions to operate without need to reenter the VM. This may also improve performance of profilers and debuggers, but would likely come at a cost for the case where no such extension is used. ------------------------------------------------------------------------ [2016-12-08 14:03:48] cmb@php.net Well, simplified reproduce script: <?php function foo() { foo(); } foo(); Crashes all PHP versions. Anyway, as you insist this is a bug in PHP, I'm re-opening. ------------------------------------------------------------------------ [2016-12-08 13:56:32] thisisabug at server dot com This is php bug, because php trying write data with incorrect pointer or incorrect size. Xdebug/etc. just limiter. Without xdebug can be segfault. But maybe (as you see) this issue not for all php versions/packages. ------------------------------------------------------------------------ [2016-12-08 13:29:16] cmb@php.net Yes, this is a bug, but it is not a bug in PHP, but rather in the supplied reproduce script. ------------------------------------------------------------------------ [2016-12-08 13:16:01] thisisabug at server dot com This is a bug, because OS kill php process with incorrect write to memory. ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=73684 -- Edit this bug report at https://bugs.php.net/bug.php?id=73684&edit=1

« previous php.bugs (#205852) next »