Bug #74361 [Opn->Csd]: Compaction in array_rand() violates COW
| From: | nikic@php.net | Date: | Sun, 02 Apr 2017 11:20:31 +0000 |
| Subject: | Bug #74361 [Opn->Csd]: Compaction in array_rand() violates COW | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-208278@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=74361&edit=1
ID: 74361
Updated by: nikic@php.net
Reported by: nikic@php.net
Summary: Compaction in array_rand() violates COW
-Status: Open
+Status: Closed
Type: Bug
Package: Arrays related
PHP Version: 7.1.4RC1
Block user comment: N
Private report: N
New Comment:
Automatic comment on behalf of nikita.ppv@gmail.com
Revision: http://git.php.net/?p=php-src.git;a=commit;h=c8034514edadbafc4376f107e2a4ba52b7b17ff4
Log: Fixed bug #74361
Previous Comments:
------------------------------------------------------------------------
[2017-04-02 10:56:13] nikic@php.net
Description:
------------
From http://stackoverflow.com/questions/43162831/zend-mm-heap-corrupted-with-php-7-1.
If numUsed occupancy is <= 3/4 array_rand() compacts the array prior to sampling. This is done on
a potentially shared array.
This may lead to SHM corruption, for example:
$array = [1 => 1, 2 => 2];
var_dump(array_rand($array));
Crashes on opcache.
It can also have other side effects:
<?php
$array = range(0, 100);
for ($i = 0; $i < 50; $i++) {
unset($array[$i]);
}
foreach ($array as $x) {
var_dump($x);
if ($x == 55) {
array_rand($array, 1);
}
}
Here the array is resized during the loop, leaving a dangling pointer.
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=74361&edit=1