Bug #75655 [NEW]: Segfault when using magic methods AND reference to self in property
From: michael at imagely dot com
Operating system: Any
PHP version: 7.2.0
Package: Scripting Engine problem
Bug Type: Bug
Bug description:Segfault when using magic methods AND reference to self in property
Description:
------------
This will produce a segfault in PHP 7.2, 7.1.12, and 7.0.26. Any other
versions will execute this and exit clean.
The example code is extracted from NextGEN Gallery, a popular WordPress
plugin with over 1 million installs. The code is used extensively by the
plugin and therefore causing major havoc.
If you remove "$this->object = $this", the segfault will not occur.
Test script:
---------------
<?php
class ExtensibleObject
{
var $object = NULL;
function __construct()
{
$this->object = $this;
}
}
class C_DataMapper_Model extends ExtensibleObject
{
var $_stdObject = NULL;
function __construct()
{
parent::__construct();
$this->_stdObject = new stdClass();
}
function &__get($property)
{
if (isset($this->_stdObject->$property)) {
$retval = &$this->_stdObject->$property;
return $retval;
}
else {
// We need to assign NULL to a variable first, since only
// variables can be returned by reference
$retval = NULL;
return $retval;
}
}
function &__set($property, $value)
{
$retval = $this->_stdObject->$property= $value;
return $retval;
}
function __isset($property_name)
{
return isset($this->_stdObject->$property_name);
}
}
class C_Display_Type extends C_DataMapper_Model
{
function __construct()
{
parent::__construct();
}
function &__get($property)
{
if (isset($this->settings) && isset($this->settings[$property])) {
$retval = &$this->settings[$property];
return $retval;
}
else return parent::__get($property);
}
}
// This will segfault
$display_type = new C_Display_Type();
if (!isset($display_type->settings)) $display_type->settings = array();
for ($i=0; $i<10; $i++) {
$key = 'foo_'.$i;
$display_type->settings[$key] = 'bar';
}
var_dump($display_type->settings);
Expected result:
----------------
array(10) {
["foo_0"]=>
string(3) "bar"
["foo_1"]=>
string(3) "bar"
["foo_2"]=>
string(3) "bar"
["foo_3"]=>
string(3) "bar"
["foo_4"]=>
string(3) "bar"
["foo_5"]=>
string(3) "bar"
["foo_6"]=>
string(3) "bar"
["foo_7"]=>
string(3) "bar"
["foo_8"]=>
string(3) "bar"
["foo_9"]=>
string(3) "bar"
}
Actual result:
--------------
Segmentation fault (core dumped)
--
Edit bug report at https://bugs.php.net/bug.php?id=75655&edit=1
--
Try a snapshot (PHP 5.4): https://bugs.php.net/fix.php?id=75655&r=trysnapshot54
Try a snapshot (PHP 5.5): https://bugs.php.net/fix.php?id=75655&r=trysnapshot55
Try a snapshot (trunk): https://bugs.php.net/fix.php?id=75655&r=trysnapshottrunk
Fixed in SVN: https://bugs.php.net/fix.php?id=75655&r=fixed
Fixed in release: https://bugs.php.net/fix.php?id=75655&r=alreadyfixed
Need backtrace: https://bugs.php.net/fix.php?id=75655&r=needtrace
Need Reproduce Script: https://bugs.php.net/fix.php?id=75655&r=needscript
Try newer version: https://bugs.php.net/fix.php?id=75655&r=oldversion
Not developer issue: https://bugs.php.net/fix.php?id=75655&r=support
Expected behavior: https://bugs.php.net/fix.php?id=75655&r=notwrong
Not enough info: https://bugs.php.net/fix.php?id=75655&r=notenoughinfo
Submitted twice: https://bugs.php.net/fix.php?id=75655&r=submittedtwice
register_globals: https://bugs.php.net/fix.php?id=75655&r=globals
PHP 4 support discontinued: https://bugs.php.net/fix.php?id=75655&r=php4
Daylight Savings: https://bugs.php.net/fix.php?id=75655&r=dst
IIS Stability: https://bugs.php.net/fix.php?id=75655&r=isapi
Install GNU Sed: https://bugs.php.net/fix.php?id=75655&r=gnused
Floating point limitations: https://bugs.php.net/fix.php?id=75655&r=float
No Zend Extensions: https://bugs.php.net/fix.php?id=75655&r=nozend
MySQL Configuration Error: https://bugs.php.net/fix.php?id=75655&r=mysqlcfg
Thread (5 messages)
- michael at imagely dot com