Bug #76446 [Ana]: zend_variables.c:73: zend_string_destroy: Assertion `!(zval_gc_flags((str)->gc.
| From: | laruence@php.net | Date: | Tue, 12 Jun 2018 10:51:52 +0000 |
| Subject: | Bug #76446 [Ana]: zend_variables.c:73: zend_string_destroy: Assertion `!(zval_gc_flags((str)->gc. | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-215643@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=76446&edit=1
ID: 76446
Updated by: laruence@php.net
Reported by: spam2 at rhsoft dot net
Summary: zend_variables.c:73: zend_string_destroy: Assertion
`!(zval_gc_flags((str)->gc.
Status: Analyzed
Type: Bug
Package: Reproducible crash
PHP Version: master-Git-2018-06-11 (Git)
Block user comment: N
Private report: N
New Comment:
as nikic said. a short reproduciable script is:
<?php
function test()
{
$addlang = '';
$openstr2 = "&openmenu={$openmenu}{$addlang} \"";
}
test('1');
Previous Comments:
------------------------------------------------------------------------
[2018-06-12 07:07:25] nikic@php.net
@rhsoft: Thanks. From that code it seems pretty clear that this is really the DCE bug mentioned
above. The variable $openstr2 = "&openmenu={$openmenu}{$addlang}"; is not used
anywhere, so it will be DCEd together with the rope expression.
------------------------------------------------------------------------
[2018-06-12 06:59:16] spam2 at rhsoft dot net
https://access.thelounge.net/harry/bug76446_php.txt
is the affected function which is basically the navigation on the left at https://www.rhsoft.net/
probably you are faster to create a way smaller and database independent reproducer with the
interals of the zendengine in mind, basicly the lines with "&openmenu" seems to be
the trigger for hwatever reson given that i work that way on thousands of other places
------------------------------------------------------------------------
[2018-06-12 06:53:52] nikic@php.net
@rhsoft: That commit was just some drive-by cleanup, it wasn't supposed to fix anything :)
I think we should first fix the DCE issue and see if it also resolves your problem. If not
we'll have to debug further...
------------------------------------------------------------------------
[2018-06-12 06:35:57] spam2 at rhsoft dot net
sorry, no, way too much stuff on the machine nad i also don't see a way to isolate the affected
code for now but that's something i will try sooner or later (currently at vacation and made
the mistake "hey let's look if our codebase triggers any php-warning with the current
master")
------------------------------------------------------------------------
[2018-06-12 04:01:25] laruence@php.net
is that possible that you could grant me a ssh access to your box to debugging it? (vid mail)
that will be much helpful :)
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=76446
--
Edit this bug report at https://bugs.php.net/bug.php?id=76446&edit=1