Bug #76446 [Com]: zend_variables.c:73: zend_string_destroy: Assertion `!(zval_gc_flags((str)->gc.
| From: | spam2 at rhsoft dot net | Date: | Tue, 12 Jun 2018 11:45:19 +0000 |
| Subject: | Bug #76446 [Com]: zend_variables.c:73: zend_string_destroy: Assertion `!(zval_gc_flags((str)->gc. | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-215646@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=76446&edit=1
ID: 76446
Comment by: spam2 at rhsoft dot net
Reported by: spam2 at rhsoft dot net
Summary: zend_variables.c:73: zend_string_destroy: Assertion
`!(zval_gc_flags((str)->gc.
Status: Analyzed
Type: Bug
Package: Reproducible crash
PHP Version: master-Git-2018-06-11 (Git)
Block user comment: N
Private report: N
New Comment:
in the current case there are additional outputs which maybe are helpful for you guys
In function cl_podcast_eintraege::edit (before dfa):
var 11 (TMP) has array key type but not value type
var 12 (TMP) has array key type but not value type
var 14 (TMP) has array key type but not value type
var 15 (CV $old_data) has array key type but not value type
In function cl_podcast_eintraege::edit (after sccp):
var 11 (TMP) has array key type but not value type
var 12 (TMP) has array key type but not value type
var 14 (TMP) has array key type but not value type
var 15 (CV $old_data) has array key type but not value type
In function cl_podcast_eintraege::edit (after calls):
var 11 (TMP) has array key type but not value type
var 12 (TMP) has array key type but not value type
var 14 (TMP) has array key type but not value type
var 15 (CV $old_data) has array key type but not value type
In function cl_podcast_eintraege::edit (after dce):
var 11 (TMP) has array key type but not value type
var 12 (TMP) has array key type but not value type
var 14 (TMP) has array key type but not value type
var 15 (CV $old_data) has array key type but not value type
In function cl_podcast_eintraege::edit (after dfa):
var 11 (TMP) has array key type but not value type
var 12 (TMP) has array key type but not value type
var 14 (TMP) has array key type but not value type
var 15 (CV $old_data) has array key type but not value type
php: /home/builduser/rpmbuild/BUILD/php-7.3.0/Zend/zend_variables.c:73: zend_string_destroy:
Assertion `!(zval_gc_flags((str)->gc.u.type_info) & (1<<6))' failed.
Program received signal SIGABRT, Aborted.
0x00007ffff68e2660 in raise () from /lib64/libc.so.6
Missing separate debuginfos, use: dnf debuginfo-install bzip2-libs-1.0.6-24.fc27.x86_64
cyrus-sasl-lib-2.1.26-34.fc27.x86_64 expat-2.2.5-1.fc27.x86_64 fontconfig-2.12.6-4.fc27.x86_64
freetype-2.8-8.fc27.x86_64 gd-2.2.5-3.fc27.x86_64 jbigkit-libs-2.1-8.fc27.x86_64
keyutils-libs-1.5.10-3.fc27.x86_64 krb5-libs-1.15.2-9.fc27.x86_64 libX11-1.6.5-4.fc27.x86_64
libXau-1.0.8-9.fc27.x86_64 libXpm-3.5.12-4.fc27.x86_64 libcom_err-1.43.5-2.fc27.x86_64
libcrypt-nss-2.26-28.fc27.x86_64 libcurl-7.55.1-12.fc27.x86_64 libgcc-7.3.1-5.fc27.x86_64
libgomp-7.3.1-5.fc27.x86_64 libicu-57.1-9.fc27.x86_64 libidn2-2.0.5-1.fc27.x86_64
libjpeg-turbo-1.5.3-1.fc27.x86_64 libnghttp2-1.31.1-1.fc27.x86_64 libpng-1.6.31-1.fc27.x86_64
libpsl-0.18.0-3.fc27.x86_64 libselinux-2.7-3.fc27.x86_64 libssh2-1.8.0-5.fc27.x86_64
libstdc++-7.3.1-5.fc27.x86_64 libtidy-5.4.0-3.fc27.x86_64 libtiff-4.0.9-10.fc27.x86_64
libunistring-0.9.10-1.fc27.x86_64 libwebp-1.0.0-1.fc27.x86_64 libxcb-1.12-5.fc27.x86_64
libxml2-2.9.7-1.fc2!
7.x86_64 libzip-1.3.2-1.fc27.x86_64 nspr-4.19.0-1.fc27.x86_64 nss-3.37.3-1.0.fc27.x86_64
nss-softokn-freebl-3.37.3-1.0.fc27.x86_64 nss-util-3.37.3-1.0.fc27.x86_64
openldap-2.4.45-4.fc27.x86_64 openssl-libs-1.1.0h-3.fc27.x86_64 pcre2-10.31-4.fc27.x86_64
systemd-libs-234-11.git5f8984e.fc27.x86_64 xz-libs-5.2.3-4.fc27.x86_64
(gdb) f 4
#4 0x000055555588a52e in zend_string_destroy (str=0x7fffe3c7e6e0, __zend_filename=0x5555559ce4a8
"/home/builduser/rpmbuild/BUILD/php-7.3.0/Zend/zend_vm_execute.h",
__zend_lineno=12424) at /home/builduser/rpmbuild/BUILD/php-7.3.0/Zend/zend_variables.c:73
73 ZEND_ASSERT(!ZSTR_IS_INTERNED(str));
(gdb) p (char*)str->val
$1 = 0x7fffe3c7e6f8 "http://localhost"
Previous Comments:
------------------------------------------------------------------------
[2018-06-12 11:41:23] spam2 at rhsoft dot net
$openstr2 = "&openmenu={$openmenu}{$addlang}"; is not used anywhere, so it will be
DCEd together with the rope
hell, yeah, that line is obsolete, now the testsuite crashes in a different file
can we have a php.ini option to trigger warnings in error_log when DCE steps in but without crashes
:-)
seriously
------------------------------------------------------------------------
[2018-06-12 10:51:49] laruence@php.net
as nikic said. a short reproduciable script is:
<?php
function test()
{
$addlang = '';
$openstr2 = "&openmenu={$openmenu}{$addlang} \"";
}
test('1');
------------------------------------------------------------------------
[2018-06-12 07:07:25] nikic@php.net
@rhsoft: Thanks. From that code it seems pretty clear that this is really the DCE bug mentioned
above. The variable $openstr2 = "&openmenu={$openmenu}{$addlang}"; is not used
anywhere, so it will be DCEd together with the rope expression.
------------------------------------------------------------------------
[2018-06-12 06:59:16] spam2 at rhsoft dot net
https://access.thelounge.net/harry/bug76446_php.txt
is the affected function which is basically the navigation on the left at https://www.rhsoft.net/
probably you are faster to create a way smaller and database independent reproducer with the
interals of the zendengine in mind, basicly the lines with "&openmenu" seems to be
the trigger for hwatever reson given that i work that way on thousands of other places
------------------------------------------------------------------------
[2018-06-12 06:53:52] nikic@php.net
@rhsoft: That commit was just some drive-by cleanup, it wasn't supposed to fix anything :)
I think we should first fix the DCE issue and see if it also resolves your problem. If not
we'll have to debug further...
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=76446
--
Edit this bug report at https://bugs.php.net/bug.php?id=76446&edit=1