Bug #76446 [Com]: zend_variables.c:73: zend_string_destroy: Assertion `!(zval_gc_flags((str)->gc.

From: Date: Tue, 12 Jun 2018 13:08:57 +0000
Subject: Bug #76446 [Com]: zend_variables.c:73: zend_string_destroy: Assertion `!(zval_gc_flags((str)->gc.
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-215653@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=76446&edit=1 ID: 76446 Comment by: spam2 at rhsoft dot net Reported by: spam2 at rhsoft dot net Summary: zend_variables.c:73: zend_string_destroy: Assertion `!(zval_gc_flags((str)->gc. Status: Analyzed Type: Bug Package: Reproducible crash PHP Version: master-Git-2018-06-11 (Git) Block user comment: N Private report: N New Comment: BTW: would it be possible to extend the "zend_variables.c:73: zend_string_destroy: Assertion `!(zval_gc_flags((str)->gc" at least with the path to the script/include and if possible method/function/line strace, gdb, valgrind - no chance to find out where it is triggered and besides the bug i would like to remove the dead code anyways Previous Comments: ------------------------------------------------------------------------ [2018-06-12 12:57:07] laruence@php.net this one has been fixed https://bugs.php.net/bug.php?id=76463 about the original problem, a simple fix is make ROPE_END as side-affect instrction, however I am still thinking maybe we should remove the whole ROPE_INIT/ADD/END all-togther ------------------------------------------------------------------------ [2018-06-12 11:53:08] spam2 at rhsoft dot net - $old_data = isset($old_data) ? (array)$old_data : []; + $old_data = []; is silencing that ones: In function cl_podcast_eintraege::edit (before dfa): var 11 (TMP) has array key type but not value type var 12 (TMP) has array key type but not value type var 14 (TMP) has array key type but not value type var 15 (CV $old_data) has array key type but not value type ------------------------------------------------------------------------ [2018-06-12 11:45:15] spam2 at rhsoft dot net in the current case there are additional outputs which maybe are helpful for you guys In function cl_podcast_eintraege::edit (before dfa): var 11 (TMP) has array key type but not value type var 12 (TMP) has array key type but not value type var 14 (TMP) has array key type but not value type var 15 (CV $old_data) has array key type but not value type In function cl_podcast_eintraege::edit (after sccp): var 11 (TMP) has array key type but not value type var 12 (TMP) has array key type but not value type var 14 (TMP) has array key type but not value type var 15 (CV $old_data) has array key type but not value type In function cl_podcast_eintraege::edit (after calls): var 11 (TMP) has array key type but not value type var 12 (TMP) has array key type but not value type var 14 (TMP) has array key type but not value type var 15 (CV $old_data) has array key type but not value type In function cl_podcast_eintraege::edit (after dce): var 11 (TMP) has array key type but not value type var 12 (TMP) has array key type but not value type var 14 (TMP) has array key type but not value type var 15 (CV $old_data) has array key type but not value type In function cl_podcast_eintraege::edit (after dfa): var 11 (TMP) has array key type but not value type var 12 (TMP) has array key type but not value type var 14 (TMP) has array key type but not value type var 15 (CV $old_data) has array key type but not value type php: /home/builduser/rpmbuild/BUILD/php-7.3.0/Zend/zend_variables.c:73: zend_string_destroy: Assertion `!(zval_gc_flags((str)->gc.u.type_info) & (1<<6))' failed. Program received signal SIGABRT, Aborted. 0x00007ffff68e2660 in raise () from /lib64/libc.so.6 Missing separate debuginfos, use: dnf debuginfo-install bzip2-libs-1.0.6-24.fc27.x86_64 cyrus-sasl-lib-2.1.26-34.fc27.x86_64 expat-2.2.5-1.fc27.x86_64 fontconfig-2.12.6-4.fc27.x86_64 freetype-2.8-8.fc27.x86_64 gd-2.2.5-3.fc27.x86_64 jbigkit-libs-2.1-8.fc27.x86_64 keyutils-libs-1.5.10-3.fc27.x86_64 krb5-libs-1.15.2-9.fc27.x86_64 libX11-1.6.5-4.fc27.x86_64 libXau-1.0.8-9.fc27.x86_64 libXpm-3.5.12-4.fc27.x86_64 libcom_err-1.43.5-2.fc27.x86_64 libcrypt-nss-2.26-28.fc27.x86_64 libcurl-7.55.1-12.fc27.x86_64 libgcc-7.3.1-5.fc27.x86_64 libgomp-7.3.1-5.fc27.x86_64 libicu-57.1-9.fc27.x86_64 libidn2-2.0.5-1.fc27.x86_64 libjpeg-turbo-1.5.3-1.fc27.x86_64 libnghttp2-1.31.1-1.fc27.x86_64 libpng-1.6.31-1.fc27.x86_64 libpsl-0.18.0-3.fc27.x86_64 libselinux-2.7-3.fc27.x86_64 libssh2-1.8.0-5.fc27.x86_64 libstdc++-7.3.1-5.fc27.x86_64 libtidy-5.4.0-3.fc27.x86_64 libtiff-4.0.9-10.fc27.x86_64 libunistring-0.9.10-1.fc27.x86_64 libwebp-1.0.0-1.fc27.x86_64 libxcb-1.12-5.fc27.x86_64 libxml2-2.9.7-1.fc2! 7.x86_64 libzip-1.3.2-1.fc27.x86_64 nspr-4.19.0-1.fc27.x86_64 nss-3.37.3-1.0.fc27.x86_64 nss-softokn-freebl-3.37.3-1.0.fc27.x86_64 nss-util-3.37.3-1.0.fc27.x86_64 openldap-2.4.45-4.fc27.x86_64 openssl-libs-1.1.0h-3.fc27.x86_64 pcre2-10.31-4.fc27.x86_64 systemd-libs-234-11.git5f8984e.fc27.x86_64 xz-libs-5.2.3-4.fc27.x86_64 (gdb) f 4 #4 0x000055555588a52e in zend_string_destroy (str=0x7fffe3c7e6e0, __zend_filename=0x5555559ce4a8 "/home/builduser/rpmbuild/BUILD/php-7.3.0/Zend/zend_vm_execute.h", __zend_lineno=12424) at /home/builduser/rpmbuild/BUILD/php-7.3.0/Zend/zend_variables.c:73 73 ZEND_ASSERT(!ZSTR_IS_INTERNED(str)); (gdb) p (char*)str->val $1 = 0x7fffe3c7e6f8 "http://localhost" ------------------------------------------------------------------------ [2018-06-12 11:41:23] spam2 at rhsoft dot net $openstr2 = "&amp;openmenu={$openmenu}{$addlang}"; is not used anywhere, so it will be DCEd together with the rope hell, yeah, that line is obsolete, now the testsuite crashes in a different file can we have a php.ini option to trigger warnings in error_log when DCE steps in but without crashes :-) seriously ------------------------------------------------------------------------ [2018-06-12 10:51:49] laruence@php.net as nikic said. a short reproduciable script is: <?php function test() { $addlang = ''; $openstr2 = "&amp;openmenu={$openmenu}{$addlang} \""; } test('1'); ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=76446 -- Edit this bug report at https://bugs.php.net/bug.php?id=76446&edit=1

« previous php.bugs (#215653) next »