Bug #77533 [NEW]: Found crash when appending element to pass-by-ref array with []
| From: | timandes@php.net | Date: | Mon, 28 Jan 2019 02:43:12 +0000 |
| Subject: | Bug #77533 [NEW]: Found crash when appending element to pass-by-ref array with [] | ||
| Groups: | php.bugs | ||
| Request: | Send a blank email to php-bugs+get-219232@lists.php.net to get a copy of this message | ||
From: timandes
Operating system: CentOS Linux release 7.6.1810 (C
PHP version: 7.3.1
Package: Reproducible crash
Bug Type: Bug
Bug description:Found crash when appending element to pass-by-ref array with []
Description:
------------
Last week, I found a CI failure[1] of pecl/zookeeper. I thought it would
be compatibility problem because I turned on PHP-7.3 in .travis.yml.
When I looked into that issue, I found it's weird because the crash
point was in the PHP src, and it only crashed when I passed an empty
array to the function provided pass-by-ref var.
So I wrote a small ext to reproduce that:
```c
PHP_FUNCTION(caseone_test1)
{
zval *param;
if (zend_parse_parameters(ZEND_NUM_ARGS(), "z", ¶m) ==
FAILURE) {
return;
}
if (param) {
ZVAL_DEREF(param);
}
if (Z_TYPE_P(param) != IS_ARRAY) {
array_init(param);
}
add_assoc_long_ex(param, ZEND_STRL("foo"), 0);
}
```
```php
$param = [];
caseone_test1($param);
```
```gdb
#0 0x000056193020c64e in zend_hash_real_init_mixed_ex
(ht=ht@entry=0x5619305fe220 <zend_empty_array>) at
/usr/src/debug/php-7.3.1/Zend/zend_hash.c:131
#1 zend_hash_real_init_mixed (ht=ht@entry=0x5619305fe220
<zend_empty_array>) at /usr/src/debug/php-7.3.1/Zend/zend_hash.c:260
#2 0x000056193020db88 in _zend_hash_str_add_or_update_i (flag=1,
pData=0x7fffbb8834d0, h=9223372037048267657, len=3, str=0x7ff29e4b7d93
"foo", ht=0x5619305fe220 <zend_empty_array>)
at /usr/src/debug/php-7.3.1/Zend/zend_hash.c:746
#3 zend_hash_str_update (ht=ht@entry=0x5619305fe220 <zend_empty_array>,
str=str@entry=0x7ff29e4b7d93 "foo", len=len@entry=3,
pData=pData@entry=0x7fffbb8834d0)
at /usr/src/debug/php-7.3.1/Zend/zend_hash.c:854
#4 0x00005619302021a8 in zend_symtable_str_update
(pData=0x7fffbb8834d0, len=3, str=0x7ff29e4b7d93 "foo",
ht=0x5619305fe220 <zend_empty_array>)
at /usr/src/debug/php-7.3.1/Zend/zend_hash.h:498
#5 add_assoc_long_ex (arg=<optimized out>, key=key@entry=0x7ff29e4b7d93
"foo", key_len=key_len@entry=3, n=n@entry=0) at
/usr/src/debug/php-7.3.1/Zend/zend_API.c:1359
#6 0x00007ff29e4b7c7c in zif_caseone_test1 (execute_data=<optimized
out>, return_value=<optimized out>) at
/root/php-7.3.1/ext/caseone/caseone.c:29
#7 0x000056193028b2f9 in ZEND_DO_ICALL_SPEC_RETVAL_UNUSED_HANDLER () at
/usr/src/debug/php-7.3.1/Zend/zend_vm_execute.h:645
#8 execute_ex (ex=0x5619305fe220 <zend_empty_array>) at
/usr/src/debug/php-7.3.1/Zend/zend_vm_execute.h:55414
#9 0x000056193028f3a3 in zend_execute
(op_array=op_array@entry=0x7ff2a267d2a0, return_value=0x0,
return_value@entry=0x7ff2a267d3e0)
at /usr/src/debug/php-7.3.1/Zend/zend_vm_execute.h:60834
#10 0x0000561930200622 in zend_execute_scripts (type=type@entry=8,
retval=0x7ff2a267d3e0, retval@entry=0x0, file_count=-1570648016,
file_count@entry=3)
at /usr/src/debug/php-7.3.1/Zend/zend.c:1568
#11 0x00005619301a05d0 in php_execute_script
(primary_file=primary_file@entry=0x7fffbb885b80) at
/usr/src/debug/php-7.3.1/main/main.c:2630
#12 0x0000561930291892 in do_cli (argc=3, argv=0x561930f3f960) at
/usr/src/debug/php-7.3.1/sapi/cli/php_cli.c:997
#13 0x000056193000121b in main (argc=3, argv=0x561930f3f960) at
/usr/src/debug/php-7.3.1/sapi/cli/php_cli.c:1389
```
When I changed the former PHP script to :
```php
$param = '';
caseone_test1($param);
```
or
```php
$param = [0];
caseone_test1($param);
```
, they worked fine.
This issue can only be reproduced under Linux.
I'm not sure it's a bug or not, so I turned to you guys for help.
System info:
```shell
uname -a
Linux 93a912e38b29 4.9.125-linuxkit #1 SMP Fri Sep 7 08:20:28 UTC 2018
x86_64 x86_64 x86_64 GNU/Linux
```
```shell
cat /etc/redhat-release
CentOS Linux release 7.6.1810 (Core)
```
[1] https://api.travis-ci.org/v3/job/484167428/log.txt
--
Edit bug report at https://bugs.php.net/bug.php?id=77533&edit=1
--
Try a snapshot (PHP 5.4): https://bugs.php.net/fix.php?id=77533&r=trysnapshot54
Try a snapshot (PHP 5.5): https://bugs.php.net/fix.php?id=77533&r=trysnapshot55
Try a snapshot (trunk): https://bugs.php.net/fix.php?id=77533&r=trysnapshottrunk
Fixed in SVN: https://bugs.php.net/fix.php?id=77533&r=fixed
Fixed in release: https://bugs.php.net/fix.php?id=77533&r=alreadyfixed
Need backtrace: https://bugs.php.net/fix.php?id=77533&r=needtrace
Need Reproduce Script: https://bugs.php.net/fix.php?id=77533&r=needscript
Try newer version: https://bugs.php.net/fix.php?id=77533&r=oldversion
Not developer issue: https://bugs.php.net/fix.php?id=77533&r=support
Expected behavior: https://bugs.php.net/fix.php?id=77533&r=notwrong
Not enough info: https://bugs.php.net/fix.php?id=77533&r=notenoughinfo
Submitted twice: https://bugs.php.net/fix.php?id=77533&r=submittedtwice
register_globals: https://bugs.php.net/fix.php?id=77533&r=globals
PHP 4 support discontinued: https://bugs.php.net/fix.php?id=77533&r=php4
Daylight Savings: https://bugs.php.net/fix.php?id=77533&r=dst
IIS Stability: https://bugs.php.net/fix.php?id=77533&r=isapi
Install GNU Sed: https://bugs.php.net/fix.php?id=77533&r=gnused
Floating point limitations: https://bugs.php.net/fix.php?id=77533&r=float
No Zend Extensions: https://bugs.php.net/fix.php?id=77533&r=nozend
MySQL Configuration Error: https://bugs.php.net/fix.php?id=77533&r=mysqlcfg