Bug #77533 [NEW]: Found crash when appending element to pass-by-ref array with []

From: Date: Mon, 28 Jan 2019 02:43:12 +0000
Subject: Bug #77533 [NEW]: Found crash when appending element to pass-by-ref array with []
Groups: php.bugs 
Request: Send a blank email to php-bugs+get-219232@lists.php.net to get a copy of this message
From: timandes Operating system: CentOS Linux release 7.6.1810 (C PHP version: 7.3.1 Package: Reproducible crash Bug Type: Bug Bug description:Found crash when appending element to pass-by-ref array with [] Description: ------------ Last week, I found a CI failure[1] of pecl/zookeeper. I thought it would be compatibility problem because I turned on PHP-7.3 in .travis.yml. When I looked into that issue, I found it's weird because the crash point was in the PHP src, and it only crashed when I passed an empty array to the function provided pass-by-ref var. So I wrote a small ext to reproduce that: ```c PHP_FUNCTION(caseone_test1) { zval *param; if (zend_parse_parameters(ZEND_NUM_ARGS(), "z", &param) == FAILURE) { return; } if (param) { ZVAL_DEREF(param); } if (Z_TYPE_P(param) != IS_ARRAY) { array_init(param); } add_assoc_long_ex(param, ZEND_STRL("foo"), 0); } ``` ```php $param = []; caseone_test1($param); ``` ```gdb #0 0x000056193020c64e in zend_hash_real_init_mixed_ex (ht=ht@entry=0x5619305fe220 <zend_empty_array>) at /usr/src/debug/php-7.3.1/Zend/zend_hash.c:131 #1 zend_hash_real_init_mixed (ht=ht@entry=0x5619305fe220 <zend_empty_array>) at /usr/src/debug/php-7.3.1/Zend/zend_hash.c:260 #2 0x000056193020db88 in _zend_hash_str_add_or_update_i (flag=1, pData=0x7fffbb8834d0, h=9223372037048267657, len=3, str=0x7ff29e4b7d93 "foo", ht=0x5619305fe220 <zend_empty_array>) at /usr/src/debug/php-7.3.1/Zend/zend_hash.c:746 #3 zend_hash_str_update (ht=ht@entry=0x5619305fe220 <zend_empty_array>, str=str@entry=0x7ff29e4b7d93 "foo", len=len@entry=3, pData=pData@entry=0x7fffbb8834d0) at /usr/src/debug/php-7.3.1/Zend/zend_hash.c:854 #4 0x00005619302021a8 in zend_symtable_str_update (pData=0x7fffbb8834d0, len=3, str=0x7ff29e4b7d93 "foo", ht=0x5619305fe220 <zend_empty_array>) at /usr/src/debug/php-7.3.1/Zend/zend_hash.h:498 #5 add_assoc_long_ex (arg=<optimized out>, key=key@entry=0x7ff29e4b7d93 "foo", key_len=key_len@entry=3, n=n@entry=0) at /usr/src/debug/php-7.3.1/Zend/zend_API.c:1359 #6 0x00007ff29e4b7c7c in zif_caseone_test1 (execute_data=<optimized out>, return_value=<optimized out>) at /root/php-7.3.1/ext/caseone/caseone.c:29 #7 0x000056193028b2f9 in ZEND_DO_ICALL_SPEC_RETVAL_UNUSED_HANDLER () at /usr/src/debug/php-7.3.1/Zend/zend_vm_execute.h:645 #8 execute_ex (ex=0x5619305fe220 <zend_empty_array>) at /usr/src/debug/php-7.3.1/Zend/zend_vm_execute.h:55414 #9 0x000056193028f3a3 in zend_execute (op_array=op_array@entry=0x7ff2a267d2a0, return_value=0x0, return_value@entry=0x7ff2a267d3e0) at /usr/src/debug/php-7.3.1/Zend/zend_vm_execute.h:60834 #10 0x0000561930200622 in zend_execute_scripts (type=type@entry=8, retval=0x7ff2a267d3e0, retval@entry=0x0, file_count=-1570648016, file_count@entry=3) at /usr/src/debug/php-7.3.1/Zend/zend.c:1568 #11 0x00005619301a05d0 in php_execute_script (primary_file=primary_file@entry=0x7fffbb885b80) at /usr/src/debug/php-7.3.1/main/main.c:2630 #12 0x0000561930291892 in do_cli (argc=3, argv=0x561930f3f960) at /usr/src/debug/php-7.3.1/sapi/cli/php_cli.c:997 #13 0x000056193000121b in main (argc=3, argv=0x561930f3f960) at /usr/src/debug/php-7.3.1/sapi/cli/php_cli.c:1389 ``` When I changed the former PHP script to : ```php $param = ''; caseone_test1($param); ``` or ```php $param = [0]; caseone_test1($param); ``` , they worked fine. This issue can only be reproduced under Linux. I'm not sure it's a bug or not, so I turned to you guys for help. System info: ```shell uname -a Linux 93a912e38b29 4.9.125-linuxkit #1 SMP Fri Sep 7 08:20:28 UTC 2018 x86_64 x86_64 x86_64 GNU/Linux ``` ```shell cat /etc/redhat-release CentOS Linux release 7.6.1810 (Core) ``` [1] https://api.travis-ci.org/v3/job/484167428/log.txt -- Edit bug report at https://bugs.php.net/bug.php?id=77533&edit=1 -- Try a snapshot (PHP 5.4): https://bugs.php.net/fix.php?id=77533&r=trysnapshot54 Try a snapshot (PHP 5.5): https://bugs.php.net/fix.php?id=77533&r=trysnapshot55 Try a snapshot (trunk): https://bugs.php.net/fix.php?id=77533&r=trysnapshottrunk Fixed in SVN: https://bugs.php.net/fix.php?id=77533&r=fixed Fixed in release: https://bugs.php.net/fix.php?id=77533&r=alreadyfixed Need backtrace: https://bugs.php.net/fix.php?id=77533&r=needtrace Need Reproduce Script: https://bugs.php.net/fix.php?id=77533&r=needscript Try newer version: https://bugs.php.net/fix.php?id=77533&r=oldversion Not developer issue: https://bugs.php.net/fix.php?id=77533&r=support Expected behavior: https://bugs.php.net/fix.php?id=77533&r=notwrong Not enough info: https://bugs.php.net/fix.php?id=77533&r=notenoughinfo Submitted twice: https://bugs.php.net/fix.php?id=77533&r=submittedtwice register_globals: https://bugs.php.net/fix.php?id=77533&r=globals PHP 4 support discontinued: https://bugs.php.net/fix.php?id=77533&r=php4 Daylight Savings: https://bugs.php.net/fix.php?id=77533&r=dst IIS Stability: https://bugs.php.net/fix.php?id=77533&r=isapi Install GNU Sed: https://bugs.php.net/fix.php?id=77533&r=gnused Floating point limitations: https://bugs.php.net/fix.php?id=77533&r=float No Zend Extensions: https://bugs.php.net/fix.php?id=77533&r=nozend MySQL Configuration Error: https://bugs.php.net/fix.php?id=77533&r=mysqlcfg

« previous php.bugs (#219232) next »