Bug #78230 [Opn]: c0000005 in PHP7.dll, Offset 0000000000007a05
| From: | ASchmidt at Anamera dot net | Date: | Tue, 02 Jul 2019 20:01:31 +0000 |
| Subject: | Bug #78230 [Opn]: c0000005 in PHP7.dll, Offset 0000000000007a05 | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-221589@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=78230&edit=1
ID: 78230
User updated by: ASchmidt at Anamera dot net
Reported by: ASchmidt at Anamera dot net
Summary: c0000005 in PHP7.dll, Offset 0000000000007a05
Status: Open
Type: Bug
Package: opcache
Operating System: Win x64
PHP Version: 7.3.7RC3
Block user comment: N
Private report: N
New Comment:
I have spent days trying to pinpoint this better. It's triggered if an "is_array()"
is used against a variable, if that variable was assigned from a function parameter that is an
object property holding an array, and if in the assignment an explicit coercion to an array was
performed:
$thevar = (array) $functionparm->property; // property IS an array
is_array( $thevar ); // will crash OPcache later in the code path.
It will NOT fail for:
a) is_array( $functionparm->property ) ⦠or
b) is_array( (array) $functionparm->property ) ⦠or
c) if the (array) coercion is omitted: $thevar = $functionparm->property
It will NOT crash AT THE TIME of the "is_array()", but it will crash later, if the code is
allowed to proceed from there.
For reference, here the actual code snippet with various var_dumps added to see what works, and what
does not:
static $mypass = 0;
function start_el( &$output, $item, $depth = 0, $args = array(), $id = 0 ) {
var_dump( self::$mypass, $item->classes );
var_dump( is_array( $item->classes ) );
var_dump( is_array( (array) $item->classes ) );
$myvar1 = $item->classes;
$myvar2 = (array) $item->classes;
var_dump( is_array( $myvar1 ) );
if ( 0 == self::$mypass++ ) { // It doesn't matter, if the "is_array" only executes
once.
var_dump( is_array( $myvar2 ) ); // This will trigger the crash LATER in the code.
// die( 'x'); // It will NOT crash, if the code stops here.
}
Previous Comments:
------------------------------------------------------------------------
[2019-06-28 18:56:51] ASchmidt at Anamera dot net
Description:
------------
Problem reproducable on fresh, "out-of-the-box" WordPress 4.9.10, with only "Max Mega
Menu" plugin installed.
Crash will occur the moment site's home page is requested (as long as the menu is handled by
"Max Mega Menu"), but will not occur for other pages and/or non-WP pages.
Problem can be temporarily circumvented by either:
opcache.enable = 0
or by disabling the plug-in.
Test script:
---------------
Unfortunately, there is insufficient information for me to pinpoint the particular code sequence in
the plug-in that causes OPcache to misbehave.
But I confirmed the consistent nature of the problem by setting up a fresh site from scratch.
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=78230&edit=1