Bug #78230 [Opn->Asn]: c0000005 in PHP7.dll, Offset 0000000000007a05

From: Date: Wed, 03 Jul 2019 08:00:28 +0000
Subject: Bug #78230 [Opn->Asn]: c0000005 in PHP7.dll, Offset 0000000000007a05
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-221598@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=78230&edit=1 ID: 78230 Updated by: nikic@php.net Reported by: ASchmidt at Anamera dot net Summary: c0000005 in PHP7.dll, Offset 0000000000007a05 -Status: Open +Status: Assigned Type: Bug Package: opcache Operating System: Win x64 PHP Version: 7.3.7RC3 -Assigned To: +Assigned To: nikic Block user comment: N Private report: N New Comment: Converting #230.T15 [bool] = TYPE_CHECK (array) #47.CV7($classes) [array of [any, ref]] to FREE #47.CV7($classes) [array of [any, ref]] Previous Comments: ------------------------------------------------------------------------ [2019-07-02 21:30:11] ASchmidt at Anamera dot net Not sure if I had made that clear enough: the crash occurs in a plug-in of the WordPress CMS. So, it's not just a simple single PHP file. Here the link to the plug in (there is the download link): https://wordpress.org/plugins/megamenu/#installation The particular code section is in "walker.class.php". Also I have created an "out of the box" WordPress debug site, with that plug-in loaded, to which I can supply FTP access if that would be helpful at all. ------------------------------------------------------------------------ [2019-07-02 21:06:28] nikic@php.net Could you please provide the full source code of the relevant file? (To nikic@php.net if not public.) This sounds like an optimization bug. ------------------------------------------------------------------------ [2019-07-02 20:04:40] ASchmidt at Anamera dot net PS: the size of the array is small, only a handful of short strings: array (size=6) 0 => string '' (length=0) 1 => string 'menu-item' (length=9) 2 => string 'menu-item-type-taxonomy' (length=23) 3 => string 'menu-item-object-category' (length=25) 4 => string 'align-bottom-left' (length=17) 5 => string 'menu-flyout' (length=11) ------------------------------------------------------------------------ [2019-07-02 20:01:31] ASchmidt at Anamera dot net I have spent days trying to pinpoint this better. It's triggered if an "is_array()" is used against a variable, if that variable was assigned from a function parameter that is an object property holding an array, and if in the assignment an explicit coercion to an array was performed: $thevar = (array) $functionparm->property; // property IS an array is_array( $thevar ); // will crash OPcache later in the code path. It will NOT fail for: a) is_array( $functionparm->property ) … or b) is_array( (array) $functionparm->property ) … or c) if the (array) coercion is omitted: $thevar = $functionparm->property It will NOT crash AT THE TIME of the "is_array()", but it will crash later, if the code is allowed to proceed from there. For reference, here the actual code snippet with various var_dumps added to see what works, and what does not: static $mypass = 0; function start_el( &$output, $item, $depth = 0, $args = array(), $id = 0 ) { var_dump( self::$mypass, $item->classes ); var_dump( is_array( $item->classes ) ); var_dump( is_array( (array) $item->classes ) ); $myvar1 = $item->classes; $myvar2 = (array) $item->classes; var_dump( is_array( $myvar1 ) ); if ( 0 == self::$mypass++ ) { // It doesn't matter, if the "is_array" only executes once. var_dump( is_array( $myvar2 ) ); // This will trigger the crash LATER in the code. // die( 'x'); // It will NOT crash, if the code stops here. } ------------------------------------------------------------------------ [2019-06-28 18:56:51] ASchmidt at Anamera dot net Description: ------------ Problem reproducable on fresh, "out-of-the-box" WordPress 4.9.10, with only "Max Mega Menu" plugin installed. Crash will occur the moment site's home page is requested (as long as the menu is handled by "Max Mega Menu"), but will not occur for other pages and/or non-WP pages. Problem can be temporarily circumvented by either: opcache.enable = 0 or by disabling the plug-in. Test script: --------------- Unfortunately, there is insufficient information for me to pinpoint the particular code sequence in the plug-in that causes OPcache to misbehave. But I confirmed the consistent nature of the problem by setting up a fresh site from scratch. ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=78230&edit=1

« previous php.bugs (#221598) next »