Bug #78409 [Opn->Ana]: Segfault when creating instance of ArrayIterator without constructor

From: Date: Thu, 15 Aug 2019 08:35:26 +0000
Subject: Bug #78409 [Opn->Ana]: Segfault when creating instance of ArrayIterator without constructor
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-222257@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=78409&edit=1 ID: 78409 Updated by: nikic@php.net Reported by: nicolas dot grekas+php at gmail dot com Summary: Segfault when creating instance of ArrayIterator without constructor -Status: Open +Status: Analyzed Type: Bug Package: Reproducible crash PHP Version: 7.4.0beta2 Block user comment: N Private report: N New Comment: I believe the root cause here is this: $a = new ArrayObject; $u = [ 0, [], [], ]; $a->__unserialize($u); var_dump($u); array(3) { [0]=> int(0) [1]=> NULL <-- changed to NULL [2]=> array(0) { } } Previous Comments: ------------------------------------------------------------------------ [2019-08-13 17:00:38] nicolas dot grekas+php at gmail dot com Description: ------------ This is related to the new serialization mechanism of PHP 7.4. I don't have a better reproducer because when I try to isolate the crash, it works... Here is my reproducer, sorry I don't have a better one for now: Clone https://github.com/nicolas-grekas/symfony checkout branch "ve-php74" Then run ./phpunit src/Symfony/Component/VarExporter/ --do-not-cache-result --filter testExport#6 boom What the code does is that it: - uses newInstanceWithoutConstructor to create an ArrayIterator - clones that instance - calls __unserialize on the clone instance with a valid payload The crash happens after these step, when e.g. calling print_r() on the object. When done "manually", it works. But in the context of the test case, it segfaults. ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=78409&edit=1

« previous php.bugs (#222257) next »