Bug #78502 [Opn]: Segmentation Fault in array_map

From: Date: Fri, 06 Sep 2019 06:33:17 +0000
Subject: Bug #78502 [Opn]: Segmentation Fault in array_map
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-222589@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=78502&edit=1 ID: 78502 User updated by: phofstetter at sensational dot ch Reported by: phofstetter at sensational dot ch Summary: Segmentation Fault in array_map Status: Open Type: Bug Package: Reproducible crash -Operating System: macos 10.14 +Operating System: macos 10.14, Debian 10 PHP Version: 7.4.0RC1 Block user comment: N Private report: N New Comment: Also happens on Debian 10 Previous Comments: ------------------------------------------------------------------------ [2019-09-06 06:12:37] phofstetter at sensational dot ch Description: ------------ The test script attached to this bug report will cause a segmenation fault, however, unfortunately, it doesn't happen when a debubgger is attached(??) pilif@celes:~| ⇒ php --version PHP 7.4.0RC1 (cli) (built: Sep 6 2019 07:35:43) ( NTS ) Copyright (c) The PHP Group Zend Engine v3.4.0-dev, Copyright (c) Zend Technologies pilif@celes:~| ⇒ php segv.php [1] 73522 segmentation fault php segv.php pilif@celes:~| ⇒ Test script: --------------- <?php $tree = [ 'name' => 'a', 'quant' => 1, 'children' => [ ['name' => 'b', 'quant' => 1], ['name' => 'c', 'quant' => 1, 'children' => [ ['name' => 'd', 'quant' => 1], ]], ], ]; function tree_map($tree, $recursive_attr, closure $callback){ if(isset($tree[$recursive_attr])){ $tree[$recursive_attr] = array_map(function($c) use($recursive_attr, $callback){ return tree_map($c, $recursive_attr, $callback); }, $tree[$recursive_attr]); } return $callback($tree); } tree_map($tree, 'children', function ($node) {}); Expected result: ---------------- no segfault Actual result: -------------- segfault. My attempts at getting a proper backtrace were foiled by this not crashing when e debugger is attached. However, a slightly more complicated version of the script produced the following trace in lldb: pilif@celes:~| ⇒ lldb php (lldb) target create "php" Current executable set to 'php' (x86_64). (lldb) run segv.php Process 96419 launched: '/usr/local/bin/php' (x86_64) Process 96419 stopped * thread #1, queue = 'com.apple.main-thread', stop reason = EXC_BAD_ACCESS (code=EXC_I386_GPFLT) frame #0: 0x00000001003c2a3c php`zend_leave_helper_SPEC + 60 php`zend_leave_helper_SPEC: -> 0x1003c2a3c <+60>: decl (%rdi) 0x1003c2a3e <+62>: je 0x1003c2a66 ; <+102> 0x1003c2a40 <+64>: movl 0x4(%rdi), %eax 0x1003c2a43 <+67>: cmpl $0xa, %eax Target 0: (php) stopped. (lldb) bt * thread #1, queue = 'com.apple.main-thread', stop reason = EXC_BAD_ACCESS (code=EXC_I386_GPFLT) * frame #0: 0x00000001003c2a3c php`zend_leave_helper_SPEC + 60 frame #1: 0x000000010037f4ff php`execute_ex + 35 frame #2: 0x0000000100335102 php`zend_call_function + 1230 frame #3: 0x0000000100256cc0 php`zif_array_map + 448 frame #4: 0x00000001003b0365 php`ZEND_DO_ICALL_SPEC_RETVAL_USED_HANDLER + 80 frame #5: 0x000000010037f4ff php`execute_ex + 35 frame #6: 0x000000010037f6b7 php`zend_execute + 352 frame #7: 0x0000000100342981 php`zend_execute_scripts + 338 frame #8: 0x00000001002eb7bc php`php_execute_script + 482 frame #9: 0x00000001003c86fb php`do_cli + 3893 frame #10: 0x00000001003c7659 php`main + 1229 frame #11: 0x00007fff644192a5 libdyld.dylib`start + 1 (lldb) ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=78502&edit=1

« previous php.bugs (#222589) next »