Bug #78502 [Opn]: Segmentation Fault in array_map
| From: | phofstetter at sensational dot ch | Date: | Fri, 06 Sep 2019 06:33:17 +0000 |
| Subject: | Bug #78502 [Opn]: Segmentation Fault in array_map | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-222589@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=78502&edit=1
ID: 78502
User updated by: phofstetter at sensational dot ch
Reported by: phofstetter at sensational dot ch
Summary: Segmentation Fault in array_map
Status: Open
Type: Bug
Package: Reproducible crash
-Operating System: macos 10.14
+Operating System: macos 10.14, Debian 10
PHP Version: 7.4.0RC1
Block user comment: N
Private report: N
New Comment:
Also happens on Debian 10
Previous Comments:
------------------------------------------------------------------------
[2019-09-06 06:12:37] phofstetter at sensational dot ch
Description:
------------
The test script attached to this bug report will cause a segmenation fault, however, unfortunately,
it doesn't happen when a debubgger is attached(??)
pilif@celes:~| â php --version
PHP 7.4.0RC1 (cli) (built: Sep 6 2019 07:35:43) ( NTS )
Copyright (c) The PHP Group
Zend Engine v3.4.0-dev, Copyright (c) Zend Technologies
pilif@celes:~| â php segv.php
[1] 73522 segmentation fault php segv.php
pilif@celes:~| â
Test script:
---------------
<?php
$tree = [
'name' => 'a',
'quant' => 1,
'children' => [
['name' => 'b', 'quant' => 1],
['name' => 'c', 'quant' => 1, 'children' =>
[
['name' => 'd', 'quant' => 1],
]],
],
];
function tree_map($tree, $recursive_attr, closure $callback){
if(isset($tree[$recursive_attr])){
$tree[$recursive_attr] = array_map(function($c) use($recursive_attr, $callback){
return tree_map($c, $recursive_attr, $callback);
}, $tree[$recursive_attr]);
}
return $callback($tree);
}
tree_map($tree, 'children', function ($node) {});
Expected result:
----------------
no segfault
Actual result:
--------------
segfault. My attempts at getting a proper backtrace were foiled by this not crashing when e debugger
is attached.
However, a slightly more complicated version of the script produced the following trace in lldb:
pilif@celes:~| â lldb php
(lldb) target create "php"
Current executable set to 'php' (x86_64).
(lldb) run segv.php
Process 96419 launched: '/usr/local/bin/php' (x86_64)
Process 96419 stopped
* thread #1, queue = 'com.apple.main-thread', stop reason = EXC_BAD_ACCESS
(code=EXC_I386_GPFLT)
frame #0: 0x00000001003c2a3c php`zend_leave_helper_SPEC + 60
php`zend_leave_helper_SPEC:
-> 0x1003c2a3c <+60>: decl (%rdi)
0x1003c2a3e <+62>: je 0x1003c2a66 ; <+102>
0x1003c2a40 <+64>: movl 0x4(%rdi), %eax
0x1003c2a43 <+67>: cmpl $0xa, %eax
Target 0: (php) stopped.
(lldb) bt
* thread #1, queue = 'com.apple.main-thread', stop reason = EXC_BAD_ACCESS
(code=EXC_I386_GPFLT)
* frame #0: 0x00000001003c2a3c php`zend_leave_helper_SPEC + 60
frame #1: 0x000000010037f4ff php`execute_ex + 35
frame #2: 0x0000000100335102 php`zend_call_function + 1230
frame #3: 0x0000000100256cc0 php`zif_array_map + 448
frame #4: 0x00000001003b0365 php`ZEND_DO_ICALL_SPEC_RETVAL_USED_HANDLER + 80
frame #5: 0x000000010037f4ff php`execute_ex + 35
frame #6: 0x000000010037f6b7 php`zend_execute + 352
frame #7: 0x0000000100342981 php`zend_execute_scripts + 338
frame #8: 0x00000001002eb7bc php`php_execute_script + 482
frame #9: 0x00000001003c86fb php`do_cli + 3893
frame #10: 0x00000001003c7659 php`main + 1229
frame #11: 0x00007fff644192a5 libdyld.dylib`start + 1
(lldb)
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=78502&edit=1