Bug #78715 [Com]: Segmentation fault in zend_type_to_string_resolved

From: Date: Tue, 22 Oct 2019 12:59:11 +0000
Subject: Bug #78715 [Com]: Segmentation fault in zend_type_to_string_resolved
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-223378@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=78715&edit=1

 ID:                 78715
 Comment by:         a dot dankovtsev at mail dot ru
 Reported by:        a dot dankovtsev at mail dot ru
 Summary:            Segmentation fault in zend_type_to_string_resolved
 Status:             Open
 Type:               Bug
 Package:            Reflection related
 Operating System:   Mac OS
 PHP Version:        master-Git-2019-10-22 (Git)
 Block user comment: N
 Private report:     N

 New Comment:

Hm... i rebuild again extension for redis with version 5.0.2
(https://github.com/phpredis/phpredis/tree/5.0.2)
Parameter with segfault was:
Type: array
Parameter: aggregate
Rebuild is resolve this segmentation fault...
Sorry for spent time...


Previous Comments:
------------------------------------------------------------------------
[2019-10-22 10:56:08] a dot dankovtsev at mail dot ru

reproduce in this code

php:
{code}
<?php

declare(strict_types = 1);

$refClass = new \ReflectionClass(\Redis::class);

$refMethod = $refClass->getMethod('zinterstore');
foreach ($refMethod->getParameters() as $param) {
    echo 'Parameter: ' . $param->getName() . PHP_EOL;
    $type = $param->getType();
    if ($type instanceof \ReflectionNamedType) {
        var_dump($type);
        $typeDeclaration = $type->getName() . ' '; // segfault this
    }
}

{code}

output:
{code}
php test.php
Parameter: key
Parameter: keys
object(ReflectionNamedType)#7 (0) {
}
Parameter: weights
object(ReflectionNamedType)#8 (0) {
}
[1]    55227 segmentation fault (core dumped)  php test.php
{code}

------------------------------------------------------------------------
[2019-10-22 09:44:21] nikic@php.net

type=29 is corrupt, but I can't tell where it originates based on the trace.

------------------------------------------------------------------------
[2019-10-22 06:40:03] a dot dankovtsev at mail dot ru

Description:
------------
Sorry, i can't izolate test stend for reproduce.
Segmentation fault while run unit-tests in some project
core dump:

lldb --core /cores/core.39217
(lldb) target create --core "/cores/core.39217"
btCore file '/cores/core.39217' (x86_64) was loaded.
(lldb) bt all
php was compiled with optimization - stepping may behave oddly; variables may not be available.
* thread #1, stop reason = signal SIGSTOP
  * frame #0: 0x000000010b1224c2 php`zend_type_to_string_resolved(type=29, scope=0x0000000000000000)
at zend_compile.c:1099 [opt]
    frame #1: 0x000000010afe8658
php`zim_reflection_named_type_getName(execute_data=<unavailable>,
return_value=0x000000010c221340) at php_reflection.c:2837 [opt]
    frame #2: 0x000000010b1c1d56
php`ZEND_DO_FCALL_SPEC_RETVAL_USED_HANDLER(execute_data=0x000000010c2215c0) at
zend_vm_execute.h:1673 [opt]
    frame #3: 0x000000010b1a3e08 php`execute_ex(ex=0x000000010c221050) at zend_vm_execute.h:52102
[opt]
    frame #4: 0x000000010b1a3fcc php`zend_execute(op_array=0x000000010c27a540,
return_value=0x0000000000000000) at zend_vm_execute.h:56355 [opt]
    frame #5: 0x000000010b159761 php`zend_execute_scripts(type=8, retval=0x0000000000000000,
file_count=3) at zend.c:1645 [opt]
    frame #6: 0x000000010b0e36f1 php`php_execute_script(primary_file=<unavailable>) at
main.c:2586 [opt]
    frame #7: 0x000000010b1f378b php`do_cli(argc=<unavailable>, argv=<unavailable>) at
php_cli.c:959 [opt]
    frame #8: 0x000000010b1f25f8 php`main(argc=3, argv=0x00007ffee4d9bad0) at php_cli.c:1350 [opt]
    frame #9: 0x00007fff73d35015 libdyld.dylib`start + 1




------------------------------------------------------------------------



--
Edit this bug report at https://bugs.php.net/bug.php?id=78715&edit=1


Thread (5 messages)

« previous php.bugs (#223378) next »