Bug #80096 [Asn->Csd]: Segmentation fault with named arguments in nested call

From: Date: Mon, 14 Sep 2020 13:50:43 +0000
Subject: Bug #80096 [Asn->Csd]: Segmentation fault with named arguments in nested call
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-229003@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=80096&edit=1 ID: 80096 Updated by: nikic@php.net Reported by: thekid@php.net Summary: Segmentation fault with named arguments in nested call -Status: Assigned +Status: Closed Type: Bug Package: Scripting Engine problem Operating System: Ubuntu / WSL PHP Version: 8.0Git-2020-09-12 (Git) Assigned To: nikic Block user comment: N Private report: N New Comment: Automatic comment on behalf of nikita.ppv@gmail.com Revision: http://git.php.net/?p=php-src.git;a=commit;h=57a4a2c5a8ddd7e2f1214d5b05c270992e19451e Log: Fixed bug #80096 Previous Comments: ------------------------------------------------------------------------ [2020-09-12 13:14:38] thekid@php.net This does not occur if instead of htmlentities, a userland function is used: thekid@Surface:~/bin/php$ ./sapi/cli/php -r 'function html($string, $flags= 2, $double= true) { return htmlentities($string, $flags, null, $double); } function p($arg) { echo $arg, "\n"; } p(html("The < character is encoded as &lt;", double: false));' The &lt; character is encoded as &lt; ------------------------------------------------------------------------ [2020-09-12 12:13:14] thekid@php.net thekid@Surface:~/bin/php$ cat Zend/tests/bug80096.phpt --TEST-- Bug #80096 (Segmentation fault with named arguments) --FILE-- <?php function println($arg) { echo $arg, "\n"; } println(htmlentities("The < character is encoded as &lt;", double_encode: false)); ?> --EXPECT-- The &lt; character is encoded as &lt; ------------------------------------------------------------------------ [2020-09-12 12:13:14] thekid@php.net Related To: Bug #80096 ------------------------------------------------------------------------ [2020-09-12 11:19:35] thekid@php.net Program received signal SIGSEGV, Segmentation fault. 0x00005555558e6d3a in ZEND_SEND_VAR_SPEC_VAR_UNUSED_HANDLER () at /home/thekid/bin/php/Zend/zend_vm_execute.h:28375 28375 ZVAL_COPY_VALUE(arg, varptr); (gdb) bt #0 0x00005555558e6d3a in ZEND_SEND_VAR_SPEC_VAR_UNUSED_HANDLER () at /home/thekid/bin/php/Zend/zend_vm_execute.h:28375 #1 execute_ex (ex=0x0) at /home/thekid/bin/php/Zend/zend_vm_execute.h:58125 #2 0x00005555558ed7df in zend_execute (op_array=<optimized out>, return_value=0x7fffffffcc80) at /home/thekid/bin/php/Zend/zend_vm_execute.h:59928 #3 0x0000555555873600 in zend_eval_stringl ( str=0x555556573fc0 "function p($arg) { echo $arg, \"\\n\"; } p(htmlentities(\"The < character is encoded as &lt;\", double_encode: false));", str_len=<optimized out>, retval_ptr=0x0, string_name=0x5555560a4615 "Command line code") at /home/thekid/bin/php/Zend/zend_execute_API.c:1195 #4 0x00005555558737c9 in zend_eval_stringl_ex (str=<optimized out>, str_len=<optimized out>, retval_ptr=<optimized out>, string_name=<optimized out>, handle_exceptions=<optimized out>) at /home/thekid/bin/php/Zend/zend_execute_API.c:1236 #5 0x00005555559136f3 in do_cli (argc=3, argv=0x555556573f40) at /home/thekid/bin/php/sapi/cli/php_cli.c:979 #6 0x00005555556462db in main (argc=3, argv=0x555556573f40) at /home/thekid/bin/php/sapi/cli/php_cli.c:1336 ------------------------------------------------------------------------ [2020-09-12 11:17:54] thekid@php.net Description: ------------ Passing a function invoked with named arguments as an argument to a function results in PHP crashing with a segmentation fault. Test script: --------------- thekid@Surface:~/bin/php$ ./sapi/cli/php -r 'function p($arg) { echo $arg, "\n"; } p(htmlentities("The < character is encoded as &lt;", do uble_encode: false));' Segmentation fault thekid@Surface:~/bin/php$ ./sapi/cli/php -v PHP 8.0.0-dev (cli) (built: Sep 12 2020 04:33:25) ( NTS ) Copyright (c) The PHP Group Zend Engine v4.0.0-dev, Copyright (c) Zend Technologies Expected result: ---------------- The &lt; character is encoded as &lt; Actual result: -------------- Segmentation fault ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=80096&edit=1

« previous php.bugs (#229003) next »