Bug #80096 [Asn->Csd]: Segmentation fault with named arguments in nested call
| From: | nikic@php.net | Date: | Mon, 14 Sep 2020 13:50:43 +0000 |
| Subject: | Bug #80096 [Asn->Csd]: Segmentation fault with named arguments in nested call | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-229003@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=80096&edit=1
ID: 80096
Updated by: nikic@php.net
Reported by: thekid@php.net
Summary: Segmentation fault with named arguments in nested
call
-Status: Assigned
+Status: Closed
Type: Bug
Package: Scripting Engine problem
Operating System: Ubuntu / WSL
PHP Version: 8.0Git-2020-09-12 (Git)
Assigned To: nikic
Block user comment: N
Private report: N
New Comment:
Automatic comment on behalf of nikita.ppv@gmail.com
Revision: http://git.php.net/?p=php-src.git;a=commit;h=57a4a2c5a8ddd7e2f1214d5b05c270992e19451e
Log: Fixed bug #80096
Previous Comments:
------------------------------------------------------------------------
[2020-09-12 13:14:38] thekid@php.net
This does not occur if instead of htmlentities, a userland function is used:
thekid@Surface:~/bin/php$ ./sapi/cli/php -r 'function html($string, $flags= 2, $double= true) {
return htmlentities($string, $flags, null, $double); } function p($arg) { echo $arg, "\n";
} p(html("The < character is encoded as <", double: false));'
The < character is encoded as <
------------------------------------------------------------------------
[2020-09-12 12:13:14] thekid@php.net
thekid@Surface:~/bin/php$ cat Zend/tests/bug80096.phpt
--TEST--
Bug #80096 (Segmentation fault with named arguments)
--FILE--
<?php
function println($arg) {
echo $arg, "\n";
}
println(htmlentities("The < character is encoded as <", double_encode: false));
?>
--EXPECT--
The < character is encoded as <
------------------------------------------------------------------------
[2020-09-12 12:13:14] thekid@php.net
Related To: Bug #80096
------------------------------------------------------------------------
[2020-09-12 11:19:35] thekid@php.net
Program received signal SIGSEGV, Segmentation fault.
0x00005555558e6d3a in ZEND_SEND_VAR_SPEC_VAR_UNUSED_HANDLER () at
/home/thekid/bin/php/Zend/zend_vm_execute.h:28375
28375 ZVAL_COPY_VALUE(arg, varptr);
(gdb) bt
#0 0x00005555558e6d3a in ZEND_SEND_VAR_SPEC_VAR_UNUSED_HANDLER () at
/home/thekid/bin/php/Zend/zend_vm_execute.h:28375
#1 execute_ex (ex=0x0) at /home/thekid/bin/php/Zend/zend_vm_execute.h:58125
#2 0x00005555558ed7df in zend_execute (op_array=<optimized out>, return_value=0x7fffffffcc80)
at /home/thekid/bin/php/Zend/zend_vm_execute.h:59928
#3 0x0000555555873600 in zend_eval_stringl (
str=0x555556573fc0 "function p($arg) { echo $arg, \"\\n\"; }
p(htmlentities(\"The < character is encoded as <\", double_encode:
false));", str_len=<optimized out>, retval_ptr=0x0, string_name=0x5555560a4615
"Command line code")
at /home/thekid/bin/php/Zend/zend_execute_API.c:1195
#4 0x00005555558737c9 in zend_eval_stringl_ex (str=<optimized out>, str_len=<optimized
out>, retval_ptr=<optimized out>,
string_name=<optimized out>, handle_exceptions=<optimized out>) at
/home/thekid/bin/php/Zend/zend_execute_API.c:1236
#5 0x00005555559136f3 in do_cli (argc=3, argv=0x555556573f40) at
/home/thekid/bin/php/sapi/cli/php_cli.c:979
#6 0x00005555556462db in main (argc=3, argv=0x555556573f40) at
/home/thekid/bin/php/sapi/cli/php_cli.c:1336
------------------------------------------------------------------------
[2020-09-12 11:17:54] thekid@php.net
Description:
------------
Passing a function invoked with named arguments as an argument to a function results in PHP crashing
with a segmentation fault.
Test script:
---------------
thekid@Surface:~/bin/php$ ./sapi/cli/php -r 'function p($arg) { echo $arg, "\n"; }
p(htmlentities("The < character is encoded as <", do
uble_encode: false));'
Segmentation fault
thekid@Surface:~/bin/php$ ./sapi/cli/php -v
PHP 8.0.0-dev (cli) (built: Sep 12 2020 04:33:25) ( NTS )
Copyright (c) The PHP Group
Zend Engine v4.0.0-dev, Copyright (c) Zend Technologies
Expected result:
----------------
The < character is encoded as <
Actual result:
--------------
Segmentation fault
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=80096&edit=1