#22463 [Ver->Csd]: array_reduce segmentation fault

From: Date: Sun, 11 May 2003 06:39:57 +0000
Subject: #22463 [Ver->Csd]: array_reduce segmentation fault
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-39436@lists.php.net to get a copy of this message
ID: 22463 Updated by: moriyoshi@php.net Reported By: mccannwj at pha dot jhu dot edu -Status: Verified +Status: Closed Bug Type: Arrays related Operating System: redhat-linux-8.0 PHP Version: 4.3.2-dev New Comment: This bug has been fixed in CVS. In case this was a PHP problem, snapshots of the sources are packaged every three hours; this change will be in the next snapshot. You can grab the snapshot at http://snaps.php.net/. In case this was a documentation problem, the fix will show up soon at http://www.php.net/manual/. In case this was a PHP.net website problem, the change will show up on the PHP.net site and on the mirror sites in short time. Thank you for the report, and for helping us make PHP better. Previous Comments: ------------------------------------------------------------------------ [2003-03-25 13:57:12] tal@php.net It coredumps with latest 5.0.0-dev Backtrace (relevant lines): #0 _zend_is_inconsistent (ht=0x7312f8dc, file=0x8139340 "/home/tal/php5/Zend/zend_hash.c", line=1048) at /home/tal/php5/Zend/zend_hash.c:79 #1 0x080fa6a0 in zend_hash_move_forward_ex (ht=0x7312f8dc, pos=0xbfffb700) at /home/tal/php5/Zend/zend_hash.c:1048 #2 0x08065fb8 in zif_array_reduce (ht=-1073760512, return_value=0x4021a3c8, this_ptr=0x0, return_value_used=1, tsrm_ls=0x8147e38) at /home/tal/php5/ext/standard/array.c:3371 Seems like some corruption? ------------------------------------------------------------------------ [2003-03-25 13:37:57] andrey@php.net On my debian/ 4.3.2-dev it doesn't segfault. Valgring reports memoery read errors. Here is the script modified : <?php $a['one']['two']['three']['four'][] = array("FILE_NUMBER"=>2256, "INGEST_DATE"=>'2003-01-16'); $a['one']['two']['three']['four'][] = array("FILE_NUMBER"=>2258, "INGEST_DATE"=>'2003-01-17'); $num = nodeCount($a); print $num; function checkNode($v, $var) { var_dump($v, $var); echo str_repeat("-=",30)."\n"; if (is_scalar($var)) { $v += 1; } elseif (is_null($var)) { } else { echo "Recursy down\n"; $v += nodeCount($var); //$v = 2; echo "Recursy up\n"; } echo "checkNode - END\n"; return $v; } function nodeCount($array) { $number = 0; if (is_array($array)) { $number = array_reduce($array, "checkNode" , 0); } return $number; } ?> checkNode calls recursively itself. After getting of the recursy something bad happens at this line : zend_hash_move_forward_ex(Z_ARRVAL_PP(input), &pos); I think this is the line. Unfortunately I cannot help more atm. ------------------------------------------------------------------------ [2003-02-27 15:50:07] iliaa@php.net Updated version & verified ------------------------------------------------------------------------ [2003-02-27 15:08:05] mccannwj at pha dot jhu dot edu It core dumps when I run it from the command line. % gdb /usr/bin/php core.30270 [symbols blah blah] #0 0x0814c3d5 in zif_array_reduce () ------------------------------------------------------------------------ [2003-02-27 14:42:52] mccannwj at pha dot jhu dot edu Using array_reduce on a nested list causes a segfault. The following code isolates the problem. <?php $a['ANY']['F550M']['HRC']['j6jt01dlq_flt.fits'][] = array("FILE_NUMBER"=>2256, "INGEST_DATE"=>'2003-01-16'); $a['ANY']['F550M']['HRC']['j6jt01dll_flt.fits'][] = array("FILE_NUMBER"=>2258, "INGEST_DATE"=>'2003-01-17'); $num = nodeCount($a); print $num; function checkNode($v,$var) { print "<pre>"; print_r($var); print "</pre>"; if (is_scalar($var)) { $v += 1; } elseif (is_null($var)) { } else { $v += nodeCount($var); } return $v; } function nodeCount($array) { $number = 0; if (is_array($array)) $number = array_reduce($array,"checkNode",0); return $number; } ?> How reproducible: Always Steps to Reproduce: 1. Execute code snippet Actual Results: apache error_log: [Fri Feb 21 12:52:52 2003] [notice] child pid 5618 exit signal Segmentation fault (11) Expected Results: This code should count the scalar nodes in the nested list. It should print the number 4. Additional info: ------------------------------------------------------------------------ -- Edit this bug report at http://bugs.php.net/?id=22463&edit=1

« previous php.bugs (#39436) next »