Bug #17115: lambda functions produce segfault with static vars
| From: | dan at widearea dot co dot uk | Date: | Thu, 09 May 2002 11:42:00 +0000 |
| Subject: | Bug #17115: lambda functions produce segfault with static vars | ||
| Groups: | php.bugs | ||
| Request: | Send a blank email to php-bugs+get-7312@lists.php.net to get a copy of this message | ||
From: dan@widearea.co.uk
Operating system: Redhat 7.1
PHP version: 4.2.0
PHP Bug Type: Reproducible crash
Bug description: lambda functions produce segfault with static vars
Code is -
<?php
$f = create_function('$s', 'static $foo = 0; echo "\$s is $s
[".$foo++."]\n";');
print_r($f("one"));
print_r($f("two"));
print_r($f("three"));
?>
When run from the command-line this core-dumps under 4.2.0. Running 4.1.1
compiled with --apxs for apache produces incorrect results -
$s is one []
$s is two []
$s is three []
But if used in array_map() different results are produced (still using
4.1.1)
code -
<?php
$f = create_function('$s', 'static $foo = 0; return "\$s is $s
[".$foo++."]\n";');
echo $f("one"), "<br>", $f("two"), "<br>",
$f("three"), "<br>";
echo "<p>";
echo join(" | ", array_map($f, array("abc","def","ghi"));
?>
result -
$s is one []
$s is two []
$s is three []
$s is abc [] | $s is def [1] | $s is ghi [2]
But take you the first three calls to $f and the page never returns. And
there are many more bizarre results like 4.1.1 (but there is always a
coredump in 4.2.0).
Details
configure line (4.2.0) -
'./configure' '--enable-cli' '--disable-short-tags'
'--enable-overload'
'--enable-sockets' '--with-readline'
configure line (4.1.1) -
'./configure' '--with-apache=../apache_1.3.20' '--with-gd'
'--with-mysql=/usr/local/mysql' '--enable-debug=no'
'--enable-track-vars=yes' '--enable-magic-quotes=yes' '--with-gdbm'
'--with-ndbm' '--with-db' '--with-png-dir=/usr/local'
'--with-zlib-dir=/usr/local' '--with-jpeg-dir=/usr/local'
gdb bt (running 4.2.0 from the commandline) -
#0 0x080e7cd5 in zend_hash_find (ht=0x8183e1c, arKey=0x8183bb4 "foo",
nKeyLength=4, pData=0xbfffdf74) at zend_hash.c:861
#1 0x080fab7a in zend_fetch_var_address (opline=0x8182b1c, Ts=0xbfffdfa0,
type=1) at ./zend_execute.c:560
#2 0x080fc6b8 in execute (op_array=0x8183ee8) at ./zend_execute.c:1239
#3 0x080dcdc3 in call_user_function_ex (function_table=0x8153530,
object_pp=0x0, function_name=0x818199c, retval_ptr_ptr=0xbfffe304,
param_count=1,
params=0x8184154, no_separation=0, symbol_table=0x0) at
zend_execute_API.c:517
#4 0x080f8118 in zif_array_map (ht=2, return_value=0x8184044,
this_ptr=0x0, return_value_used=1) at array.c:3228
#5 0x080fe283 in execute (op_array=0x8181ac4) at ./zend_execute.c:1598
#6 0x080e3efe in zend_execute_scripts (type=8, retval=0x0, file_count=3)
at zend.c:810
#7 0x08062b71 in php_execute_script (primary_file=0xbffff7f0) at
main.c:1381
#8 0x08060b7c in main (argc=3, argv=0xbffff89c) at cgi_main.c:785
#9 0x40136177 in __libc_start_main (main=0x8060374 <main>, argc=3,
ubp_av=0xbffff89c, init=0x805efc8 <_init>, fini=0x8102db0 <_fini>,
rtld_fini=0x4000e184 <_dl_fini>, stack_end=0xbffff88c) at
../sysdeps/generic/libc-start.c:129
--
Edit bug report at http://bugs.php.net/?id=17115&edit=1
--
Fixed in CVS: http://bugs.php.net/fix.php?id=17115&r=fixedcvs
Fixed in release: http://bugs.php.net/fix.php?id=17115&r=alreadyfixed
Need backtrace: http://bugs.php.net/fix.php?id=17115&r=needtrace
Try newer version: http://bugs.php.net/fix.php?id=17115&r=oldversion
Not developer issue: http://bugs.php.net/fix.php?id=17115&r=support
Expected behavior: http://bugs.php.net/fix.php?id=17115&r=notwrong
Not enough info: http://bugs.php.net/fix.php?id=17115&r=notenoughinfo
Submitted twice: http://bugs.php.net/fix.php?id=17115&r=submittedtwice
register_globals: http://bugs.php.net/fix.php?id=17115&r=globals