Bug #17115: lambda functions produce segfault with static vars

From: Date: Thu, 09 May 2002 11:42:00 +0000
Subject: Bug #17115: lambda functions produce segfault with static vars
Groups: php.bugs 
Request: Send a blank email to php-bugs+get-7312@lists.php.net to get a copy of this message
From: dan@widearea.co.uk Operating system: Redhat 7.1 PHP version: 4.2.0 PHP Bug Type: Reproducible crash Bug description: lambda functions produce segfault with static vars Code is - <?php $f = create_function('$s', 'static $foo = 0; echo "\$s is $s [".$foo++."]\n";'); print_r($f("one")); print_r($f("two")); print_r($f("three")); ?> When run from the command-line this core-dumps under 4.2.0. Running 4.1.1 compiled with --apxs for apache produces incorrect results - $s is one [] $s is two [] $s is three [] But if used in array_map() different results are produced (still using 4.1.1) code - <?php $f = create_function('$s', 'static $foo = 0; return "\$s is $s [".$foo++."]\n";'); echo $f("one"), "<br>", $f("two"), "<br>", $f("three"), "<br>"; echo "<p>"; echo join(" | ", array_map($f, array("abc","def","ghi")); ?> result - $s is one [] $s is two [] $s is three [] $s is abc [] | $s is def [1] | $s is ghi [2] But take you the first three calls to $f and the page never returns. And there are many more bizarre results like 4.1.1 (but there is always a coredump in 4.2.0). Details configure line (4.2.0) - './configure' '--enable-cli' '--disable-short-tags' '--enable-overload' '--enable-sockets' '--with-readline' configure line (4.1.1) - './configure' '--with-apache=../apache_1.3.20' '--with-gd' '--with-mysql=/usr/local/mysql' '--enable-debug=no' '--enable-track-vars=yes' '--enable-magic-quotes=yes' '--with-gdbm' '--with-ndbm' '--with-db' '--with-png-dir=/usr/local' '--with-zlib-dir=/usr/local' '--with-jpeg-dir=/usr/local' gdb bt (running 4.2.0 from the commandline) - #0 0x080e7cd5 in zend_hash_find (ht=0x8183e1c, arKey=0x8183bb4 "foo", nKeyLength=4, pData=0xbfffdf74) at zend_hash.c:861 #1 0x080fab7a in zend_fetch_var_address (opline=0x8182b1c, Ts=0xbfffdfa0, type=1) at ./zend_execute.c:560 #2 0x080fc6b8 in execute (op_array=0x8183ee8) at ./zend_execute.c:1239 #3 0x080dcdc3 in call_user_function_ex (function_table=0x8153530, object_pp=0x0, function_name=0x818199c, retval_ptr_ptr=0xbfffe304, param_count=1, params=0x8184154, no_separation=0, symbol_table=0x0) at zend_execute_API.c:517 #4 0x080f8118 in zif_array_map (ht=2, return_value=0x8184044, this_ptr=0x0, return_value_used=1) at array.c:3228 #5 0x080fe283 in execute (op_array=0x8181ac4) at ./zend_execute.c:1598 #6 0x080e3efe in zend_execute_scripts (type=8, retval=0x0, file_count=3) at zend.c:810 #7 0x08062b71 in php_execute_script (primary_file=0xbffff7f0) at main.c:1381 #8 0x08060b7c in main (argc=3, argv=0xbffff89c) at cgi_main.c:785 #9 0x40136177 in __libc_start_main (main=0x8060374 <main>, argc=3, ubp_av=0xbffff89c, init=0x805efc8 <_init>, fini=0x8102db0 <_fini>, rtld_fini=0x4000e184 <_dl_fini>, stack_end=0xbffff88c) at ../sysdeps/generic/libc-start.c:129 -- Edit bug report at http://bugs.php.net/?id=17115&edit=1 -- Fixed in CVS: http://bugs.php.net/fix.php?id=17115&r=fixedcvs Fixed in release: http://bugs.php.net/fix.php?id=17115&r=alreadyfixed Need backtrace: http://bugs.php.net/fix.php?id=17115&r=needtrace Try newer version: http://bugs.php.net/fix.php?id=17115&r=oldversion Not developer issue: http://bugs.php.net/fix.php?id=17115&r=support Expected behavior: http://bugs.php.net/fix.php?id=17115&r=notwrong Not enough info: http://bugs.php.net/fix.php?id=17115&r=notenoughinfo Submitted twice: http://bugs.php.net/fix.php?id=17115&r=submittedtwice register_globals: http://bugs.php.net/fix.php?id=17115&r=globals

« previous php.bugs (#7312) next »