#30346 [Asn->Fbk]: arrayAcces & using $this
| From: | tony2001@php.net | Date: | Sat, 14 May 2005 10:26:04 +0000 |
| Subject: | #30346 [Asn->Fbk]: arrayAcces & using $this | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-78998@lists.php.net to get a copy of this message | ||
ID: 30346
Updated by: tony2001@php.net
Reported By: profic at kursknet dot ru
-Status: Assigned
+Status: Feedback
Bug Type: Zend Engine 2 problem
Operating System: *
PHP Version: 5CVS-2005-03-13
Assigned To: helly
New Comment:
Please try using this CVS snapshot:
http://snaps.php.net/php5-STABLE-latest.tar.gz
For Windows:
http://snaps.php.net/win32/php5.0-win32-latest.zip
Not reproducible anymore.
Previous Comments:
------------------------------------------------------------------------
[2005-03-13 19:22:07] helly@php.net
There is still a problem with uninitialized temp and cv vars. This is
related to http://bugs.php.net/32252
------------------------------------------------------------------------
[2004-11-28 13:31:48] tony2001@php.net
Well, no, not exactly. HEAD segfaults for me with this code:
Starting program: /home/dev/php-src/sapi/cli/php -f /www/index.php
ZZZZZZZZZ
Warning: String is not zero-terminated (ZZZZZZZZZZ└ë▐*)
(source: /home/dev/php-src/Zend/zend_variables.h:35) in /www/index.php
on line 12
[Sun Nov 28 15:28:18 2004] Script: '/www/index.php'
---------------------------------------
/home/dev/php-src/Zend/zend_vm_execute.h(6619) : Block 0xBFFFB4D8
status:
/home/dev/php-src/Zend/zend_execute.h(64) : Actual location (location
was relayed)
Beginning: Overrun (magic=0x00666669, expected=0x7312F8DC)
Program received signal SIGSEGV, Segmentation fault.
0x4207c5ac in memcpy () from /lib/tls/libc.so.6
(gdb) bt
#0 0x4207c5ac in memcpy () from /lib/tls/libc.so.6
#1 0x081bb0af in _mem_block_check (ptr=0xbfffb4fc, silent=0,
__zend_filename=0x8291260 "/home/dev/php-src/Zend/zend_vm_execute.h",
__zend_lineno=6619,
__zend_orig_filename=0x828c000
"/home/dev/php-src/Zend/zend_execute.h", __zend_orig_lineno=64) at
/home/dev/php-src/Zend/zend_alloc.c:737
#2 0x081bb07b in _mem_block_check (ptr=0xbfffb4fc, silent=1,
__zend_filename=0x8291260 "/home/dev/php-src/Zend/zend_vm_execute.h",
__zend_lineno=6619,
__zend_orig_filename=0x828c000
"/home/dev/php-src/Zend/zend_execute.h", __zend_orig_lineno=64) at
/home/dev/php-src/Zend/zend_alloc.c:729
#3 0x081ba0de in _efree (ptr=0xbfffb4fc, __zend_filename=0x8291260
"/home/dev/php-src/Zend/zend_vm_execute.h", __zend_lineno=6619,
__zend_orig_filename=0x828c000
"/home/dev/php-src/Zend/zend_execute.h", __zend_orig_lineno=64) at
/home/dev/php-src/Zend/zend_alloc.c:287
#4 0x081ca5ca in safe_free_zval_ptr_rel (p=0xbfffb4fc,
__zend_filename=0x8291260 "/home/dev/php-src/Zend/zend_vm_execute.h",
__zend_lineno=6619,
__zend_orig_filename=0x828bb20
"/home/dev/php-src/Zend/zend_execute_API.c", __zend_orig_lineno=392) at
zend_execute.h:64
#5 0x081c77ac in _zval_ptr_dtor (zval_ptr=0xbfffb428,
__zend_filename=0x8291260 "/home/dev/php-src/Zend/zend_vm_execute.h",
__zend_lineno=6619)
at /home/dev/php-src/Zend/zend_execute_API.c:392
#6 0x0820d6c1 in ZEND_ECHO_SPEC_VAR_HANDLER (execute_data=0xbfffb810)
at zend_vm_execute.h:6619
#7 0x081fc5ad in execute (op_array=0x834bca4) at zend_vm_execute.h:58
#8 0x081d59fa in zend_execute_scripts (type=8, retval=0x0,
file_count=3) at /home/dev/php-src/Zend/zend.c:1053
#9 0x0818d3ca in php_execute_script (primary_file=0xbfffdc20) at
/home/dev/php-src/main/main.c:1635
#10 0x0824fc2f in main (argc=3, argv=0xbfffdcb4) at
/home/dev/php-src/sapi/cli/php_cli.c:943
In the same time, 5_0 works fine, printing "page_show".
------------------------------------------------------------------------
[2004-10-26 20:27:57] helly@php.net
Thanks for the script.
The issue is fixed in 5.1 - i'll give 5.0 a try.
------------------------------------------------------------------------
[2004-10-26 12:16:41] benneh at gmail dot com
I've just run into this, however I've managed to reduce to a test case
with out extended classes. It should be the same thing as the crash
like yours appears to be caused by concatenating in the array index.
Minimal Testcase :
------------------
class Post_Header implements ArrayAccess {
public function __construct() { }
public function offsetExists( $offset ) { return false; }
public function offsetGet( $offset ) { return $offset; }
public function offsetSet( $offset, $data ) { }
public function offsetUnset( $offset ) { }
}
$post = new Post_Header;
$id = 'page';
echo $post[$id.'_show'];
Expected Results :
------------------
Test
Actual Results :
----------------
Crashes on the last line
Hope this more minimal testcase helps.
------------------------------------------------------------------------
[2004-10-24 14:08:23] tony2001@php.net
Segfaults only with 5.0.x.
5.1 works fine (i.e. gives expected result and doesn't segfault).
bt:
Program received signal SIGSEGV, Segmentation fault.
0x08175639 in _efree (ptr=0xbfffcc28) at
/home/dev/php-src_5_0/Zend/zend_alloc.c:281
281 REMOVE_POINTER_FROM_LIST(p);
(gdb) bt
#0 0x08175639 in _efree (ptr=0xbfffcc28) at
/home/dev/php-src_5_0/Zend/zend_alloc.c:281
#1 0x081802b1 in _zval_ptr_dtor (zval_ptr=0xbfffcc28) at
zend_execute.h:61
#2 0x08180ccc in zend_call_function (fci=0xbfffc8c0,
fci_cache=0xbfffc8a0, tsrm_ls=0x82370b0) at zend_execute.h:124
#3 0x0819879f in zend_call_method (object_pp=0xbfffc980,
obj_ce=0x82ea01c, fn_proxy=0x0, function_name=0x81e9cb4 "offsetget",
function_name_len=9,
retval_ptr_ptr=0xbfffc94c, param_count=-1073753328,
arg1=0xbfffcc28, arg2=0x0, tsrm_ls=0x82370b0) at
/home/dev/php-src_5_0/Zend/zend_interfaces.c:79
#4 0x0819b77b in zend_std_read_dimension (object=0x82ed3b4,
offset=0xbfffcc28, type=0, tsrm_ls=0x82370b0)
at /home/dev/php-src_5_0/Zend/zend_object_handlers.c:390
#5 0x081a7ce0 in zend_fetch_dimension_address (result=0x82ec17c,
op1=0x82ed3b4, op2=0x82ec1a4, Ts=0xbfffca30, type=0,
tsrm_ls=0x82370b0)
at /home/dev/php-src_5_0/Zend/zend_execute.c:1000
#6 0x081aaac1 in zend_fetch_dim_r_handler (execute_data=0xbfffd040,
opline=0x82ec178, op_array=0x82ea2ec, tsrm_ls=0x82370b0)
at /home/dev/php-src_5_0/Zend/zend_execute.c:2067
#7 0x081a90e9 in execute (op_array=0x82ea2ec, tsrm_ls=0x82370b0) at
/home/dev/php-src_5_0/Zend/zend_execute.c:1400
#8 0x081ac9c0 in zend_do_fcall_common_helper (execute_data=0xbfffd480,
opline=0x82eef7c, op_array=0x82e3e54, tsrm_ls=0x82370b0)
at /home/dev/php-src_5_0/Zend/zend_execute.c:2740
#9 0x081acd0d in zend_do_fcall_by_name_handler
(execute_data=0xbfffd310, opline=0x82eef7c, op_array=0x82e3e54,
tsrm_ls=0x82370b0)
at /home/dev/php-src_5_0/Zend/zend_execute.c:2825
#10 0x081a90e9 in execute (op_array=0x82e3e54, tsrm_ls=0x82370b0) at
/home/dev/php-src_5_0/Zend/zend_execute.c:1400
#11 0x0818b387 in zend_execute_scripts (type=8, tsrm_ls=0x82370b0,
retval=0x0, file_count=3) at /home/dev/php-src_5_0/Zend/zend.c:1060
#12 0x081544ac in php_execute_script (primary_file=0xbffff870,
tsrm_ls=0x82370b0) at /home/dev/php-src_5_0/main/main.c:1628
#13 0x081b4eb4 in main (argc=3, argv=0xbffff8f4) at
/home/dev/php-src_5_0/sapi/cli/php_cli.c:943
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
http://bugs.php.net/30346
--
Edit this bug report at http://bugs.php.net/?id=30346&edit=1