#32252 [Asn->Fbk]: Segfault when offsetSet throws an Exception (only without debug)

From: Date: Sat, 14 May 2005 10:40:40 +0000
Subject: #32252 [Asn->Fbk]: Segfault when offsetSet throws an Exception (only without debug)
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-79000@lists.php.net to get a copy of this message
 ID:               32252
 Updated by:       tony2001@php.net
 Reported By:      shulmanb at il dot ibm dot com
-Status:           Assigned
+Status:           Feedback
 Bug Type:         Zend Engine 2 problem
 Operating System: *
 PHP Version:      5.*
 Assigned To:      helly
 New Comment:

Please try using this CVS snapshot:

  http://snaps.php.net/php5-STABLE-latest.tar.gz
 
For Windows:
 
  http://snaps.php.net/win32/php5.0-win32-latest.zip

Can't reproduce it on Linux with latest CVS of 5.0 & 5.1 without
debug.
Make sure that you're trying the right binary.


Previous Comments:
------------------------------------------------------------------------

[2005-05-11 11:44:10] shulmanb at il dot ibm dot com

Tested with the latest snapshot (200505110630) on Windows XP, and it is
still crashing.

------------------------------------------------------------------------

[2005-05-03 14:55:02] helly@php.net

Runs in php 5.1 now.

------------------------------------------------------------------------

[2005-03-13 19:22:42] helly@php.net

Related to http://bugs.php.net/30346

------------------------------------------------------------------------

[2005-03-09 15:13:34] helly@php.net

The first problem here is that the negative key results in incomplete
initialized zvals internally *before* even calling offsetSet().

------------------------------------------------------------------------

[2005-03-09 14:38:38] shulmanb at il dot ibm dot com

Description:
------------
In some cases, when offsetSet throws an exception a segfault occurs.

This does not happen when compiled with --enable-debug.

Note that if the index passed to $list is positive or a string, not
segfault occurs.

Reproduce code:
---------------
class a implements ArrayAccess
{
    function offsetExists ($offset) { return false; }
    function offsetGet ($offset) { return null; }
 	function offsetSet ($offset, $value) { throw new Exception ("Ooops");
}
 	function offsetUnset ($offset) {}
}
function test()
{
    $list = new a();
    try {
        $list[-1] = 123;
    } catch (Exception $e) { }
    return true;
}
print test();


Expected result:
----------------
The output should be "1".

Actual result:
--------------
Segmentation fault.

The stack trace reported in Visual Studio, using the latest snapshot
and debug pack is:

php5ts.dll!shutdown_memory_manager(int silent=0, int full_shutdown=0,
void * * * tsrm_ls=0x00364b38)  Line 490 + 0xb	C
php5ts.dll!php_request_shutdown(void * dummy=0x00000000)  Line 1225 +
0x2f	C
msvcrt.dll!77c37bbe() 	
user32.dll!77d5f160() 	



------------------------------------------------------------------------


-- 
Edit this bug report at http://bugs.php.net/?id=32252&edit=1


Thread (11 messages)

« previous php.bugs (#79000) next »