#34269 [Opn->WFx]: memory overwrite
| From: | derick@php.net | Date: | Tue, 30 Aug 2005 07:19:54 +0000 |
| Subject: | #34269 [Opn->WFx]: memory overwrite | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-84164@lists.php.net to get a copy of this message | ||
ID: 34269
Updated by: derick@php.net
Reported By: eka1970 at mail dot ru
-Status: Open
+Status: Wont fix
Bug Type: Arrays related
Operating System: red hat 7.3
PHP Version: 4CVS-2005-08-29 (only)
New Comment:
This is actually expected behavior. In PHP 4 the refcount is a short,
meaning that you can have a maximum of 6553x (internal) references to
the same value. In PHP 5 this is now an int, meaning that you can use
about 2 million of them.
Previous Comments:
------------------------------------------------------------------------
[2005-08-29 02:25:35] eka1970 at mail dot ru
Problem is not found in v5 but we're not going to migrate to it until
stable 5.1 is released
------------------------------------------------------------------------
[2005-08-28 10:42:41] tony2001@php.net
Jani asked to *TRY* PHP5, not to install and use it instead of PHP4.
Please do so or tell that you're not interested in solution for your
problem. Thank you.
------------------------------------------------------------------------
[2005-08-28 07:09:36] eka1970 at mail dot ru
If you're not going to fix this and propose to use v5, please confirm
there will be no more updates for v4.x.
------------------------------------------------------------------------
[2005-08-28 00:57:33] sniper@php.net
Please try using this CVS snapshot:
http://snaps.php.net/php5-latest.tar.gz
For Windows:
http://snaps.php.net/win32/php5-win32-latest.zip
------------------------------------------------------------------------
[2005-08-26 19:36:29] eka1970 at mail dot ru
Description:
------------
hundreds of thousands of "$a[]= ..." and "array_pop()" calls triggers
memory overwrite.
Reproduce code:
---------------
<?php
$a = array(0,1,2,3,4,5,6,7,8,9,10);
$paths = array();
$stack = array();
for($i=0; $i<100000; $i++) {
$steps = mt_rand(2,6);
// move forward
for($j=0; $j<$steps; $j++) { $stack[] = array('x'=>$a[$j]); }
$paths[] = $stack;
// move backward
for($j=0; $j<$steps; $j++) { array_pop($stack); }
}
print_r($a);
?>
Expected result:
----------------
array $a is never modified in the code, but when you print it at the
end of the script it spills out a whole lot of unexpected reccursions
or just dies with no output.
------------------------------------------------------------------------
--
Edit this bug report at http://bugs.php.net/?id=34269&edit=1