#34320 [Opn->Fbk]: Segfault with DomDocument

From: Date: Wed, 31 Aug 2005 19:26:11 +0000
Subject: #34320 [Opn->Fbk]: Segfault with DomDocument
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-84262@lists.php.net to get a copy of this message
 ID:               34320
 Updated by:       rrichards@php.net
 Reported By:      php at owenpshaw dot net
-Status:           Open
+Status:           Feedback
 Bug Type:         Reproducible crash
 Operating System: Linux
 PHP Version:      5.1.0RC1
 New Comment:

Thank you for this bug report. To properly diagnose the problem, we
need a short but complete example script to be able to reproduce
this bug ourselves. 

A proper reproducing script starts with <?php and ends with ?>,
is max. 10-20 lines long and does not require any external 
resources such as databases, etc.

If possible, make the script source available online and provide
an URL to it here. Try to avoid embedding huge scripts into the report.

Can't see how your cases could cause this and cant reproduce. need
exact script that produces this crash.


Previous Comments:
------------------------------------------------------------------------

[2005-08-31 21:10:08] php at owenpshaw dot net

#0  0xb7305f7f in _int_free () from /lib/tls/libc.so.6
#1  0xb7304f78 in free () from /lib/tls/libc.so.6
#2  0xb741bc4c in xmlFreeNodeList () from /usr/lib/libxml2.so.2
#3  0xb741944d in xmlFreeDoc () from /usr/lib/libxml2.so.2
#4  0x08083b9b in php_libxml_decrement_doc_ref (object=0x848c1a4)
    at /home/oshaw/build/php-5.1.0RC1/ext/libxml/libxml.c:898
#5  0x080ab886 in dom_objects_free_storage (object=0x848c1a4)
    at /home/oshaw/build/php-5.1.0RC1/ext/dom/php_dom.c:904
#6  0x08286580 in zend_objects_store_del_ref (zobject=0x847a3bc)
    at /home/oshaw/build/php-5.1.0RC1/Zend/zend_objects_API.c:161
#7  0x0826af34 in _zval_dtor_func (zvalue=0x847a3bc,
    __zend_filename=0x834c460
"/home/oshaw/build/php-5.1.0RC1/Zend/zend_variables.h",
    __zend_lineno=35) at
/home/oshaw/build/php-5.1.0RC1/Zend/zend_variables.c:52
#8  0x08262a1e in _zval_dtor (zvalue=0x847a3bc,
    __zend_filename=0x834bf80
"/home/oshaw/build/php-5.1.0RC1/Zend/zend_execute_API.c",
__zend_lineno=386) at zend_variables.h:35
#9  0x08260138 in _zval_ptr_dtor (zval_ptr=0x8487858,
    __zend_filename=0x834d0e0
"/home/oshaw/build/php-5.1.0RC1/Zend/zend_variables.c",
    __zend_lineno=175) at
/home/oshaw/build/php-5.1.0RC1/Zend/zend_execute_API.c:386
#10 0x0826b198 in _zval_ptr_dtor_wrapper (zval_ptr=0x8487858)
    at /home/oshaw/build/php-5.1.0RC1/Zend/zend_variables.c:175
#11 0x08274c8c in zend_hash_apply_deleter (ht=0x83da930, p=0x848784c)
    at /home/oshaw/build/php-5.1.0RC1/Zend/zend_hash.c:574
#12 0x08274eb1 in zend_hash_graceful_reverse_destroy (ht=0x83da930)
    at /home/oshaw/build/php-5.1.0RC1/Zend/zend_hash.c:640
#13 0x0825fb00 in shutdown_executor ()
    at /home/oshaw/build/php-5.1.0RC1/Zend/zend_execute_API.c:216
#14 0x0826c4f9 in zend_deactivate () at
/home/oshaw/build/php-5.1.0RC1/Zend/zend.c:823
#15 0x0822b1e0 in php_request_shutdown (dummy=0x0)
    at /home/oshaw/build/php-5.1.0RC1/main/main.c:1238
#16 0x082d8c33 in main (argc=2, argv=0xbfffdfd4)
    at /home/oshaw/build/php-5.1.0RC1/sapi/cli/php_cli.c:1142

------------------------------------------------------------------------

[2005-08-31 19:34:38] rrichards@php.net

Thank you for this bug report. To properly diagnose the problem, we
need a backtrace to see what is happening behind the scenes. To
find out how to generate a backtrace, please read
http://bugs.php.net/bugs-generating-backtrace.php

Once you have generated a backtrace, please submit it to this bug
report and change the status back to "Open". Thank you for helping
us make PHP better.



------------------------------------------------------------------------

[2005-08-31 19:13:49] php at owenpshaw dot net

Description:
------------
As near as I can tell, a DomDocument object causes a crash when it is
unset.  I cannot duplicate the crash with any other kind of object.

Reproduce code:
---------------
1)
$d = DomDocument::load('test.xml');

2)
$d = DomDocument::load('test.xml');
var_dump($d);

3)
$d = DomDocument::load('test.xml');
$d = DomDocument::load('test.xml');
var_dump($d);




Expected result:
----------------
1)
(nothing)

2)
object(DOMDocument)#1 (0) {
}

3)
object(DOMDocument)#2 (0) {
}

Actual result:
--------------
1)
Segmentation fault

2)
object(DOMDocument)#1 (0) {
}
Segmentation fault

3)
Segmentation fault


------------------------------------------------------------------------


-- 
Edit this bug report at http://bugs.php.net/?id=34320&edit=1


Thread (8 messages)

« previous php.bugs (#84262) next »