#36234 [Opn]: segfault when testing property of an overloaded class in switch a statement

From: Date: Tue, 31 Jan 2006 17:30:37 +0000
Subject: #36234 [Opn]: segfault when testing property of an overloaded class in switch a statement
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-92722@lists.php.net to get a copy of this message
ID: 36234 User updated by: matt dot flaherty at hildebrand dot co dot uk Reported By: matt dot flaherty at hildebrand dot co dot uk Status: Open Bug Type: Reproducible crash Operating System: SUSE LINUX 10.0 (i586) PHP Version: 4.4.2 New Comment: Almost forgot. PHP is configured in the standard way for this distro: ./configure --prefix=/usr --datadir=/usr/share/php --mandir=/usr/share/man --bindir=/usr/bin --libdir=/usr/share --includedir=/usr/include --sysconfdir=/etc --with-_lib=lib --with-config-file-path=/etc --with-exec-dir=/usr/lib/php/bin --disable-debug --enable-inline-optimization --enable-memory-limit --enable-magic-quotes --enable-safe-mode --enable-sigchild --disable-ctype --disable-session --without-mysql --disable-cli --without-pear --with-openssl --with-apxs2=/usr/sbin/apxs2-prefork i586-suse-linux Previous Comments: ------------------------------------------------------------------------ [2006-01-31 18:22:51] matt dot flaherty at hildebrand dot co dot uk Description: ------------ Apologies in advance if this turns out to be user error, but it seems odd to me. A segmentation fault occurs when evaluating in a switch statement an instance property of an overloaded class with which has a __get() method. It does not matter whether the evaluated property is native to the instance or overloaded. Also, native and overloaded properties on an overloaded class instance don't like to be passed by reference. If you change the switch statements to cast the argument to (string), as in "switch ((string)$decorator->bar) {" (a memory copy), then the expected result occurs. If you leave either of the switch statements alone there is a crash. Interestingly, with both of the switch statements "fixed" and the block uncommented that calls function reverse_me, the output looks like this: ----%<---- I can see that the value of bar is 'bar' and the value of myVar is 'mine'. I've tested === and that worked okay. So did ==. subst function is okay too. Fatal error: Only variables can be passed by reference in /srv/www/htdocs/seagull/www/crash.php on line 54 ----%<---- This is a native property on the instance so I can't understand why passing by reference is bad. Turning off overloading produces the expected result there, which is this: ----%<---- I can see that the value of bar is '' and the value of myVar is 'mine'. I've tested === and that worked okay. So did ==. subst function is okay too. Just passed by myVar by reference and reversed the string. The value is now enim I am not expecting a switch statemtent on bar to segfault. Switch says the value of bar is not 'bar'. It's 'baz'. I am not expecting a switch statemtent on myVar to segfault. Switch says the value of myVar is not 'mine'. It's 'yours'. ----%<---- I have observed this behaviour in php 4.4.0 and 4.4.2. Very strange. Reproduce code: --------------- http://www.jellybee.co.uk/overload_fault.txt Expected result: ---------------- I can see that the value of bar is 'bar' and the value of myVar is 'mine'. I've tested === and that worked okay. So did ==. subst function is okay too. I am not expecting a switch statemtent on bar to segfault. Switch says the value of bar is not 'bar'. It's 'baz'. I am not expecting a switch statemtent on myVar to segfault. Switch says the value of myVar is not 'mine'. It's 'yours'. Actual result: -------------- Last few lines of Apache2 strace... open("/srv/www/htdocs/seagull/www/crash.php", O_RDONLY) = 35 fstat64(35, {st_mode=S_IFREG|0644, st_size=2110, ...}) = 0 fstat64(35, {st_mode=S_IFREG|0644, st_size=2110, ...}) = 0 lseek(35, 0, SEEK_CUR) = 0 lseek(35, 0, SEEK_SET) = 0 read(35, "<?php\nclass Decorator_Foo {\n "..., 8192) = 2110 brk(0x8045f000) = 0x8045f000 read(35, "", 8192) = 0 close(35) = 0 --- SIGSEGV (Segmentation fault) @ 0 (0) --- chdir("/srv/www") = 0 rt_sigaction(SIGSEGV, {SIG_DFL}, {SIG_DFL}, 8) = 0 kill(18058, SIGSEGV) = 0 sigreturn() = ? (mask now []) --- SIGSEGV (Segmentation fault) @ 0 (0) --- ------------------------------------------------------------------------ -- Edit this bug report at http://bugs.php.net/?id=36234&edit=1

« previous php.bugs (#92722) next »