Re: Bug #3835: segfault in func_get_args with implode
| From: | Flavien LEBARBE | Date: | Wed, 15 Mar 2000 18:34:11 +0000 |
| Subject: | Re: Bug #3835: segfault in func_get_args with implode | ||
| References: | 1 | Groups: | php.dev |
| Request: | Send a blank email to php-dev+get-16840@lists.php.net to get a copy of this message | ||
Hi,
I did some testing using current CVS (2 hours ago) :
minimal example to crash (not involving implode) :
-----------
<?php
function blah () {}
function foo () {
blah ( 0 , func_get_args() ); // CRASH.
}
foo();
?>
-----------
func_get_args() examines EG(argument_stack) to get the arguments
of the function foo :
---Zend/zend_builtin_functions.c"
158: ZEND_FUNCTION(func_get_args)
159:
160: void **p;
161: int arg_count;
162: int i;
163:
164: p = EG(argument_stack).top_element-1;
165: arg_count = (ulong) *p;
166: /* this is the amount of arguments passed to func_num_args(); */
---
The first object on top of the stack is supposed to be the number of
arguments of the function.
The problem is that in this particular case, the first argument of the
function blah (-ie- '0') has already been pushed on top of the stack.
Instead of getting the number of arguments (on line 165), arg_count is
initialized with a reference to the object '0' ! :-(
Andi? Zeev? any idea how to solve this ? May be having some kind of
delimiter on the stack for this case ???
Flavien Lebarbé.
---
Open Care.