Bug #14783 Updated: Using unlink causes segfault
| From: | mfkahn2 at yahoo dot com | Date: | Tue, 01 Jan 2002 16:15:45 +0000 |
| Subject: | Bug #14783 Updated: Using unlink causes segfault | ||
| References: | 1 | Groups: | php.dev |
| Request: | Send a blank email to php-dev+get-75504@lists.php.net to get a copy of this message | ||
ID: 14783
User updated by: mfkahn2@yahoo.com
Reported By: mfkahn2@yahoo.com
Status: Closed
Bug Type: DOM XML related
Operating System: RH6.2/Apache/libxml2.4.12
Old PHP Version: 4.1.1
PHP Version: CVS Jan. 1 2002
New Comment:
Just checked out and built from CVS this morning (2002/1/1). The test script still crashes.
Previous Comments:
------------------------------------------------------------------------
[2002-01-01 07:11:54] mfischer@php.net
This has been fixed in CVS.
------------------------------------------------------------------------
[2001-12-31 16:16:27] mfkahn2@yahoo.com
Symptoms:
- using unlink() causes segfault
Script to reproduce:
<?php
$xml = <<<END_XML
<?xml version="1.0"?>
<test>
<foo id="x">Hello</foo>
<foo id="y">World</foo>
</test>
END_XML;
$dom = xmldoc($xml);
// this so I can see it.
header('Content-type: text/plain');
$ctx = $dom->xpath_new_context();
$res = xpath_eval($ctx,"//foo");
foreach ($res->nodeset as $child) {
$child->unlink();
}
echo $dom->dumpmem();
?>
Other notes:
- some cursory debugging I did suggested that it was the cleanup routines at the end of the script
that were causing the crash. Looking at php_domxml.c, the recursive node memory cleanup appears to
be choking on a pointer already freed during the unlink() call.
------------------------------------------------------------------------
Edit this bug report at http://bugs.php.net/?id=14783&edit=1