5.0.4 refcounting bug?
| From: | Joe Orton | Date: | Mon, 27 Jun 2005 15:06:41 +0000 |
| Subject: | 5.0.4 refcounting bug? | ||
| Groups: | php.internals | ||
| Request: | Send a blank email to internals+get-16940@lists.php.net to get a copy of this message | ||
We're getting a lot of reports from Fedora Core 4 users that the shipped
PHP 5.0.4 is triggering some refcounting bug breaking some common apps;
the attached file is a repro case which triggers the segfault after
following the link.
I've traced this through and it seems that the refcount on
PS(http_session_vars) prematurely drops to zero on leaving the foreach()
loop, but haven't looked any further. Does this ring any bells with
anyone? It seems to work OK in the 5.1.0 beta2 release but I can't see
anything relevant mentioned explicitly in NEWS, and I'm not sure if
we'll be able to ship 5.1.0 as an update for FC4 since it breaks binary
module compatibility...
Regards,
joe
<?php session_start(); print_r(gettimeofday()); if (isset($_GET['segv'])) { foreach($_SESSION as $key => $value) { $$key =& $_SESSION[$key]; } } $_SESSION['fish'] = "SAUSAGES"; ?><br><br> <a href="sess2.php?segv">Follow Link to Trigger segfault</a></li>
<?php session_start(); print_r(gettimeofday()); if (isset($_GET['segv'])) { foreach($_SESSION as $key => $value) { $$key =& $_SESSION[$key]; } } $_SESSION['fish'] = "SAUSAGES"; ?><br><br> <a href="sess2.php?segv">Follow Link to Trigger segfault</a></li>