php.net |  support |  documentation |  report a bug |  advanced search |  search howto |  statistics |  random bug |  login
Bug #18668 Initialization of static hash array variable crashes PHP
Submitted: 2002-07-31 09:53 UTC Modified: 2002-09-09 10:11 UTC
Votes:3
Avg. Score:3.3 ± 0.5
Reproduced:2 of 2 (100.0%)
Same Version:2 (100.0%)
Same OS:1 (50.0%)
From: michiwalter at gmx dot de Assigned:
Status: Closed Package: Scripting Engine problem
PHP Version: 4.3.0-dev OS: Windows 2000, Linux
Private report: No CVE-ID: None
 [2002-07-31 09:53 UTC] michiwalter at gmx dot de
Summary:

Initialization of a static hash array variable in a function crashes PHP under certain circumstances.

Crash reproducable on these platforms:
- Windows 2000/IIS/PHP 4.2.1 (CGI)
- Windows 2000/Apache 1.3.24/PHP 4.2.0
- Linux deathrow 2.4.9-34/Apache 1.3.26/PHP 4.2.2

Test Script:
<?php
  define('A', 'A');
  define('B', 'B');
  
  function test()
  {
    // Apparently only crashes under the following circumstances:
    // 1. The key has to be a define().
    // 2. The value has to contain a string.
    // 3. The hash has to be a static function member.
    // 4. The hash has to contain at least 2 entries.
    static $test=array(
      A=>'A',
      B=>'B'
    );
  }
  
  test();
?>

Further Information:
error/access_log don't contain any information about the crash (what about an SEH handler:).

Patches

Pull Requests

History

AllCommentsChangesGit/SVN commitsRelated reports
 [2002-07-31 10:00 UTC] kalowsky@php.net
Can reproduce on OSX.   BT shows:

Program received signal EXC_BAD_ACCESS, Could not access memory.
0x000d2dfc in shutdown_memory_manager (silent=6358384, clean_cache=6358384) at /Users/dank/Development/php4-cvs/Zend/zend_alloc.c:439
439                                     REMOVE_POINTER_FROM_LIST(ptr);
(gdb) bt
#0  0x000d2dfc in shutdown_memory_manager (silent=6358384, clean_cache=6358384) at /Users/dank/Development/php4-cvs/Zend/zend_alloc.c:439
#1  0x000ba678 in php_request_shutdown (dummy=0x610570) at /Users/dank/Development/php4-cvs/main/main.c:795
#2  0x000ffa58 in main (argc=2, argv=0xbffff9fc) at /Users/dank/Development/php4-cvs/sapi/cgi/cgi_main.c:1100
#3  0x000018c0 in _start ()
#4  0x000016f0 in start ()
 [2002-07-31 10:01 UTC] kalowsky@php.net
BTW thats with CVS HEAD
 [2002-07-31 10:24 UTC] nohn@php.net
Cannot very this with PHP 4.3.0-dev-200207300000 on Compaq Tru64

....

      B=>'B'
    );
    var_dump($test);
  }

gives back NULL.

So it does'nt crash, but the result seems not to be the expected one.
 [2002-07-31 11:08 UTC] kalowsky@php.net
Just pulled down recent fixes, and results in:

Fatal error in zend_hash_update: p->pData == pData
Fatal error in zend_hash_update: p->pData == pData


On Both OSX and FreeBSD.
 [2002-07-31 18:30 UTC] sniper@php.net
reclassified and updated version and OS.

 [2002-08-11 12:44 UTC] tater at potatoe dot com
with PHP 4.3.0-dev (cli), Zend Engine v2.0.0-alpha2,
built from CVS, on OS X, I don't see a crash. Instead,
with debug enabled, I get a memory leak message unless
I call the function at least once:

% php -r 'define("BAR",1); function foo() { static $x = array(BAR=>"bar"); var_dump($x);}'
/usr/local/book/php4/Zend/zend_language_scanner.l(1169) :  Freeing 0x0054B610 (4 bytes), script=-

% php -r 'define("BAR",1); function foo() { static $x = array(BAR=>"bar"); var_dump($x);} foo();'
array(1) {
  [1]=>
  string(3) "bar"           
}
 [2002-08-11 12:55 UTC] michiwalter at gmx dot de
@tater:

// 4. The hash has to contain at least 2 entries.
 [2002-09-09 10:11 UTC] stas@php.net
This bug has been fixed in CVS.

In case this was a PHP problem, snapshots of the sources are packaged
every three hours; this change will be in the next snapshot. You can
grab the snapshot at http://snaps.php.net/.
 
In case this was a documentation problem, the fix will show up soon at
http://www.php.net/manual/.

In case this was a PHP.net website problem, the change will show
up on the PHP.net site and on the mirror sites in short time.
 
Thank you for the report, and for helping us make PHP better.


 
PHP Copyright © 2001-2026 The PHP Group
All rights reserved.
Last updated: Wed Oct 07 14:00:01 2026 UTC