php.net |  support |  documentation |  report a bug |  advanced search |  search howto |  statistics |  random bug |  login
Bug #68539 Crash with simple script that contains __debugInfo method
Submitted: 2014-12-03 09:14 UTC Modified: 2014-12-03 09:19 UTC
From: eran at zend dot com Assigned: dmitry (profile)
Status: Closed Package: *General Issues
PHP Version: 5.6.3 OS: Linux
Private report: No CVE-ID: None
View Developer Edit
Welcome! If you don't have a Git account, you can't do anything here.
If you reported this bug, you can edit this bug over here.
(description)
Block user comment
Status: Assign to:
Package:
Bug Type:
Summary:
From: eran at zend dot com
New email:
PHP Version: OS:

 

 [2014-12-03 09:14 UTC] eran at zend dot com
Description:
------------
Hello,
Running the below Test Script results in segfault.

I compiled PHP with debug info + OPcache with debug info and ran PHP under valgrind like this (more useful than gdb in this case):

valgrind --log-file=/tmp/vg.log /usr/sbin/apache2 -X
Shows consistent 'Invalid free/delete' error messages

here is sample from valgrind output:

==14364== Invalid free() / delete / delete[] / realloc()
==14364==    at 0x4C2BDEC: free (in /usr/lib/valgrind/vgpreload_memcheck-amd64-linux.so)
==14364==    by 0x8E08625: _efree (zend_alloc.c:2437)
==14364==    by 0x8E2FEB7: destroy_op_array (zend_opcode.c:361)
==14364==    by 0x8E2F4B5: destroy_zend_function (zend_opcode.c:116)
==14364==    by 0x8E2F4D2: zend_function_dtor (zend_opcode.c:128)
==14364==    by 0x8E51F67: zend_hash_destroy (zend_hash.c:548)
==14364==    by 0x8E2FC20: destroy_zend_class (zend_opcode.c:300)
==14364==    by 0x8E5073B: zend_hash_bucket_delete (zend_hash.c:182)
==14364==    by 0x8E52628: zend_hash_reverse_apply (zend_hash.c:733)
==14364==    by 0x8E294C6: shutdown_executor (zend_execute_API.c:303)
==14364==    by 0x8E3FDB6: zend_deactivate (zend.c:949)
==14364==    by 0x8DAEE2A: php_request_shutdown (main.c:1884)
==14364==  Address 0x1dae38f0 is 0 bytes inside a block of size 16 free'd
==14364==    at 0x4C2BDEC: free (in /usr/lib/valgrind/vgpreload_memcheck-amd64-linux.so)
==14364==    by 0x8E08625: _efree (zend_alloc.c:2437)
==14364==    by 0x8E2FEB7: destroy_op_array (zend_opcode.c:361)
==14364==    by 0x8E2F4B5: destroy_zend_function (zend_opcode.c:116)
==14364==    by 0x8E2F4D2: zend_function_dtor (zend_opcode.c:128)
==14364==    by 0x8E51F67: zend_hash_destroy (zend_hash.c:548)
==14364==    by 0x8E2FC20: destroy_zend_class (zend_opcode.c:300)
==14364==    by 0x8E5073B: zend_hash_bucket_delete (zend_hash.c:182)
==14364==    by 0x8E52628: zend_hash_reverse_apply (zend_hash.c:733)
==14364==    by 0x8E294C6: shutdown_executor (zend_execute_API.c:303)
==14364==    by 0x8E3FDB6: zend_deactivate (zend.c:949)
==14364==    by 0x8DAEE2A: php_request_shutdown (main.c:1884)

everything was tested on Linux Mint 17, 64 bit
Using PHP 5.6.3.

Test script:
---------------
<?php
 
class C {
  public $val;
  public function __debugInfo() {
    return $this->val;
  }
  public function __construct($val) {
    $this->val = $val;
  }
}
 
$c = new C(0);
var_dump($c);


Expected result:
----------------
No crash

Actual result:
--------------
Segmentation fault

Patches

Pull Requests

History

AllCommentsChangesGit/SVN commitsRelated reports
 [2014-12-03 09:19 UTC] dmitry@php.net
-Status: Open +Status: Closed -Assigned To: +Assigned To: dmitry
 
PHP Copyright © 2001-2026 The PHP Group
All rights reserved.
Last updated: Wed Oct 07 21:00:02 2026 UTC