php.net |  support |  documentation |  report a bug |  advanced search |  search howto |  statistics |  random bug |  login
Bug #34320 Segfault with DomDocument
Submitted: 2005-08-31 19:13 UTC Modified: 2005-09-01 01:49 UTC
From: php at owenpshaw dot net Assigned:
Status: Not a bug Package: Reproducible crash
PHP Version: 5.1.0RC1 OS: Linux
Private report: No CVE-ID: None
Welcome back! If you're the original bug submitter, here's where you can edit the bug or add additional notes.
If you forgot your password, you can retrieve your password here.
Password:
Status:
Package:
Bug Type:
Summary:
From: php at owenpshaw dot net
New email:
PHP Version: OS:

 

 [2005-08-31 19:13 UTC] php at owenpshaw dot net
Description:
------------
As near as I can tell, a DomDocument object causes a crash when it is unset.  I cannot duplicate the crash with any other kind of object.

Reproduce code:
---------------
1)
$d = DomDocument::load('test.xml');

2)
$d = DomDocument::load('test.xml');
var_dump($d);

3)
$d = DomDocument::load('test.xml');
$d = DomDocument::load('test.xml');
var_dump($d);




Expected result:
----------------
1)
(nothing)

2)
object(DOMDocument)#1 (0) {
}

3)
object(DOMDocument)#2 (0) {
}

Actual result:
--------------
1)
Segmentation fault

2)
object(DOMDocument)#1 (0) {
}
Segmentation fault

3)
Segmentation fault

Patches

Pull Requests

History

AllCommentsChangesGit/SVN commitsRelated reports
 [2005-08-31 19:34 UTC] rrichards@php.net
Thank you for this bug report. To properly diagnose the problem, we
need a backtrace to see what is happening behind the scenes. To
find out how to generate a backtrace, please read
http://bugs.php.net/bugs-generating-backtrace.php

Once you have generated a backtrace, please submit it to this bug
report and change the status back to "Open". Thank you for helping
us make PHP better.


 [2005-08-31 21:10 UTC] php at owenpshaw dot net
#0  0xb7305f7f in _int_free () from /lib/tls/libc.so.6
#1  0xb7304f78 in free () from /lib/tls/libc.so.6
#2  0xb741bc4c in xmlFreeNodeList () from /usr/lib/libxml2.so.2
#3  0xb741944d in xmlFreeDoc () from /usr/lib/libxml2.so.2
#4  0x08083b9b in php_libxml_decrement_doc_ref (object=0x848c1a4)
    at /home/oshaw/build/php-5.1.0RC1/ext/libxml/libxml.c:898
#5  0x080ab886 in dom_objects_free_storage (object=0x848c1a4)
    at /home/oshaw/build/php-5.1.0RC1/ext/dom/php_dom.c:904
#6  0x08286580 in zend_objects_store_del_ref (zobject=0x847a3bc)
    at /home/oshaw/build/php-5.1.0RC1/Zend/zend_objects_API.c:161
#7  0x0826af34 in _zval_dtor_func (zvalue=0x847a3bc,
    __zend_filename=0x834c460 "/home/oshaw/build/php-5.1.0RC1/Zend/zend_variables.h",
    __zend_lineno=35) at /home/oshaw/build/php-5.1.0RC1/Zend/zend_variables.c:52
#8  0x08262a1e in _zval_dtor (zvalue=0x847a3bc,
    __zend_filename=0x834bf80 "/home/oshaw/build/php-5.1.0RC1/Zend/zend_execute_API.c", __zend_lineno=386) at zend_variables.h:35
#9  0x08260138 in _zval_ptr_dtor (zval_ptr=0x8487858,
    __zend_filename=0x834d0e0 "/home/oshaw/build/php-5.1.0RC1/Zend/zend_variables.c",
    __zend_lineno=175) at /home/oshaw/build/php-5.1.0RC1/Zend/zend_execute_API.c:386
#10 0x0826b198 in _zval_ptr_dtor_wrapper (zval_ptr=0x8487858)
    at /home/oshaw/build/php-5.1.0RC1/Zend/zend_variables.c:175
#11 0x08274c8c in zend_hash_apply_deleter (ht=0x83da930, p=0x848784c)
    at /home/oshaw/build/php-5.1.0RC1/Zend/zend_hash.c:574
#12 0x08274eb1 in zend_hash_graceful_reverse_destroy (ht=0x83da930)
    at /home/oshaw/build/php-5.1.0RC1/Zend/zend_hash.c:640
#13 0x0825fb00 in shutdown_executor ()
    at /home/oshaw/build/php-5.1.0RC1/Zend/zend_execute_API.c:216
#14 0x0826c4f9 in zend_deactivate () at /home/oshaw/build/php-5.1.0RC1/Zend/zend.c:823
#15 0x0822b1e0 in php_request_shutdown (dummy=0x0)
    at /home/oshaw/build/php-5.1.0RC1/main/main.c:1238
#16 0x082d8c33 in main (argc=2, argv=0xbfffdfd4)
    at /home/oshaw/build/php-5.1.0RC1/sapi/cli/php_cli.c:1142
 [2005-08-31 21:26 UTC] rrichards@php.net
Thank you for this bug report. To properly diagnose the problem, we
need a short but complete example script to be able to reproduce
this bug ourselves. 

A proper reproducing script starts with <?php and ends with ?>,
is max. 10-20 lines long and does not require any external 
resources such as databases, etc.

If possible, make the script source available online and provide
an URL to it here. Try to avoid embedding huge scripts into the report.

Can't see how your cases could cause this and cant reproduce. need exact script that produces this crash.
 [2005-08-31 22:30 UTC] php at owenpshaw dot net
<?php

$d = DomDocument::load('test.xml');

?>

------
test.xml

<?xml version="1.0"?>
<test/>

I know it doesn't seem like this should cause a crash.  I would say that it's my system, but php 5.0.4 works just fine, as did earlier 5.1 builds.  I've also checked the latest 5.1 snapshot and it crashes.
 [2005-08-31 23:46 UTC] rrichards@php.net
What version of libxml2?

Can you try doing the following and see if it crashes:
$dom = new DOMDocument();
$dom->load('test.xml');

also try the following:
$sxe = simplexml_load_file('test.xml');


 [2005-09-01 00:45 UTC] php at owenpshaw dot net
libxml2-2.6.6

<?php
$d = new DomDocument();
$d->load('test.xml');
?>
does not crash

<?php
$d = new DomDocument();
$d->load('test.xml');
$d = null;
?>
does crash, with a similar backtrace:

#0  0xb749ae0c in xmlDictOwns () from /usr/lib/libxml2.so.2
#1  0xb7419333 in xmlFreeDoc () from /usr/lib/libxml2.so.2
#2  0x08083b9b in php_libxml_decrement_doc_ref (object=0x848c21c)
    at /home/oshaw/build/php-5.1.0RC1/ext/libxml/libxml.c:898
#3  0x080ab886 in dom_objects_free_storage (object=0x848c21c)
    at /home/oshaw/build/php-5.1.0RC1/ext/dom/php_dom.c:904
#4  0x08286580 in zend_objects_store_del_ref (zobject=0x84863cc)
    at /home/oshaw/build/php-5.1.0RC1/Zend/zend_objects_API.c:161
#5  0x0826af34 in _zval_dtor_func (zvalue=0x84863cc,
    __zend_filename=0x8356a00 "/home/oshaw/build/php-5.1.0RC1/Zend/zend_variables.h",
    __zend_lineno=35) at /home/oshaw/build/php-5.1.0RC1/Zend/zend_variables.c:52
#6  0x082d501e in _zval_dtor (zvalue=0x84863cc,
    __zend_filename=0x8351960 "/home/oshaw/build/php-5.1.0RC1/Zend/zend_execute.c",
    __zend_lineno=814) at zend_variables.h:35
#7  0x082d6c19 in zend_assign_to_variable (result=0x848b118, op1=0x848b12c,
    op2=0x848b140, value=0xbfffbd18, type=2, Ts=0xbfffbca0)
    at /home/oshaw/build/php-5.1.0RC1/Zend/zend_execute.c:814
#8  0x082caec5 in ZEND_ASSIGN_SPEC_CV_TMP_HANDLER (execute_data=0xbfffbd40)
    at zend_vm_execute.h:22140
#9  0x082930ef in execute (op_array=0x8486c54) at zend_vm_execute.h:87
#10 0x0826cd43 in zend_execute_scripts (type=8, retval=0x0, file_count=3)
    at /home/oshaw/build/php-5.1.0RC1/Zend/zend.c:1078
#11 0x0822bd76 in php_execute_script (primary_file=0xbfffe160)
    at /home/oshaw/build/php-5.1.0RC1/main/main.c:1672
#12 0x082d881c in main (argc=2, argv=0xbfffe244)
    at /home/oshaw/build/php-5.1.0RC1/sapi/cli/php_cli.c:1039


Simplexml does not crash
 [2005-09-01 01:49 UTC] rrichards@php.net
Sorry, but your problem does not imply a bug in PHP itself.  For a
list of more appropriate places to ask for help using PHP, please
visit http://www.php.net/support.php as this bug system is not the
appropriate forum for asking support questions.  Due to the volume
of reports we can not explain in detail here why your report is not
a bug.  The support channels will be able to provide an explanation
for you.

Thank you for your interest in PHP.

upgrade to libxml2 2.6.8 or newer
previous versions corrupt memory
 
PHP Copyright © 2001-2026 The PHP Group
All rights reserved.
Last updated: Tue Oct 06 17:00:01 2026 UTC