php.net |  support |  documentation |  report a bug |  advanced search |  search howto |  statistics |  random bug |  login
Bug #68539 Crash with simple script that contains __debugInfo method
Submitted: 2014-12-03 09:14 UTC Modified: 2014-12-03 09:19 UTC
From: eran at zend dot com Assigned: dmitry (profile)
Status: Closed Package: *General Issues
PHP Version: 5.6.3 OS: Linux
Private report: No CVE-ID: None
Welcome back! If you're the original bug submitter, here's where you can edit the bug or add additional notes.
If you forgot your password, you can retrieve your password here.
Password:
Status:
Package:
Bug Type:
Summary:
From: eran at zend dot com
New email:
PHP Version: OS:

 

 [2014-12-03 09:14 UTC] eran at zend dot com
Description:
------------
Hello,
Running the below Test Script results in segfault.

I compiled PHP with debug info + OPcache with debug info and ran PHP under valgrind like this (more useful than gdb in this case):

valgrind --log-file=/tmp/vg.log /usr/sbin/apache2 -X
Shows consistent 'Invalid free/delete' error messages

here is sample from valgrind output:

==14364== Invalid free() / delete / delete[] / realloc()
==14364==    at 0x4C2BDEC: free (in /usr/lib/valgrind/vgpreload_memcheck-amd64-linux.so)
==14364==    by 0x8E08625: _efree (zend_alloc.c:2437)
==14364==    by 0x8E2FEB7: destroy_op_array (zend_opcode.c:361)
==14364==    by 0x8E2F4B5: destroy_zend_function (zend_opcode.c:116)
==14364==    by 0x8E2F4D2: zend_function_dtor (zend_opcode.c:128)
==14364==    by 0x8E51F67: zend_hash_destroy (zend_hash.c:548)
==14364==    by 0x8E2FC20: destroy_zend_class (zend_opcode.c:300)
==14364==    by 0x8E5073B: zend_hash_bucket_delete (zend_hash.c:182)
==14364==    by 0x8E52628: zend_hash_reverse_apply (zend_hash.c:733)
==14364==    by 0x8E294C6: shutdown_executor (zend_execute_API.c:303)
==14364==    by 0x8E3FDB6: zend_deactivate (zend.c:949)
==14364==    by 0x8DAEE2A: php_request_shutdown (main.c:1884)
==14364==  Address 0x1dae38f0 is 0 bytes inside a block of size 16 free'd
==14364==    at 0x4C2BDEC: free (in /usr/lib/valgrind/vgpreload_memcheck-amd64-linux.so)
==14364==    by 0x8E08625: _efree (zend_alloc.c:2437)
==14364==    by 0x8E2FEB7: destroy_op_array (zend_opcode.c:361)
==14364==    by 0x8E2F4B5: destroy_zend_function (zend_opcode.c:116)
==14364==    by 0x8E2F4D2: zend_function_dtor (zend_opcode.c:128)
==14364==    by 0x8E51F67: zend_hash_destroy (zend_hash.c:548)
==14364==    by 0x8E2FC20: destroy_zend_class (zend_opcode.c:300)
==14364==    by 0x8E5073B: zend_hash_bucket_delete (zend_hash.c:182)
==14364==    by 0x8E52628: zend_hash_reverse_apply (zend_hash.c:733)
==14364==    by 0x8E294C6: shutdown_executor (zend_execute_API.c:303)
==14364==    by 0x8E3FDB6: zend_deactivate (zend.c:949)
==14364==    by 0x8DAEE2A: php_request_shutdown (main.c:1884)

everything was tested on Linux Mint 17, 64 bit
Using PHP 5.6.3.

Test script:
---------------
<?php
 
class C {
  public $val;
  public function __debugInfo() {
    return $this->val;
  }
  public function __construct($val) {
    $this->val = $val;
  }
}
 
$c = new C(0);
var_dump($c);


Expected result:
----------------
No crash

Actual result:
--------------
Segmentation fault

Patches

Pull Requests

History

AllCommentsChangesGit/SVN commitsRelated reports
 [2014-12-03 09:19 UTC] dmitry@php.net
-Status: Open +Status: Closed -Assigned To: +Assigned To: dmitry
 
PHP Copyright © 2001-2026 The PHP Group
All rights reserved.
Last updated: Wed Oct 07 22:00:01 2026 UTC