php.net |  support |  documentation |  report a bug |  advanced search |  search howto |  statistics |  random bug |  login
Bug #19172 limited recursive class call results segfault
Submitted: 2002-08-29 10:19 UTC Modified: 2002-08-29 10:51 UTC
From: alberty at neptunelabs dot de Assigned:
Status: Not a bug Package: Reproducible crash
PHP Version: 4CVS-2002-08-29 OS: i686-pc-linux-gnu
Private report: No CVE-ID: None
 [2002-08-29 10:19 UTC] alberty at neptunelabs dot de
Hi,

the follow call results a segfault:

<?php
class foo {
	function out(){
	static $stopper=0;
		if ($stopper < 10) $this->out();
		$stopper++;
	}
}

$foo = new foo;
$foo->out();
?>


Tested with gcc3.1.1 and libc2.2.4


here is the backtrace:
Program received signal SIGSEGV, Segmentation fault.
0x4044d4cc in _get_zval_ptr (node=0x816b018, Ts=0xbf8000bc, should_free=0xbf80008c) at /usr/src/php4/Zend/zend_execute.c:71
71      {
(gdb) bt
#0  0x4044d4cc in _get_zval_ptr (node=0x816b018, Ts=0xbf8000bc, should_free=0xbf80008c) at /usr/src/php4/Zend/zend_execute.c:71
#1  0x40445495 in zend_fetch_var_address (opline=0x816b004, Ts=0xbf8000bc, type=1) at /usr/src/php4/Zend/zend_execute.c:529
#2  0x40447900 in execute (op_array=0x816bf34) at /usr/src/php4/Zend/zend_execute.c:1237
#3  0x40449b55 in execute (op_array=0x816bf34) at /usr/src/php4/Zend/zend_execute.c:1643
#4  0x40449b55 in execute (op_array=0x816bf34) at /usr/src/php4/Zend/zend_execute.c:1643
#5  0x40449b55 in execute (op_array=0x816bf34) at /usr/src/php4/Zend/zend_execute.c:1643
...

Regards,

Steve

Patches

Pull Requests

History

AllCommentsChangesGit/SVN commitsRelated reports
 [2002-08-29 10:22 UTC] derick@php.net
erm,

you're initializing the variable to 0 every time you enter this function, and the result will be that this function keeps calling itself indefinetely.
As disucussed on the dev list before we will not fix this.

Derick
 [2002-08-29 10:31 UTC] alberty at neptunelabs dot de
Yes, i know, but you have not read the script.

I have declared $stopper as static!

And also this script without any initializing 
also crashes:

<?php
class foo {
	var $stopper=0;
	function out(){
		if ($this->stopper < 10) $this->out();
		$this->stopper++;
	}
}

$foo = new foo;
$foo->out();
?>

backtrace:
Program received signal SIGSEGV, Segmentation fault.
0x4044d45d in zend_clean_garbage () at /usr/src/php4/Zend/zend_execute_locks.h:24
24      {
(gdb) bt
#0  0x4044d45d in zend_clean_garbage () at /usr/src/php4/Zend/zend_execute_locks.h:24
#1  0x40446b66 in execute (op_array=0x816c314) at /usr/src/php4/Zend/zend_execute.c:1054
#2  0x40449b55 in execute (op_array=0x816c314) at /usr/src/php4/Zend/zend_execute.c:1643
#3  0x40449b55 in execute (op_array=0x816c314) at /usr/src/php4/Zend/zend_execute.c:1643


Regards,

Steve
 [2002-08-29 10:33 UTC] derick@php.net
Of course it does, you do the next function call before you increase $stopper.
This way $stopper will always stay 0 when it enters the function again.

Derick
 [2002-08-29 10:34 UTC] cynic@php.net
no, it's actually you who has not read the script. you have a bug there.
leave this PR bogusified.

 [2002-08-29 10:36 UTC] cynic@php.net
umm, derick, my last comment was for the OP, you were too fast. :)

 [2002-08-29 10:44 UTC] alberty at neptunelabs dot de
Okay, this was absolutly my fault.
This BR was not really intelligent.

Sorry.
 [2002-08-29 10:50 UTC] derick@php.net
user errors should have the bogus state -> bogus
 [2002-08-29 10:51 UTC] derick@php.net
bogus I said :)
 
PHP Copyright © 2001-2026 The PHP Group
All rights reserved.
Last updated: Wed Oct 07 10:00:01 2026 UTC