PHP  
 PHP_5_5
downloads | QA | documentation | faq | getting help | mailing lists | reporting bugs | php.net sites | links | my php.net 
 

Valgrind Report for Zend/tests/bug64896.phpt ('Bug #64896 (Segfault with gc_collect_cycles using unserialize on certain objects)')

Script

1: <?php
2: $bar 
NULL;
3: class 
bad
4:
{
5:     private 
$_private = array();
6:
7:     public function 
__construct()
8:     {
9:         
$this->_private[] = 'php';
10:     }
11:
12:     public function 
__destruct()
13:     {
14:         global 
$bar;
15:         
$bar $this;
16:     }
17: }
18:
19:
$foo = new stdclass;
20:
$foo->foo $foo;
21:
$foo->bad = new bad;
22:
23:
gc_disable();
24:
25:
unserialize(serialize($foo));
26:
gc_collect_cycles();
27:
var_dump($bar); 
28:
/*  will output:
29: object(bad)#4 (1) {
30:   ["_private":"bad":private]=>
31:   &UNKNOWN:0
32: }
33: */
34:
?>
35:

Report

==14241== Invalid read of size 1
==14241==    at 0xC94CE5: php_var_dump (var.c:99)
==14241==    by 0xC94C55: php_object_property_dump (var.c:82)
==14241==    by 0xEBF326: zend_hash_apply_with_arguments (zend_hash.c:772)
==14241==    by 0xC955D2: php_var_dump (var.c:146)
==14241==    by 0xC958E4: zif_var_dump (var.c:183)
==14241==    by 0xF09699: zend_do_fcall_common_helper_SPEC (zend_vm_execute.h:550)
==14241==    by 0xF137D3: ZEND_DO_FCALL_SPEC_CONST_HANDLER (zend_vm_execute.h:2336)
==14241==    by 0xF072E8: execute_ex (zend_vm_execute.h:363)
==14241==    by 0xF07E7A: zend_execute (zend_vm_execute.h:388)
==14241==    by 0xEA43A4: zend_execute_scripts (zend.c:1327)
==14241==    by 0xDC6C0E: php_execute_script (main.c:2525)
==14241==    by 0x108D6B9: do_cli (php_cli.c:994)
==14241==  Address 0x153add54 is 20 bytes inside a block of size 32 free'd
==14241==    at 0x4C27C24: free (vg_replace_malloc.c:473)
==14241==    by 0xE4F2E0: _efree (zend_alloc.c:2437)
==14241==    by 0xEE5C7F: gc_collect_cycles (zend_gc.c:846)
==14241==    by 0xEC4735: zif_gc_collect_cycles (zend_builtin_functions.c:361)
==14241==    by 0xF09699: zend_do_fcall_common_helper_SPEC (zend_vm_execute.h:550)
==14241==    by 0xF137D3: ZEND_DO_FCALL_SPEC_CONST_HANDLER (zend_vm_execute.h:2336)
==14241==    by 0xF072E8: execute_ex (zend_vm_execute.h:363)
==14241==    by 0xF07E7A: zend_execute (zend_vm_execute.h:388)
==14241==    by 0xEA43A4: zend_execute_scripts (zend.c:1327)
==14241==    by 0xDC6C0E: php_execute_script (main.c:2525)
==14241==    by 0x108D6B9: do_cli (php_cli.c:994)
==14241==    by 0x108EE66: main (php_cli.c:1378)
==14241== 
==14241== Invalid read of size 1
==14241==    at 0xC94DD8: zval_isref_p (zend.h:413)
==14241==    by 0xC94DD8: php_var_dump (var.c:104)
==14241==    by 0xC94C55: php_object_property_dump (var.c:82)
==14241==    by 0xEBF326: zend_hash_apply_with_arguments (zend_hash.c:772)
==14241==    by 0xC955D2: php_var_dump (var.c:146)
==14241==    by 0xC958E4: zif_var_dump (var.c:183)
==14241==    by 0xF09699: zend_do_fcall_common_helper_SPEC (zend_vm_execute.h:550)
==14241==    by 0xF137D3: ZEND_DO_FCALL_SPEC_CONST_HANDLER (zend_vm_execute.h:2336)
==14241==    by 0xF072E8: execute_ex (zend_vm_execute.h:363)
==14241==    by 0xF07E7A: zend_execute (zend_vm_execute.h:388)
==14241==    by 0xEA43A4: zend_execute_scripts (zend.c:1327)
==14241==    by 0xDC6C0E: php_execute_script (main.c:2525)
==14241==    by 0x108D6B9: do_cli (php_cli.c:994)
==14241==  Address 0x153add55 is 21 bytes inside a block of size 32 free'd
==14241==    at 0x4C27C24: free (vg_replace_malloc.c:473)
==14241==    by 0xE4F2E0: _efree (zend_alloc.c:2437)
==14241==    by 0xEE5C7F: gc_collect_cycles (zend_gc.c:846)
==14241==    by 0xEC4735: zif_gc_collect_cycles (zend_builtin_functions.c:361)
==14241==    by 0xF09699: zend_do_fcall_common_helper_SPEC (zend_vm_execute.h:550)
==14241==    by 0xF137D3: ZEND_DO_FCALL_SPEC_CONST_HANDLER (zend_vm_execute.h:2336)
==14241==    by 0xF072E8: execute_ex (zend_vm_execute.h:363)
==14241==    by 0xF07E7A: zend_execute (zend_vm_execute.h:388)
==14241==    by 0xEA43A4: zend_execute_scripts (zend.c:1327)
==14241==    by 0xDC6C0E: php_execute_script (main.c:2525)
==14241==    by 0x108D6B9: do_cli (php_cli.c:994)
==14241==    by 0x108EE66: main (php_cli.c:1378)
==14241== 
==14241== Invalid read of size 4
==14241==    at 0xE80AB4: zval_delref_p (zend.h:409)
==14241==    by 0xE80AB4: i_zval_ptr_dtor (zend_execute.h:76)
==14241==    by 0xE80AB4: _zval_ptr_dtor (zend_execute_API.c:423)
==14241==    by 0xEBE60D: zend_hash_destroy (zend_hash.c:560)
==14241==    by 0xEEBC30: zend_object_std_dtor (zend_objects.c:44)
==14241==    by 0xEEC394: zend_objects_free_object_storage (zend_objects.c:137)
==14241==    by 0xEFB9DE: zend_objects_store_del_ref_by_handle_ex (zend_objects_API.c:226)
==14241==    by 0xEFB578: zend_objects_store_del_ref (zend_objects_API.c:178)
==14241==    by 0xE9ED9D: _zval_dtor_func (zend_variables.c:54)
==14241==    by 0xE80B56: _zval_dtor (zend_variables.h:35)
==14241==    by 0xE80B56: i_zval_ptr_dtor (zend_execute.h:81)
==14241==    by 0xE80B56: _zval_ptr_dtor (zend_execute_API.c:423)
==14241==    by 0xEBEB6E: zend_hash_apply_deleter (zend_hash.c:650)
==14241==    by 0xEBF55C: zend_hash_reverse_apply (zend_hash.c:804)
==14241==    by 0xE7FC4D: shutdown_destructors (zend_execute_API.c:214)
==14241==    by 0xEA2678: zend_call_destructors (zend.c:930)
==14241==  Address 0x153add50 is 16 bytes inside a block of size 32 free'd
==14241==    at 0x4C27C24: free (vg_replace_malloc.c:473)
==14241==    by 0xE4F2E0: _efree (zend_alloc.c:2437)
==14241==    by 0xEE5C7F: gc_collect_cycles (zend_gc.c:846)
==14241==    by 0xEC4735: zif_gc_collect_cycles (zend_builtin_functions.c:361)
==14241==    by 0xF09699: zend_do_fcall_common_helper_SPEC (zend_vm_execute.h:550)
==14241==    by 0xF137D3: ZEND_DO_FCALL_SPEC_CONST_HANDLER (zend_vm_execute.h:2336)
==14241==    by 0xF072E8: execute_ex (zend_vm_execute.h:363)
==14241==    by 0xF07E7A: zend_execute (zend_vm_execute.h:388)
==14241==    by 0xEA43A4: zend_execute_scripts (zend.c:1327)
==14241==    by 0xDC6C0E: php_execute_script (main.c:2525)
==14241==    by 0x108D6B9: do_cli (php_cli.c:994)
==14241==    by 0x108EE66: main (php_cli.c:1378)
==14241== 
==14241== Invalid write of size 4
==14241==    at 0xE80ABE: zval_delref_p (zend.h:409)
==14241==    by 0xE80ABE: i_zval_ptr_dtor (zend_execute.h:76)
==14241==    by 0xE80ABE: _zval_ptr_dtor (zend_execute_API.c:423)
==14241==    by 0xEBE60D: zend_hash_destroy (zend_hash.c:560)
==14241==    by 0xEEBC30: zend_object_std_dtor (zend_objects.c:44)
==14241==    by 0xEEC394: zend_objects_free_object_storage (zend_objects.c:137)
==14241==    by 0xEFB9DE: zend_objects_store_del_ref_by_handle_ex (zend_objects_API.c:226)
==14241==    by 0xEFB578: zend_objects_store_del_ref (zend_objects_API.c:178)
==14241==    by 0xE9ED9D: _zval_dtor_func (zend_variables.c:54)
==14241==    by 0xE80B56: _zval_dtor (zend_variables.h:35)
==14241==    by 0xE80B56: i_zval_ptr_dtor (zend_execute.h:81)
==14241==    by 0xE80B56: _zval_ptr_dtor (zend_execute_API.c:423)
==14241==    by 0xEBEB6E: zend_hash_apply_deleter (zend_hash.c:650)
==14241==    by 0xEBF55C: zend_hash_reverse_apply (zend_hash.c:804)
==14241==    by 0xE7FC4D: shutdown_destructors (zend_execute_API.c:214)
==14241==    by 0xEA2678: zend_call_destructors (zend.c:930)
==14241==  Address 0x153add50 is 16 bytes inside a block of size 32 free'd
==14241==    at 0x4C27C24: free (vg_replace_malloc.c:473)
==14241==    by 0xE4F2E0: _efree (zend_alloc.c:2437)
==14241==    by 0xEE5C7F: gc_collect_cycles (zend_gc.c:846)
==14241==    by 0xEC4735: zif_gc_collect_cycles (zend_builtin_functions.c:361)
==14241==    by 0xF09699: zend_do_fcall_common_helper_SPEC (zend_vm_execute.h:550)
==14241==    by 0xF137D3: ZEND_DO_FCALL_SPEC_CONST_HANDLER (zend_vm_execute.h:2336)
==14241==    by 0xF072E8: execute_ex (zend_vm_execute.h:363)
==14241==    by 0xF07E7A: zend_execute (zend_vm_execute.h:388)
==14241==    by 0xEA43A4: zend_execute_scripts (zend.c:1327)
==14241==    by 0xDC6C0E: php_execute_script (main.c:2525)
==14241==    by 0x108D6B9: do_cli (php_cli.c:994)
==14241==    by 0x108EE66: main (php_cli.c:1378)
==14241== 
==14241== Invalid read of size 4
==14241==    at 0xE80AC5: zval_delref_p (zend.h:409)
==14241==    by 0xE80AC5: i_zval_ptr_dtor (zend_execute.h:76)
==14241==    by 0xE80AC5: _zval_ptr_dtor (zend_execute_API.c:423)
==14241==    by 0xEBE60D: zend_hash_destroy (zend_hash.c:560)
==14241==    by 0xEEBC30: zend_object_std_dtor (zend_objects.c:44)
==14241==    by 0xEEC394: zend_objects_free_object_storage (zend_objects.c:137)
==14241==    by 0xEFB9DE: zend_objects_store_del_ref_by_handle_ex (zend_objects_API.c:226)
==14241==    by 0xEFB578: zend_objects_store_del_ref (zend_objects_API.c:178)
==14241==    by 0xE9ED9D: _zval_dtor_func (zend_variables.c:54)
==14241==    by 0xE80B56: _zval_dtor (zend_variables.h:35)
==14241==    by 0xE80B56: i_zval_ptr_dtor (zend_execute.h:81)
==14241==    by 0xE80B56: _zval_ptr_dtor (zend_execute_API.c:423)
==14241==    by 0xEBEB6E: zend_hash_apply_deleter (zend_hash.c:650)
==14241==    by 0xEBF55C: zend_hash_reverse_apply (zend_hash.c:804)
==14241==    by 0xE7FC4D: shutdown_destructors (zend_execute_API.c:214)
==14241==    by 0xEA2678: zend_call_destructors (zend.c:930)
==14241==  Address 0x153add50 is 16 bytes inside a block of size 32 free'd
==14241==    at 0x4C27C24: free (vg_replace_malloc.c:473)
==14241==    by 0xE4F2E0: _efree (zend_alloc.c:2437)
==14241==    by 0xEE5C7F: gc_collect_cycles (zend_gc.c:846)
==14241==    by 0xEC4735: zif_gc_collect_cycles (zend_builtin_functions.c:361)
==14241==    by 0xF09699: zend_do_fcall_common_helper_SPEC (zend_vm_execute.h:550)
==14241==    by 0xF137D3: ZEND_DO_FCALL_SPEC_CONST_HANDLER (zend_vm_execute.h:2336)
==14241==    by 0xF072E8: execute_ex (zend_vm_execute.h:363)
==14241==    by 0xF07E7A: zend_execute (zend_vm_execute.h:388)
==14241==    by 0xEA43A4: zend_execute_scripts (zend.c:1327)
==14241==    by 0xDC6C0E: php_execute_script (main.c:2525)
==14241==    by 0x108D6B9: do_cli (php_cli.c:994)
==14241==    by 0x108EE66: main (php_cli.c:1378)
==14241== 
==14241== Invalid read of size 4
==14241==    at 0xE80BAA: zval_refcount_p (zend.h:397)
==14241==    by 0xE80BAA: i_zval_ptr_dtor (zend_execute.h:86)
==14241==    by 0xE80BAA: _zval_ptr_dtor (zend_execute_API.c:423)
==14241==    by 0xEBE60D: zend_hash_destroy (zend_hash.c:560)
==14241==    by 0xEEBC30: zend_object_std_dtor (zend_objects.c:44)
==14241==    by 0xEEC394: zend_objects_free_object_storage (zend_objects.c:137)
==14241==    by 0xEFB9DE: zend_objects_store_del_ref_by_handle_ex (zend_objects_API.c:226)
==14241==    by 0xEFB578: zend_objects_store_del_ref (zend_objects_API.c:178)
==14241==    by 0xE9ED9D: _zval_dtor_func (zend_variables.c:54)
==14241==    by 0xE80B56: _zval_dtor (zend_variables.h:35)
==14241==    by 0xE80B56: i_zval_ptr_dtor (zend_execute.h:81)
==14241==    by 0xE80B56: _zval_ptr_dtor (zend_execute_API.c:423)
==14241==    by 0xEBEB6E: zend_hash_apply_deleter (zend_hash.c:650)
==14241==    by 0xEBF55C: zend_hash_reverse_apply (zend_hash.c:804)
==14241==    by 0xE7FC4D: shutdown_destructors (zend_execute_API.c:214)
==14241==    by 0xEA2678: zend_call_destructors (zend.c:930)
==14241==  Address 0x153add50 is 16 bytes inside a block of size 32 free'd
==14241==    at 0x4C27C24: free (vg_replace_malloc.c:473)
==14241==    by 0xE4F2E0: _efree (zend_alloc.c:2437)
==14241==    by 0xEE5C7F: gc_collect_cycles (zend_gc.c:846)
==14241==    by 0xEC4735: zif_gc_collect_cycles (zend_builtin_functions.c:361)
==14241==    by 0xF09699: zend_do_fcall_common_helper_SPEC (zend_vm_execute.h:550)
==14241==    by 0xF137D3: ZEND_DO_FCALL_SPEC_CONST_HANDLER (zend_vm_execute.h:2336)
==14241==    by 0xF072E8: execute_ex (zend_vm_execute.h:363)
==14241==    by 0xF07E7A: zend_execute (zend_vm_execute.h:388)
==14241==    by 0xEA43A4: zend_execute_scripts (zend.c:1327)
==14241==    by 0xDC6C0E: php_execute_script (main.c:2525)
==14241==    by 0x108D6B9: do_cli (php_cli.c:994)
==14241==    by 0x108EE66: main (php_cli.c:1378)
==14241== 
==14241== Invalid write of size 1
==14241==    at 0xE80BBE: zval_unset_isref_p (zend.h:421)
==14241==    by 0xE80BBE: i_zval_ptr_dtor (zend_execute.h:87)
==14241==    by 0xE80BBE: _zval_ptr_dtor (zend_execute_API.c:423)
==14241==    by 0xEBE60D: zend_hash_destroy (zend_hash.c:560)
==14241==    by 0xEEBC30: zend_object_std_dtor (zend_objects.c:44)
==14241==    by 0xEEC394: zend_objects_free_object_storage (zend_objects.c:137)
==14241==    by 0xEFB9DE: zend_objects_store_del_ref_by_handle_ex (zend_objects_API.c:226)
==14241==    by 0xEFB578: zend_objects_store_del_ref (zend_objects_API.c:178)
==14241==    by 0xE9ED9D: _zval_dtor_func (zend_variables.c:54)
==14241==    by 0xE80B56: _zval_dtor (zend_variables.h:35)
==14241==    by 0xE80B56: i_zval_ptr_dtor (zend_execute.h:81)
==14241==    by 0xE80B56: _zval_ptr_dtor (zend_execute_API.c:423)
==14241==    by 0xEBEB6E: zend_hash_apply_deleter (zend_hash.c:650)
==14241==    by 0xEBF55C: zend_hash_reverse_apply (zend_hash.c:804)
==14241==    by 0xE7FC4D: shutdown_destructors (zend_execute_API.c:214)
==14241==    by 0xEA2678: zend_call_destructors (zend.c:930)
==14241==  Address 0x153add55 is 21 bytes inside a block of size 32 free'd
==14241==    at 0x4C27C24: free (vg_replace_malloc.c:473)
==14241==    by 0xE4F2E0: _efree (zend_alloc.c:2437)
==14241==    by 0xEE5C7F: gc_collect_cycles (zend_gc.c:846)
==14241==    by 0xEC4735: zif_gc_collect_cycles (zend_builtin_functions.c:361)
==14241==    by 0xF09699: zend_do_fcall_common_helper_SPEC (zend_vm_execute.h:550)
==14241==    by 0xF137D3: ZEND_DO_FCALL_SPEC_CONST_HANDLER (zend_vm_execute.h:2336)
==14241==    by 0xF072E8: execute_ex (zend_vm_execute.h:363)
==14241==    by 0xF07E7A: zend_execute (zend_vm_execute.h:388)
==14241==    by 0xEA43A4: zend_execute_scripts (zend.c:1327)
==14241==    by 0xDC6C0E: php_execute_script (main.c:2525)
==14241==    by 0x108D6B9: do_cli (php_cli.c:994)
==14241==    by 0x108EE66: main (php_cli.c:1378)
==14241== 
==14241== Invalid read of size 1
==14241==    at 0xE80BE0: gc_zval_check_possible_root (zend_gc.h:182)
==14241==    by 0xE80BE0: i_zval_ptr_dtor (zend_execute.h:90)
==14241==    by 0xE80BE0: _zval_ptr_dtor (zend_execute_API.c:423)
==14241==    by 0xEBE60D: zend_hash_destroy (zend_hash.c:560)
==14241==    by 0xEEBC30: zend_object_std_dtor (zend_objects.c:44)
==14241==    by 0xEEC394: zend_objects_free_object_storage (zend_objects.c:137)
==14241==    by 0xEFB9DE: zend_objects_store_del_ref_by_handle_ex (zend_objects_API.c:226)
==14241==    by 0xEFB578: zend_objects_store_del_ref (zend_objects_API.c:178)
==14241==    by 0xE9ED9D: _zval_dtor_func (zend_variables.c:54)
==14241==    by 0xE80B56: _zval_dtor (zend_variables.h:35)
==14241==    by 0xE80B56: i_zval_ptr_dtor (zend_execute.h:81)
==14241==    by 0xE80B56: _zval_ptr_dtor (zend_execute_API.c:423)
==14241==    by 0xEBEB6E: zend_hash_apply_deleter (zend_hash.c:650)
==14241==    by 0xEBF55C: zend_hash_reverse_apply (zend_hash.c:804)
==14241==    by 0xE7FC4D: shutdown_destructors (zend_execute_API.c:214)
==14241==    by 0xEA2678: zend_call_destructors (zend.c:930)
==14241==  Address 0x153add54 is 20 bytes inside a block of size 32 free'd
==14241==    at 0x4C27C24: free (vg_replace_malloc.c:473)
==14241==    by 0xE4F2E0: _efree (zend_alloc.c:2437)
==14241==    by 0xEE5C7F: gc_collect_cycles (zend_gc.c:846)
==14241==    by 0xEC4735: zif_gc_collect_cycles (zend_builtin_functions.c:361)
==14241==    by 0xF09699: zend_do_fcall_common_helper_SPEC (zend_vm_execute.h:550)
==14241==    by 0xF137D3: ZEND_DO_FCALL_SPEC_CONST_HANDLER (zend_vm_execute.h:2336)
==14241==    by 0xF072E8: execute_ex (zend_vm_execute.h:363)
==14241==    by 0xF07E7A: zend_execute (zend_vm_execute.h:388)
==14241==    by 0xEA43A4: zend_execute_scripts (zend.c:1327)
==14241==    by 0xDC6C0E: php_execute_script (main.c:2525)
==14241==    by 0x108D6B9: do_cli (php_cli.c:994)
==14241==    by 0x108EE66: main (php_cli.c:1378)
==14241== 
==14241== Invalid read of size 1
==14241==    at 0xE80BFE: gc_zval_check_possible_root (zend_gc.h:182)
==14241==    by 0xE80BFE: i_zval_ptr_dtor (zend_execute.h:90)
==14241==    by 0xE80BFE: _zval_ptr_dtor (zend_execute_API.c:423)
==14241==    by 0xEBE60D: zend_hash_destroy (zend_hash.c:560)
==14241==    by 0xEEBC30: zend_object_std_dtor (zend_objects.c:44)
==14241==    by 0xEEC394: zend_objects_free_object_storage (zend_objects.c:137)
==14241==    by 0xEFB9DE: zend_objects_store_del_ref_by_handle_ex (zend_objects_API.c:226)
==14241==    by 0xEFB578: zend_objects_store_del_ref (zend_objects_API.c:178)
==14241==    by 0xE9ED9D: _zval_dtor_func (zend_variables.c:54)
==14241==    by 0xE80B56: _zval_dtor (zend_variables.h:35)
==14241==    by 0xE80B56: i_zval_ptr_dtor (zend_execute.h:81)
==14241==    by 0xE80B56: _zval_ptr_dtor (zend_execute_API.c:423)
==14241==    by 0xEBEB6E: zend_hash_apply_deleter (zend_hash.c:650)
==14241==    by 0xEBF55C: zend_hash_reverse_apply (zend_hash.c:804)
==14241==    by 0xE7FC4D: shutdown_destructors (zend_execute_API.c:214)
==14241==    by 0xEA2678: zend_call_destructors (zend.c:930)
==14241==  Address 0x153add54 is 20 bytes inside a block of size 32 free'd
==14241==    at 0x4C27C24: free (vg_replace_malloc.c:473)
==14241==    by 0xE4F2E0: _efree (zend_alloc.c:2437)
==14241==    by 0xEE5C7F: gc_collect_cycles (zend_gc.c:846)
==14241==    by 0xEC4735: zif_gc_collect_cycles (zend_builtin_functions.c:361)
==14241==    by 0xF09699: zend_do_fcall_common_helper_SPEC (zend_vm_execute.h:550)
==14241==    by 0xF137D3: ZEND_DO_FCALL_SPEC_CONST_HANDLER (zend_vm_execute.h:2336)
==14241==    by 0xF072E8: execute_ex (zend_vm_execute.h:363)
==14241==    by 0xF07E7A: zend_execute (zend_vm_execute.h:388)
==14241==    by 0xEA43A4: zend_execute_scripts (zend.c:1327)
==14241==    by 0xDC6C0E: php_execute_script (main.c:2525)
==14241==    by 0x108D6B9: do_cli (php_cli.c:994)
==14241==    by 0x108EE66: main (php_cli.c:1378)
==14241== 

 

Generated at Sat, 25 Jul 2015 01:11:20 +0000 (6 days ago)

Copyright © 2005-2015 The PHP Group
All rights reserved.