Assertion failure in gc with invalid variable (OOM)
Open
Nobody has claimed this yet.
Bug
Category: Engine
Status: Verified
- Dominant language
- C
- Stars
- 40.4k
- Forks
- 8.1k
- Avg merge
- 2d 13h
- Merged PRs (30d)
- 96
Description
Description
The following code:
<?php
$cls = new finfo();
class foo {
public $x;
static public $y;
public function a() {
return $this->x;
}
static public function b() {
return self::$y;
}
}
$foo = new foo;
$h = $foo->a()[0]->a;
$h = foo::b()[1]->b;
var_dump($h);
$fusion = $h;
$base = curl_init('http://www.google.com/');
curl_setopt($base, CURLOPT_RETURNTRANSFER, true);
$mh = curl_multi_init();
for ($i = 0; $fusion < 2; ++$i) {
$ch = curl_copy_handle($base);
curl_setopt($ch, CURLOPT_HTTPHEADER, ['Foo: Bar']);
curl_multi_add_handle($mh, $ch);
}
?>
Resulted in this output:
php: Zend/zend_types.h:1346: uint32_t zend_gc_delref(zend_refcounted_h *): Assertion `p->refcount > 0' failed.
Aborted (core dumped)
PHP Version
nightly
Operating System
ubuntu 22.04
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Start by running the supplied PHP reproducer with a nightly build on Ubuntu 22.04, then inspect the assertion in Zend/zend_types.h at line 1346. Trace the invalid variable and reference-count changes through the reproducer; done means the script no longer aborts with the zend_gc_delref assertion.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- c, php
- Domain
- backend
- Issue type
- Bug
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 35/100