ID: 22284 User updated by: White_Angel at gmx dot de -Summary: Dynamic Var Accessing Classes crashes PHP Reported By: White_Angel at gmx dot de Status: Verified Bug Type: Zend Engine 2 problem -Operating System: Linux;RedHat8.0;2.4.18-24 +Operating System: all -PHP Version: 5CVS-2003-02-18 (dev) +PHP Version: 5CVS-2003-02-21 (dev) New Comment:
Yes. It`s the same #22237 . Sorry for double Report. Previous Comments: ------------------------------------------------------------------------ [2003-02-22 05:37:23] peter at globalvision dot com dot au Isn't this identical to my report? (22237) ------------------------------------------------------------------------ [2003-02-18 22:48:47] [EMAIL PROTECTED] must be ZE2 prob since the script just gives me parse error with php4.3.2-dev ------------------------------------------------------------------------ [2003-02-18 16:55:38] [EMAIL PROTECTED] #0 0x0817d606 in zend_hash_exists (ht=0x401e3ce0, arKey=0x6c <Address 0x6c out of bounds>, nKeyLength=1) at /php/php/php5/Zend/zend_hash.c:923 tmp = 0x6c <Address 0x6c out of bounds> h = 1075731160 nIndex = 8 p = (struct bucket *) 0x1 #1 0x08167571 in zend_do_fetch_property (result=0xbfffbe90, object=0xbfffbd00, property=0xbfffc118) at /php/php/php5/Zend/zend_compile.c:2327 le = (struct _zend_llist_element *) 0x401e5c28 opline = {handler = 0x81e6c98 <alloc_globals+11448>, result = {op_type = 1075731304, throw_list = 0x18, u = {constant = {value = {lval = 67, dval = 3.3102398271363518e-322, str = { val = 0x43 <Address 0x43 out of bounds>, len = 0}, ht = 0x43, obj = {handle = 67, handlers = 0x0}}, refcount = 0, type = 8 '\b', is_ref = 188 '¼'}, var = 67, opline_num = 67, op_array = 0x43, jmp_addr = 0x43, EA = {var = 67, type = 0}}}, op1 = { op_type = 3, throw_list = 0x18, u = {constant = {value = {lval = 1075731304, dval = -1.9834215645439262, str = {val = 0x401e5b68 "", len = -1073759208}, ht = 0x401e5b68, obj = {handle = 1075731304, handlers = 0xbfffbc18}}, refcount = 135743298, type = 140 '\214', is_ref = 91 '['}, var = 1075731304, opline_num = 1075731304, op_array = 0x401e5b68, jmp_addr = 0x401e5b68, EA = {var = 1075731304, type = 3221208088}}}, op2 = {op_type = 136113376, throw_list = 0x43, u = {constant = {value = {lval = 0, dval = 0, str = { val = 0x0, len = 0}, ht = 0x0, obj = {handle = 0, handlers = 0x0}}, refcount = 0, type = 56 '8', is_ref = 188 '¼'}, var = 0, opline_num = 0, op_array = 0x0, jmp_addr = 0x0, EA = {var = 0, type = 0}}}, extended_value = 135689985, lineno = 136211908, opcode = 52 '4'} fetch_list_ptr = (struct _zend_llist *) 0x401e5b38 opline_ptr = (struct _zend_op *) 0x401e5c30 #2 0x08158777 in zendparse () at /php/php/php5/Zend/zend_language_parser.y:811 tmp_znode = {op_type = 4, throw_list = 0x0, u = {constant = {value = {lval = 72, dval = 3.3951932691017084e-313, str = {val = 0x48 <Address 0x48 out of bounds>, len = 16}, ht = 0x48, obj = {handle = 72, handlers = 0x10}}, refcount = 0, type = 0 '\0', is_ref = 0 '\0'}, var = 72, opline_num = 72, op_array = 0x48, jmp_addr = 0x48, EA = {var = 72, type = 16}}} zendchar = 59 zendlval = {op_type = 1, throw_list = 0x0, u = {constant = {value = {lval = 1075731652, dval = 9.0194652172583403e-314, str = {val = 0x401e5cc4 "name", len = 4}, ht = 0x401e5cc4, obj = {handle = 1075731652, handlers = 0x4}}, refcount = 1, type = 1 '\001', is_ref = 0 '\0'}, var = 1075731652, opline_num = 1075731652, op_array = 0x401e5cc4, jmp_addr = 0x401e5cc4, EA = {var = 1075731652, type = 4}}} and it goes on and on. ------------------------------------------------------------------------ [2003-02-18 16:45:11] White_Angel at gmx dot de Added: Must be a Problem in the Syntax Check because php -l in syntax check only crashes also. ------------------------------------------------------------------------ [2003-02-18 16:29:33] White_Angel at gmx dot de ups. ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at http://bugs.php.net/22284 -- Edit this bug report at http://bugs.php.net/?id=22284&edit=1