From 157ccaf507b7a94c43db4ec1b7321aac5cc68e8b Mon Sep 17 00:00:00 2001 From: Xinchen Hui Date: Tue, 25 Jun 2013 13:47:50 +0800 Subject: [PATCH] Fixed bug #64827 Segfault in zval_mark_grey (zend_gc.c) I can not get a reproduce script since the context is very strict. Of course I will try to make one, but for now, I just commit this first. --- NEWS | 1 + ext/opcache/ZendAccelerator.c | 4 ++++ 2 files changed, 5 insertions(+) diff --git a/NEWS b/NEWS index ee3d858e69a..18eedd3f3e6 100644 --- a/NEWS +++ b/NEWS @@ -9,6 +9,7 @@ PHP NEWS (David Soria Parra, Laruence) - OPcache + . Fixed bug #64827 (Segfault in zval_mark_grey (zend_gc.c)). (Laruence) . OPcache must be compatible with LiteSpeed SAPI (Dmitry) - CLI server: diff --git a/ext/opcache/ZendAccelerator.c b/ext/opcache/ZendAccelerator.c index 4d983976bbd..efd902f4318 100644 --- a/ext/opcache/ZendAccelerator.c +++ b/ext/opcache/ZendAccelerator.c @@ -2163,7 +2163,10 @@ static void accel_fast_zval_ptr_dtor(zval **zval_ptr) case IS_CONSTANT_ARRAY: { TSRMLS_FETCH(); + GC_REMOVE_ZVAL_FROM_BUFFER(zvalue); if (zvalue->value.ht && (zvalue->value.ht != &EG(symbol_table))) { + /* break possible cycles */ + Z_TYPE_P(zvalue) = IS_NULL; zvalue->value.ht->pDestructor = (dtor_func_t)accel_fast_zval_ptr_dtor; accel_fast_hash_destroy(zvalue->value.ht); } @@ -2173,6 +2176,7 @@ static void accel_fast_zval_ptr_dtor(zval **zval_ptr) { TSRMLS_FETCH(); + GC_REMOVE_ZVAL_FROM_BUFFER(zvalue); Z_OBJ_HT_P(zvalue)->del_ref(zvalue TSRMLS_CC); } break;