Edit report at https://bugs.php.net/bug.php?id=65784&edit=1
ID: 65784
Comment by: crussell52 at gmail dot com
Reported by: r dot wilczek at web-appz dot de
Summary: Segfault with finally
Status: Open
Type: Bug
Package: *General Issues
Operating System: Linux
PHP Version: 5.5.4
Block user comment: N
Private report: N
New Comment:
The following script in php 5.5.5 demonstrates this problem.
Note, my testing indicates that all of these conditions must be true:
1. Exception is thrown in try block.
2. An Exception is thrown AND handled during execution of
the corresponding finally block.
3. The return value must be referenced.
-----------------
class Executor
{
public function go()
{
try
{
// 1. Throw exception in try block.
throw new Exception("Failed to do something!");
return true;
}
finally
{
// 2. Throw and handle exception within finally block.
// Note, this step could occur in a function/method which
// is called within the finally block.
try
{
throw new Exception("Failed to clean up.");
}
catch (Exception $E) { /* Ignore */ }
}
}
}
$Executor = new Executor();
// 3. Reference the return value.
$value = $Executor->go();
-----------------
#3 is interesting and threw me off a bit while trying to come up
with a reproduction script. See the following variations and
outcome:
$value = $Executor->go(); // fail
echo $Executor->go(); // fail
$Executor->go(); // success
Previous Comments:
------------------------------------------------------------------------
[2013-10-15 11:54:52] php-bugs at lists dot php dot net
No feedback was provided. The bug is being suspended because
we assume that you are no longer experiencing the problem.
If this is not the case and you are able to provide the
information that was requested earlier, please do so and
change the status of the bug back to "Re-Opened". Thank you.
------------------------------------------------------------------------
[2013-10-03 11:53:28] r dot wilczek at web-appz dot de
Here you are ...
/* @var $sql string */
/* @var $expr SomeInterface */
/* @var $ctxt AnotherInterface */
$trx = $this->ctxt->beginTransaction(); // an interface
$memento = $this->ctxt->getMemento(); // can be anything
try {
$this->ctxt->persist(); // don't return or throw exception
return $this->execute($expr, $sql); // return scalar[] or throw exception
} finally {
$this->ctxt->setMemento($memento); // don't return or throw exception
$trx->rollback(); // don't return or throw exception
}
Don't know, if this helps.
What I forgot to mention was, that the segfault occurs, when there is an exception thrown from
within the try-block.
------------------------------------------------------------------------
[2013-10-01 22:58:15] nikic@php.net
Could you please post the code as it is actually used (just the part containing the finally)? Your
backtrace indicates that the segfault happens during an argument send, but your code samples do not
include any function calls with arguments.
------------------------------------------------------------------------
[2013-09-29 12:26:34] r dot wilczek at web-appz dot de
(The second core-dump is created without xdebug, to keep things simple)
------------------------------------------------------------------------
[2013-09-29 12:25:34] r dot wilczek at web-appz dot de
#0 0x0000000000a41895 in zval_delref_p (pz=0x0) at /root/php-5.5.4/php-5.5.4/Zend/zend.h:409
#1 0x0000000000a4330c in zend_pzval_unlock_func (z=0x0, should_free=0x7fffa8aa9e90, unref=1) at
/root/php-5.5.4/php-5.5.4/Zend/zend_execute.c:72
#2 0x0000000000a4341b in _get_zval_ptr_var (var=4294967232, execute_data=0x7f1fceaa5098,
should_free=0x7fffa8aa9e90) at /root/php-5.5.4/php-5.5.4/Zend/zend_execute.c:186
#3 0x0000000000a63e15 in ZEND_SEND_VAR_NO_REF_SPEC_VAR_HANDLER (execute_data=0x7f1fceaa5098) at
/root/php-5.5.4/php-5.5.4/Zend/zend_vm_execute.h:13081
#4 0x0000000000a480cf in execute_ex (execute_data=0x7f1fceaa5098) at
/root/php-5.5.4/php-5.5.4/Zend/zend_vm_execute.h:363
#5 0x0000000000a48157 in zend_execute (op_array=0x2e129f0) at
/root/php-5.5.4/php-5.5.4/Zend/zend_vm_execute.h:388
#6 0x00000000009f6785 in zend_call_function (fci=0x7fffa8aaa100, fci_cache=0x7fffa8aaa0d0) at
/root/php-5.5.4/php-5.5.4/Zend/zend_execute_API.c:939
#7 0x000000000076285c in zim_reflection_method_invokeArgs (ht=2, return_value=0x2e3b2d0,
return_value_ptr=0x0, this_ptr=0x2e3b450, return_value_used=1)
at /root/php-5.5.4/php-5.5.4/ext/reflection/php_reflection.c:3018
#8 0x0000000000a489de in zend_do_fcall_common_helper_SPEC (execute_data=0x7f1fceaa49e8) at
/root/php-5.5.4/php-5.5.4/Zend/zend_vm_execute.h:550
#9 0x0000000000a491b0 in ZEND_DO_FCALL_BY_NAME_SPEC_HANDLER (execute_data=0x7f1fceaa49e8) at
/root/php-5.5.4/php-5.5.4/Zend/zend_vm_execute.h:685
#10 0x0000000000a480cf in execute_ex (execute_data=0x7f1fceaa49e8) at
/root/php-5.5.4/php-5.5.4/Zend/zend_vm_execute.h:363
#11 0x0000000000a48157 in zend_execute (op_array=0x7f1fcead9b60) at
/root/php-5.5.4/php-5.5.4/Zend/zend_vm_execute.h:388
#12 0x0000000000a0a27f in zend_execute_scripts (type=8, retval=0x0, file_count=3) at
/root/php-5.5.4/php-5.5.4/Zend/zend.c:1318
#13 0x0000000000976e9e in php_execute_script (primary_file=0x7fffa8aad7a0) at
/root/php-5.5.4/php-5.5.4/main/main.c:2489
#14 0x0000000000ab7ac7 in do_cli (argc=5, argv=0x263beb0) at
/root/php-5.5.4/php-5.5.4/sapi/cli/php_cli.c:994
#15 0x0000000000ab8bff in main (argc=5, argv=0x263beb0) at
/root/php-5.5.4/php-5.5.4/sapi/cli/php_cli.c:1378
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=65784--
Edit this bug report at https://bugs.php.net/bug.php?id=65784&edit=1