Bug #68775 [Asn->Csd]: yield in a function argument crashes or loops indefinitely

From: Date: Fri, 09 Jan 2015 16:59:52 +0000
Subject: Bug #68775 [Asn->Csd]: yield in a function argument crashes or loops indefinitely
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-189847@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=68775&edit=1 ID: 68775 Updated by: nikic@php.net Reported by: bwoebi@php.net Summary: yield in a function argument crashes or loops indefinitely -Status: Assigned +Status: Closed Type: Bug Package: Reproducible crash Operating System: Irrelevant PHP Version: master-Git-2015-01-09 (Git) Assigned To: nikic Block user comment: N Private report: N New Comment: Automatic comment on behalf of nikic Revision: http://git.php.net/?p=php-src.git;a=commit;h=41a249fef602b8cbfdc70fc8179e48cc1387b821 Log: Fix bug #68775 Previous Comments: ------------------------------------------------------------------------ [2015-01-09 09:35:08] bwoebi@php.net Description: ------------ Variants of that code (dependent on where execute_data->prev_execute_data is first needed) may also crash. My longer analysis resumed: EG(vm_stack_top) is reset to generator->stack->top in the next resume after zend_vm_stack_push_call_frame was called in the ZEND_INIT_FCALL_BY_NAME, that stack frame is now equal to EG(vm_stack_top), which is then returned in the next stack frame allocation (the var_dump one in the example) and prev_execute_data is set there to the address of the stack frame itself. Adding generator->stack->top = EG(vm_stack_top); on line 330 of zend_generators.c fixed the bug for me, but not sure if that's safe... Test script: --------------- function a($x) { var_dump($x); } function gen() { a(yield); } $g = gen(); $g->send(1); Expected result: ---------------- int(1) Actual result: -------------- Infinite loop: execute_data->prev_execute_data == execute_data ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=68775&edit=1

« previous php.bugs (#189847) next »