Bug #68775 [Asn->Csd]: yield in a function argument crashes or loops indefinitely
| From: | nikic@php.net | Date: | Fri, 09 Jan 2015 16:59:52 +0000 |
| Subject: | Bug #68775 [Asn->Csd]: yield in a function argument crashes or loops indefinitely | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-189847@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=68775&edit=1
ID: 68775
Updated by: nikic@php.net
Reported by: bwoebi@php.net
Summary: yield in a function argument crashes or loops
indefinitely
-Status: Assigned
+Status: Closed
Type: Bug
Package: Reproducible crash
Operating System: Irrelevant
PHP Version: master-Git-2015-01-09 (Git)
Assigned To: nikic
Block user comment: N
Private report: N
New Comment:
Automatic comment on behalf of nikic
Revision: http://git.php.net/?p=php-src.git;a=commit;h=41a249fef602b8cbfdc70fc8179e48cc1387b821
Log: Fix bug #68775
Previous Comments:
------------------------------------------------------------------------
[2015-01-09 09:35:08] bwoebi@php.net
Description:
------------
Variants of that code (dependent on where execute_data->prev_execute_data is first needed) may
also crash.
My longer analysis resumed:
EG(vm_stack_top) is reset to generator->stack->top in the next resume after
zend_vm_stack_push_call_frame was called in the ZEND_INIT_FCALL_BY_NAME, that stack frame is now
equal to EG(vm_stack_top), which is then returned in the next stack frame allocation (the var_dump
one in the example) and prev_execute_data is set there to the address of the stack frame itself.
Adding generator->stack->top = EG(vm_stack_top); on line 330 of zend_generators.c fixed the
bug for me, but not sure if that's safe...
Test script:
---------------
function a($x) {
var_dump($x);
}
function gen() {
a(yield);
}
$g = gen();
$g->send(1);
Expected result:
----------------
int(1)
Actual result:
--------------
Infinite loop: execute_data->prev_execute_data == execute_data
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=68775&edit=1