Bug #71133 [Opn->Ver]: segfault on exception from generator

From: Date: Wed, 16 Dec 2015 21:49:54 +0000
Subject: Bug #71133 [Opn->Ver]: segfault on exception from generator
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-197941@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=71133&edit=1 ID: 71133 Updated by: stas@php.net Reported by: Bernhard dot Liebl at rz dot uni-regensburg dot de Summary: segfault on exception from generator -Status: Open +Status: Verified Type: Bug Package: Scripting Engine problem Operating System: Linux PHP Version: 5.6.16 Block user comment: N Private report: N Previous Comments: ------------------------------------------------------------------------ [2015-12-16 21:49:39] stas@php.net Reproduces for me on 5.6: 0x00000001006935c8 in gc_zval_possible_root (zv=0x102e9f8e8) at /Users/smalyshev/php-5.6/Zend/zend_gc.c:143 143 GC_ZOBJ_CHECK_POSSIBLE_ROOT(zv); (gdb) bt #0 0x00000001006935c8 in gc_zval_possible_root (zv=0x102e9f8e8) at /Users/smalyshev/php-5.6/Zend/zend_gc.c:143 #1 0x000000010074ff65 in gc_zval_check_possible_root (z=0x102e9f8e8) at /Users/smalyshev/php-5.6/Zend/zend_gc.h:183 #2 i_zval_ptr_dtor (zval_ptr=<optimized out>, zval_ptr=<optimized out>) at /Users/smalyshev/php-5.6/Zend/zend_execute.h:86 #3 ZEND_HANDLE_EXCEPTION_SPEC_HANDLER (execute_data=0x102e69370) at /Users/smalyshev/php-5.6/Zend/zend_vm_execute.h:1240 #4 0x00000001006addb1 in execute_ex (execute_data=0x102e69370) at /Users/smalyshev/php-5.6/Zend/zend_vm_execute.h:363 #5 0x00000001006ae8a8 in zend_execute (op_array=0x102e9e490) at /Users/smalyshev/php-5.6/Zend/zend_vm_execute.h:388 #6 0x0000000100662064 in zend_execute_scripts (type=8, retval=0x0, file_count=3) at /Users/smalyshev/php-5.6/Zend/zend.c:1341 #7 0x00000001005b5849 in php_execute_script (primary_file=0x7fff5fbfee10) at /Users/smalyshev/php-5.6/main/main.c:2597 #8 0x00000001007b4a03 in do_cli (argc=2, argv=0x103800cb0) at /Users/smalyshev/php-5.6/sapi/cli/php_cli.c:994 #9 0x00000001007b3773 in main (argc=2, argv=0x103800cb0) at /Users/smalyshev/php-5.6/sapi/cli/php_cli.c:1378 ------------------------------------------------------------------------ [2015-12-16 15:08:37] laruence@php.net I can not reproduce this on Ubuntu (valgrind also clean) ------------------------------------------------------------------------ [2015-12-16 09:08:03] Bernhard dot Liebl at rz dot uni-regensburg dot de Test on my local installation: $ php -n coredump.php starting 5.5.9-1ubuntu4.14 Segmentation fault (core dumped) Also happens with php -n on clean docker images php:5.5-cli (5.5.30) and php:5.6-cli (5.6.16). ------------------------------------------------------------------------ [2015-12-16 08:21:39] laruence@php.net could you try to test agian by "php -n" , which will disable all other third-part extensions. ------------------------------------------------------------------------ [2015-12-16 07:49:30] Bernhard dot Liebl at rz dot uni-regensburg dot de Description: ------------ Throwing an exception from a generator under certain conditions produces a segfault. Happens with php 5.5.9 and php 5.6.16. Seems to be fixed with php 7. Test script: --------------- <?php $a = function() { try { yield 1; } finally { throw new Exception(); } }; $b = function() { yield 1; }; echo "starting " . phpversion() . "\n"; try { foreach ($a() as $x) { foreach ($b() as $y) { return true; } } } catch (Exception $e) { echo "caught exception.\n"; } echo "exit.\n"; Expected result: ---------------- starting 7.0.0 caught exception. exit. Actual result: -------------- OUTPUT: starting 5.6.16 COREDUMPS THEN BACKTRACE: Program received signal SIGSEGV, Segmentation fault. 0x000000000070d359 in gc_zval_possible_root () (gdb) bt #0 0x000000000070d359 in gc_zval_possible_root () #1 0x000000000079b287 in ?? () #2 0x0000000000717e28 in execute_ex () #3 0x00000000006ddf89 in dtrace_execute_ex () #4 0x00000000006efa10 in zend_execute_scripts () #5 0x000000000068f845 in php_execute_script () #6 0x00000000007a00ce in ?? () #7 0x0000000000461d90 in main () ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=71133&edit=1

« previous php.bugs (#197941) next »