Bug #71133 [Ver]: segfault on exception from generator

From: Date: Fri, 18 Dec 2015 07:40:29 +0000
Subject: Bug #71133 [Ver]: segfault on exception from generator
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-197987@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=71133&edit=1

 ID:                 71133
 Updated by:         laruence@php.net
 Reported by:        Bernhard dot Liebl at rz dot uni-regensburg dot de
 Summary:            segfault on exception from generator
 Status:             Verified
 Type:               Bug
 Package:            Scripting Engine problem
 Operating System:   Linux
 PHP Version:        5.6.16
-Assigned To:        
+Assigned To:        laruence
 Block user comment: N
 Private report:     N

 New Comment:

I can reproduce this now.

however this is somehow a knew issue.... :<


Previous Comments:
------------------------------------------------------------------------
[2015-12-16 21:49:39] stas@php.net

Reproduces for me on 5.6:

0x00000001006935c8 in gc_zval_possible_root (zv=0x102e9f8e8) at
/Users/smalyshev/php-5.6/Zend/zend_gc.c:143
143			GC_ZOBJ_CHECK_POSSIBLE_ROOT(zv);
(gdb) bt
#0  0x00000001006935c8 in gc_zval_possible_root (zv=0x102e9f8e8) at
/Users/smalyshev/php-5.6/Zend/zend_gc.c:143
#1  0x000000010074ff65 in gc_zval_check_possible_root (z=0x102e9f8e8) at
/Users/smalyshev/php-5.6/Zend/zend_gc.h:183
#2  i_zval_ptr_dtor (zval_ptr=<optimized out>, zval_ptr=<optimized out>) at
/Users/smalyshev/php-5.6/Zend/zend_execute.h:86
#3  ZEND_HANDLE_EXCEPTION_SPEC_HANDLER (execute_data=0x102e69370) at
/Users/smalyshev/php-5.6/Zend/zend_vm_execute.h:1240
#4  0x00000001006addb1 in execute_ex (execute_data=0x102e69370) at
/Users/smalyshev/php-5.6/Zend/zend_vm_execute.h:363
#5  0x00000001006ae8a8 in zend_execute (op_array=0x102e9e490) at
/Users/smalyshev/php-5.6/Zend/zend_vm_execute.h:388
#6  0x0000000100662064 in zend_execute_scripts (type=8, retval=0x0, file_count=3) at
/Users/smalyshev/php-5.6/Zend/zend.c:1341
#7  0x00000001005b5849 in php_execute_script (primary_file=0x7fff5fbfee10) at
/Users/smalyshev/php-5.6/main/main.c:2597
#8  0x00000001007b4a03 in do_cli (argc=2, argv=0x103800cb0) at
/Users/smalyshev/php-5.6/sapi/cli/php_cli.c:994
#9  0x00000001007b3773 in main (argc=2, argv=0x103800cb0) at
/Users/smalyshev/php-5.6/sapi/cli/php_cli.c:1378

------------------------------------------------------------------------
[2015-12-16 15:08:37] laruence@php.net

I can not reproduce this on Ubuntu (valgrind also clean)

------------------------------------------------------------------------
[2015-12-16 09:08:03] Bernhard dot Liebl at rz dot uni-regensburg dot de

Test on my local installation:

$ php -n coredump.php
starting 5.5.9-1ubuntu4.14
Segmentation fault (core dumped)

Also happens with php -n on clean docker images php:5.5-cli (5.5.30) and php:5.6-cli (5.6.16).

------------------------------------------------------------------------
[2015-12-16 08:21:39] laruence@php.net

could you try to test agian by "php -n" , which will disable all other third-part
extensions.

------------------------------------------------------------------------
[2015-12-16 07:49:30] Bernhard dot Liebl at rz dot uni-regensburg dot de

Description:
------------
Throwing an exception from a generator under certain conditions produces a segfault. Happens with
php 5.5.9 and php 5.6.16. Seems to be fixed with php 7.

Test script:
---------------
<?php

$a = function() {
    try {
        yield 1;
    } finally {
        throw new Exception();
    }
};

$b = function() {
    yield 1;
};

echo "starting " . phpversion() . "\n";
try {
    foreach ($a() as $x) {
        foreach ($b() as $y) {
            return true;
        }
    }
} catch (Exception $e) {
    echo "caught exception.\n";
}
echo "exit.\n";

Expected result:
----------------
starting 7.0.0
caught exception.
exit.

Actual result:
--------------
OUTPUT:
starting 5.6.16

COREDUMPS THEN
BACKTRACE:

Program received signal SIGSEGV, Segmentation fault.
0x000000000070d359 in gc_zval_possible_root ()
(gdb) bt
#0  0x000000000070d359 in gc_zval_possible_root ()
#1  0x000000000079b287 in ?? ()
#2  0x0000000000717e28 in execute_ex ()
#3  0x00000000006ddf89 in dtrace_execute_ex ()
#4  0x00000000006efa10 in zend_execute_scripts ()
#5  0x000000000068f845 in php_execute_script ()
#6  0x00000000007a00ce in ?? ()
#7  0x0000000000461d90 in main ()



------------------------------------------------------------------------



--
Edit this bug report at https://bugs.php.net/bug.php?id=71133&edit=1


Thread (1 message)

  • laruence@php.net
  • Unknown Message
    • laruence@php.net
« previous php.bugs (#197987) next »