Bug #72767 [Asn->Csd]: PHP Segfaults when trying to expand an infinite operator

From: Date: Fri, 05 Aug 2016 17:58:07 +0000
Subject: Bug #72767 [Asn->Csd]: PHP Segfaults when trying to expand an infinite operator
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-202972@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=72767&edit=1

 ID:                 72767
 Updated by:         nikic@php.net
 Reported by:        danack@php.net
 Summary:            PHP Segfaults when trying to expand an infinite
                     operator
-Status:             Assigned
+Status:             Closed
 Type:               Bug
 Package:            Scripting Engine problem
 PHP Version:        7.0.9
 Assigned To:        nikic
 Block user comment: N
 Private report:     N

 New Comment:

Automatic comment on behalf of nikic
Revision: http://git.php.net/?p=php-src.git;a=commit;h=807e81937b290ddb71152196aae3bbaca9a53c7e
Log: Fix bug #72767


Previous Comments:
------------------------------------------------------------------------
[2016-08-05 16:31:44] nikic@php.net

This is not just an infinite iterator issue, it's a problem occurring for sufficiently large
iterators. I think we forget to update vm_stack_top/end when switching stack frames.

------------------------------------------------------------------------
[2016-08-05 15:25:55] danack@php.net

Description:
------------
PHP Segfaults when trying to expand an infinite operator

Test script:
---------------
$iterator = new InfiniteIterator(new ArrayIterator([0, 1, 2, 3, 4]));
var_dump(...$iterator);

echo "Still alive!";

Expected result:
----------------
Something sensible, either the script aborting to lack of memory, or otherwise shutting down
cleanly.

Actual result:
--------------
Segfaults apparently https://3v4l.org/6IRrp/segfault#tabs

/usr/bin/php-7.0.0(zend_call_function+0x1c6)[0x72b196]
/usr/bin/php-7.0.0(zend_call_method+0x22e)[0x754f2e]
/usr/bin/php-7.0.0(zend_user_it_move_forward+0x37)[0x755457]
/usr/bin/php-7.0.0[0x7c5e8b]
/usr/bin/php-7.0.0(execute_ex+0x1b)[0x77617b]
/usr/bin/php-7.0.0(zend_execute+0x1a7)[0x7c7e37]
/usr/bin/php-7.0.0(zend_execute_scripts+0xb4)[0x739484]
/usr/bin/php-7.0.0(php_execute_script+0x280)[0x6dd2e0]
/usr/bin/php-7.0.0[0x7c9a54]
/usr/bin/php-7.0.0[0x434198]
/usr/lib/libc.so.6(__libc_start_main+0xf1)[0x7fd7c1dd2741]
/usr/bin/php-7.0.0(_start+0x29)[0x4342d9]


------------------------------------------------------------------------



--
Edit this bug report at https://bugs.php.net/bug.php?id=72767&edit=1


Thread (3 messages)

« previous php.bugs (#202972) next »