Bug #74157 [Opn->Fbk]: Segfault with nested generators
| From: | laruence@php.net | Date: | Fri, 24 Feb 2017 06:57:32 +0000 |
| Subject: | Bug #74157 [Opn->Fbk]: Segfault with nested generators | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-207539@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=74157&edit=1
ID: 74157
Updated by: laruence@php.net
Reported by: tom at inflatablecookie dot com
Summary: Segfault with nested generators
-Status: Open
+Status: Feedback
Type: Bug
Package: opcache
Operating System: OSX Sierra 10.12.3
PHP Version: 7.1.2
Block user comment: N
Private report: N
New Comment:
Thank you for this bug report. To properly diagnose the problem, we
need a short but complete example script to be able to reproduce
this bug ourselves.
A proper reproducing script starts with <?php and ends with ?>,
is max. 10-20 lines long and does not require any external
resources such as databases, etc. If the script requires a
database to demonstrate the issue, please make sure it creates
all necessary tables, stored procedures etc.
Please avoid embedding huge scripts into the report.
Previous Comments:
------------------------------------------------------------------------
[2017-02-23 20:17:20] tom at inflatablecookie dot com
Description:
------------
Upgrading to 7.1.2 has introduced a regular segfault when using nested generators - I'm
assuming it was introduced with the following from the changelog:
-Improved GENERATOR_CREATE opcode handler.
This happens regardless of platform (tested on OSX Sierra and Ubuntu), and regardless of extensions
enabled (still occurs with all available extensions disabled).
As of now, I'm struggling to come up with a decent test script as the real-world scenario
leverages a significant amount of user code, however the segfault always occurs upon entry to a
generator function called after a certain number of nested generators have successfully run.
I'll update once I can replicate in a simple test environment.
The basic premise of the code is to generate html tags - the tag object takes a generator as
argument which yields string or object contents, which generally includes more tag objects with
their own generator, etc.
Actual result:
--------------
Here's the backtrace (from OSX console)
0 0x000000010754cb01 zend_generator_close + 326
1 0x00000001075a9e90 ZEND_GENERATOR_RETURN_SPEC_CONST_HANDLER + 51
2 0x0000000107561d3e execute_ex + 44
3 0x000000010754d3b5 zend_generator_resume + 377
4 0x000000010757e877 ZEND_FE_FETCH_R_SPEC_VAR_HANDLER + 346
5 0x0000000107561d3e execute_ex + 44
6 0x00000001075157d4 zend_call_function + 1468
7 0x000000010753f7ad zend_call_method + 581
8 0x000000010755a3b7 zend_std_cast_object_tostring + 314
9 0x000000010751acb1 _zval_get_string_func + 381
10 0x00000001075724e0 ZEND_ECHO_SPEC_TMPVAR_HANDLER + 69
11 0x0000000107561d3e execute_ex + 44
12 0x0000000107561fb6 zend_execute + 551
13 0x0000000107523e94 zend_execute_scripts + 299
14 0x00000001074cb7e8 php_execute_script + 804
15 0x00000001075c9582 main + 6286
16 0x00007fff98117255 start + 1
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=74157&edit=1