Bug #78502 [Asn->Csd]: Incorrect stack size calculation for indirectly recursive function call

From: Date: Fri, 06 Sep 2019 09:33:53 +0000
Subject: Bug #78502 [Asn->Csd]: Incorrect stack size calculation for indirectly recursive function call
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-222600@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=78502&edit=1 ID: 78502 Updated by: nikic@php.net Reported by: phofstetter at sensational dot ch Summary: Incorrect stack size calculation for indirectly recursive function call -Status: Assigned +Status: Closed Type: Bug Package: Scripting Engine problem Operating System: macos 10.14, Debian 10 PHP Version: 7.4.0RC1 Assigned To: nikic Block user comment: N Private report: N New Comment: Automatic comment on behalf of nikita.ppv@gmail.com Revision: http://git.php.net/?p=php-src.git;a=commit;h=e81751ceacf79e2e21b48a12dcbe38c16f98b7da Log: Fixed bug #78502 Previous Comments: ------------------------------------------------------------------------ [2019-09-06 09:00:36] nikic@php.net @phofstetter: That commit is indeed relevant, because it changed the registration of the function to happen when we start to compile the function, rather than once it has been fully compiled. That means that stack size calculations end up being performed on a partially compiled function if it is called recursively. ------------------------------------------------------------------------ [2019-09-06 08:53:22] nikic@php.net I think the issue is an incorrect calculation of the VM stack size for one of the tree_map calls: L3 (17): INIT_FCALL 3 176 string("tree_map") The size is 11*16, which it should be 14*16. ------------------------------------------------------------------------ [2019-09-06 08:46:33] phofstetter at sensational dot ch I have bisected the issue and found b36dbdd1dd431d1a21fdb6f2508c7c41b682466c to be the culprit. I tried to naïvely just revert that one commit, but of course other changes happened since then and I'm definitely not good enough to deal with the internals at this level in order to fix the ensuing conflicts. ------------------------------------------------------------------------ [2019-09-06 08:05:54] nikic@php.net Looks like an icall retval slot ends up pointing into the execute_data frame and clobbers func. ------------------------------------------------------------------------ [2019-09-06 06:45:39] phofstetter at sensational dot ch one last update: This happens independently of whether opcache is loaded or not. ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=78502 -- Edit this bug report at https://bugs.php.net/bug.php?id=78502&edit=1

« previous php.bugs (#222600) next »