Bug #78502 [Asn->Csd]: Incorrect stack size calculation for indirectly recursive function call
| From: | nikic@php.net | Date: | Fri, 06 Sep 2019 09:33:53 +0000 |
| Subject: | Bug #78502 [Asn->Csd]: Incorrect stack size calculation for indirectly recursive function call | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-222600@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=78502&edit=1
ID: 78502
Updated by: nikic@php.net
Reported by: phofstetter at sensational dot ch
Summary: Incorrect stack size calculation for indirectly
recursive function call
-Status: Assigned
+Status: Closed
Type: Bug
Package: Scripting Engine problem
Operating System: macos 10.14, Debian 10
PHP Version: 7.4.0RC1
Assigned To: nikic
Block user comment: N
Private report: N
New Comment:
Automatic comment on behalf of nikita.ppv@gmail.com
Revision: http://git.php.net/?p=php-src.git;a=commit;h=e81751ceacf79e2e21b48a12dcbe38c16f98b7da
Log: Fixed bug #78502
Previous Comments:
------------------------------------------------------------------------
[2019-09-06 09:00:36] nikic@php.net
@phofstetter: That commit is indeed relevant, because it changed the registration of the function to
happen when we start to compile the function, rather than once it has been fully compiled. That
means that stack size calculations end up being performed on a partially compiled function if it is
called recursively.
------------------------------------------------------------------------
[2019-09-06 08:53:22] nikic@php.net
I think the issue is an incorrect calculation of the VM stack size for one of the tree_map calls:
L3 (17): INIT_FCALL 3 176 string("tree_map")
The size is 11*16, which it should be 14*16.
------------------------------------------------------------------------
[2019-09-06 08:46:33] phofstetter at sensational dot ch
I have bisected the issue and found
b36dbdd1dd431d1a21fdb6f2508c7c41b682466c
to be the culprit. I tried to naïvely just revert that one commit, but of course other changes
happened since then and I'm definitely not good enough to deal with the internals at this level
in order to fix the ensuing conflicts.
------------------------------------------------------------------------
[2019-09-06 08:05:54] nikic@php.net
Looks like an icall retval slot ends up pointing into the execute_data frame and clobbers func.
------------------------------------------------------------------------
[2019-09-06 06:45:39] phofstetter at sensational dot ch
one last update: This happens independently of whether opcache is loaded or not.
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=78502
--
Edit this bug report at https://bugs.php.net/bug.php?id=78502&edit=1