Bug #80255 [Ver]: Opcache bug (bad condition result) in 8.0.0rc1

From: Date: Mon, 19 Oct 2020 12:39:27 +0000
Subject: Bug #80255 [Ver]: Opcache bug (bad condition result) in 8.0.0rc1
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-229742@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=80255&edit=1

 ID:                 80255
 Updated by:         nikic@php.net
 Reported by:        rixafy at gmail dot com
 Summary:            Opcache bug (bad condition result) in 8.0.0rc1
 Status:             Verified
 Type:               Bug
 Package:            opcache
 Operating System:   Ubuntu 20.04
 PHP Version:        8.0.0RC2
 Block user comment: N
 Private report:     N

 New Comment:

I have arrived at a similar reduction:

<?php
function test($a, $b, $c) {
    do {
        if ($a && !$b) {
            break;
        } else if ($b) {
            echo "foo\n";
        }
        echo "bar\n";
    } while ($c);
    echo "baz\n";
}
test(true, true, false);


Previous Comments:
------------------------------------------------------------------------
[2020-10-19 12:37:32] tekiela246 at gmail dot com

To ease with the debugging I have reduced the example to the following:
=================
<?php

echo '<pre>';
$tokens = [
    5 => ':',
    6 => 'bar',
    7 => ' ',
];

for ($pos = 5; $pos < 8; $pos++) {
    $t = $tokens[$pos];
    
    if ($t === ':') { // KeyValuePair separator
        echo 'Sep: ' . $pos . PHP_EOL;
        $hasKey = true;
    } elseif ($t[0] === " ") { // Indent
        echo 'Indent: ' . $pos . PHP_EOL;

        if ($hasValue && !$hasKey) {
        } elseif ($hasKey) {
            $hasKey = $hasValue = false;
        }
    } else { // Value
        echo 'Val: ' . $pos . PHP_EOL;
        $hasValue = true;
    }
}

echo 'Return: ' . $pos . PHP_EOL;
=====================
Expected:
Sep: 5
Val: 6
Indent: 7
Return: 8
====================
With OPCache enabled this will go into infinite loop. 
I have also made a slightly different test case https://pastebin.com/sCbzpQ5D 
This one repeats loop no. 7 twice

------------------------------------------------------------------------
[2020-10-19 09:01:36] nikic@php.net

Confirming that this reproduces on current PHP-8.0 HEAD.

------------------------------------------------------------------------
[2020-10-18 19:23:05] rixafy at gmail dot com

Description:
------------
I didn't manage to isolate the bug from that package, I provided also html stacktrace in
repository and description in readme.

It seems like some condition is behaving differently when opcache is enabled, condition passed, but
there is no way this condition would even be executed, because condition above (same condition -
strlen($newIndent) > strlen($indent)) cannot pass.

Test script:
---------------
https://github.com/Rixafy/php8.0.0-rc1-opcache-bug



------------------------------------------------------------------------



--
Edit this bug report at https://bugs.php.net/bug.php?id=80255&edit=1


Thread (6 messages)

« previous php.bugs (#229742) next »