[php-src] Issue #10340: Assertion in zend_fiber_object_gc()

From: Date: Mon, 16 Jan 2023 13:52:51 +0000
Subject: [php-src] Issue #10340: Assertion in zend_fiber_object_gc()
Groups: php.bugs 
Request: Send a blank email to php-bugs+get-243461@lists.php.net to get a copy of this message
Issue: https://github.com/php/php-src/issues/10340
Author: dstogov

### Description

The following code:

```php
<?php
function f() {
    $$y = Fiber::getCurrent();
    Fiber::suspend();
}
$fiber = new Fiber(function() {
    get_defined_vars();
    f();
});
$fiber->start();
gc_collect_cycles();
?>
DONE
```

Resulted in this output:
```
DONE
```

But I expected this output instead:
```
Zend/zend_fibers.c:659: zend_fiber_object_gc: Assertion `zval_get_type(&(*(val))) == 12'
failed.
```

PHP creates IS_INDIRECT zvals to keep real zvals in CVs but have "pointers" in the symbol
table. However, it's possible to create a variable in symbol table without CV. (e.g using $$).
So variables don't have to be IS_INDIRECT. May be non IS_INDIRECT values should be just
skipped.

The bug was found by google oss-fuzz.

### PHP Version

PHP-8.1

### Operating System

*


Thread (1 message)

  • dstogov
« previous php.bugs (#243461) next »