Skip to content

Fix GH-17773: Array element initialised by reference returned from a function - #23268

Open
matthiasgoergens wants to merge 3 commits into
php:masterfrom
matthiasgoergens:gh17773-array-ref-function-return
Open

Fix GH-17773: Array element initialised by reference returned from a function#23268
matthiasgoergens wants to merge 3 commits into
php:masterfrom
matthiasgoergens:gh17773-array-ref-function-return

Conversation

@matthiasgoergens

Copy link
Copy Markdown
Contributor

Initialising an array element with a reference returned by a function, e.g.
[&foo()], is rejected at compile time although ordinary reference assignment
accepts it. Allow user-function call results in this source position while
keeping the remaining source-side safeguards of reference assignment.

zend_may_throw_ex() reported ZEND_MAKE_REF as non-throwing, but with
ZEND_RETURNS_FUNCTION it raises an E_NOTICE that a userland error handler can
turn into an exception. The JIT then emitted no exception check after calling
the interpreter handler and continued with a corrupted instruction pointer,
writing wild VM state.
When the exception escapes uncaught, ZEND_HANDLE_EXCEPTION frees the throwing
opcode's result slot, which the handler had left uninitialised. Initialise it
with ZVAL_UNDEF() so the unwinder sees a defined zval.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant