diff --git a/Zend/tests/gh20183_001.phpt b/Zend/tests/gh20183_001.phpt new file mode 100644 index 000000000000..354929efbbfb --- /dev/null +++ b/Zend/tests/gh20183_001.phpt @@ -0,0 +1,22 @@ +--TEST-- +GH-20183: Stale EG(opline_before_exception) pointer through eval +--FILE-- + +--EXPECTF-- +#0 %s(10): A->__destruct() + +Fatal error: Uncaught Error: Class "B" not found in %s:10 +Stack trace: +#0 {main} + thrown in %s on line 10 diff --git a/Zend/tests/gh20183_002.phpt b/Zend/tests/gh20183_002.phpt new file mode 100644 index 000000000000..ec4d62d0960d --- /dev/null +++ b/Zend/tests/gh20183_002.phpt @@ -0,0 +1,34 @@ +--TEST-- +GH-20183: Stale EG(opline_before_exception) pointer through eval +--CREDITS-- +Arnaud Le Blanc +--FILE-- +gen = gen(); + $this->gen->rewind(); + } +} + +B::$a = new A(); + +?> +--EXPECTF-- +#0 %s(20): gen() + +Fatal error: Uncaught Error: Class "B" not found in %s:20 +Stack trace: +#0 {main} + thrown in %s on line 20 diff --git a/Zend/zend_generators.c b/Zend/zend_generators.c index eeab16b9a135..84b40cfdc21a 100644 --- a/Zend/zend_generators.c +++ b/Zend/zend_generators.c @@ -317,9 +317,16 @@ static void zend_generator_dtor_storage(zend_object *object) /* {{{ */ ZEND_CALL_VAR(ex, ex->func->op_array.opcodes[try_catch->finally_end].op1.var); zend_generator_cleanup_unfinished_execution(generator, ex, try_catch->finally_op); - zend_object *old_exception = EG(exception); - const zend_op *old_opline_before_exception = EG(opline_before_exception); - EG(exception) = NULL; + + zend_object *old_exception = NULL; + const zend_op *old_opline_before_exception = NULL; + if (EG(exception)) { + EG(current_execute_data)->opline = EG(opline_before_exception); + old_exception = EG(exception); + old_opline_before_exception = EG(opline_before_exception); + EG(exception) = NULL; + } + Z_OBJ_P(fast_call) = NULL; Z_OPLINE_NUM_P(fast_call) = (uint32_t)-1; @@ -328,6 +335,7 @@ static void zend_generator_dtor_storage(zend_object *object) /* {{{ */ zend_generator_resume(generator); if (old_exception) { + EG(current_execute_data)->opline = EG(exception_op); EG(opline_before_exception) = old_opline_before_exception; if (EG(exception)) { zend_exception_set_previous(EG(exception), old_exception); diff --git a/Zend/zend_objects.c b/Zend/zend_objects.c index af4d1f265897..30ea22c8de44 100644 --- a/Zend/zend_objects.c +++ b/Zend/zend_objects.c @@ -164,6 +164,7 @@ ZEND_API void zend_objects_destroy_object(zend_object *object) && ZEND_USER_CODE(EG(current_execute_data)->func->common.type)) { zend_rethrow_exception(EG(current_execute_data)); } + EG(current_execute_data)->opline = EG(opline_before_exception); old_exception = EG(exception); old_opline_before_exception = EG(opline_before_exception); EG(exception) = NULL; @@ -173,6 +174,7 @@ ZEND_API void zend_objects_destroy_object(zend_object *object) zend_call_known_instance_method_with_0_params(destructor, object, NULL); if (old_exception) { + EG(current_execute_data)->opline = EG(exception_op); EG(opline_before_exception) = old_opline_before_exception; if (EG(exception)) { zend_exception_set_previous(EG(exception), old_exception);