Skip to content

Commit 9a093e7

Browse files
committed
Merge branch 'PHP-8.3' into PHP-8.4
* PHP-8.3: Fix propagation of ZEND_ACC_RETURN_REFERENCE for call trampoline
2 parents 64081d1 + 5eddcb3 commit 9a093e7

File tree

4 files changed

+23
-2
lines changed

4 files changed

+23
-2
lines changed

NEWS

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -19,6 +19,8 @@ PHP NEWS
1919
(ilutov)
2020
. Fixed bug OSS-Fuzz #71407 (Null-dereference WRITE in
2121
zend_lazy_object_clone). (Arnaud)
22+
. Fixed bug GH-16515 (Incorrect propagation of ZEND_ACC_RETURN_REFERENCE for
23+
call trampoline). (ilutov)
2224

2325
- Curl:
2426
. Fixed bug GH-16302 (CurlMultiHandle holds a reference to CurlHandle if

Zend/tests/gh16515.phpt

Lines changed: 16 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,16 @@
1+
--TEST--
2+
GH-16515: Incorrect propagation of ZEND_ACC_RETURN_REFERENCE for call trampoline
3+
--FILE--
4+
<?php
5+
6+
namespace Foo;
7+
8+
class Foo {
9+
public function &__call($method, $args) {}
10+
}
11+
12+
call_user_func((new Foo)->bar(...));
13+
14+
?>
15+
--EXPECTF--
16+
Notice: Only variable references should be returned by reference in %s on line %d

Zend/zend_closures.c

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -871,7 +871,7 @@ void zend_closure_from_frame(zval *return_value, zend_execute_data *call) { /* {
871871

872872
memset(&trampoline, 0, sizeof(zend_internal_function));
873873
trampoline.type = ZEND_INTERNAL_FUNCTION;
874-
trampoline.fn_flags = mptr->common.fn_flags & (ZEND_ACC_STATIC | ZEND_ACC_VARIADIC);
874+
trampoline.fn_flags = mptr->common.fn_flags & (ZEND_ACC_STATIC | ZEND_ACC_VARIADIC | ZEND_ACC_RETURN_REFERENCE);
875875
trampoline.handler = zend_closure_call_magic;
876876
trampoline.function_name = mptr->common.function_name;
877877
trampoline.scope = mptr->common.scope;

Zend/zend_object_handlers.c

Lines changed: 4 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1614,7 +1614,10 @@ ZEND_API zend_function *zend_get_call_trampoline_func(const zend_class_entry *ce
16141614
func->arg_flags[0] = 0;
16151615
func->arg_flags[1] = 0;
16161616
func->arg_flags[2] = 0;
1617-
func->fn_flags = ZEND_ACC_CALL_VIA_TRAMPOLINE | ZEND_ACC_PUBLIC | ZEND_ACC_VARIADIC;
1617+
func->fn_flags = ZEND_ACC_CALL_VIA_TRAMPOLINE
1618+
| ZEND_ACC_PUBLIC
1619+
| ZEND_ACC_VARIADIC
1620+
| (fbc->common.fn_flags & ZEND_ACC_RETURN_REFERENCE);
16181621
if (is_static) {
16191622
func->fn_flags |= ZEND_ACC_STATIC;
16201623
}

0 commit comments

Comments
 (0)