File tree Expand file tree Collapse file tree 2 files changed +36
-0
lines changed Expand file tree Collapse file tree 2 files changed +36
-0
lines changed Original file line number Diff line number Diff line change
1
+ --TEST--
2
+ GH-18736: Circumvented type check with return by ref + finally
3
+ --FILE--
4
+ <?php
5
+
6
+ function &test (): int {
7
+ $ x = 0 ;
8
+ try {
9
+ return $ x ;
10
+ } finally {
11
+ $ x = 'test ' ;
12
+ }
13
+ }
14
+
15
+ try {
16
+ $ x = &test ();
17
+ var_dump ($ x );
18
+ } catch (Error $ e ) {
19
+ echo $ e ->getMessage (), "\n" ;
20
+ }
21
+
22
+ ?>
23
+ --EXPECT--
24
+ test(): Return value must be of type int, string returned
Original file line number Diff line number Diff line change @@ -5699,8 +5699,20 @@ static void zend_compile_return(zend_ast *ast) /* {{{ */
5699
5699
expr_ast ? & expr_node : NULL , CG (active_op_array )-> arg_info - 1 , 0 );
5700
5700
}
5701
5701
5702
+ uint32_t opnum_before_finally = get_next_op_number ();
5703
+
5702
5704
zend_handle_loops_and_finally ((expr_node .op_type & (IS_TMP_VAR | IS_VAR )) ? & expr_node : NULL );
5703
5705
5706
+ /* Content of reference might have changed in finally, repeat type check. */
5707
+ if (by_ref
5708
+ /* Check if any opcodes were emitted since the last return type check. */
5709
+ && opnum_before_finally != get_next_op_number ()
5710
+ && !is_generator
5711
+ && (CG (active_op_array )-> fn_flags & ZEND_ACC_HAS_RETURN_TYPE )) {
5712
+ zend_emit_return_type_check (
5713
+ expr_ast ? & expr_node : NULL , CG (active_op_array )-> arg_info - 1 , 0 );
5714
+ }
5715
+
5704
5716
opline = zend_emit_op (NULL , by_ref ? ZEND_RETURN_BY_REF : ZEND_RETURN ,
5705
5717
& expr_node , NULL );
5706
5718
You can’t perform that action at this time.
0 commit comments