Language: continue/break 0 is Zend positive-integer compile fatal (#32155) - #32167
Merged
Conversation
…2155) php-cfg LoopResolver leaked Stmt_Continue for continue 0; reject non-positive depth in PHP before CFG rewrite so VM/JIT abort with php-src's message on stderr. Co-authored-by: Cursor <cursoragent@cursor.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
This was referenced Aug 18, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
continue 0/break 0now compile-abort with php-src's'continue' operator accepts only positive integers(same forbreak), instead of leaking php-parserToo high of a count for Stmt_Continue.lib/Ast/BreakContinueOperandCompileCheck.php(AST visitor before php-cfgLoopResolver); JIT stdout stays empty — fatal is on stderr as ZendPHP Fatal error.LoopResolverdistinguishes non-positive vs too-deep so a missed visitor still cannot emitStmt_Continue.php-src:
Zend/zend_compile.c(zend_compile_break_continue()).PHP:
lib/Ast/BreakContinueOperandCompileCheck.php,lib/Runtime.php.C runtime lines removed: none.
Closes #32155
Test plan
ContinueZero32155VMTest/JITTestBreakContinueOperandCompileCheckTest+GotoStatementTestVerification
Not covered: full
VMTest/JITTestsuites; AOTphpc buildof this repro;ci-fast.sh;check-selfhost-spine-coverage-sync.phpis red on this tree for 6 pre-existing inventory files not in spine (JitLdapResult.php,StreamIncludeOpen*, …) — our new unit is required from the spine.Made with Cursor