Bug #61046 [Com]: Segfault when memory limit is hit while copying hash table

From: Date: Tue, 13 Jan 2015 11:21:35 +0000
Subject: Bug #61046 [Com]: Segfault when memory limit is hit while copying hash table
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-189927@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=61046&edit=1

 ID:                 61046
 Comment by:         razvanphp at yahoo dot com
 Reported by:        nikic@php.net
 Summary:            Segfault when memory limit is hit while copying hash
                     table
 Status:             No Feedback
 Type:               Bug
 Package:            Reproducible crash
 PHP Version:        5.4.0RC7
 Assigned To:        laruence
 Block user comment: N
 Private report:     N

 New Comment:

Hi. I have the same problem with a custom CLI PHP script. The test script posted returns PHP Fatal
error:  Allowed memory size of 512000 bytes exhausted (tried to allocate 72 bytes) in /tmp/test.php
on line 7 instead of segmentation fault like my script.

Since this is the latest stable PHP version for Debian Wheezy, I think this bug is not solved yet.

As a side node, USE_ZEND_ALLOC=0 or ZEND_MM_SEG_SIZE= set to anything else than default 256k solves
the problem.

php -i |grep memory_limit
memory_limit => -1 => -1

PHP Version => 5.4.36-0+deb7u1
System => Linux srv 3.2.0-4-amd64 #1 SMP Debian 3.2.63-2+deb7u1 x86_64
Build Date => Dec 31 2014 07:30:15
HP API => 20100412
PHP Extension => 20100525
Zend Extension => 220100525
Zend Extension Build => API220100525,NTS
PHP Extension Build => API20100525,NTS
Debug Build => no
Thread Safety => disabled
Zend Signal Handling => disabled
Zend Memory Manager => enabled
Zend Multibyte Support => provided by mbstring
IPv6 Support => enabled
DTrace Support => disabled

(gdb) bt
#0  zend_mm_remove_from_free_list (heap=0x1e08290, mm_block=0x7f86af142388)
    at /tmp/buildd/php5-5.4.36/Zend/zend_alloc.c:818
#1  0x0000000000680200 in _zend_mm_free_int (heap=0x1e08290, p=0x7f86af142368)
    at /tmp/buildd/php5-5.4.36/Zend/zend_alloc.c:2101
#2  0x00000000006b4f18 in zend_hash_destroy (ht=0x7f86aefd2f70) at
/tmp/buildd/php5-5.4.36/Zend/zend_hash.c:560
#3  0x000000000069ce78 in destroy_zend_class (pce=0x1e08290) at
/tmp/buildd/php5-5.4.36/Zend/zend_opcode.c:297
#4  0x00000000006b38e5 in zend_hash_apply_deleter () at /tmp/buildd/php5-5.4.36/Zend/zend_hash.c:650
#5  0x00000000006b5421 in zend_hash_reverse_apply (ht=0x1e08bf0, apply_func=0x697a80
<clean_non_persistent_class>)
    at /tmp/buildd/php5-5.4.36/Zend/zend_hash.c:804
#6  0x0000000000698187 in shutdown_executor () at
/tmp/buildd/php5-5.4.36/Zend/zend_execute_API.c:303
#7  0x00000000006a6ba5 in zend_deactivate () at /tmp/buildd/php5-5.4.36/Zend/zend.c:948
#8  0x0000000000646a4a in php_request_shutdown (dummy=0x1e08290) at
/tmp/buildd/php5-5.4.36/main/main.c:1808
#9  0x0000000000751768 in do_cli (argc=0, argv=0x7fff3583cf1d) at
/tmp/buildd/php5-5.4.36/sapi/cli/php_cli.c:1172
#10 0x0000000000431b6f in main (argc=32767, argv=0x1e081f0) at
/tmp/buildd/php5-5.4.36/sapi/cli/php_cli.c:1365

Thank you!


Previous Comments:
------------------------------------------------------------------------
[2014-01-08 15:20:02] info at ihead dot ru

The patch https://bugs.php.net/patch-display.php?bug=61046&patch=bug61046.patch&revision=1356016047
makes the segfault disappear.

------------------------------------------------------------------------
[2014-01-08 13:43:11] info at ihead dot ru

The bug is reproducable on
PHP version 5.4.23, 5.3.28
OS: FreeBSD 9.2 amd64
memory_limit=32M

function byRef(&$ref) {}

$array = array_fill(0, 200000, '*');
$ref = $array;

byRef($array);

------------------------------------------------------------------------
[2013-02-18 00:35:40] php-bugs at lists dot php dot net

No feedback was provided. The bug is being suspended because
we assume that you are no longer experiencing the problem.
If this is not the case and you are able to provide the
information that was requested earlier, please do so and
change the status of the bug back to "Open". Thank you.

------------------------------------------------------------------------
[2012-12-20 15:28:22] laruence@php.net

another way to fix this is promote the ht point assignment in ctor(list blow), 
but there is still a chance that alloc failed when try to alloc memory for ht.

so I still think the fix I attached is the better one.

diff --git a/Zend/zend_variables.c b/Zend/zend_variables.c
index 25a66a1..bb6927a 100644
--- a/Zend/zend_variables.c
+++ b/Zend/zend_variables.c
@@ -134,9 +134,9 @@ ZEND_API void _zval_copy_ctor_func(zval *zvalue 
ZEND_FILE_LINE_DC)
 					return; /* do nothing */
 				}
 				ALLOC_HASHTABLE_REL(tmp_ht);
+				zvalue->value.ht = tmp_ht;
 				zend_hash_init(tmp_ht, 
zend_hash_num_elements(original_ht), NULL, ZVAL_PTR_DTOR, 0);
 				zend_hash_copy(tmp_ht, original_ht, 
(copy_ctor_func_t) zval_add_ref, (void *) &tmp, sizeof(zval *));
-				zvalue->value.ht = tmp_ht;
 			}
 			break;
 		case IS_OBJECT:

------------------------------------------------------------------------
[2012-12-20 15:08:30] laruence@php.net

quick fix attached, could you please verify it?

------------------------------------------------------------------------


The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at

    https://bugs.php.net/bug.php?id=61046


--
Edit this bug report at https://bugs.php.net/bug.php?id=61046&edit=1


Thread (13 messages)

« previous php.bugs (#189927) next »