Edit report at https://bugs.php.net/bug.php?id=61046&edit=1
ID: 61046
Comment by: razvanphp at yahoo dot com
Reported by: nikic@php.net
Summary: Segfault when memory limit is hit while copying hash
table
Status: No Feedback
Type: Bug
Package: Reproducible crash
PHP Version: 5.4.0RC7
Assigned To: laruence
Block user comment: N
Private report: N
New Comment:
Hi. I have the same problem with a custom CLI PHP script. The test script posted returns PHP Fatal
error: Allowed memory size of 512000 bytes exhausted (tried to allocate 72 bytes) in /tmp/test.php
on line 7 instead of segmentation fault like my script.
Since this is the latest stable PHP version for Debian Wheezy, I think this bug is not solved yet.
As a side node, USE_ZEND_ALLOC=0 or ZEND_MM_SEG_SIZE= set to anything else than default 256k solves
the problem.
php -i |grep memory_limit
memory_limit => -1 => -1
PHP Version => 5.4.36-0+deb7u1
System => Linux srv 3.2.0-4-amd64 #1 SMP Debian 3.2.63-2+deb7u1 x86_64
Build Date => Dec 31 2014 07:30:15
HP API => 20100412
PHP Extension => 20100525
Zend Extension => 220100525
Zend Extension Build => API220100525,NTS
PHP Extension Build => API20100525,NTS
Debug Build => no
Thread Safety => disabled
Zend Signal Handling => disabled
Zend Memory Manager => enabled
Zend Multibyte Support => provided by mbstring
IPv6 Support => enabled
DTrace Support => disabled
(gdb) bt
#0 zend_mm_remove_from_free_list (heap=0x1e08290, mm_block=0x7f86af142388)
at /tmp/buildd/php5-5.4.36/Zend/zend_alloc.c:818
#1 0x0000000000680200 in _zend_mm_free_int (heap=0x1e08290, p=0x7f86af142368)
at /tmp/buildd/php5-5.4.36/Zend/zend_alloc.c:2101
#2 0x00000000006b4f18 in zend_hash_destroy (ht=0x7f86aefd2f70) at
/tmp/buildd/php5-5.4.36/Zend/zend_hash.c:560
#3 0x000000000069ce78 in destroy_zend_class (pce=0x1e08290) at
/tmp/buildd/php5-5.4.36/Zend/zend_opcode.c:297
#4 0x00000000006b38e5 in zend_hash_apply_deleter () at /tmp/buildd/php5-5.4.36/Zend/zend_hash.c:650
#5 0x00000000006b5421 in zend_hash_reverse_apply (ht=0x1e08bf0, apply_func=0x697a80
<clean_non_persistent_class>)
at /tmp/buildd/php5-5.4.36/Zend/zend_hash.c:804
#6 0x0000000000698187 in shutdown_executor () at
/tmp/buildd/php5-5.4.36/Zend/zend_execute_API.c:303
#7 0x00000000006a6ba5 in zend_deactivate () at /tmp/buildd/php5-5.4.36/Zend/zend.c:948
#8 0x0000000000646a4a in php_request_shutdown (dummy=0x1e08290) at
/tmp/buildd/php5-5.4.36/main/main.c:1808
#9 0x0000000000751768 in do_cli (argc=0, argv=0x7fff3583cf1d) at
/tmp/buildd/php5-5.4.36/sapi/cli/php_cli.c:1172
#10 0x0000000000431b6f in main (argc=32767, argv=0x1e081f0) at
/tmp/buildd/php5-5.4.36/sapi/cli/php_cli.c:1365
Thank you!
Previous Comments:
------------------------------------------------------------------------
[2014-01-08 15:20:02] info at ihead dot ru
The patch https://bugs.php.net/patch-display.php?bug=61046&patch=bug61046.patch&revision=1356016047
makes the segfault disappear.
------------------------------------------------------------------------
[2014-01-08 13:43:11] info at ihead dot ru
The bug is reproducable on
PHP version 5.4.23, 5.3.28
OS: FreeBSD 9.2 amd64
memory_limit=32M
function byRef(&$ref) {}
$array = array_fill(0, 200000, '*');
$ref = $array;
byRef($array);
------------------------------------------------------------------------
[2013-02-18 00:35:40] php-bugs at lists dot php dot net
No feedback was provided. The bug is being suspended because
we assume that you are no longer experiencing the problem.
If this is not the case and you are able to provide the
information that was requested earlier, please do so and
change the status of the bug back to "Open". Thank you.
------------------------------------------------------------------------
[2012-12-20 15:28:22] laruence@php.net
another way to fix this is promote the ht point assignment in ctor(list blow),
but there is still a chance that alloc failed when try to alloc memory for ht.
so I still think the fix I attached is the better one.
diff --git a/Zend/zend_variables.c b/Zend/zend_variables.c
index 25a66a1..bb6927a 100644
--- a/Zend/zend_variables.c
+++ b/Zend/zend_variables.c
@@ -134,9 +134,9 @@ ZEND_API void _zval_copy_ctor_func(zval *zvalue
ZEND_FILE_LINE_DC)
return; /* do nothing */
}
ALLOC_HASHTABLE_REL(tmp_ht);
+ zvalue->value.ht = tmp_ht;
zend_hash_init(tmp_ht,
zend_hash_num_elements(original_ht), NULL, ZVAL_PTR_DTOR, 0);
zend_hash_copy(tmp_ht, original_ht,
(copy_ctor_func_t) zval_add_ref, (void *) &tmp, sizeof(zval *));
- zvalue->value.ht = tmp_ht;
}
break;
case IS_OBJECT:
------------------------------------------------------------------------
[2012-12-20 15:08:30] laruence@php.net
quick fix attached, could you please verify it?
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=61046
--
Edit this bug report at https://bugs.php.net/bug.php?id=61046&edit=1