Bug #69649 [Ver]: segfault with --enable-dtrace
| From: | laruence@php.net | Date: | Sun, 17 May 2015 05:29:09 +0000 |
| Subject: | Bug #69649 [Ver]: segfault with --enable-dtrace | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-192701@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=69649&edit=1
ID: 69649
Updated by: laruence@php.net
Reported by: remi@php.net
Summary: segfault with --enable-dtrace
Status: Verified
Type: Bug
Package: *General Issues
Operating System: GNU/LInux
PHP Version: master-Git-2015-05-16 (Git)
Assigned To: dmitry
Block user comment: N
Private report: N
New Comment:
A fix might be, but I think it's a little ugly, dmitry, what do you think?
diff --git a/Zend/zend_vm_def.h b/Zend/zend_vm_def.h
index c1f8558..5390206 100644
--- a/Zend/zend_vm_def.h
+++ b/Zend/zend_vm_def.h
@@ -2453,6 +2453,7 @@ ZEND_VM_HELPER(zend_leave_helper, ANY, ANY)
ZEND_VM_LEAVE();
} else {
if (ZEND_CALL_KIND_EX(call_info) == ZEND_CALL_TOP_FUNCTION) {
+ zend_object *object;
i_free_compiled_variables(execute_data);
if (UNEXPECTED(EX(symbol_table) != NULL)) {
zend_clean_and_cache_symbol_table(EX(symbol_table));
@@ -2462,6 +2463,23 @@ ZEND_VM_HELPER(zend_leave_helper, ANY, ANY)
if (UNEXPECTED(call_info & ZEND_CALL_CLOSURE)) {
OBJ_RELEASE((zend_object*)EX(func)->op_array.prototype);
}
+ if (UNEXPECTED(call_info & ZEND_CALL_RELEASE_THIS)) {
+ object = Z_OBJ(execute_data->This);
+#if 0
+ if (UNEXPECTED(EG(exception) != NULL) && (EX(opline)->op1.num & ZEND_CALL_CTOR))
{
+ if (!(EX(opline)->op1.num & ZEND_CALL_CTOR_RESULT_UNUSED)) {
+#else
+ if (UNEXPECTED(EG(exception) != NULL) && (call_info & ZEND_CALL_CTOR)) {
+ if (!(call_info & ZEND_CALL_CTOR_RESULT_UNUSED)) {
+#endif
+ GC_REFCOUNT(object)--;
+ }
+ if (GC_REFCOUNT(object) == 1) {
+ zend_object_store_ctor_failed(object);
+ }
+ }
+ OBJ_RELEASE(object);
+ }
} else /* if (call_kind == ZEND_CALL_TOP_CODE) */ {
zend_array *symbol_table = EX(symbol_table);
@@ -3712,6 +3730,9 @@ ZEND_VM_HANDLER(60, ZEND_DO_FCALL, ANY, ANY)
} else {
ZEND_ADD_CALL_FLAG(call, ZEND_CALL_TOP);
zend_execute_ex(call);
+
+ ZEND_VM_INTERRUPT_CHECK();
+ ZEND_VM_NEXT_OPCODE();
}
}
} else if (EXPECTED(fbc->type < ZEND_USER_FUNCTION)) {
Previous Comments:
------------------------------------------------------------------------
[2015-05-17 05:14:00] laruence@php.net
if dtrace enable, ZEND_DO_FCALL will make the call as TOP, thus the call will be released in
zend_leave_helper..
but later when the flow returns back to DO_FCALL -> invalid read/segfault since the call has be
freed..
------------------------------------------------------------------------
[2015-05-16 17:49:32] remi@php.net
Description:
------------
Git snapshot 2015-05-15 - c9f27ee4227268bc74fc54e0e06102317e614804
During test suite, tests/func/010.phpt raise a segfault
(no issue without dtrace)
Test script:
---------------
./configure --disable-all --enable-dtrace
gdb sapi/cli/php
(gdb) run tests/func/010.phpt
...
--TEST--
function with many parameters
--SKIPIF--
--FILE--
bool(true)
bool(true)
bool(true)
bool(true)
bool(true)
bool(true)
bool(true)
Program received signal SIGSEGV, Segmentation fault.
zend_vm_stack_free_call_frame_ex (call=0x7fffefe67020, call_info=130) at
/work/build/phpmaster/Zend/zend_execute.h:245
245 EG(vm_stack_top) = prev->top;
(gdb) bt
#0 zend_vm_stack_free_call_frame_ex (call=0x7fffefe67020, call_info=130) at
/work/build/phpmaster/Zend/zend_execute.h:245
#1 zend_vm_stack_free_call_frame (call=0x7fffefe67020) at
/work/build/phpmaster/Zend/zend_execute.h:256
#2 ZEND_DO_FCALL_SPEC_HANDLER () at /work/build/phpmaster/Zend/zend_vm_execute.h:908
#3 0x00000000005caaab in execute_ex (ex=ex@entry=0x7ffff6613540) at
/work/build/phpmaster/Zend/zend_vm_execute.h:394
#4 0x000000000057dd5a in dtrace_execute_ex (execute_data=0x7ffff6613540) at
/work/build/phpmaster/Zend/zend_dtrace.c:78
#5 0x000000000061bc4c in ZEND_INCLUDE_OR_EVAL_SPEC_CV_HANDLER () at
/work/build/phpmaster/Zend/zend_vm_execute.h:29367
#6 0x00000000005caaab in execute_ex (ex=ex@entry=0x7ffff6613030) at
/work/build/phpmaster/Zend/zend_vm_execute.h:394
#7 0x000000000057dd5a in dtrace_execute_ex (execute_data=0x7ffff6613030) at
/work/build/phpmaster/Zend/zend_dtrace.c:78
#8 0x000000000058dc78 in zend_execute_scripts (type=type@entry=8, retval=retval@entry=0x0,
file_count=file_count@entry=3)
at /work/build/phpmaster/Zend/zend.c:1389
#9 0x00000000005336b8 in php_execute_script (primary_file=primary_file@entry=0x7fffffffc9e0) at
/work/build/phpmaster/main/main.c:2479
#10 0x0000000000623848 in do_cli (argc=2, argv=0xa336a0) at
/work/build/phpmaster/sapi/cli/php_cli.c:967
#11 0x000000000041a33b in main (argc=2, argv=0xa336a0) at
/work/build/phpmaster/sapi/cli/php_cli.c:1334
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=69649&edit=1