Bug #69643 [Com]: Segmentation fault in i_zval_ptr_dtor() (zend_variables.h:56)
| From: | berdir@php.net | Date: | Tue, 26 May 2015 23:24:37 +0000 |
| Subject: | Bug #69643 [Com]: Segmentation fault in i_zval_ptr_dtor() (zend_variables.h:56) | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-192904@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=69643&edit=1
ID: 69643
Comment by: berdir@php.net
Reported by: berdir@php.net
Summary: Segmentation fault in i_zval_ptr_dtor()
(zend_variables.h:56)
Status: Feedback
Type: Bug
Package: Scripting Engine problem
Operating System: Ubuntu
PHP Version: master-Git-2015-05-15 (Git)
Assigned To: laruence
Block user comment: N
Private report: N
New Comment:
I've tried to debug this a bit more and I think current is somehow messed up. Why and what
it's supposed to be, I don't know:
(gdb) print current
$5 = (zval *) 0x7fffe3e7b4c0
(gdb) print *current
$6 = {value = {lval = 1, dval = 4.9406564584124654e-324, counted = 0x1, str = 0x1, arr = 0x1, obj =
0x1, res = 0x1, ref = 0x1, ast = 0x1, zv = 0x1, ptr = 0x1, ce = 0x1, func = 0x1,
ww = {w1 = 1, w2 = 0}}, u1 = {v = {type = 4 '\004', type_flags = 0 '\000',
const_flags = 0 '\000', reserved = 0 '\000'}, type_info = 4}, u2 = {var_flags =
4294967295,
next = 4294967295, cache_slot = 4294967295, lineno = 4294967295, num_args = 4294967295, fe_pos =
4294967295, fe_iter_idx = 4294967295}}
(gdb) print current->value
$7 = {lval = 1, dval = 4.9406564584124654e-324, counted = 0x1, str = 0x1, arr = 0x1, obj = 0x1, res
= 0x1, ref = 0x1, ast = 0x1, zv = 0x1, ptr = 0x1, ce = 0x1, func = 0x1, ww = {
w1 = 1, w2 = 0}}
(gdb) print *current->value->str
Cannot access memory at address 0x1
This is the array of postfields that are processed here:
array(9) {
["file_test_replace"]=>
int(1)
["file_subdir"]=>
string(0) ""
["extensions"]=>
string(0) ""
["is_image_file"]=>
string(1) "1"
["op"]=>
string(6) "Submit"
["form_build_id"]=>
string(48) "form-8Jctuh1GUx5Te_wooBYvPLbOJhXOSUOgsQ-emHSKW8g"
["form_token"]=>
string(43) "XcSxNC5I2nYo2-zg29Mo7rsmImYJWq7JNbK3WlwVZzc"
["form_id"]=>
string(15) "_file_test_form"
["files[file_test_upload]"]=>
object(CURLFile)#8517 (3) {
["name"]=>
string(69) "/home/berdir/Projekte/d8/sites/simpletest/127071/files/image-test.png"
["mime"]=>
string(0) ""
["postname"]=>
string(0) ""
}
}
I noticed that file_test_replace does seem to be an integer, which might be the cause for this. In
fact, when I add an explicit string cast for the value, then it works!
So I guess current is optimized and in this case a zval for an int, not a string, but the code
expects a string?
This means I can work around this in our tests, but this isn't supposed to break?
Previous Comments:
------------------------------------------------------------------------
[2015-05-21 21:56:44] berdir@php.net
Strange, now I also can't reproduce it with that test anymore.
Drupal\file\Tests\RemoteFileSaveUploadTest is still failing for me, however. But it seems to be a
completely different problem, seems to be curl related again?
gdb --args '/usr/local/bin/php7' './core/scripts/run-tests.sh' --url 'http://d8/' --php '/usr/local/bin/php7' --test-id 2123
--execute-test 'Drupal\file\Tests\RemoteFileSaveUploadTest'
(you might need a work
Program received signal SIGSEGV, Segmentation fault.
0x0000000000564861 in _php_curl_setopt (ch=ch@entry=0x7fffe4481780, option=<optimized out>,
zvalue=zvalue@entry=0x7fffe405cae0) at /home/berdir/tools/php-src/ext/curl/interface.c:2563
2563 form_error = curl_formadd(&first, &last,
(gdb) bt
#0 0x0000000000564861 in _php_curl_setopt (ch=ch@entry=0x7fffe4481780, option=<optimized
out>, zvalue=zvalue@entry=0x7fffe405cae0)
at /home/berdir/tools/php-src/ext/curl/interface.c:2563
#1 0x000000000056552c in zif_curl_setopt_array (execute_data=<optimized out>,
return_value=0x7fffed413920) at /home/berdir/tools/php-src/ext/curl/interface.c:2808
#2 0x0000000000850905 in ZEND_DO_FCALL_BY_NAME_SPEC_HANDLER () at
/home/berdir/tools/php-src/Zend/zend_vm_execute.h:692
#3 0x00000000007f8c0b in execute_ex (ex=<optimized out>) at
/home/berdir/tools/php-src/Zend/zend_vm_execute.h:394
#4 0x0000000000853f97 in zend_execute (op_array=0x7fffed4931c0, return_value=<optimized out>)
at /home/berdir/tools/php-src/Zend/zend_vm_execute.h:434
#5 0x00000000007b7cf5 in zend_execute_scripts (type=8, retval=0x7fffffffa2c3, retval@entry=0x0,
file_count=3) at /home/berdir/tools/php-src/Zend/zend.c:1389
#6 0x000000000075a140 in php_execute_script (primary_file=0x7fffffffcad0) at
/home/berdir/tools/php-src/main/main.c:2479
#7 0x00000000008558b9 in do_cli (argc=-479607560, argv=0x7fffffffa2c3) at
/home/berdir/tools/php-src/sapi/cli/php_cli.c:967
#8 0x00000000004372a0 in main (argc=-479607560, argv=0x7fffffffa2c3) at
/home/berdir/tools/php-src/sapi/cli/php_cli.c:1334
------------------------------------------------------------------------
[2015-05-16 15:10:46] laruence@php.net
seems I can not reproduce it:
Drupal\migrate_drupal\Tests\d6\MigrateUserPictureFileTest 13 passes
Test run duration: 3 sec
thanks
------------------------------------------------------------------------
[2015-05-15 20:28:21] berdir@php.net
Description:
------------
We're working on making Drupal 8 compatible with PHP7.
Around 4 of our test have a segfault and the end of the test, during shutdown. This is relatively
new (1-2weeks), they passed before.
Program received signal SIGSEGV, Segmentation fault.
i_zval_ptr_dtor (zval_ptr=0x7fffed5ffa80) at /home/berdir/tools/php-src/Zend/zend_variables.h:56
56 if (!Z_DELREF_P(zval_ptr)) {
(gdb) bt
#0 i_zval_ptr_dtor (zval_ptr=0x7fffed5ffa80) at /home/berdir/tools/php-src/Zend/zend_variables.h:56
#1 destroy_zend_class (zv=<optimized out>) at
/home/berdir/tools/php-src/Zend/zend_opcode.c:260
#2 0x00000000007cb74c in _zend_hash_del_el_ex (prev=<optimized out>, p=0x136d440, idx=710,
ht=0x113ddd0) at /home/berdir/tools/php-src/Zend/zend_hash.c:938
#3 _zend_hash_del_el (p=0x136d440, idx=710, ht=0x113ddd0) at
/home/berdir/tools/php-src/Zend/zend_hash.c:962
#4 zend_hash_reverse_apply (ht=0x113ddd0, apply_func=apply_func@entry=0x7a6ee0
<clean_non_persistent_class>) at /home/berdir/tools/php-src/Zend/zend_hash.c:1532
#5 0x00000000007a772b in shutdown_executor () at
/home/berdir/tools/php-src/Zend/zend_execute_API.c:351
#6 0x00000000007b6e2b in zend_deactivate () at /home/berdir/tools/php-src/Zend/zend.c:964
#7 0x0000000000758c22 in php_request_shutdown (dummy=<optimized out>) at
/home/berdir/tools/php-src/main/main.c:1818
#8 0x0000000000854532 in do_cli (argc=-18992, argv=0x0) at
/home/berdir/tools/php-src/sapi/cli/php_cli.c:1135
#9 0x00000000004372a0 in main (argc=-18992, argv=0x0) at
/home/berdir/tools/php-src/sapi/cli/php_cli.c:1334
One of the failing tests is Drupal\migrate_drupal\Tests\d6\MigrateUserPictureFileTest.
Instructions on how to run the test are in https://bugs.php.net/bug.php?id=69371, for
example.
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=69643&edit=1