Bug #69643 [Com]: Segmentation fault in i_zval_ptr_dtor() (zend_variables.h:56)
| From: | berdir@php.net | Date: | Fri, 29 May 2015 06:15:59 +0000 |
| Subject: | Bug #69643 [Com]: Segmentation fault in i_zval_ptr_dtor() (zend_variables.h:56) | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-192989@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=69643&edit=1
ID: 69643
Comment by: berdir@php.net
Reported by: berdir@php.net
Summary: Segmentation fault in i_zval_ptr_dtor()
(zend_variables.h:56)
Status: Closed
Type: Bug
Package: Scripting Engine problem
Operating System: Ubuntu
PHP Version: master-Git-2015-05-15 (Git)
Assigned To: laruence
Block user comment: N
Private report: N
New Comment:
If you get errors/exceptions, use --verbose --color instead of --concurrency to see what the problem
is. My guess is that you're missing an extension or something like that.
Previous Comments:
------------------------------------------------------------------------
[2015-05-29 03:05:54] laruence@php.net
What I got is:
$ php7 core/scripts/run-tests.sh --repeat 20 --concurrency 8 --sqlite '/tmp/test.sqlite'
--dburl 'sqlite://tmp/db.sqlite' --url http://d8/ --class
"Drupal\migrate_drupal\Tests\d6\MigrateFieldTest"
Drupal test run
---------------
Tests to be run:
- Drupal\migrate_drupal\Tests\d6\MigrateFieldTest
Test run started:
Friday, May 29, 2015 - 03:01
Test summary
------------
Drupal\migrate_drupal\Tests\d6\MigrateFieldTest 1 passes 1 exceptions
Drupal\migrate_drupal\Tests\d6\MigrateFieldTest 1 passes 1 exceptions
Drupal\migrate_drupal\Tests\d6\MigrateFieldTest 1 passes 1 exceptions
Drupal\migrate_drupal\Tests\d6\MigrateFieldTest 1 passes 1 exceptions
Drupal\migrate_drupal\Tests\d6\MigrateFieldTest 1 passes 1 exceptions
Drupal\migrate_drupal\Tests\d6\MigrateFieldTest 1 passes 1 exceptions
Drupal\migrate_drupal\Tests\d6\MigrateFieldTest 1 passes 1 exceptions
Drupal\migrate_drupal\Tests\d6\MigrateFieldTest 1 passes 1 exceptions
Drupal\migrate_drupal\Tests\d6\MigrateFieldTest 1 passes 1 exceptions
Drupal\migrate_drupal\Tests\d6\MigrateFieldTest 1 passes 1 exceptions
Drupal\migrate_drupal\Tests\d6\MigrateFieldTest 1 passes 1 exceptions
Drupal\migrate_drupal\Tests\d6\MigrateFieldTest 1 passes 1 exceptions
Drupal\migrate_drupal\Tests\d6\MigrateFieldTest 1 passes 1 exceptions
Drupal\migrate_drupal\Tests\d6\MigrateFieldTest 1 passes 1 exceptions
Drupal\migrate_drupal\Tests\d6\MigrateFieldTest 1 passes 1 exceptions
Drupal\migrate_drupal\Tests\d6\MigrateFieldTest 1 passes 1 exceptions
Drupal\migrate_drupal\Tests\d6\MigrateFieldTest 1 passes 1 exceptions
Drupal\migrate_drupal\Tests\d6\MigrateFieldTest 1 passes 1 exceptions
Drupal\migrate_drupal\Tests\d6\MigrateFieldTest 1 passes 1 exceptions
Drupal\migrate_drupal\Tests\d6\MigrateFieldTest 1 passes 1 exceptions
Test run duration: 1 min
------------------------------------------------------------------------
[2015-05-28 22:20:28] berdir@php.net
Ok, this is annoying.
i found a way to reproduce the origin segfault. It only happens when running the tests with
concurrency.
I was able to generate a core file for a non-packaged executable on ubuntu by doing this:
as root:
# echo "/tmp/core.%e.%p.%h.%t" > /proc/sys/kernel/core_pattern
Then run:
php7 core/scripts/run-tests.sh --repeat 20 --concurrency 8 --url http://d8/
--class "Drupal\migrate_drupal\Tests\d6\MigrateFieldTest"
You should get an output like this:
...
Drupal\migrate_drupal\Tests\d6\MigrateFieldTest 31 passes
Drupal\migrate_drupal\Tests\d6\MigrateFieldTest 31 passes
Drupal\migrate_drupal\Tests\d6\MigrateFieldTest 31 passes
Drupal\migrate_drupal\Tests\d6\MigrateFieldTest 31 passes
Segmentation fault (core dumped)
FATAL Drupal\migrate_drupal\Tests\d6\MigrateFieldTest: test runner returned a non-zero error code
(139).
- Found database prefix 'simpletest866096' for test ID 1804.
Segmentation fault (core dumped)
Segmentation fault (core dumped)
FATAL Drupal\migrate_drupal\Tests\d6\MigrateFieldTest: test runner returned a non-zero error code
(139).
- Found database prefix 'simpletest667328' for test ID 1800.
FATAL Drupal\migrate_drupal\Tests\d6\MigrateFieldTest: test runner returned a non-zero error code
(139).
- Found database prefix 'simpletest325478' for test ID 1806.
Segmentation fault (core dumped)
FATAL Drupal\migrate_drupal\Tests\d6\MigrateFieldTest: test runner returned a non-zero error code
(139).
- Found database prefix 'simpletest901902' for test ID 1803.
Drupal\migrate_drupal\Tests\d6\MigrateFieldTest 31 passes
...
And then find the core dumps in /tmp.
(gdb) print zval_ptr
$1 = (zval *) 0x7fa473d0d0d8
(gdb) print *zval_ptr
$2 = {value = {lval = 139638785192025, dval = 6.8990726590384926e-310, counted = 0x7f0030303059, str
= 0x7f0030303059, arr = 0x7f0030303059, obj = 0x7f0030303059, res = 0x7f0030303059,
ref = 0x7f0030303059, ast = 0x7f0030303059, zv = 0x7f0030303059, ptr = 0x7f0030303059, ce =
0x7f0030303059, func = 0x7f0030303059, ww = {w1 = 808464473, w2 = 32512}}, u1 = {v = {
type = 8 '\b', type_flags = 12 '\f', const_flags = 0 '\000',
reserved = 0 '\000'}, type_info = 3080}, u2 = {var_flags = 1953066601, next = 1953066601,
cache_slot = 1953066601,
lineno = 1953066601, num_args = 1953066601, fe_pos = 1953066601, fe_iter_idx = 1953066601}}.
(gdb) print zval_ptr->value
$3 = {lval = 139638785192025, dval = 6.8990726590384926e-310, counted = 0x7f0030303059, str =
0x7f0030303059, arr = 0x7f0030303059, obj = 0x7f0030303059, res = 0x7f0030303059,
ref = 0x7f0030303059, ast = 0x7f0030303059, zv = 0x7f0030303059, ptr = 0x7f0030303059, ce =
0x7f0030303059, func = 0x7f0030303059, ww = {w1 = 808464473, w2 = 32512}}
(gdb) print zval_ptr->value->str
$4 = (zend_string *) 0x7f0030303059
(gdb) print *zval_ptr->value->str
Cannot access memory at address 0x7f0030303059
------------------------------------------------------------------------
[2015-05-28 20:07:01] berdir@php.net
I can confirm that this fixed now!
No more segfaults with php7 in our test suite. Two new test fails thought, looking into those now.
------------------------------------------------------------------------
[2015-05-28 16:05:44] laruence@php.net
Automatic comment on behalf of laruence
Revision: http://git.php.net/?p=php-src.git;a=commit;h=50e08d60b66d7cdc47f61fbe73b7ebfea8da0acc
Log: Attempt to fix #69643
------------------------------------------------------------------------
[2015-05-26 23:24:36] berdir@php.net
I've tried to debug this a bit more and I think current is somehow messed up. Why and what
it's supposed to be, I don't know:
(gdb) print current
$5 = (zval *) 0x7fffe3e7b4c0
(gdb) print *current
$6 = {value = {lval = 1, dval = 4.9406564584124654e-324, counted = 0x1, str = 0x1, arr = 0x1, obj =
0x1, res = 0x1, ref = 0x1, ast = 0x1, zv = 0x1, ptr = 0x1, ce = 0x1, func = 0x1,
ww = {w1 = 1, w2 = 0}}, u1 = {v = {type = 4 '\004', type_flags = 0 '\000',
const_flags = 0 '\000', reserved = 0 '\000'}, type_info = 4}, u2 = {var_flags =
4294967295,
next = 4294967295, cache_slot = 4294967295, lineno = 4294967295, num_args = 4294967295, fe_pos =
4294967295, fe_iter_idx = 4294967295}}
(gdb) print current->value
$7 = {lval = 1, dval = 4.9406564584124654e-324, counted = 0x1, str = 0x1, arr = 0x1, obj = 0x1, res
= 0x1, ref = 0x1, ast = 0x1, zv = 0x1, ptr = 0x1, ce = 0x1, func = 0x1, ww = {
w1 = 1, w2 = 0}}
(gdb) print *current->value->str
Cannot access memory at address 0x1
This is the array of postfields that are processed here:
array(9) {
["file_test_replace"]=>
int(1)
["file_subdir"]=>
string(0) ""
["extensions"]=>
string(0) ""
["is_image_file"]=>
string(1) "1"
["op"]=>
string(6) "Submit"
["form_build_id"]=>
string(48) "form-8Jctuh1GUx5Te_wooBYvPLbOJhXOSUOgsQ-emHSKW8g"
["form_token"]=>
string(43) "XcSxNC5I2nYo2-zg29Mo7rsmImYJWq7JNbK3WlwVZzc"
["form_id"]=>
string(15) "_file_test_form"
["files[file_test_upload]"]=>
object(CURLFile)#8517 (3) {
["name"]=>
string(69) "/home/berdir/Projekte/d8/sites/simpletest/127071/files/image-test.png"
["mime"]=>
string(0) ""
["postname"]=>
string(0) ""
}
}
I noticed that file_test_replace does seem to be an integer, which might be the cause for this. In
fact, when I add an explicit string cast for the value, then it works!
So I guess current is optimized and in this case a zval for an int, not a string, but the code
expects a string?
This means I can work around this in our tests, but this isn't supposed to break?
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=69643
--
Edit this bug report at https://bugs.php.net/bug.php?id=69643&edit=1