Bug #69816 [Com]: SIGSEGV in zend_hash_index_find_bucket

From: Date: Fri, 03 Jul 2015 09:08:36 +0000
Subject: Bug #69816 [Com]: SIGSEGV in zend_hash_index_find_bucket
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-194096@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=69816&edit=1

 ID:                 69816
 Comment by:         arjen at react dot com
 Reported by:        filip at prochazka dot su
 Summary:            SIGSEGV in zend_hash_index_find_bucket
 Status:             Assigned
 Type:               Bug
 Package:            Reproducible crash
 Operating System:   Linux
 PHP Version:        7.0.0alpha1
 Assigned To:        laruence
 Block user comment: N
 Private report:     N

 New Comment:

Hi filip, did you try to run it with gc_collect_cycles() uncommented?

It looks like some sort of memory corruption, which could be triggered earlier than the locations
you specified. By calling gc_collect_cycles() every tick the problem can appear earlier.


Previous Comments:
------------------------------------------------------------------------
[2015-06-28 04:22:20] php-bugs at lists dot php dot net

No feedback was provided. The bug is being suspended because
we assume that you are no longer experiencing the problem.
If this is not the case and you are able to provide the
information that was requested earlier, please do so and
change the status of the bug back to "Re-Opened". Thank you.

------------------------------------------------------------------------
[2015-06-27 16:29:39] filip at prochazka dot su

I've tried arjen's tick function and it dies in this file either here
https://github.com/nette/di/blob/26637ad8fa71bfc60935646fb04a9ef8815a0ab6/src/DI/ContainerBuilder.php#L833
or while calling the function. Also, on other few lines for example here https://github.com/nette/di/blob/26637ad8fa71bfc60935646fb04a9ef8815a0ab6/src/DI/ContainerBuilder.php#L742.
Is it stupid to thinkg that accessing the index of array somehow got broken?

Also, I've been running this on alpha2 and the core dump with backtrace is pretty similar

(gdb) bt full
#0  0x0000000000ad6cdf in zend_hash_index_find_bucket (ht=0x7ff45fabb6c0, h=0) at
/opt/php-7.0.0alpha2/Zend/zend_hash.c:464
        nIndex = 0
        idx = 11370103
        p = 0x7ff45fabb6c0
        arData = 0x1e
        __PRETTY_FUNCTION__ = "zend_hash_index_find_bucket"
#1  0x0000000000adb1e0 in zend_hash_index_exists (ht=0x7ff45fabb6c0, h=0) at
/opt/php-7.0.0alpha2/Zend/zend_hash.c:1935
        p = 0x7ff460c19a60
#2  0x00000000008ef394 in zif_array_key_exists (execute_data=0x7ff460c19a00,
return_value=0x7ff460c195d0) at /opt/php-7.0.0alpha2/ext/standard/array.c:5036
        key = 0x7ff460c19a60
        array = 0x7ff45fabb6c0
        __PRETTY_FUNCTION__ = "zif_array_key_exists"
#3  0x0000000000b1e7a7 in ZEND_DO_FCALL_BY_NAME_SPEC_HANDLER () at
/opt/php-7.0.0alpha2/Zend/zend_vm_execute.h:705
        call = 0x7ff460c19a00
        fbc = 0x27f8130
        ret = 0x7ff460c195d0
        __PRETTY_FUNCTION__ = "ZEND_DO_FCALL_BY_NAME_SPEC_HANDLER"
#4  0x0000000000b1dc3e in execute_ex (ex=0x7ff460c16fc0) at
/opt/php-7.0.0alpha2/Zend/zend_vm_execute.h:403
        orig_opline = 0x7ff460087ec0
        orig_execute_data = 0x7ff460c16d30
#5  0x0000000000aac99e in zend_call_function (fci=0x7fffd02112d0, fci_cache=0x7fffd02112a0) at
/opt/php-7.0.0alpha2/Zend/zend_execute_API.c:841
        call_via_handler = 0
        i = 1
        calling_scope = 0x7ff4600d6840
        call = 0x7ff460c16fc0
        dummy_execute_data = {opline = 0x7ff45fc1a408, call = 0x7fffd02112e0, return_value =
0x7ff460c16fa0, func = 0x7ff45fc203c0, This = {value = {lval = 140736685216272, dval =
6,953316127493364e-310, counted = 0x7fffd0211210, 
              str = 0x7fffd0211210, arr = 0x7fffd0211210, obj = 0x7fffd0211210, res =
0x7fffd0211210, ref = 0x7fffd0211210, ast = 0x7fffd0211210, zv = 0x7fffd0211210, ptr =
0x7fffd0211210, ce = 0x7fffd0211210, func = 0x7fffd0211210, ww = {
                w1 = 3491828240, w2 = 32767}}, u1 = {v = {type = 224 '\340', type_flags =
215 '\327', const_flags = 225 '\341', reserved = 95 '_'}, type_info =
1608636384}, u2 = {var_flags = 32756, next = 32756, cache_slot = 32756, 
              lineno = 32756, num_args = 32756, fe_pos = 32756, fe_iter_idx = 32756}},
run_time_cache = 0x7ff45fc1a408, literals = 0x7ff460159fc0, called_scope = 0x7fffd0211210,
prev_execute_data = 0xad272b <zend_fcall_info_args+37>, 
          symbol_table = 0x7ff460c16fb0}
        fci_cache_local = {initialized = 144 '\220', function_handler = 0x40a00000000,
calling_scope = 0x7ff45fe1d7f0, called_scope = 0x7ff45fc1a428, object = 0x7ff45fc1a428}
        func = 0x7ff460c10aa0
        orig_scope = 0x7ff4601edab8
        __PRETTY_FUNCTION__ = "zend_call_function"
#6  0x00000000008f4f97 in zif_call_user_func_array (execute_data=0x7ff460c16f40,
return_value=0x7ff460c16e40) at /opt/php-7.0.0alpha2/ext/standard/basic_functions.c:4805
        params = 0x7ff460c16fb0
        retval = {value = {lval = 0, dval = 0, counted = 0x0, str = 0x0, arr = 0x0, obj = 0x0, res =
0x0, ref = 0x0, ast = 0x0, zv = 0x0, ptr = 0x0, ce = 0x0, func = 0x0, ww = {w1 = 0, w2 = 0}}, u1 =
{v = {type = 0 '\000',
              type_flags = 0 '\000', const_flags = 0 '\000', reserved = 0
'\000'}, type_info = 0}, u2 = {var_flags = 32756, next = 32756, cache_slot = 32756, lineno
= 32756, num_args = 32756, fe_pos = 32756, fe_iter_idx = 32756}}
        fci = {size = 72, function_table = 0x7ff4600d6880, function_name = {value = {lval =
140687555298240, dval = 6,9508887870251033e-310, counted = 0x7ff45fc203c0, str = 0x7ff45fc203c0, arr
= 0x7ff45fc203c0, obj = 0x7ff45fc203c0,
              res = 0x7ff45fc203c0, ref = 0x7ff45fc203c0, ast = 0x7ff45fc203c0, zv = 0x7ff45fc203c0,
ptr = 0x7ff45fc203c0, ce = 0x7ff45fc203c0, func = 0x7ff45fc203c0, ww = {w1 = 1606550464, w2 =
32756}}, u1 = {v = {type = 7 '\a',
                type_flags = 28 '\034', const_flags = 0 '\000', reserved = 0
'\000'}, type_info = 7175}, u2 = {var_flags = 32767, next = 32767, cache_slot = 32767,
lineno = 32767, num_args = 32767, fe_pos = 32767, fe_iter_idx = 32767}},
          symbol_table = 0x0, retval = 0x7fffd0211290, params = 0x7ff45fe1d7e0, object =
0x7ff460c74240, no_separation = 1 '\001', param_count = 1}
        fci_cache = {initialized = 1 '\001', function_handler = 0x7ff460c10aa0,
calling_scope = 0x7ff4600d6840, called_scope = 0x7ff4600d6840, object = 0x7ff460c74240}
        __PRETTY_FUNCTION__ = "zif_call_user_func_array"
#7  0x0000000000b1e7a7 in ZEND_DO_FCALL_BY_NAME_SPEC_HANDLER () at
/opt/php-7.0.0alpha2/Zend/zend_vm_execute.h:705
        call = 0x7ff460c16f40
        fbc = 0x279a720
        ret = 0x7ff460c16e40
        __PRETTY_FUNCTION__ = "ZEND_DO_FCALL_BY_NAME_SPEC_HANDLER"
#8  0x0000000000b1dc3e in execute_ex (ex=0x7ff460c16030) at
/opt/php-7.0.0alpha2/Zend/zend_vm_execute.h:403
        orig_opline = 0x0
        orig_execute_data = 0x0
#9  0x0000000000b1dd50 in zend_execute (op_array=0x7ff460c71000, return_value=0x0) at
/opt/php-7.0.0alpha2/Zend/zend_vm_execute.h:447
        execute_data = 0x7ff460c16030
#10 0x0000000000ac4559 in zend_execute_scripts (type=8, retval=0x0, file_count=3) at
/opt/php-7.0.0alpha2/Zend/zend.c:1389
        files = {{gp_offset = 40, fp_offset = 48, overflow_arg_area = 0x7fffd0211550, reg_save_area
= 0x7fffd0211490}}
        i = 1
        file_handle = 0x7fffd0213880
        op_array = 0x7ff460c71000
#11 0x0000000000a31105 in php_execute_script (primary_file=0x7fffd0213880) at
/opt/php-7.0.0alpha2/main/main.c:2475
        realfile = "\001\333\336/\000\200\377\377\060(!\320\377\177\000\000\003",
'\000' <repeats 31 times>,
"\300\210\222\002\000\000\000\000\006\024\000\000\000\000\000\000\220u\202\r\000\000\000\000/\305\td\364\177\000\000\000\000\001\000\002\000\023\000+\000!\320\377\177\000\000\260-!\320\377\177",
'\000' <repeats 34 times>,
"\234N2l\364\177\000\000\377\377\377\377\377\377\377\377\220u\202\r\000\000\000\000\034\000\000\000\000\000\000\000D\000\000\000\000\000\000\000x:Ol\364\177\000\000\026X2l\364\177\000\000\002\000\000\000\000\000\000\000"...
        __orig_bailout = 0x7fffd02138f0
        __bailout = {{__jmpbuf = {16, 5475004362929379715, 4497408, 140736685226864, 0, 0,
5475004361815792003, -5475041851745461885}, __mask_was_saved = 0, __saved_mask = {__val =
{140736685222224, 193291665912, 18139557, 140736685225568,
                11021397, 18446744069414584319, 8589934592, 8589934592, 0, 0, 140736685225408, 128,
140736685221808, 140736685221808, 140736685222208, 140736685222208}}}}
        prepend_file_p = 0x0
        append_file_p = 0x0
---Type <return> to continue, or q <return> to quit---
        prepend_file = {handle = {fd = 0, fp = 0x0, stream = {handle = 0x0, isatty = 0, mmap = {len
= 0, pos = 0, map = 0x0, buf = 0x0, old_handle = 0x0, old_closer = 0x0}, reader = 0x0, fsizer = 0x0,
closer = 0x0}}, filename = 0x0,
          opened_path = 0x0, type = ZEND_HANDLE_FILENAME, free_filename = 0 '\000'}
        append_file = {handle = {fd = 0, fp = 0x0, stream = {handle = 0x0, isatty = 0, mmap = {len =
0, pos = 0, map = 0x0, buf = 0x0, old_handle = 0x0, old_closer = 0x0}, reader = 0x0, fsizer = 0x0,
closer = 0x0}}, filename = 0x0,
          opened_path = 0x0, type = ZEND_HANDLE_FILENAME, free_filename = 0 '\000'}
        old_cwd = 0x7fffd0211550 "/"
        use_heap = 0 '\000'
        retval = 0
#12 0x0000000000b92382 in main (argc=3, argv=0x7fffd0213b78) at
/opt/php-7.0.0alpha2/sapi/fpm/fpm/fpm_main.c:1941
        primary_script = 0x7ff460c04500 "/var/www/hosts/rohlik.l/index.php"
        __orig_bailout = 0x0
        __bailout = {{__jmpbuf = {0, 5475004362830813571, 4497408, 140736685226864, 0, 0,
5475004362931476867, -5475042041189197437}, __mask_was_saved = 0, __saved_mask = {__val = {4351400,
140687688703352, 4249168, 4294967296, 4294969392,
                140736685226384, 140736685226728, 140736685226688, 140687765872784, 1,
140687766189344, 140687766188488, 140687763986833, 0, 140687765872784, 140685948747777}}}}
        exit_status = 0
        cgi = 0
        c = -1
        use_extended_info = 0
        file_handle = {handle = {fd = 1623614080, fp = 0x7ff460c66280, stream = {handle =
0x7ff460c66280, isatty = 0, mmap = {len = 553, pos = 0, map = 0x0, buf = 0x7ff46c50f000 <error:
Cannot access memory at address 0x7ff46c50f000>,
                old_handle = 0x0, old_closer = 0x0}, reader = 0xa4ee67 <_php_stream_read>,
fsizer = 0xa2e9ab <php_zend_stream_fsizer>, closer = 0xa2e985
<php_zend_stream_mmap_closer>}},
          filename = 0x7ff460c04000 "/var/www/hosts/rohlik.l/index.php", opened_path =
0x0, type = ZEND_HANDLE_MAPPED, free_filename = 0 '\000'}
        orig_optind = 1
        orig_optarg = 0x0
        ini_entries_len = 0
        max_requests = 500
        requests = 0
        fcgi_fd = 0
        request = 0x292af20
        fpm_config = 0x7fffd0214f6f ""
        fpm_prefix = 0x0
        fpm_pid = 0x0
        test_conf = 0
        force_daemon = -1
        force_stderr = 0
        php_information = 0
        php_allow_to_run_as_root = 0
        __func__ = "main"

------------------------------------------------------------------------
[2015-06-16 08:24:23] arjen at react dot com

Poor mans debugging: register a tick function which prints the current file and line every n ticks
(current file and line can be fetched from debug_backtrace()).

declare(ticks=1);

register_tick_function(function(){
 $bt = debug_backtrace(DEBUG_BACKTRACE_IGNORE_ARGS, 2);
 //gc_collect_cycles(); // uncomment to run gc collection to find invalid object destruction early,
not at end of request
 echo $bt[0]['file'] . '::' . $bt[0]['line'] . PHP_EOL;
});

This has worked for me to find exact location (file, line) of errors in big projects.

------------------------------------------------------------------------


The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at

    https://bugs.php.net/bug.php?id=69816


--
Edit this bug report at https://bugs.php.net/bug.php?id=69816&edit=1


Thread (18 messages)

« previous php.bugs (#194096) next »