Bug #69816 [Com]: SIGSEGV in zend_hash_index_find_bucket

From: Date: Fri, 14 Aug 2015 09:13:25 +0000
Subject: Bug #69816 [Com]: SIGSEGV in zend_hash_index_find_bucket
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-195200@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=69816&edit=1 ID: 69816 Comment by: bugs dot php dot net at majkl578 dot cz Reported by: filip at prochazka dot su Summary: SIGSEGV in zend_hash_index_find_bucket Status: Assigned Type: Bug Package: Reproducible crash Operating System: Linux PHP Version: 7.0.0alpha1 Assigned To: laruence Block user comment: N Private report: N New Comment: Hi laruence, could you please have a look ať #70262? It seems to be exactly the same bug, but with a repro script/demo included. Thanks! Previous Comments: ------------------------------------------------------------------------ [2015-07-03 09:08:35] arjen at react dot com Hi filip, did you try to run it with gc_collect_cycles() uncommented? It looks like some sort of memory corruption, which could be triggered earlier than the locations you specified. By calling gc_collect_cycles() every tick the problem can appear earlier. ------------------------------------------------------------------------ [2015-06-28 04:22:20] php-bugs at lists dot php dot net No feedback was provided. The bug is being suspended because we assume that you are no longer experiencing the problem. If this is not the case and you are able to provide the information that was requested earlier, please do so and change the status of the bug back to "Re-Opened". Thank you. ------------------------------------------------------------------------ [2015-06-27 16:29:39] filip at prochazka dot su I've tried arjen's tick function and it dies in this file either here https://github.com/nette/di/blob/26637ad8fa71bfc60935646fb04a9ef8815a0ab6/src/DI/ContainerBuilder.php#L833 or while calling the function. Also, on other few lines for example here https://github.com/nette/di/blob/26637ad8fa71bfc60935646fb04a9ef8815a0ab6/src/DI/ContainerBuilder.php#L742. Is it stupid to thinkg that accessing the index of array somehow got broken? Also, I've been running this on alpha2 and the core dump with backtrace is pretty similar (gdb) bt full #0 0x0000000000ad6cdf in zend_hash_index_find_bucket (ht=0x7ff45fabb6c0, h=0) at /opt/php-7.0.0alpha2/Zend/zend_hash.c:464 nIndex = 0 idx = 11370103 p = 0x7ff45fabb6c0 arData = 0x1e __PRETTY_FUNCTION__ = "zend_hash_index_find_bucket" #1 0x0000000000adb1e0 in zend_hash_index_exists (ht=0x7ff45fabb6c0, h=0) at /opt/php-7.0.0alpha2/Zend/zend_hash.c:1935 p = 0x7ff460c19a60 #2 0x00000000008ef394 in zif_array_key_exists (execute_data=0x7ff460c19a00, return_value=0x7ff460c195d0) at /opt/php-7.0.0alpha2/ext/standard/array.c:5036 key = 0x7ff460c19a60 array = 0x7ff45fabb6c0 __PRETTY_FUNCTION__ = "zif_array_key_exists" #3 0x0000000000b1e7a7 in ZEND_DO_FCALL_BY_NAME_SPEC_HANDLER () at /opt/php-7.0.0alpha2/Zend/zend_vm_execute.h:705 call = 0x7ff460c19a00 fbc = 0x27f8130 ret = 0x7ff460c195d0 __PRETTY_FUNCTION__ = "ZEND_DO_FCALL_BY_NAME_SPEC_HANDLER" #4 0x0000000000b1dc3e in execute_ex (ex=0x7ff460c16fc0) at /opt/php-7.0.0alpha2/Zend/zend_vm_execute.h:403 orig_opline = 0x7ff460087ec0 orig_execute_data = 0x7ff460c16d30 #5 0x0000000000aac99e in zend_call_function (fci=0x7fffd02112d0, fci_cache=0x7fffd02112a0) at /opt/php-7.0.0alpha2/Zend/zend_execute_API.c:841 call_via_handler = 0 i = 1 calling_scope = 0x7ff4600d6840 call = 0x7ff460c16fc0 dummy_execute_data = {opline = 0x7ff45fc1a408, call = 0x7fffd02112e0, return_value = 0x7ff460c16fa0, func = 0x7ff45fc203c0, This = {value = {lval = 140736685216272, dval = 6,953316127493364e-310, counted = 0x7fffd0211210, str = 0x7fffd0211210, arr = 0x7fffd0211210, obj = 0x7fffd0211210, res = 0x7fffd0211210, ref = 0x7fffd0211210, ast = 0x7fffd0211210, zv = 0x7fffd0211210, ptr = 0x7fffd0211210, ce = 0x7fffd0211210, func = 0x7fffd0211210, ww = { w1 = 3491828240, w2 = 32767}}, u1 = {v = {type = 224 '\340', type_flags = 215 '\327', const_flags = 225 '\341', reserved = 95 '_'}, type_info = 1608636384}, u2 = {var_flags = 32756, next = 32756, cache_slot = 32756, lineno = 32756, num_args = 32756, fe_pos = 32756, fe_iter_idx = 32756}}, run_time_cache = 0x7ff45fc1a408, literals = 0x7ff460159fc0, called_scope = 0x7fffd0211210, prev_execute_data = 0xad272b <zend_fcall_info_args+37>, symbol_table = 0x7ff460c16fb0} fci_cache_local = {initialized = 144 '\220', function_handler = 0x40a00000000, calling_scope = 0x7ff45fe1d7f0, called_scope = 0x7ff45fc1a428, object = 0x7ff45fc1a428} func = 0x7ff460c10aa0 orig_scope = 0x7ff4601edab8 __PRETTY_FUNCTION__ = "zend_call_function" #6 0x00000000008f4f97 in zif_call_user_func_array (execute_data=0x7ff460c16f40, return_value=0x7ff460c16e40) at /opt/php-7.0.0alpha2/ext/standard/basic_functions.c:4805 params = 0x7ff460c16fb0 retval = {value = {lval = 0, dval = 0, counted = 0x0, str = 0x0, arr = 0x0, obj = 0x0, res = 0x0, ref = 0x0, ast = 0x0, zv = 0x0, ptr = 0x0, ce = 0x0, func = 0x0, ww = {w1 = 0, w2 = 0}}, u1 = {v = {type = 0 '\000', type_flags = 0 '\000', const_flags = 0 '\000', reserved = 0 '\000'}, type_info = 0}, u2 = {var_flags = 32756, next = 32756, cache_slot = 32756, lineno = 32756, num_args = 32756, fe_pos = 32756, fe_iter_idx = 32756}} fci = {size = 72, function_table = 0x7ff4600d6880, function_name = {value = {lval = 140687555298240, dval = 6,9508887870251033e-310, counted = 0x7ff45fc203c0, str = 0x7ff45fc203c0, arr = 0x7ff45fc203c0, obj = 0x7ff45fc203c0, res = 0x7ff45fc203c0, ref = 0x7ff45fc203c0, ast = 0x7ff45fc203c0, zv = 0x7ff45fc203c0, ptr = 0x7ff45fc203c0, ce = 0x7ff45fc203c0, func = 0x7ff45fc203c0, ww = {w1 = 1606550464, w2 = 32756}}, u1 = {v = {type = 7 '\a', type_flags = 28 '\034', const_flags = 0 '\000', reserved = 0 '\000'}, type_info = 7175}, u2 = {var_flags = 32767, next = 32767, cache_slot = 32767, lineno = 32767, num_args = 32767, fe_pos = 32767, fe_iter_idx = 32767}}, symbol_table = 0x0, retval = 0x7fffd0211290, params = 0x7ff45fe1d7e0, object = 0x7ff460c74240, no_separation = 1 '\001', param_count = 1} fci_cache = {initialized = 1 '\001', function_handler = 0x7ff460c10aa0, calling_scope = 0x7ff4600d6840, called_scope = 0x7ff4600d6840, object = 0x7ff460c74240} __PRETTY_FUNCTION__ = "zif_call_user_func_array" #7 0x0000000000b1e7a7 in ZEND_DO_FCALL_BY_NAME_SPEC_HANDLER () at /opt/php-7.0.0alpha2/Zend/zend_vm_execute.h:705 call = 0x7ff460c16f40 fbc = 0x279a720 ret = 0x7ff460c16e40 __PRETTY_FUNCTION__ = "ZEND_DO_FCALL_BY_NAME_SPEC_HANDLER" #8 0x0000000000b1dc3e in execute_ex (ex=0x7ff460c16030) at /opt/php-7.0.0alpha2/Zend/zend_vm_execute.h:403 orig_opline = 0x0 orig_execute_data = 0x0 #9 0x0000000000b1dd50 in zend_execute (op_array=0x7ff460c71000, return_value=0x0) at /opt/php-7.0.0alpha2/Zend/zend_vm_execute.h:447 execute_data = 0x7ff460c16030 #10 0x0000000000ac4559 in zend_execute_scripts (type=8, retval=0x0, file_count=3) at /opt/php-7.0.0alpha2/Zend/zend.c:1389 files = {{gp_offset = 40, fp_offset = 48, overflow_arg_area = 0x7fffd0211550, reg_save_area = 0x7fffd0211490}} i = 1 file_handle = 0x7fffd0213880 op_array = 0x7ff460c71000 #11 0x0000000000a31105 in php_execute_script (primary_file=0x7fffd0213880) at /opt/php-7.0.0alpha2/main/main.c:2475 realfile = "\001\333\336/\000\200\377\377\060(!\320\377\177\000\000\003", '\000' <repeats 31 times>, "\300\210\222\002\000\000\000\000\006\024\000\000\000\000\000\000\220u\202\r\000\000\000\000/\305\td\364\177\000\000\000\000\001\000\002\000\023\000+\000!\320\377\177\000\000\260-!\320\377\177", '\000' <repeats 34 times>, "\234N2l\364\177\000\000\377\377\377\377\377\377\377\377\220u\202\r\000\000\000\000\034\000\000\000\000\000\000\000D\000\000\000\000\000\000\000x:Ol\364\177\000\000\026X2l\364\177\000\000\002\000\000\000\000\000\000\000"... __orig_bailout = 0x7fffd02138f0 __bailout = {{__jmpbuf = {16, 5475004362929379715, 4497408, 140736685226864, 0, 0, 5475004361815792003, -5475041851745461885}, __mask_was_saved = 0, __saved_mask = {__val = {140736685222224, 193291665912, 18139557, 140736685225568, 11021397, 18446744069414584319, 8589934592, 8589934592, 0, 0, 140736685225408, 128, 140736685221808, 140736685221808, 140736685222208, 140736685222208}}}} prepend_file_p = 0x0 append_file_p = 0x0 ---Type <return> to continue, or q <return> to quit--- prepend_file = {handle = {fd = 0, fp = 0x0, stream = {handle = 0x0, isatty = 0, mmap = {len = 0, pos = 0, map = 0x0, buf = 0x0, old_handle = 0x0, old_closer = 0x0}, reader = 0x0, fsizer = 0x0, closer = 0x0}}, filename = 0x0, opened_path = 0x0, type = ZEND_HANDLE_FILENAME, free_filename = 0 '\000'} append_file = {handle = {fd = 0, fp = 0x0, stream = {handle = 0x0, isatty = 0, mmap = {len = 0, pos = 0, map = 0x0, buf = 0x0, old_handle = 0x0, old_closer = 0x0}, reader = 0x0, fsizer = 0x0, closer = 0x0}}, filename = 0x0, opened_path = 0x0, type = ZEND_HANDLE_FILENAME, free_filename = 0 '\000'} old_cwd = 0x7fffd0211550 "/" use_heap = 0 '\000' retval = 0 #12 0x0000000000b92382 in main (argc=3, argv=0x7fffd0213b78) at /opt/php-7.0.0alpha2/sapi/fpm/fpm/fpm_main.c:1941 primary_script = 0x7ff460c04500 "/var/www/hosts/rohlik.l/index.php" __orig_bailout = 0x0 __bailout = {{__jmpbuf = {0, 5475004362830813571, 4497408, 140736685226864, 0, 0, 5475004362931476867, -5475042041189197437}, __mask_was_saved = 0, __saved_mask = {__val = {4351400, 140687688703352, 4249168, 4294967296, 4294969392, 140736685226384, 140736685226728, 140736685226688, 140687765872784, 1, 140687766189344, 140687766188488, 140687763986833, 0, 140687765872784, 140685948747777}}}} exit_status = 0 cgi = 0 c = -1 use_extended_info = 0 file_handle = {handle = {fd = 1623614080, fp = 0x7ff460c66280, stream = {handle = 0x7ff460c66280, isatty = 0, mmap = {len = 553, pos = 0, map = 0x0, buf = 0x7ff46c50f000 <error: Cannot access memory at address 0x7ff46c50f000>, old_handle = 0x0, old_closer = 0x0}, reader = 0xa4ee67 <_php_stream_read>, fsizer = 0xa2e9ab <php_zend_stream_fsizer>, closer = 0xa2e985 <php_zend_stream_mmap_closer>}}, filename = 0x7ff460c04000 "/var/www/hosts/rohlik.l/index.php", opened_path = 0x0, type = ZEND_HANDLE_MAPPED, free_filename = 0 '\000'} orig_optind = 1 orig_optarg = 0x0 ini_entries_len = 0 max_requests = 500 requests = 0 fcgi_fd = 0 request = 0x292af20 fpm_config = 0x7fffd0214f6f "" fpm_prefix = 0x0 fpm_pid = 0x0 test_conf = 0 force_daemon = -1 force_stderr = 0 php_information = 0 php_allow_to_run_as_root = 0 __func__ = "main" ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=69816 -- Edit this bug report at https://bugs.php.net/bug.php?id=69816&edit=1

« previous php.bugs (#195200) next »