Bug #70601 [Asn->Csd]: Segfault in gc_remove_from_buffer()

From: Date: Sun, 04 Oct 2015 06:17:15 +0000
Subject: Bug #70601 [Asn->Csd]: Segfault in gc_remove_from_buffer()
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-196382@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=70601&edit=1 ID: 70601 Updated by: laruence@php.net Reported by: p at wspnr dot com Summary: Segfault in gc_remove_from_buffer() -Status: Assigned +Status: Closed Type: Bug Package: Reproducible crash Operating System: Debian x86_64 PHP Version: 5.6Git-2015-09-29 (Git) Assigned To: laruence Block user comment: N Private report: N New Comment: Automatic comment on behalf of laruence@gmail.com Revision: http://git.php.net/?p=php-src.git;a=commit;h=c147d90dbfcc4f9fd494215b7e5740e497d818c1 Log: Fixed bug #70601 (Segfault in gc_remove_from_buffer()) Previous Comments: ------------------------------------------------------------------------ [2015-10-03 17:51:11] p at wspnr dot com Applied patch and recompiled -- problem seems to be resolved! ------------------------------------------------------------------------ [2015-10-03 16:41:19] laruence@php.net hmm, forget to say: please help verify the fix. :) ------------------------------------------------------------------------ [2015-10-03 16:38:34] laruence@php.net okey, great, thanks for the script, I get what's going wrong there, a quick fix could be: diff --git a/ext/opcache/Optimizer/pass1_5.c b/ext/opcache/Optimizer/pass1_5.c index 4ed3dd4..949be9e 100644 --- a/ext/opcache/Optimizer/pass1_5.c +++ b/ext/opcache/Optimizer/pass1_5.c @@ -314,6 +314,8 @@ if (ZEND_OPTIMIZER_PASS_1 & OPTIMIZATION_LEVEL) { ZEND_IS_CONSTANT_TYPE(Z_TYPE(t))) { break; } + } else if (Z_TYPE_PP(c) == IS_ARRAY) { + break; } else { t = **c; zval_copy_ctor(&t); anyway, I need discuss with Dmitry about this before I commit it.. thanks ------------------------------------------------------------------------ [2015-10-03 10:11:01] p at wspnr dot com After some poking around with gdb, I've managed to narrow the issue down. It only happens with opcache enabled, and with concurrent requests. I was using ab -n 10000 -c 100 "http://my.server/crash.php"` to test. The following code causes the issue to appear: -- BEGIN CODE -- <?php class a { const REPLACEMENTS_PASS_1 = [ "\x00" => "", "\x01" => "", "\x02" => "", "\x03" => "", "\x04" => "", "\x05" => "", "\x06" => "", "\x07" => "", "\x08" => "", "\x0B" => "", "\x0C" => "", "\x0D" => "", "\x0E" => "", "\x0F" => "", "\x10" => "", "\x11" => "", "\x12" => "", "\x13" => "", "\x14" => "", "\x15" => "", "\x16" => "", "\x17" => "", "\x18" => "", "\x19" => "", "\x1A" => "", "\x1B" => "", "\x1C" => "", "\x1D" => "", "\x1E" => "", "\x1F" => "", "\x7F" => "", ]; public function __construct() { echo strtr("abcd", self::REPLACEMENTS_PASS_1); } } new a(); -- END CODE -- ------------------------------------------------------------------------ [2015-10-02 14:25:37] laruence@php.net Thank you for this bug report. To properly diagnose the problem, we need a short but complete example script to be able to reproduce this bug ourselves. A proper reproducing script starts with <?php and ends with ?>, is max. 10-20 lines long and does not require any external resources such as databases, etc. If the script requires a database to demonstrate the issue, please make sure it creates all necessary tables, stored procedures etc. Please avoid embedding huge scripts into the report. I am sorry, but if no reproduce script provided, we can not do much things here.. ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=70601 -- Edit this bug report at https://bugs.php.net/bug.php?id=70601&edit=1

« previous php.bugs (#196382) next »