Bug #70601 [Com]: Segfault in gc_remove_from_buffer()
| From: | hajo dot passon at form4 dot de | Date: | Mon, 05 Oct 2015 12:23:18 +0000 |
| Subject: | Bug #70601 [Com]: Segfault in gc_remove_from_buffer() | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-196399@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=70601&edit=1
ID: 70601
Comment by: hajo dot passon at form4 dot de
Reported by: p at wspnr dot com
Summary: Segfault in gc_remove_from_buffer()
Status: Closed
Type: Bug
Package: Reproducible crash
Operating System: Debian x86_64
PHP Version: 5.6Git-2015-09-29 (Git)
Assigned To: laruence
Block user comment: N
Private report: N
New Comment:
We encounter the same problem on 5.5.9-1ubuntu4.13. In the backtrace the gdb shows the same problem
at Zend/zend_gc.h:189.
Please, could someone backport the solution to 5.5?
Previous Comments:
------------------------------------------------------------------------
[2015-10-04 06:17:14] laruence@php.net
Automatic comment on behalf of laruence@gmail.com
Revision: http://git.php.net/?p=php-src.git;a=commit;h=c147d90dbfcc4f9fd494215b7e5740e497d818c1
Log: Fixed bug #70601 (Segfault in gc_remove_from_buffer())
------------------------------------------------------------------------
[2015-10-03 17:51:11] p at wspnr dot com
Applied patch and recompiled -- problem seems to be resolved!
------------------------------------------------------------------------
[2015-10-03 16:41:19] laruence@php.net
hmm, forget to say: please help verify the fix. :)
------------------------------------------------------------------------
[2015-10-03 16:38:34] laruence@php.net
okey, great, thanks for the script, I get what's going wrong there, a quick fix could be:
diff --git a/ext/opcache/Optimizer/pass1_5.c b/ext/opcache/Optimizer/pass1_5.c
index 4ed3dd4..949be9e 100644
--- a/ext/opcache/Optimizer/pass1_5.c
+++ b/ext/opcache/Optimizer/pass1_5.c
@@ -314,6 +314,8 @@ if (ZEND_OPTIMIZER_PASS_1 & OPTIMIZATION_LEVEL) {
ZEND_IS_CONSTANT_TYPE(Z_TYPE(t))) {
break;
}
+ } else if (Z_TYPE_PP(c) == IS_ARRAY) {
+ break;
} else {
t = **c;
zval_copy_ctor(&t);
anyway, I need discuss with Dmitry about this before I commit it..
thanks
------------------------------------------------------------------------
[2015-10-03 10:11:01] p at wspnr dot com
After some poking around with gdb, I've managed to narrow the issue down.
It only happens with opcache enabled, and with concurrent requests. I was using
ab -n 10000 -c
100 "http://my.server/crash.php"` to
test.
The following code causes the issue to appear:
-- BEGIN CODE --
<?php
class a {
const
REPLACEMENTS_PASS_1 = [
"\x00" => "", "\x01" => "", "\x02"
=> "", "\x03" => "",
"\x04" => "", "\x05" => "", "\x06" =>
"", "\x07" => "",
"\x08" => "", "\x0B" => "", "\x0C" =>
"", "\x0D" => "",
"\x0E" => "", "\x0F" => "", "\x10" =>
"", "\x11" => "",
"\x12" => "", "\x13" => "", "\x14" =>
"", "\x15" => "",
"\x16" => "", "\x17" => "", "\x18" =>
"", "\x19" => "",
"\x1A" => "", "\x1B" => "", "\x1C" =>
"", "\x1D" => "",
"\x1E" => "", "\x1F" => "", "\x7F" =>
"",
];
public function __construct() {
echo strtr("abcd", self::REPLACEMENTS_PASS_1);
}
}
new a();
-- END CODE --
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=70601
--
Edit this bug report at https://bugs.php.net/bug.php?id=70601&edit=1