Bug #70601 [Com]: Segfault in gc_remove_from_buffer()

From: Date: Mon, 05 Oct 2015 12:23:18 +0000
Subject: Bug #70601 [Com]: Segfault in gc_remove_from_buffer()
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-196399@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=70601&edit=1 ID: 70601 Comment by: hajo dot passon at form4 dot de Reported by: p at wspnr dot com Summary: Segfault in gc_remove_from_buffer() Status: Closed Type: Bug Package: Reproducible crash Operating System: Debian x86_64 PHP Version: 5.6Git-2015-09-29 (Git) Assigned To: laruence Block user comment: N Private report: N New Comment: We encounter the same problem on 5.5.9-1ubuntu4.13. In the backtrace the gdb shows the same problem at Zend/zend_gc.h:189. Please, could someone backport the solution to 5.5? Previous Comments: ------------------------------------------------------------------------ [2015-10-04 06:17:14] laruence@php.net Automatic comment on behalf of laruence@gmail.com Revision: http://git.php.net/?p=php-src.git;a=commit;h=c147d90dbfcc4f9fd494215b7e5740e497d818c1 Log: Fixed bug #70601 (Segfault in gc_remove_from_buffer()) ------------------------------------------------------------------------ [2015-10-03 17:51:11] p at wspnr dot com Applied patch and recompiled -- problem seems to be resolved! ------------------------------------------------------------------------ [2015-10-03 16:41:19] laruence@php.net hmm, forget to say: please help verify the fix. :) ------------------------------------------------------------------------ [2015-10-03 16:38:34] laruence@php.net okey, great, thanks for the script, I get what's going wrong there, a quick fix could be: diff --git a/ext/opcache/Optimizer/pass1_5.c b/ext/opcache/Optimizer/pass1_5.c index 4ed3dd4..949be9e 100644 --- a/ext/opcache/Optimizer/pass1_5.c +++ b/ext/opcache/Optimizer/pass1_5.c @@ -314,6 +314,8 @@ if (ZEND_OPTIMIZER_PASS_1 & OPTIMIZATION_LEVEL) { ZEND_IS_CONSTANT_TYPE(Z_TYPE(t))) { break; } + } else if (Z_TYPE_PP(c) == IS_ARRAY) { + break; } else { t = **c; zval_copy_ctor(&t); anyway, I need discuss with Dmitry about this before I commit it.. thanks ------------------------------------------------------------------------ [2015-10-03 10:11:01] p at wspnr dot com After some poking around with gdb, I've managed to narrow the issue down. It only happens with opcache enabled, and with concurrent requests. I was using ab -n 10000 -c 100 "http://my.server/crash.php"` to test. The following code causes the issue to appear: -- BEGIN CODE -- <?php class a { const REPLACEMENTS_PASS_1 = [ "\x00" => "", "\x01" => "", "\x02" => "", "\x03" => "", "\x04" => "", "\x05" => "", "\x06" => "", "\x07" => "", "\x08" => "", "\x0B" => "", "\x0C" => "", "\x0D" => "", "\x0E" => "", "\x0F" => "", "\x10" => "", "\x11" => "", "\x12" => "", "\x13" => "", "\x14" => "", "\x15" => "", "\x16" => "", "\x17" => "", "\x18" => "", "\x19" => "", "\x1A" => "", "\x1B" => "", "\x1C" => "", "\x1D" => "", "\x1E" => "", "\x1F" => "", "\x7F" => "", ]; public function __construct() { echo strtr("abcd", self::REPLACEMENTS_PASS_1); } } new a(); -- END CODE -- ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=70601 -- Edit this bug report at https://bugs.php.net/bug.php?id=70601&edit=1

« previous php.bugs (#196399) next »