Edit report at https://bugs.php.net/bug.php?id=70805&edit=1
ID: 70805
Comment by: fabian at tag1consulting dot com
Reported by: alex dot a dot pott at gmail dot com
Summary: Segmentation faults whilst running Drupal 8 test
suite
Status: Feedback
Type: Bug
Package: Reproducible crash
Operating System: OS X & Linux
PHP Version: 7.0.0RC5
Block user comment: N
Private report: N
New Comment:
Together with setting:
#define GC_ROOT_BUFFER_MAX_ENTRIES 20001
the following script produces a segfault: A different backtrace, but it seems related so posting
here, as I hope that the fix for this script might also fix this issue here.
---
<?php
class Foo {
protected $list = [];
protected function doSomething($var) {
$var->ref = $this;
$this->list[] = $var;
}
public function init() {
$array = [];
for ($i = 0; $i < 19000; $i++) {
$array[] = new \StdClass();
}
foreach ($array as $value) {
$this->doSomething($value);
}
$this->list = [];
$array = [];
}
}
$foo = new Foo();
$foo->init();
---
Backtrace:
Program terminated with signal SIGSEGV, Segmentation fault.
#0 0x00000000009a3dce in gc_remove_from_roots (root=0x7f72b10e9050) at
/home/ubuntu/php7/php-src/Zend/zend_gc.c:120
120 root->prev->next = root->next;
Traceback (most recent call last):
File "/usr/share/gdb/auto-load/usr/lib/x86_64-linux-gnu/libstdc++.so.6.0.19-gdb.py",
line 63, in <module>
from libstdcxx.v6.printers import register_libstdcxx_printers
ImportError: No module named 'libstdcxx'
(gdb) bt
#0 0x00000000009a3dce in gc_remove_from_roots (root=0x7f72b10e9050) at
/home/ubuntu/php7/php-src/Zend/zend_gc.c:120
#1 0x00000000009a4326 in gc_remove_from_buffer (ref=0x7f72a87d9fa0) at
/home/ubuntu/php7/php-src/Zend/zend_gc.c:286
#2 0x00000000009bd0d8 in zend_objects_store_del (object=0x7f72a87d9fa0) at
/home/ubuntu/php7/php-src/Zend/zend_objects_API.c:190
#3 0x000000000096f190 in _zval_dtor_func_for_ptr (p=0x7f72a87d9fa0, __zend_filename=0xfc9940
"/home/ubuntu/php7/php-src/Zend/zend_hash.c",
__zend_lineno=1261) at /home/ubuntu/php7/php-src/Zend/zend_variables.c:109
#4 0x000000000098354e in i_zval_ptr_dtor (zval_ptr=0x7f72a7542fe8, __zend_filename=0xfc9940
"/home/ubuntu/php7/php-src/Zend/zend_hash.c",
__zend_lineno=1261) at /home/ubuntu/php7/php-src/Zend/zend_variables.h:58
#5 0x00000000009870a8 in zend_array_destroy (ht=0x7f72a8659540) at
/home/ubuntu/php7/php-src/Zend/zend_hash.c:1261
#6 0x000000000096f13a in _zval_dtor_func_for_ptr (p=0x7f72a8659540, __zend_filename=0xfcec40
"/home/ubuntu/php7/php-src/Zend/zend_execute.h",
__zend_lineno=103) at /home/ubuntu/php7/php-src/Zend/zend_variables.c:96
#7 0x00000000009c4fc3 in zend_assign_to_variable (variable_ptr=0x7f72a8614150,
value=0x7f72a8674410, value_type=1 '\001')
at /home/ubuntu/php7/php-src/Zend/zend_execute.h:103
#8 0x0000000000a0fbfc in ZEND_ASSIGN_SPEC_CV_CONST_HANDLER () at
/home/ubuntu/php7/php-src/Zend/zend_vm_execute.h:31718
#9 0x00000000009cd2ff in execute_ex (ex=0x7f72a8614030) at
/home/ubuntu/php7/php-src/Zend/zend_vm_execute.h:414
#10 0x00000000009cd411 in zend_execute (op_array=0x7f72a867e000, return_value=0x0) at
/home/ubuntu/php7/php-src/Zend/zend_vm_execute.h:458
#11 0x0000000000972c42 in zend_execute_scripts (type=8, retval=0x0, file_count=3) at
/home/ubuntu/php7/php-src/Zend/zend.c:1428
#12 0x00000000008e048d in php_execute_script (primary_file=0x7ffd2b501520) at
/home/ubuntu/php7/php-src/main/main.c:2471
#13 0x0000000000a31509 in do_cli (argc=2, argv=0x252fe40) at
/home/ubuntu/php7/php-src/sapi/cli/php_cli.c:974
#14 0x0000000000a326cd in main (argc=2, argv=0x252fe40) at
/home/ubuntu/php7/php-src/sapi/cli/php_cli.c:1345
Previous Comments:
------------------------------------------------------------------------
[2015-10-29 18:45:13] fabian at tag1consulting dot com
Some more information:
By setting:
#define GC_ROOT_BUFFER_MAX_ENTRIES 20001
in zend_gc.c the bug occurs way way earlier in the test run.
Also a normal call of index.php did give:
zend_gc_collect_cycles
php: /home/ubuntu/php7/php-src/Zend/zend_gc.c:226: gc_possible_root: Assertion
`(ref)->gc.u.v.type == 7 || (ref)->gc.u.v.type == 8' failed.
Aborted (core dumped)
Not sure if this is helpful yet, but getting closer to a reproducible script.
------------------------------------------------------------------------
[2015-10-29 18:11:44] fabian at tag1consulting dot com
It is possible that call_user_func_array() calls a class or function that itself calls
call_user_func_array() again after a while.
Especially with Dependency Injection that can happen quite easily.
--
I would love to have an easier repro case, but already simple changes like removing one of the
passes that affect the graph lead to the problem no longer being reproducible.
--
If you are using that channel could you invite 'Fabianx', 'neclimdul' and
'alexpott' to #php on FreeNode?
It would be great to discuss this bug more in real time ...
------------------------------------------------------------------------
[2015-10-29 17:14:07] ab@php.net
@neclimdul, still having a reproduce code were the preferable way. I've a question to ask yet.
Is call_user_func_array() called recursively? From the later backtrace, it might be good the case.
But such recursive calls are often causing stack overflow and there's no protection against
such stuff in PHP (I mean even in PHP5 and earlier). Could you guys please analyze this part? If it
is possible to extract a synthetic repro case, that would rock.
Thanks.
------------------------------------------------------------------------
[2015-10-29 17:08:04] ab@php.net
Yeah, I've just switched to MySQL to fix that. Now only can reproduce with APache, the dev
server just hangs. But tested also on Windows and can confirm the BT
> php7ts.dll!_emalloc(unsigned __int64 size) Line 2442 C
php7ts.dll!zend_array_dup(_zend_array * source) Line 1717 C
php7ts.dll!_zval_copy_ctor_func(_zval_struct * zvalue) Line 222 C
php7ts.dll!object_properties_init(_zend_object * object, _zend_class_entry * class_type) Line
1180 C
php7ts.dll!_object_and_properties_init(_zval_struct * arg, _zend_class_entry * class_type,
_zend_array * properties) Line 1285 C
php7ts.dll!ZEND_NEW_SPEC_CONST_HANDLER(_zend_execute_data * execute_data) Line 3356 C
php7ts.dll!execute_ex(_zend_execute_data * ex) Line 417 C
php7ts.dll!zend_call_function(_zend_fcall_info * fci, _zend_fcall_info_cache * fci_cache) Line
855 C
php7ts.dll!zif_call_user_func_array(_zend_execute_data * execute_data, _zval_struct *
return_value) Line 4809 C
php7ts.dll!ZEND_DO_FCALL_BY_NAME_SPEC_HANDLER(_zend_execute_data * execute_data) Line 723 C
php7ts.dll!execute_ex(_zend_execute_data * ex) Line 417 C
php7ts.dll!zend_call_function(_zend_fcall_info * fci, _zend_fcall_info_cache * fci_cache) Line
855 C
php7ts.dll!zif_call_user_func_array(_zend_execute_data * execute_data, _zval_struct *
return_value) Line 4809 C
php7ts.dll!ZEND_DO_FCALL_BY_NAME_SPEC_HANDLER(_zend_execute_data * execute_data) Line 723 C
php7ts.dll!execute_ex(_zend_execute_data * ex) Line 417 C
php7ts.dll!zend_execute(_zend_op_array * op_array, _zval_struct * return_value) Line 459 C
php7ts.dll!zend_execute_scripts(int type, _zval_struct * retval, int file_count, ...) Line 1429 C
php7ts.dll!php_execute_script(_zend_file_handle * primary_file) Line 2471 C
Thanks.
------------------------------------------------------------------------
[2015-10-29 16:52:38] neclimdul at gmail dot com
Sounds like the web user doesn't have access to your sites directory. Changing that should fix
the error.
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=70805
--
Edit this bug report at https://bugs.php.net/bug.php?id=70805&edit=1