Bug #70805 [Fbk]: Segmentation faults whilst running Drupal 8 test suite

From: Date: Thu, 29 Oct 2015 19:28:28 +0000
Subject: Bug #70805 [Fbk]: Segmentation faults whilst running Drupal 8 test suite
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-196892@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=70805&edit=1

 ID:                 70805
 Updated by:         ab@php.net
 Reported by:        alex dot a dot pott at gmail dot com
 Summary:            Segmentation faults whilst running Drupal 8 test
                     suite
 Status:             Feedback
 Type:               Bug
 Package:            Reproducible crash
 Operating System:   OS X & Linux
 PHP Version:        7.0.0RC5
 Block user comment: N
 Private report:     N

 New Comment:

Hm, but the script doesn't crash with the original case. We'd better have a reproducer for
the unchanged PHP to reproduce the original case as base.

Thanks.


Previous Comments:
------------------------------------------------------------------------
[2015-10-29 19:19:25] ab@php.net

@Fabian thanks for the further investigation. Seems that we really need a stable case to reproduce.
Right now it's really tedious as the most time is spent to setup Drupal and still no good
understanding what happens :(

Btw. the most of the core devs sit in #php.pecl on EFnet, it doesn't require special rights to
join.

Thanks.

------------------------------------------------------------------------
[2015-10-29 19:17:02] fabian at tag1consulting dot com

Together with setting:

   #define GC_ROOT_BUFFER_MAX_ENTRIES 20001

the following script produces a segfault: A different backtrace, but it seems related so posting
here, as I hope that the fix for this script might also fix this issue here.

---
<?php

class Foo {

  protected $list = [];

  protected function doSomething($var) {
    $var->ref = $this;
    $this->list[] = $var;
  }

  public function init() {
      $array = [];
      for ($i = 0; $i < 19000; $i++) {
        $array[] = new \StdClass();
      }

      foreach ($array as $value) {
        $this->doSomething($value);
      }

      $this->list = [];
      $array = [];
  }
}

$foo = new Foo();
$foo->init();
---

Backtrace:

Program terminated with signal SIGSEGV, Segmentation fault.
#0  0x00000000009a3dce in gc_remove_from_roots (root=0x7f72b10e9050) at
/home/ubuntu/php7/php-src/Zend/zend_gc.c:120
120		root->prev->next = root->next;
Traceback (most recent call last):
  File "/usr/share/gdb/auto-load/usr/lib/x86_64-linux-gnu/libstdc++.so.6.0.19-gdb.py",
line 63, in <module>
    from libstdcxx.v6.printers import register_libstdcxx_printers
ImportError: No module named 'libstdcxx'
(gdb) bt
#0  0x00000000009a3dce in gc_remove_from_roots (root=0x7f72b10e9050) at
/home/ubuntu/php7/php-src/Zend/zend_gc.c:120
#1  0x00000000009a4326 in gc_remove_from_buffer (ref=0x7f72a87d9fa0) at
/home/ubuntu/php7/php-src/Zend/zend_gc.c:286
#2  0x00000000009bd0d8 in zend_objects_store_del (object=0x7f72a87d9fa0) at
/home/ubuntu/php7/php-src/Zend/zend_objects_API.c:190
#3  0x000000000096f190 in _zval_dtor_func_for_ptr (p=0x7f72a87d9fa0, __zend_filename=0xfc9940
"/home/ubuntu/php7/php-src/Zend/zend_hash.c", 
    __zend_lineno=1261) at /home/ubuntu/php7/php-src/Zend/zend_variables.c:109
#4  0x000000000098354e in i_zval_ptr_dtor (zval_ptr=0x7f72a7542fe8, __zend_filename=0xfc9940
"/home/ubuntu/php7/php-src/Zend/zend_hash.c", 
    __zend_lineno=1261) at /home/ubuntu/php7/php-src/Zend/zend_variables.h:58
#5  0x00000000009870a8 in zend_array_destroy (ht=0x7f72a8659540) at
/home/ubuntu/php7/php-src/Zend/zend_hash.c:1261
#6  0x000000000096f13a in _zval_dtor_func_for_ptr (p=0x7f72a8659540, __zend_filename=0xfcec40
"/home/ubuntu/php7/php-src/Zend/zend_execute.h", 
    __zend_lineno=103) at /home/ubuntu/php7/php-src/Zend/zend_variables.c:96
#7  0x00000000009c4fc3 in zend_assign_to_variable (variable_ptr=0x7f72a8614150,
value=0x7f72a8674410, value_type=1 '\001')
    at /home/ubuntu/php7/php-src/Zend/zend_execute.h:103
#8  0x0000000000a0fbfc in ZEND_ASSIGN_SPEC_CV_CONST_HANDLER () at
/home/ubuntu/php7/php-src/Zend/zend_vm_execute.h:31718
#9  0x00000000009cd2ff in execute_ex (ex=0x7f72a8614030) at
/home/ubuntu/php7/php-src/Zend/zend_vm_execute.h:414
#10 0x00000000009cd411 in zend_execute (op_array=0x7f72a867e000, return_value=0x0) at
/home/ubuntu/php7/php-src/Zend/zend_vm_execute.h:458
#11 0x0000000000972c42 in zend_execute_scripts (type=8, retval=0x0, file_count=3) at
/home/ubuntu/php7/php-src/Zend/zend.c:1428
#12 0x00000000008e048d in php_execute_script (primary_file=0x7ffd2b501520) at
/home/ubuntu/php7/php-src/main/main.c:2471
#13 0x0000000000a31509 in do_cli (argc=2, argv=0x252fe40) at
/home/ubuntu/php7/php-src/sapi/cli/php_cli.c:974
#14 0x0000000000a326cd in main (argc=2, argv=0x252fe40) at
/home/ubuntu/php7/php-src/sapi/cli/php_cli.c:1345

------------------------------------------------------------------------
[2015-10-29 18:45:13] fabian at tag1consulting dot com

Some more information:

By setting:

#define GC_ROOT_BUFFER_MAX_ENTRIES 20001

in zend_gc.c the bug occurs way way earlier in the test run.

Also a normal call of index.php did give:

zend_gc_collect_cycles
php: /home/ubuntu/php7/php-src/Zend/zend_gc.c:226: gc_possible_root: Assertion
`(ref)->gc.u.v.type == 7 || (ref)->gc.u.v.type == 8' failed.
Aborted (core dumped)

Not sure if this is helpful yet, but getting closer to a reproducible script.

------------------------------------------------------------------------
[2015-10-29 18:11:44] fabian at tag1consulting dot com

It is possible that call_user_func_array() calls a class or function that itself calls
call_user_func_array() again after a while.

Especially with Dependency Injection that can happen quite easily.

--

I would love to have an easier repro case, but already simple changes like removing one of the
passes that affect the graph lead to the problem no longer being reproducible.

--

If you are using that channel could you invite 'Fabianx', 'neclimdul' and
'alexpott' to #php on FreeNode?

It would be great to discuss this bug more in real time ...

------------------------------------------------------------------------
[2015-10-29 17:14:07] ab@php.net

@neclimdul, still having a reproduce code were the preferable way. I've a question to ask yet.

Is call_user_func_array() called recursively? From the later backtrace, it might be good the case.
But such recursive calls are often causing stack overflow and there's no protection against
such stuff in PHP (I mean even in PHP5 and earlier). Could you guys please analyze this part? If it
is possible to extract a synthetic repro case, that would rock.

Thanks.

------------------------------------------------------------------------


The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at

    https://bugs.php.net/bug.php?id=70805


--
Edit this bug report at https://bugs.php.net/bug.php?id=70805&edit=1


Thread (23 messages)

« previous php.bugs (#196892) next »