Bug #70805 [Com]: Segmentation faults whilst running Drupal 8 test suite

From: Date: Thu, 29 Oct 2015 19:57:17 +0000
Subject: Bug #70805 [Com]: Segmentation faults whilst running Drupal 8 test suite
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-196893@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=70805&edit=1

 ID:                 70805
 Comment by:         fabian at tag1consulting dot com
 Reported by:        alex dot a dot pott at gmail dot com
 Summary:            Segmentation faults whilst running Drupal 8 test
                     suite
 Status:             Feedback
 Type:               Bug
 Package:            Reproducible crash
 Operating System:   OS X & Linux
 PHP Version:        7.0.0RC5
 Block user comment: N
 Private report:     N

 New Comment:

I managed to simplify, Still need the 20001 entry, but getting the original backtrace now:

1. Download Drupal 8
2. Install Drupal via LAMP stack (Still trying to avoid that)
3. Copy the following into front.php and run it:

<?php

use Drupal\Core\DrupalKernel;
use Symfony\Component\HttpFoundation\Request;

$autoloader = require_once 'autoload.php';

$request = Request::createFromGlobals();
$kernel = DrupalKernel::createFromRequest($request, $autoloader, 'prod', FALSE);
$kernel->boot();
$kernel->rebuildContainer();
print "OK".PHP_EOL;

Creates the usual backtrace:

Program received signal SIGSEGV, Segmentation fault.
0x000000000093ca6a in zend_mm_alloc_small (heap=0x7fffef400040, size=88, bin_num=9, 
    __zend_filename=0xfc9940 "/home/ubuntu/php7/php-src/Zend/zend_hash.c",
__zend_lineno=1716, __zend_orig_filename=0x0, __zend_orig_lineno=0)
    at /home/ubuntu/php7/php-src/Zend/zend_alloc.c:1291
1291			heap->free_slot[bin_num] = p->next_free_slot;
(gdb) bt
#0  0x000000000093ca6a in zend_mm_alloc_small (heap=0x7fffef400040, size=88, bin_num=9, 
    __zend_filename=0xfc9940 "/home/ubuntu/php7/php-src/Zend/zend_hash.c",
__zend_lineno=1716, __zend_orig_filename=0x0, __zend_orig_lineno=0)
    at /home/ubuntu/php7/php-src/Zend/zend_alloc.c:1291
#1  0x000000000093ccc1 in zend_mm_alloc_heap (heap=0x7fffef400040, size=88, __zend_filename=0xfc9940
"/home/ubuntu/php7/php-src/Zend/zend_hash.c", 
    __zend_lineno=1716, __zend_orig_filename=0x0, __zend_orig_lineno=0) at
/home/ubuntu/php7/php-src/Zend/zend_alloc.c:1359
#2  0x000000000093f724 in _emalloc (size=56, __zend_filename=0xfc9940
"/home/ubuntu/php7/php-src/Zend/zend_hash.c", __zend_lineno=1716,


Previous Comments:
------------------------------------------------------------------------
[2015-10-29 19:28:28] ab@php.net

Hm, but the script doesn't crash with the original case. We'd better have a reproducer for
the unchanged PHP to reproduce the original case as base.

Thanks.

------------------------------------------------------------------------
[2015-10-29 19:19:25] ab@php.net

@Fabian thanks for the further investigation. Seems that we really need a stable case to reproduce.
Right now it's really tedious as the most time is spent to setup Drupal and still no good
understanding what happens :(

Btw. the most of the core devs sit in #php.pecl on EFnet, it doesn't require special rights to
join.

Thanks.

------------------------------------------------------------------------
[2015-10-29 19:17:02] fabian at tag1consulting dot com

Together with setting:

   #define GC_ROOT_BUFFER_MAX_ENTRIES 20001

the following script produces a segfault: A different backtrace, but it seems related so posting
here, as I hope that the fix for this script might also fix this issue here.

---
<?php

class Foo {

  protected $list = [];

  protected function doSomething($var) {
    $var->ref = $this;
    $this->list[] = $var;
  }

  public function init() {
      $array = [];
      for ($i = 0; $i < 19000; $i++) {
        $array[] = new \StdClass();
      }

      foreach ($array as $value) {
        $this->doSomething($value);
      }

      $this->list = [];
      $array = [];
  }
}

$foo = new Foo();
$foo->init();
---

Backtrace:

Program terminated with signal SIGSEGV, Segmentation fault.
#0  0x00000000009a3dce in gc_remove_from_roots (root=0x7f72b10e9050) at
/home/ubuntu/php7/php-src/Zend/zend_gc.c:120
120		root->prev->next = root->next;
Traceback (most recent call last):
  File "/usr/share/gdb/auto-load/usr/lib/x86_64-linux-gnu/libstdc++.so.6.0.19-gdb.py",
line 63, in <module>
    from libstdcxx.v6.printers import register_libstdcxx_printers
ImportError: No module named 'libstdcxx'
(gdb) bt
#0  0x00000000009a3dce in gc_remove_from_roots (root=0x7f72b10e9050) at
/home/ubuntu/php7/php-src/Zend/zend_gc.c:120
#1  0x00000000009a4326 in gc_remove_from_buffer (ref=0x7f72a87d9fa0) at
/home/ubuntu/php7/php-src/Zend/zend_gc.c:286
#2  0x00000000009bd0d8 in zend_objects_store_del (object=0x7f72a87d9fa0) at
/home/ubuntu/php7/php-src/Zend/zend_objects_API.c:190
#3  0x000000000096f190 in _zval_dtor_func_for_ptr (p=0x7f72a87d9fa0, __zend_filename=0xfc9940
"/home/ubuntu/php7/php-src/Zend/zend_hash.c", 
    __zend_lineno=1261) at /home/ubuntu/php7/php-src/Zend/zend_variables.c:109
#4  0x000000000098354e in i_zval_ptr_dtor (zval_ptr=0x7f72a7542fe8, __zend_filename=0xfc9940
"/home/ubuntu/php7/php-src/Zend/zend_hash.c", 
    __zend_lineno=1261) at /home/ubuntu/php7/php-src/Zend/zend_variables.h:58
#5  0x00000000009870a8 in zend_array_destroy (ht=0x7f72a8659540) at
/home/ubuntu/php7/php-src/Zend/zend_hash.c:1261
#6  0x000000000096f13a in _zval_dtor_func_for_ptr (p=0x7f72a8659540, __zend_filename=0xfcec40
"/home/ubuntu/php7/php-src/Zend/zend_execute.h", 
    __zend_lineno=103) at /home/ubuntu/php7/php-src/Zend/zend_variables.c:96
#7  0x00000000009c4fc3 in zend_assign_to_variable (variable_ptr=0x7f72a8614150,
value=0x7f72a8674410, value_type=1 '\001')
    at /home/ubuntu/php7/php-src/Zend/zend_execute.h:103
#8  0x0000000000a0fbfc in ZEND_ASSIGN_SPEC_CV_CONST_HANDLER () at
/home/ubuntu/php7/php-src/Zend/zend_vm_execute.h:31718
#9  0x00000000009cd2ff in execute_ex (ex=0x7f72a8614030) at
/home/ubuntu/php7/php-src/Zend/zend_vm_execute.h:414
#10 0x00000000009cd411 in zend_execute (op_array=0x7f72a867e000, return_value=0x0) at
/home/ubuntu/php7/php-src/Zend/zend_vm_execute.h:458
#11 0x0000000000972c42 in zend_execute_scripts (type=8, retval=0x0, file_count=3) at
/home/ubuntu/php7/php-src/Zend/zend.c:1428
#12 0x00000000008e048d in php_execute_script (primary_file=0x7ffd2b501520) at
/home/ubuntu/php7/php-src/main/main.c:2471
#13 0x0000000000a31509 in do_cli (argc=2, argv=0x252fe40) at
/home/ubuntu/php7/php-src/sapi/cli/php_cli.c:974
#14 0x0000000000a326cd in main (argc=2, argv=0x252fe40) at
/home/ubuntu/php7/php-src/sapi/cli/php_cli.c:1345

------------------------------------------------------------------------
[2015-10-29 18:45:13] fabian at tag1consulting dot com

Some more information:

By setting:

#define GC_ROOT_BUFFER_MAX_ENTRIES 20001

in zend_gc.c the bug occurs way way earlier in the test run.

Also a normal call of index.php did give:

zend_gc_collect_cycles
php: /home/ubuntu/php7/php-src/Zend/zend_gc.c:226: gc_possible_root: Assertion
`(ref)->gc.u.v.type == 7 || (ref)->gc.u.v.type == 8' failed.
Aborted (core dumped)

Not sure if this is helpful yet, but getting closer to a reproducible script.

------------------------------------------------------------------------
[2015-10-29 18:11:44] fabian at tag1consulting dot com

It is possible that call_user_func_array() calls a class or function that itself calls
call_user_func_array() again after a while.

Especially with Dependency Injection that can happen quite easily.

--

I would love to have an easier repro case, but already simple changes like removing one of the
passes that affect the graph lead to the problem no longer being reproducible.

--

If you are using that channel could you invite 'Fabianx', 'neclimdul' and
'alexpott' to #php on FreeNode?

It would be great to discuss this bug more in real time ...

------------------------------------------------------------------------


The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at

    https://bugs.php.net/bug.php?id=70805


--
Edit this bug report at https://bugs.php.net/bug.php?id=70805&edit=1


Thread (23 messages)

« previous php.bugs (#196893) next »