Bug #70805 [Fbk]: Segmentation faults whilst running Drupal 8 test suite

From: Date: Tue, 03 Nov 2015 19:55:11 +0000
Subject: Bug #70805 [Fbk]: Segmentation faults whilst running Drupal 8 test suite
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-197001@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=70805&edit=1

 ID:                 70805
 Updated by:         dmitry@php.net
 Reported by:        alex dot a dot pott at gmail dot com
 Summary:            Segmentation faults whilst running Drupal 8 test
                     suite
 Status:             Feedback
 Type:               Bug
 Package:            Reproducible crash
 Operating System:   OS X & Linux
 PHP Version:        7.0.0RC5
 Assigned To:        laruence
 Block user comment: N
 Private report:     N

 New Comment:

unset($a) or unser($GLOBAL["a"]) triggered GC and destructors calls that tried to release
the same global variable $a  once again. As result it's reference counter was decremented twice
and this caused use-after-free, double-free, etc.

The proposed cumulative fix for all related problems:

https://gist.github.com/dstogov/7aa9d24876e2b3fce8c5


Previous Comments:
------------------------------------------------------------------------
[2015-11-02 14:31:14] fabian at tag1consulting dot com

I provided laruence with a EC2 instance, where the segfault happens.

------------------------------------------------------------------------
[2015-11-02 09:45:52] ab@php.net

I've managed to get a bit more concrete BT

 	ntdll.dll!00007ff9b8e54b74()	Unknown
 	ucrtbase.dll!free() + 27 bytes	Unknown
>	php7ts.dll!zend_gc_collect_cycles() Line 1124	C
 	php7ts.dll!gc_possible_root(_zend_refcounted * ref=0x000000d059641220) Line 244	C
 	php7ts.dll!zend_leave_helper_SPEC(_zend_execute_data * execute_data=0x000000d056501040) Line 497	C
 	php7ts.dll!execute_ex(_zend_execute_data * ex) Line 417	C
 	php7ts.dll!zend_call_function(_zend_fcall_info * fci=0x000000d05602d950, _zend_fcall_info_cache *
fci_cache=0x000000d05602d9a0) Line 855	C
 	php7ts.dll!zif_call_user_func_array(_zend_execute_data * execute_data=0x000000d0564fd990,
_zval_struct * return_value=0x000000d0564fd980) Line 4809	C
 	php7ts.dll!ZEND_DO_FCALL_BY_NAME_SPEC_HANDLER(_zend_execute_data *
execute_data=0x000000d0564fd8c0) Line 723	C
 	php7ts.dll!execute_ex(_zend_execute_data * ex) Line 417	C
 	php7ts.dll!zend_call_function(_zend_fcall_info * fci=0x000000d05602dbc0, _zend_fcall_info_cache *
fci_cache=0x000000d05602dc10) Line 855	C
 	php7ts.dll!zif_call_user_func_array(_zend_execute_data * execute_data=0x000000d0564fd3d0,
_zval_struct * return_value=0x000000d0564fd260) Line 4809	C
 	php7ts.dll!ZEND_DO_FCALL_BY_NAME_SPEC_HANDLER(_zend_execute_data *
execute_data=0x000000d0564fcfa0) Line 723	C
 	php7ts.dll!execute_ex(_zend_execute_data * ex) Line 417	C
 	php7ts.dll!zend_execute(_zend_op_array * op_array, _zval_struct * return_value=0x0000000000000000)
Line 459	C
 	php7ts.dll!zend_execute_scripts(int type=8, _zval_struct * retval=0x0000000000000000, int
file_count=3, ...) Line 1429	C
 	php7ts.dll!php_execute_script(_zend_file_handle * primary_file=0x000000d05602f2b0) Line 2471	C
 	php7apache2_4.dll!php_handler(request_rec * r=0x000000d05916e278) Line 679	C

It looks indeed like a GC issue, most likely function args passed to call_user_func_array() are
double free'd. 

Thanks.

------------------------------------------------------------------------
[2015-11-01 10:08:40] laruence@php.net

@alex , maybe you can grant me a ssh access to the reproducible box? (via mail)

thanks

------------------------------------------------------------------------
[2015-10-30 18:38:12] fabian at tag1consulting dot com

Another test that often fails is:

Drupal\\config\\Tests\\ConfigEntityListTest

And yes it needs several runs of creating and destroying ContainerBuilder instances, which really
makes it hard to reproduce.

------------------------------------------------------------------------
[2015-10-30 10:07:52] ab@php.net

After the further investigation, I can now reproduce the crash with Apache/mod_php on Windows almost
always and it gives the backtrice I've posted above. Can confirm that it always has to do with
the Symfony\\Component\\DependencyInjection\\Compiler\\ServiceReferenceGraphNode component and
related Drupal code. However it is only reproducible with the complete
Drupal\basic_auth\Tests\Authentication\BasicAuthTest test, running parts of it like
Drupal\basic_auth\Tests\Authentication\BasicAuthTest::testBasicAuth doesn't reproduce. It seems
that it's only reproducible when some criticall mass was reached and has less to do with the
concrete codes. So guess it'll be quite hard to write a reproduce script :( But it'd be
great to at least simplify it, like getting rid of the server part. Digging further.

Thanks.

------------------------------------------------------------------------


The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at

    https://bugs.php.net/bug.php?id=70805


--
Edit this bug report at https://bugs.php.net/bug.php?id=70805&edit=1


Thread (23 messages)

« previous php.bugs (#197001) next »