Edit report at https://bugs.php.net/bug.php?id=70805&edit=1
ID: 70805
Updated by: dmitry@php.net
Reported by: alex dot a dot pott at gmail dot com
Summary: Segmentation faults whilst running Drupal 8 test
suite
Status: Feedback
Type: Bug
Package: Reproducible crash
Operating System: OS X & Linux
PHP Version: 7.0.0RC5
Assigned To: laruence
Block user comment: N
Private report: N
New Comment:
unset($a) or unser($GLOBAL["a"]) triggered GC and destructors calls that tried to release
the same global variable $a once again. As result it's reference counter was decremented twice
and this caused use-after-free, double-free, etc.
The proposed cumulative fix for all related problems:
https://gist.github.com/dstogov/7aa9d24876e2b3fce8c5
Previous Comments:
------------------------------------------------------------------------
[2015-11-02 14:31:14] fabian at tag1consulting dot com
I provided laruence with a EC2 instance, where the segfault happens.
------------------------------------------------------------------------
[2015-11-02 09:45:52] ab@php.net
I've managed to get a bit more concrete BT
ntdll.dll!00007ff9b8e54b74() Unknown
ucrtbase.dll!free() + 27 bytes Unknown
> php7ts.dll!zend_gc_collect_cycles() Line 1124 C
php7ts.dll!gc_possible_root(_zend_refcounted * ref=0x000000d059641220) Line 244 C
php7ts.dll!zend_leave_helper_SPEC(_zend_execute_data * execute_data=0x000000d056501040) Line 497 C
php7ts.dll!execute_ex(_zend_execute_data * ex) Line 417 C
php7ts.dll!zend_call_function(_zend_fcall_info * fci=0x000000d05602d950, _zend_fcall_info_cache *
fci_cache=0x000000d05602d9a0) Line 855 C
php7ts.dll!zif_call_user_func_array(_zend_execute_data * execute_data=0x000000d0564fd990,
_zval_struct * return_value=0x000000d0564fd980) Line 4809 C
php7ts.dll!ZEND_DO_FCALL_BY_NAME_SPEC_HANDLER(_zend_execute_data *
execute_data=0x000000d0564fd8c0) Line 723 C
php7ts.dll!execute_ex(_zend_execute_data * ex) Line 417 C
php7ts.dll!zend_call_function(_zend_fcall_info * fci=0x000000d05602dbc0, _zend_fcall_info_cache *
fci_cache=0x000000d05602dc10) Line 855 C
php7ts.dll!zif_call_user_func_array(_zend_execute_data * execute_data=0x000000d0564fd3d0,
_zval_struct * return_value=0x000000d0564fd260) Line 4809 C
php7ts.dll!ZEND_DO_FCALL_BY_NAME_SPEC_HANDLER(_zend_execute_data *
execute_data=0x000000d0564fcfa0) Line 723 C
php7ts.dll!execute_ex(_zend_execute_data * ex) Line 417 C
php7ts.dll!zend_execute(_zend_op_array * op_array, _zval_struct * return_value=0x0000000000000000)
Line 459 C
php7ts.dll!zend_execute_scripts(int type=8, _zval_struct * retval=0x0000000000000000, int
file_count=3, ...) Line 1429 C
php7ts.dll!php_execute_script(_zend_file_handle * primary_file=0x000000d05602f2b0) Line 2471 C
php7apache2_4.dll!php_handler(request_rec * r=0x000000d05916e278) Line 679 C
It looks indeed like a GC issue, most likely function args passed to call_user_func_array() are
double free'd.
Thanks.
------------------------------------------------------------------------
[2015-11-01 10:08:40] laruence@php.net
@alex , maybe you can grant me a ssh access to the reproducible box? (via mail)
thanks
------------------------------------------------------------------------
[2015-10-30 18:38:12] fabian at tag1consulting dot com
Another test that often fails is:
Drupal\\config\\Tests\\ConfigEntityListTest
And yes it needs several runs of creating and destroying ContainerBuilder instances, which really
makes it hard to reproduce.
------------------------------------------------------------------------
[2015-10-30 10:07:52] ab@php.net
After the further investigation, I can now reproduce the crash with Apache/mod_php on Windows almost
always and it gives the backtrice I've posted above. Can confirm that it always has to do with
the Symfony\\Component\\DependencyInjection\\Compiler\\ServiceReferenceGraphNode component and
related Drupal code. However it is only reproducible with the complete
Drupal\basic_auth\Tests\Authentication\BasicAuthTest test, running parts of it like
Drupal\basic_auth\Tests\Authentication\BasicAuthTest::testBasicAuth doesn't reproduce. It seems
that it's only reproducible when some criticall mass was reached and has less to do with the
concrete codes. So guess it'll be quite hard to write a reproduce script :( But it'd be
great to at least simplify it, like getting rid of the server part. Digging further.
Thanks.
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=70805
--
Edit this bug report at https://bugs.php.net/bug.php?id=70805&edit=1