Bug #70977 [Com]: Segmentation fault (core dumped) with opcache.huge_code_pages=1

From: Date: Fri, 27 Nov 2015 14:42:13 +0000
Subject: Bug #70977 [Com]: Segmentation fault (core dumped) with opcache.huge_code_pages=1
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-197464@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=70977&edit=1 ID: 70977 Comment by: remi@php.net Reported by: reynierpm at gmail dot com Summary: Segmentation fault (core dumped) with opcache.huge_code_pages=1 Status: Feedback Type: Bug Package: Reproducible crash Operating System: CentOS 6.7 PHP Version: 7.0.0RC8 Assigned To: laruence Block user comment: N Private report: N New Comment: With latest laruence's patch, segfault disappear. Previous Comments: ------------------------------------------------------------------------ [2015-11-27 11:40:21] laruence@php.net sorry, wrong paste, use this instead: http://pastebin.com/sqXMzZLT ------------------------------------------------------------------------ [2015-11-27 11:01:40] laruence@php.net could you please try the patch here? : http://pastebin.com/Xg2eVzYq thanks ------------------------------------------------------------------------ [2015-11-26 16:43:08] remi@php.net With patch proposed on 70973, same segfault. ------------------------------------------------------------------------ [2015-11-26 16:10:43] nikic@php.net @remi: That commit looks suspicious. If I get the code right, this means that we'll skip memcpy'ing the text segment back into the newly mapped memory if the madvise fails. This means that when control flow returns to the PHP text segment we're executing uninitialized memory. Btw, is it possible to map these as PROT_READ | PROT_WRITE only? I know it's only temporary, but it doesn't seem necessary to have this as w+x memory. ------------------------------------------------------------------------ [2015-11-26 16:01:29] remi@php.net @laruence: I'm giving first a try to http://git.php.net/?p=php-src.git;a=commitdiff;h=eb59dd7d8137c6567afcd579bcb3bd0298f5bbc4 which is not part of RC8 ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=70977 -- Edit this bug report at https://bugs.php.net/bug.php?id=70977&edit=1

« previous php.bugs (#197464) next »