Bug #70977 [Fbk->Csd]: Segmentation fault (core dumped) with opcache.huge_code_pages=1
| From: | laruence@php.net | Date: | Fri, 27 Nov 2015 15:32:34 +0000 |
| Subject: | Bug #70977 [Fbk->Csd]: Segmentation fault (core dumped) with opcache.huge_code_pages=1 | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-197468@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=70977&edit=1
ID: 70977
Updated by: laruence@php.net
Reported by: reynierpm at gmail dot com
Summary: Segmentation fault (core dumped) with
opcache.huge_code_pages=1
-Status: Feedback
+Status: Closed
Type: Bug
Package: Reproducible crash
Operating System: CentOS 6.7
PHP Version: 7.0.0RC8
Assigned To: laruence
Block user comment: N
Private report: N
New Comment:
Automatic comment on behalf of laruence@gmail.com
Revision: http://git.php.net/?p=php-src.git;a=commit;h=e9a8d7ff1d59cbcaf4b5cec728a94fb0d54dd993
Log: Fixed bug #70977, #70973 (Segmentation fault with opcache.huge_code_pages=1)
Previous Comments:
------------------------------------------------------------------------
[2015-11-27 14:42:12] remi@php.net
With latest laruence's patch, segfault disappear.
------------------------------------------------------------------------
[2015-11-27 11:40:21] laruence@php.net
sorry, wrong paste, use this instead: http://pastebin.com/sqXMzZLT
------------------------------------------------------------------------
[2015-11-27 11:01:40] laruence@php.net
could you please try the patch here? : http://pastebin.com/Xg2eVzYq
thanks
------------------------------------------------------------------------
[2015-11-26 16:43:08] remi@php.net
With patch proposed on 70973, same segfault.
------------------------------------------------------------------------
[2015-11-26 16:10:43] nikic@php.net
@remi: That commit looks suspicious. If I get the code right, this means that we'll skip
memcpy'ing the text segment back into the newly mapped memory if the madvise fails. This means
that when control flow returns to the PHP text segment we're executing uninitialized memory.
Btw, is it possible to map these as PROT_READ | PROT_WRITE only? I know it's only temporary,
but it doesn't seem necessary to have this as w+x memory.
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=70977
--
Edit this bug report at https://bugs.php.net/bug.php?id=70977&edit=1