Bug #71342 [Fbk->Opn]: Crash in "zend_mm_gc"

From: Date: Mon, 18 Jan 2016 02:53:55 +0000
Subject: Bug #71342 [Fbk->Opn]: Crash in "zend_mm_gc"
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-198743@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=71342&edit=1

 ID:                 71342
 User updated by:    michael dot hartmann at refx dot com
 Reported by:        michael dot hartmann at refx dot com
 Summary:            Crash in "zend_mm_gc"
-Status:             Feedback
+Status:             Open
 Type:               Bug
 Package:            Reproducible crash
 Operating System:   Windows 10
 PHP Version:        7.0.2
 Block user comment: N
 Private report:     N

 New Comment:

I wish I could send you a short script that causes it, but it seems everything "simple"
just works.

This website uses AltoRouter, Twig and some custom functions (mainly Twig extensions) to render our
website.

How do I create the core-dump or a complete backtrace? Keep in mind, I can't run this in the
command-line.

My offer that somebody trustworthy does a remote-desktop session and works on my computer directly
still stands.


Previous Comments:
------------------------------------------------------------------------
[2016-01-17 19:41:48] ab@php.net

@michael thanks for the follow up. Were it possible you to extract a small reproduce case? A
backtrace or a core dump could be very helpful, too. Please exclude any non core extensions while
doing that.

Thanks.

------------------------------------------------------------------------
[2016-01-14 22:28:57] michael dot hartmann at refx dot com

I've removed YAML from my php.ini and replaced the necessary functions with the Symfony/YAML
parser. It is definitely more stable, but still crashes in 10% of the cases at the exact same
location.

Except Wincache, this PHP 7.0.2 installation is vanilla.

Also I can only manage to make it crash if I reload a certain page that does array-value
manipulations like this:

// Assign specific display parameters to each price
foreach ($prices as &$prc)
{
	$price = $prc[$_SESSION['GEO']['CURRENCY']];
	$price = $price < 79? ceil($price) : floor($price);

	$prc['PRICE'] = number_format($price, 0, $prdDisp['DECIMAL'],
$prdDisp['THOU']);

	// Christmas pricing active?
	if ($this->config['B_CHRISTMAS_PRICES'])
	{
		$prc['OLD_PRICE'] = $prc['PRICE'];

		$price = $prc[$_SESSION['GEO']['CURRENCY'] . '_SPEC'];
		$price = $price < 79? ceil($price) : floor($price);

		$prc['PRICE'] = number_format($price, 0, $prdDisp['DECIMAL'],
$prdDisp['THOU']);
	}
}

// Assign various properties to products
foreach ($products as &$prd)
{
	// Slug
	$prd['SLUG'] = trim(preg_replace('/[^a-z0-9-]+/', '-',
strtolower($prd['DISPLAY_NAME'])), "-");

	// Price
	$price = $prices[$prd['PRICE_CATEGORY']];
	if ($price['PRICE'] != '0')
	{
		$prd['PRICE'] = $price['PRICE'];
		if ($price['OLD_PRICE'])
		{
			$prd['OLD_PRICE'] = $price['OLD_PRICE'];
		}
		$prd['CURRENCY'] = $prdDisp['SYMBOL'];
	}

	// Age
	$prd['NEW'] = (time() - strtotime($prd['RELEASEDATE'])) < (90 * 24 * 60 *
60);
}

As you can see, I add new array-elements in the foreach loop and I work on references instead of the
values.

If I comment this code out, then (even with the yaml.dll) the website get's a LOT more stable.

------------------------------------------------------------------------
[2016-01-12 03:30:43] laruence@php.net

btw, I think it probably relates to YAML, could you try with out it? (like use a pure php
implementation of Yaml instead ext)

------------------------------------------------------------------------
[2016-01-12 03:30:05] laruence@php.net

Thank you for this bug report. To properly diagnose the problem, we
need a short but complete example script to be able to reproduce
this bug ourselves. 

A proper reproducing script starts with <?php and ends with ?>,
is max. 10-20 lines long and does not require any external 
resources such as databases, etc. If the script requires a 
database to demonstrate the issue, please make sure it creates 
all necessary tables, stored procedures etc.

Please avoid embedding huge scripts into the report.



------------------------------------------------------------------------
[2016-01-11 22:35:35] michael dot hartmann at refx dot com

Description:
------------
Downloaded Windows PHP 7.0.2 x64 (NTS), Wincache 2.0.0.4 and YAML 2.0.0(RC7)

Website works 20% of the time, the other 80% of the time I get:

Faulting application name: php-cgi.exe, version: 7.0.2.0, time stamp: 0x568d8141
Faulting module name: php7.dll, version: 7.0.2.0, time stamp: 0x568d8c40
Exception code: 0xc0000005
Fault offset: 0x000000000039be3e
Faulting process id: 0xe58
Faulting application start time: 0x01d14cbc989dfd84
Faulting application path: E:\PHP7\php-cgi.exe
Faulting module path: E:\PHP7\php7.dll
Report Id: 4d36902c-9377-4fb8-bb37-890a846cf0a4
Faulting package full name: 
Faulting package-relative application ID: 

In the event-viewer

I've used a 3rd party tool to find the fault address, which seems to be

zend_mm_gc + 6E

so it seems it crashes somewhere in the garbage collector.

With 7.0.0 and 7.0.1 I got 100% crashes and the site never worked.

Site is working perfectly fine in all PHP 5.5 and 5.6 versions.

If need be, I would be open for a remote-desktop session from a trusted developer to diagnose the
problem further.



------------------------------------------------------------------------



--
Edit this bug report at https://bugs.php.net/bug.php?id=71342&edit=1


Thread (14 messages)

« previous php.bugs (#198743) next »