Bug #71342 [Opn]: Crash in "zend_mm_gc"

From: Date: Tue, 19 Jan 2016 23:34:24 +0000
Subject: Bug #71342 [Opn]: Crash in "zend_mm_gc"
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-198781@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=71342&edit=1

 ID:                 71342
 User updated by:    michael dot hartmann at refx dot com
 Reported by:        michael dot hartmann at refx dot com
 Summary:            Crash in "zend_mm_gc"
 Status:             Open
 Type:               Bug
 Package:            Reproducible crash
 Operating System:   Windows 10
 PHP Version:        7.0.2
 Block user comment: N
 Private report:     N

 New Comment:

I've used the DebugDiag Analysis tool to get the backtrace:

ntdll!NtWaitForMultipleObjects+14    
KERNELBASE!WaitForMultipleObjectsEx+ef    
KERNELBASE!WaitForMultipleObjects+e    
kernel32!WerpReportFaultInternal+4ab    
kernel32!WerpReportFault+52    
KERNELBASE!UnhandledExceptionFilter+277    
ntdll!RtlUserThreadStart$filt$0+3e    
ntdll!_C_specific_handler+96    
ntdll!RtlpExecuteHandlerForException+d    
ntdll!RtlDispatchException+3a9    
ntdll!KiUserExceptionDispatch+3a    
php7!zend_mm_gc+6e [c:\php-sdk\php70dev\vc14\x64\php-7.0.2\zend\zend_alloc.c @ 1891]  
c:\php-sdk\php70dev\vc14\x64\php-7.0.2\zend\zend_alloc.c @ 1891 
php7!zend_mm_alloc_huge+96 [c:\php-sdk\php70dev\vc14\x64\php-7.0.2\zend\zend_alloc.c @ 1761 + 8]  
c:\php-sdk\php70dev\vc14\x64\php-7.0.2\zend\zend_alloc.c @ 1761 + 8 
php7!_emalloc+32ffcd [c:\php-sdk\php70dev\vc14\x64\php-7.0.2\zend\zend_alloc.c @ 2442 + 12]  
c:\php-sdk\php70dev\vc14\x64\php-7.0.2\zend\zend_alloc.c @ 2442 + 12 
php7!ZEND_CONCAT_SPEC_TMPVAR_TMPVAR_HANDLER+355021
[c:\php-sdk\php70dev\vc14\x64\php-7.0.2\zend\zend_vm_execute.h @ 44492]  
c:\php-sdk\php70dev\vc14\x64\php-7.0.2\zend\zend_vm_execute.h @ 44492 
php7!execute_ex+62 [c:\php-sdk\php70dev\vc14\x64\php-7.0.2\zend\zend_vm_execute.h @ 417 + 5]  
c:\php-sdk\php70dev\vc14\x64\php-7.0.2\zend\zend_vm_execute.h @ 417 + 5 
php7!zend_call_function+355dcd [c:\php-sdk\php70dev\vc14\x64\php-7.0.2\zend\zend_execute_api.c @
861]   c:\php-sdk\php70dev\vc14\x64\php-7.0.2\zend\zend_execute_api.c @ 861 
php7!php_array_user_key_compare+cc [c:\php-sdk\php70dev\vc14\x64\php-7.0.2\ext\standard\array.c @
1122 + 26]   c:\php-sdk\php70dev\vc14\x64\php-7.0.2\ext\standard\array.c @ 1122 + 26 
php7!zend_sort+1d8 [c:\php-sdk\php70dev\vc14\x64\php-7.0.2\zend\zend_sort.c @ 351 + f]  
c:\php-sdk\php70dev\vc14\x64\php-7.0.2\zend\zend_sort.c @ 351 + f 
php7!zend_sort+282 [c:\php-sdk\php70dev\vc14\x64\php-7.0.2\zend\zend_sort.c @ 371]  
c:\php-sdk\php70dev\vc14\x64\php-7.0.2\zend\zend_sort.c @ 371 
php7!zend_hash_sort_ex+85 [c:\php-sdk\php70dev\vc14\x64\php-7.0.2\zend\zend_hash.c @ 2256]  
c:\php-sdk\php70dev\vc14\x64\php-7.0.2\zend\zend_hash.c @ 2256 
php7!php_usort+179 [c:\php-sdk\php70dev\vc14\x64\php-7.0.2\ext\standard\array.c @ 1060 + 8]  
c:\php-sdk\php70dev\vc14\x64\php-7.0.2\ext\standard\array.c @ 1060 + 8 
php7!ZEND_DO_FCALL_BY_NAME_SPEC_HANDLER+35609e
[c:\php-sdk\php70dev\vc14\x64\php-7.0.2\zend\zend_vm_execute.h @ 723]  
c:\php-sdk\php70dev\vc14\x64\php-7.0.2\zend\zend_vm_execute.h @ 723 
php7!execute_ex+62 [c:\php-sdk\php70dev\vc14\x64\php-7.0.2\zend\zend_vm_execute.h @ 417 + 5]  
c:\php-sdk\php70dev\vc14\x64\php-7.0.2\zend\zend_vm_execute.h @ 417 + 5 
php7!zend_execute+16c [c:\php-sdk\php70dev\vc14\x64\php-7.0.2\zend\zend_vm_execute.h @ 459]  
c:\php-sdk\php70dev\vc14\x64\php-7.0.2\zend\zend_vm_execute.h @ 459 
php7!zend_execute_scripts+119 [c:\php-sdk\php70dev\vc14\x64\php-7.0.2\zend\zend.c @ 1428]  
c:\php-sdk\php70dev\vc14\x64\php-7.0.2\zend\zend.c @ 1428 
php7!php_execute_script+463 [c:\php-sdk\php70dev\vc14\x64\php-7.0.2\main\main.c @ 2471 + 1b]  
c:\php-sdk\php70dev\vc14\x64\php-7.0.2\main\main.c @ 2471 + 1b 
php_cgi!main+117a [c:\php-sdk\php70dev\vc14\x64\php-7.0.2\sapi\cgi\cgi_main.c @ 2492]  
c:\php-sdk\php70dev\vc14\x64\php-7.0.2\sapi\cgi\cgi_main.c @ 2492 
php_cgi!__scrt_common_main_seh+124 [f:\dd\vctools\crt\vcstartup\src\startup\exe_common.inl @ 264 +
22]   f:\dd\vctools\crt\vcstartup\src\startup\exe_common.inl @ 264 + 22 
kernel32!BaseThreadInitThunk+22    
ntdll!RtlUserThreadStart+34


Previous Comments:
------------------------------------------------------------------------
[2016-01-19 23:28:15] michael dot hartmann at refx dot com

I've created a full crash-dump. It's 187 MB. Even with simple ZIP compression I get it
down to 18 MB. Or is a mini-crash dump enough?

How do you want me to submit that file?

------------------------------------------------------------------------
[2016-01-19 10:00:22] ab@php.net

On creating core dumps, an info is here https://bugs.php.net/bugs-generating-backtrace-win32.php
or here https://msdn.microsoft.com/en-us/library/windows/desktop/bb787181%28v=vs.85%29.aspx?f=255&MSPPError=-2147217396
.

I would see RDP to your machine as not very rational, as you most likely miss all the tools needed
to debug and develop the PHP core on Windows. So quite some time would be needed for setups, etc.
Please lets see what we have in the dumps (be sure there's no sensitive information in there
before posting).

Thanks.

------------------------------------------------------------------------
[2016-01-18 02:53:51] michael dot hartmann at refx dot com

I wish I could send you a short script that causes it, but it seems everything "simple"
just works.

This website uses AltoRouter, Twig and some custom functions (mainly Twig extensions) to render our
website.

How do I create the core-dump or a complete backtrace? Keep in mind, I can't run this in the
command-line.

My offer that somebody trustworthy does a remote-desktop session and works on my computer directly
still stands.

------------------------------------------------------------------------
[2016-01-17 19:41:48] ab@php.net

@michael thanks for the follow up. Were it possible you to extract a small reproduce case? A
backtrace or a core dump could be very helpful, too. Please exclude any non core extensions while
doing that.

Thanks.

------------------------------------------------------------------------
[2016-01-14 22:28:57] michael dot hartmann at refx dot com

I've removed YAML from my php.ini and replaced the necessary functions with the Symfony/YAML
parser. It is definitely more stable, but still crashes in 10% of the cases at the exact same
location.

Except Wincache, this PHP 7.0.2 installation is vanilla.

Also I can only manage to make it crash if I reload a certain page that does array-value
manipulations like this:

// Assign specific display parameters to each price
foreach ($prices as &$prc)
{
	$price = $prc[$_SESSION['GEO']['CURRENCY']];
	$price = $price < 79? ceil($price) : floor($price);

	$prc['PRICE'] = number_format($price, 0, $prdDisp['DECIMAL'],
$prdDisp['THOU']);

	// Christmas pricing active?
	if ($this->config['B_CHRISTMAS_PRICES'])
	{
		$prc['OLD_PRICE'] = $prc['PRICE'];

		$price = $prc[$_SESSION['GEO']['CURRENCY'] . '_SPEC'];
		$price = $price < 79? ceil($price) : floor($price);

		$prc['PRICE'] = number_format($price, 0, $prdDisp['DECIMAL'],
$prdDisp['THOU']);
	}
}

// Assign various properties to products
foreach ($products as &$prd)
{
	// Slug
	$prd['SLUG'] = trim(preg_replace('/[^a-z0-9-]+/', '-',
strtolower($prd['DISPLAY_NAME'])), "-");

	// Price
	$price = $prices[$prd['PRICE_CATEGORY']];
	if ($price['PRICE'] != '0')
	{
		$prd['PRICE'] = $price['PRICE'];
		if ($price['OLD_PRICE'])
		{
			$prd['OLD_PRICE'] = $price['OLD_PRICE'];
		}
		$prd['CURRENCY'] = $prdDisp['SYMBOL'];
	}

	// Age
	$prd['NEW'] = (time() - strtotime($prd['RELEASEDATE'])) < (90 * 24 * 60 *
60);
}

As you can see, I add new array-elements in the foreach loop and I work on references instead of the
values.

If I comment this code out, then (even with the yaml.dll) the website get's a LOT more stable.

------------------------------------------------------------------------


The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at

    https://bugs.php.net/bug.php?id=71342


--
Edit this bug report at https://bugs.php.net/bug.php?id=71342&edit=1


Thread (14 messages)

« previous php.bugs (#198781) next »