Bug #71342 [Opn->Csd]: Crash in "zend_mm_gc"

From: Date: Wed, 27 Jan 2016 02:47:44 +0000
Subject: Bug #71342 [Opn->Csd]: Crash in "zend_mm_gc"
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-198913@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=71342&edit=1

 ID:                 71342
 User updated by:    michael dot hartmann at refx dot com
 Reported by:        michael dot hartmann at refx dot com
 Summary:            Crash in "zend_mm_gc"
-Status:             Open
+Status:             Closed
 Type:               Bug
 Package:            Reproducible crash
 Operating System:   Windows 10
 PHP Version:        7.0.2
 Block user comment: N
 Private report:     N

 New Comment:

Issue resolved.


Previous Comments:
------------------------------------------------------------------------
[2016-01-27 00:46:51] michael dot hartmann at refx dot com

Good news. Today a new version of Wincache was released (2.0.5) and after updating the crashes are
gone!

So it seems that Wincache was corrupting memory!

Sorry for the wild goose chase.

------------------------------------------------------------------------
[2016-01-26 00:48:47] michael dot hartmann at refx dot com

I will try to create a tiny script that creates a small array, modifies it via references in a
foreach loop and then calls usort()/uksort() to provoke the crash.

Please don't close this.

------------------------------------------------------------------------
[2016-01-21 21:29:54] michael dot hartmann at refx dot com

I've added USE_ZEND_ALLOC=0 as the environment variables for the FCGI process in IIS and now
it's much less table. It crashes 80% of the time.

Here is the new backtrace of that crash:

ntdll!NtWaitForMultipleObjects+14    
ntdll!RtlReportExceptionEx+480    
ntdll!RtlReportException+c3    
ntdll!RtlReportCriticalFailure$filt$0+33    
ntdll!_C_specific_handler+96    
ntdll!_GSHandlerCheck_SEH+76    
ntdll!RtlpExecuteHandlerForException+d    
ntdll!RtlDispatchException+3a9    
ntdll!RtlRaiseException+324    
ntdll!RtlReportCriticalFailure+8c    
ntdll!RtlpHeapHandleError+12    
ntdll!RtlpLogHeapFailure+96    
ntdll!RtlpReAllocateHeapInternal+8fda5    
ntdll!RtlReAllocateHeap+31    
AcLayers!NS_FaultTolerantHeap::APIHook_RtlReAllocateHeap+31f4    
ucrtbase!realloc+3d    
php7!_erealloc+347d58 [c:\php-sdk\php70dev\vc14\x64\php-7.0.2\zend\zend_alloc.c @ 2468 + 8]
php7!ZEND_CONCAT_SPEC_TMPVAR_TMPVAR_HANDLER+97
[c:\php-sdk\php70dev\vc14\x64\php-7.0.2\zend\zend_vm_execute.h @ 44487]
php7!execute_ex+62 [c:\php-sdk\php70dev\vc14\x64\php-7.0.2\zend\zend_vm_execute.h @ 417 + 5]
php7!zend_call_function+355dcd [c:\php-sdk\php70dev\vc14\x64\php-7.0.2\zend\zend_execute_api.c @
861]
php7!php_array_user_key_compare+cc [c:\php-sdk\php70dev\vc14\x64\php-7.0.2\ext\standard\array.c @
1122 + 26]
php7!zend_sort+11e [c:\php-sdk\php70dev\vc14\x64\php-7.0.2\zend\zend_sort.c @ 334 + d]
php7!zend_hash_sort_ex+85 [c:\php-sdk\php70dev\vc14\x64\php-7.0.2\zend\zend_hash.c @ 2256]
php7!php_usort+179 [c:\php-sdk\php70dev\vc14\x64\php-7.0.2\ext\standard\array.c @ 1060 + 8]
php7!ZEND_DO_FCALL_BY_NAME_SPEC_HANDLER+35609e
[c:\php-sdk\php70dev\vc14\x64\php-7.0.2\zend\zend_vm_execute.h @ 723]
php7!execute_ex+62 [c:\php-sdk\php70dev\vc14\x64\php-7.0.2\zend\zend_vm_execute.h @ 417 + 5]
php7!zend_execute+16c [c:\php-sdk\php70dev\vc14\x64\php-7.0.2\zend\zend_vm_execute.h @ 459]
php7!zend_execute_scripts+119 [c:\php-sdk\php70dev\vc14\x64\php-7.0.2\zend\zend.c @ 1428]
php7!php_execute_script+463 [c:\php-sdk\php70dev\vc14\x64\php-7.0.2\main\main.c @ 2471 + 1b]
php_cgi!main+117a [c:\php-sdk\php70dev\vc14\x64\php-7.0.2\sapi\cgi\cgi_main.c @ 2492]
php_cgi!__scrt_common_main_seh+124 [f:\dd\vctools\crt\vcstartup\src\startup\exe_common.inl @ 264 +
22]
ntdll!RtlUserThreadStart+34

------------------------------------------------------------------------
[2016-01-20 10:46:06] ab@php.net

Thanks for the backtrace. The analyze shows, that it might be a GC bug while executing some
userspace sort functions (like usort, uksort, etc.). Could you please check the places in your code?

Also, please try to rerun PHP with environment variable USE_ZEND_ALLOC=0 set to the PHP environment
(fe can be added to the FCGI options in IIS).

Thanks.

------------------------------------------------------------------------
[2016-01-19 23:34:20] michael dot hartmann at refx dot com

I've used the DebugDiag Analysis tool to get the backtrace:

ntdll!NtWaitForMultipleObjects+14    
KERNELBASE!WaitForMultipleObjectsEx+ef    
KERNELBASE!WaitForMultipleObjects+e    
kernel32!WerpReportFaultInternal+4ab    
kernel32!WerpReportFault+52    
KERNELBASE!UnhandledExceptionFilter+277    
ntdll!RtlUserThreadStart$filt$0+3e    
ntdll!_C_specific_handler+96    
ntdll!RtlpExecuteHandlerForException+d    
ntdll!RtlDispatchException+3a9    
ntdll!KiUserExceptionDispatch+3a    
php7!zend_mm_gc+6e [c:\php-sdk\php70dev\vc14\x64\php-7.0.2\zend\zend_alloc.c @ 1891]  
c:\php-sdk\php70dev\vc14\x64\php-7.0.2\zend\zend_alloc.c @ 1891 
php7!zend_mm_alloc_huge+96 [c:\php-sdk\php70dev\vc14\x64\php-7.0.2\zend\zend_alloc.c @ 1761 + 8]  
c:\php-sdk\php70dev\vc14\x64\php-7.0.2\zend\zend_alloc.c @ 1761 + 8 
php7!_emalloc+32ffcd [c:\php-sdk\php70dev\vc14\x64\php-7.0.2\zend\zend_alloc.c @ 2442 + 12]  
c:\php-sdk\php70dev\vc14\x64\php-7.0.2\zend\zend_alloc.c @ 2442 + 12 
php7!ZEND_CONCAT_SPEC_TMPVAR_TMPVAR_HANDLER+355021
[c:\php-sdk\php70dev\vc14\x64\php-7.0.2\zend\zend_vm_execute.h @ 44492]  
c:\php-sdk\php70dev\vc14\x64\php-7.0.2\zend\zend_vm_execute.h @ 44492 
php7!execute_ex+62 [c:\php-sdk\php70dev\vc14\x64\php-7.0.2\zend\zend_vm_execute.h @ 417 + 5]  
c:\php-sdk\php70dev\vc14\x64\php-7.0.2\zend\zend_vm_execute.h @ 417 + 5 
php7!zend_call_function+355dcd [c:\php-sdk\php70dev\vc14\x64\php-7.0.2\zend\zend_execute_api.c @
861]   c:\php-sdk\php70dev\vc14\x64\php-7.0.2\zend\zend_execute_api.c @ 861 
php7!php_array_user_key_compare+cc [c:\php-sdk\php70dev\vc14\x64\php-7.0.2\ext\standard\array.c @
1122 + 26]   c:\php-sdk\php70dev\vc14\x64\php-7.0.2\ext\standard\array.c @ 1122 + 26 
php7!zend_sort+1d8 [c:\php-sdk\php70dev\vc14\x64\php-7.0.2\zend\zend_sort.c @ 351 + f]  
c:\php-sdk\php70dev\vc14\x64\php-7.0.2\zend\zend_sort.c @ 351 + f 
php7!zend_sort+282 [c:\php-sdk\php70dev\vc14\x64\php-7.0.2\zend\zend_sort.c @ 371]  
c:\php-sdk\php70dev\vc14\x64\php-7.0.2\zend\zend_sort.c @ 371 
php7!zend_hash_sort_ex+85 [c:\php-sdk\php70dev\vc14\x64\php-7.0.2\zend\zend_hash.c @ 2256]  
c:\php-sdk\php70dev\vc14\x64\php-7.0.2\zend\zend_hash.c @ 2256 
php7!php_usort+179 [c:\php-sdk\php70dev\vc14\x64\php-7.0.2\ext\standard\array.c @ 1060 + 8]  
c:\php-sdk\php70dev\vc14\x64\php-7.0.2\ext\standard\array.c @ 1060 + 8 
php7!ZEND_DO_FCALL_BY_NAME_SPEC_HANDLER+35609e
[c:\php-sdk\php70dev\vc14\x64\php-7.0.2\zend\zend_vm_execute.h @ 723]  
c:\php-sdk\php70dev\vc14\x64\php-7.0.2\zend\zend_vm_execute.h @ 723 
php7!execute_ex+62 [c:\php-sdk\php70dev\vc14\x64\php-7.0.2\zend\zend_vm_execute.h @ 417 + 5]  
c:\php-sdk\php70dev\vc14\x64\php-7.0.2\zend\zend_vm_execute.h @ 417 + 5 
php7!zend_execute+16c [c:\php-sdk\php70dev\vc14\x64\php-7.0.2\zend\zend_vm_execute.h @ 459]  
c:\php-sdk\php70dev\vc14\x64\php-7.0.2\zend\zend_vm_execute.h @ 459 
php7!zend_execute_scripts+119 [c:\php-sdk\php70dev\vc14\x64\php-7.0.2\zend\zend.c @ 1428]  
c:\php-sdk\php70dev\vc14\x64\php-7.0.2\zend\zend.c @ 1428 
php7!php_execute_script+463 [c:\php-sdk\php70dev\vc14\x64\php-7.0.2\main\main.c @ 2471 + 1b]  
c:\php-sdk\php70dev\vc14\x64\php-7.0.2\main\main.c @ 2471 + 1b 
php_cgi!main+117a [c:\php-sdk\php70dev\vc14\x64\php-7.0.2\sapi\cgi\cgi_main.c @ 2492]  
c:\php-sdk\php70dev\vc14\x64\php-7.0.2\sapi\cgi\cgi_main.c @ 2492 
php_cgi!__scrt_common_main_seh+124 [f:\dd\vctools\crt\vcstartup\src\startup\exe_common.inl @ 264 +
22]   f:\dd\vctools\crt\vcstartup\src\startup\exe_common.inl @ 264 + 22 
kernel32!BaseThreadInitThunk+22    
ntdll!RtlUserThreadStart+34

------------------------------------------------------------------------


The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at

    https://bugs.php.net/bug.php?id=71342


--
Edit this bug report at https://bugs.php.net/bug.php?id=71342&edit=1


Thread (14 messages)

« previous php.bugs (#198913) next »