Bug #71135 [Com]: Random memory corruption with strings

From: Date: Sat, 05 Mar 2016 12:06:33 +0000
Subject: Bug #71135 [Com]: Random memory corruption with strings
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-199606@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=71135&edit=1

 ID:                 71135
 Comment by:         vojtech dot kurka at gmail dot com
 Reported by:        iquito at gmx dot net
 Summary:            Random memory corruption with strings
 Status:             Assigned
 Type:               Bug
 Package:            opcache
 Operating System:   Debian Jessie
 PHP Version:        7.0.0
 Assigned To:        laruence
 Block user comment: N
 Private report:     N

 New Comment:

We have 7.0.4 in production for 48 hours and it is running without any problems with json_encode() -
seems fixed for us.

Thank you, Dmitri!


Previous Comments:
------------------------------------------------------------------------
[2016-02-24 21:29:56] vojtech dot kurka at gmail dot com

Dmitry, are all these fixes included in 7.0.4? Thank you

------------------------------------------------------------------------
[2016-02-24 21:03:36] dmitry@php.net

The problem was caused by incorrect synchronization of processes during opcache reload. Some
processes might crash or might not crash because of race-conditions. The commit mentioned above and
a couple of following fixes, should solve the problem.

------------------------------------------------------------------------
[2016-02-22 22:36:15] iquito at gmx dot net

Would be great if this problem was fixed, but the linked changes do not seem related to the bug here
(as far as I can tell) - in my configuration it sometimes occured after a opcache_reset(), but those
were not the majority cases, usually it just happened at seemingly random times when the opcache was
warmed up and in full swing for many hours.

I do use opcache_invalidate quite regularly on some files, but the error occured so infrequently
that I do not know if that is linked to this bug - the errors occured once a day, but within that
timeframe I used opcache_reset and opcache_invalidate many times without problems. I also never had
a crash, only one "flipped" character in a string, which seems an odd and hard-to-pinpoint
bug anyway - almost all strings were still correct, only 1-2 strings were one character off. This
makes this bug so intimidating - if strings can change a bit seemingly random, than that can be a
real problem for an application and can also stay unnoticed for some time.

------------------------------------------------------------------------
[2016-02-22 22:12:45] matej21 at matej21 dot cz

this issue is probably fixed by https://github.com/php/php-src/commit/d2287529396539fd2cba6f449ae9679cac64c3b9

------------------------------------------------------------------------
[2016-02-08 17:59:02] matej21 at matej21 dot cz

Hi, I'm experiencing similar issue. It sometimes happens to me after opcache_reset (not only
manual but also automatic cache reset when opcache is out of a memory). I was able to reproduce it
on my dev machine using "ab" requesting the site and running opcache_reset few times (it
happens in about 10% of opcache_reset calls)

I tried it with both enabled and disabled protected_memory. And here are some errors and traces:


with opcache.protected_memory=1


Program terminated with signal SIGSEGV, Segmentation fault.
#0  0x0000000000a5e9dd in zend_string_release (s=0x7f5937855d80) at
/home/matej21/tmp/php-7.0.3/Zend/zend_string.h:270
270                     if (--GC_REFCOUNT(s) == 0) {

(gdb) bt
#0  0x0000000000a5e9dd in zend_string_release (s=0x7f5937855d80) at
/home/matej21/tmp/php-7.0.3/Zend/zend_string.h:270
#1  0x0000000000a629f1 in zend_hash_destroy (ht=0x7f593599ef60) at
/home/matej21/tmp/php-7.0.3/Zend/zend_hash.c:1265
#2  0x0000000000a81e45 in zend_gc_collect_cycles () at
/home/matej21/tmp/php-7.0.3/Zend/zend_gc.c:1117
#3  0x0000000000a3517f in shutdown_executor () at
/home/matej21/tmp/php-7.0.3/Zend/zend_execute_API.c:352
#4  0x0000000000a4cf98 in zend_deactivate () at /home/matej21/tmp/php-7.0.3/Zend/zend.c:967
#5  0x00000000009ba30d in php_request_shutdown (dummy=0x0) at
/home/matej21/tmp/php-7.0.3/main/main.c:1823
#6  0x0000000000b1d4ae in main (argc=4, argv=0x7ffe1f4434a8) at
/home/matej21/tmp/php-7.0.3/sapi/fpm/fpm/fpm_main.c:1972


Program terminated with signal SIGSEGV, Segmentation fault.
#0  0x0000000000a5e9dd in zend_string_release (s=0x7f593779d6b0) at
/home/matej21/tmp/php-7.0.3/Zend/zend_string.h:270
270                     if (--GC_REFCOUNT(s) == 0) {

(gdb) bt
#0  0x0000000000a5e9dd in zend_string_release (s=0x7f593779d6b0) at
/home/matej21/tmp/php-7.0.3/Zend/zend_string.h:270
#1  0x0000000000a629f1 in zend_hash_destroy (ht=0x7f59360751c0) at
/home/matej21/tmp/php-7.0.3/Zend/zend_hash.c:1265
#2  0x0000000000a3b042 in destroy_zend_class (zv=0x7ffe1f442c40) at
/home/matej21/tmp/php-7.0.3/Zend/zend_opcode.c:289
#3  0x0000000000a6203f in _zend_hash_del_el_ex (ht=0x30df4a0, idx=700, p=0x34138c0, prev=0x0) at
/home/matej21/tmp/php-7.0.3/Zend/zend_hash.c:1013
#4  0x0000000000a6210a in _zend_hash_del_el (ht=0x30df4a0, idx=700, p=0x34138c0) at
/home/matej21/tmp/php-7.0.3/Zend/zend_hash.c:1037
#5  0x0000000000a639a6 in zend_hash_reverse_apply (ht=0x30df4a0, apply_func=0xa3454a
<clean_non_persistent_class>) at /home/matej21/tmp/php-7.0.3/Zend/zend_hash.c:1615
#6  0x0000000000a35269 in shutdown_executor () at
/home/matej21/tmp/php-7.0.3/Zend/zend_execute_API.c:367
#7  0x0000000000a4cf98 in zend_deactivate () at /home/matej21/tmp/php-7.0.3/Zend/zend.c:967
#8  0x00000000009ba30d in php_request_shutdown (dummy=0x0) at
/home/matej21/tmp/php-7.0.3/main/main.c:1823
#9  0x0000000000b1d4ae in main (argc=4, argv=0x7ffe1f4434a8) at
/home/matej21/tmp/php-7.0.3/sapi/fpm/fpm/fpm_main.c:1972


---------------------------------------

with opcache.protected_memory=0

first some error messages showing corrupted memory:

require(): Failed opening required
'/var/www/foo-project/vendor/composer/autoload_namespaces.phpᅵᅵᅵᅵ'
require_once(): Failed opening required
'/var/www-foo-project/vendor/composer/autoload_real.pfp'
require_once(): Failed opening required
'/var/www/foo-project/vendor/composer/autoload_real.pgpᅵᅵ' 
include(): Failed opening
'/var/www/foo-project/vendor/nette/utils/src/Utils/DateTime.phpᅵ/Cube`'
Fatal Error: Class 'Solarium\Core\Configurableÿÿ' not found-obleceni/
Error: Class 'Nette\Http\SessionSectionÿÿÿ' not found
Error: Class 'Nette\Caching\Storages\FileStorageÿÿ' not found
Uncaught Error: Call to undefined method
ComposerAutoloaderInit41,89608998d7c84bcc13a727394dca1::getLoader() 
Error: Class 'App\Security\UserStorageÿÿÿÿ' not found in
/var/www/foo-project/temp/cache/Nette.Configurator/Container_1efc2a7985.php:7427


sometimes "only" segfault has happened, but opcache was not corrupted (IIRC), therefore
other requests didn't fail:

Program terminated with signal SIGSEGV, Segmentation fault.
#0  0x00007f47ada7dfb7 in kill () at ../sysdeps/unix/syscall-template.S:81
81      ../sysdeps/unix/syscall-template.S: Adresář nebo soubor neexistuje.

(gdb) bt
#0  0x00007f47ada7dfb7 in kill () at ../sysdeps/unix/syscall-template.S:81
#1  0x0000000000a1663f in zend_mm_panic (message=0x1135a1d "zend_mm_heap corrupted") at
/home/matej21/tmp/php-7.0.3/Zend/zend_alloc.c:364
#2  0x0000000000a18346 in zend_mm_free_heap (heap=0x7f47a7800040, ptr=0x7f47a35988b0,
__zend_filename=0x113ce20 "/home/matej21/tmp/php-7.0.3/Zend/zend_string.h",
__zend_lineno=271, __zend_orig_filename=0x0, __zend_orig_lineno=0)
    at /home/matej21/tmp/php-7.0.3/Zend/zend_alloc.c:1400
#3  0x0000000000a1ac7e in _efree (ptr=0x7f47a35988b0, __zend_filename=0x113ce20
"/home/matej21/tmp/php-7.0.3/Zend/zend_string.h", __zend_lineno=271,
__zend_orig_filename=0x0, __zend_orig_lineno=0)
    at /home/matej21/tmp/php-7.0.3/Zend/zend_alloc.c:2458
#4  0x0000000000a5ea2c in zend_string_release (s=0x7f47a35988b0) at
/home/matej21/tmp/php-7.0.3/Zend/zend_string.h:271
#5  0x0000000000a629f1 in zend_hash_destroy (ht=0x7f47a2920fc0) at
/home/matej21/tmp/php-7.0.3/Zend/zend_hash.c:1265
#6  0x0000000000a3b042 in destroy_zend_class (zv=0x7fffbfa67e60) at
/home/matej21/tmp/php-7.0.3/Zend/zend_opcode.c:289
#7  0x0000000000a6203f in _zend_hash_del_el_ex (ht=0x20884a0, idx=535, p=0x23b3360, prev=0x0) at
/home/matej21/tmp/php-7.0.3/Zend/zend_hash.c:1013
#8  0x0000000000a6210a in _zend_hash_del_el (ht=0x20884a0, idx=535, p=0x23b3360) at
/home/matej21/tmp/php-7.0.3/Zend/zend_hash.c:1037
#9  0x0000000000a639a6 in zend_hash_reverse_apply (ht=0x20884a0, apply_func=0xa3454a
<clean_non_persistent_class>) at /home/matej21/tmp/php-7.0.3/Zend/zend_hash.c:1615
#10 0x0000000000a35269 in shutdown_executor () at
/home/matej21/tmp/php-7.0.3/Zend/zend_execute_API.c:367
#11 0x0000000000a4cf98 in zend_deactivate () at /home/matej21/tmp/php-7.0.3/Zend/zend.c:967
#12 0x00000000009ba30d in php_request_shutdown (dummy=0x0) at
/home/matej21/tmp/php-7.0.3/main/main.c:1823
#13 0x0000000000b1d4ae in main (argc=4, argv=0x7fffbfa686c8) at
/home/matej21/tmp/php-7.0.3/sapi/fpm/fpm/fpm_main.c:1972



Program terminated with signal SIGABRT, Aborted.
#0  0x00007f47ada7dcc9 in __GI_raise (sig=sig@entry=6) at ../nptl/sysdeps/unix/sysv/linux/raise.c:56
56      ../nptl/sysdeps/unix/sysv/linux/raise.c: Adresář nebo soubor neexistuje.

(gdb) bt
#0  0x00007f47ada7dcc9 in __GI_raise (sig=sig@entry=6) at ../nptl/sysdeps/unix/sysv/linux/raise.c:56
#1  0x00007f47ada810d8 in __GI_abort () at abort.c:89
#2  0x00007f47ada76b86 in __assert_fail_base (fmt=0x7f47b1835029 <error: Cannot access memory at
address 0x7f47b1835029>, assertion=assertion@entry=0x113d04d "*end == '\\0'",

    file=file@entry=0x113cf08 "/home/matej21/tmp/php-7.0.3/Zend/zend_hash.c",
line=line@entry=2432, function=function@entry=0x113d200 <__PRETTY_FUNCTION__.8927>
"_zend_handle_numeric_str_ex") at assert.c:92
#3  0x00007f47ada76c32 in __GI___assert_fail (assertion=0x113d04d "*end ==
'\\0'", file=0x113cf08 "/home/matej21/tmp/php-7.0.3/Zend/zend_hash.c",
line=2432, 
    function=0x113d200 <__PRETTY_FUNCTION__.8927> "_zend_handle_numeric_str_ex") at
assert.c:101
#4  0x0000000000a65c03 in _zend_handle_numeric_str_ex (key=0x7f47a36645c8 "234\377",
length=3, idx=0x7fffbfa65c18) at /home/matej21/tmp/php-7.0.3/Zend/zend_hash.c:2432
#5  0x0000000000aa0236 in _zend_handle_numeric_str (key=0x7f47a36645c8 "234\377",
length=3, idx=0x7fffbfa65c18) at /home/matej21/tmp/php-7.0.3/Zend/zend_hash.h:264
#6  0x0000000000b07c30 in ZEND_ISSET_ISEMPTY_DIM_OBJ_SPEC_TMPVAR_CV_HANDLER () at
/home/matej21/tmp/php-7.0.3/Zend/zend_vm_execute.h:44069
#7  0x0000000000aa93ff in execute_ex (ex=0x7f47a7815060) at
/home/matej21/tmp/php-7.0.3/Zend/zend_vm_execute.h:414
#8  0x0000000000a36ce7 in zend_call_function (fci=0x7fffbfa65e90, fci_cache=0x7fffbfa65e60) at
/home/matej21/tmp/php-7.0.3/Zend/zend_execute_API.c:860
#9  0x00000000008943f8 in zif_call_user_func_array (execute_data=0x7f47a7814fe0,
return_value=0x7f47a7814fa0) at /home/matej21/tmp/php-7.0.3/ext/standard/basic_functions.c:4811
#10 0x0000000000aa9f6a in ZEND_DO_FCALL_BY_NAME_SPEC_HANDLER () at
/home/matej21/tmp/php-7.0.3/Zend/zend_vm_execute.h:714
#11 0x0000000000aa93ff in execute_ex (ex=0x7f47a7814030) at
/home/matej21/tmp/php-7.0.3/Zend/zend_vm_execute.h:414
#12 0x0000000000aa9511 in zend_execute (op_array=0x7f47a7865000, return_value=0x0) at
/home/matej21/tmp/php-7.0.3/Zend/zend_vm_execute.h:458
#13 0x0000000000a4e394 in zend_execute_scripts (type=8, retval=0x0, file_count=3) at
/home/matej21/tmp/php-7.0.3/Zend/zend.c:1427
#14 0x00000000009bb7a1 in php_execute_script (primary_file=0x7fffbfa683d0) at
/home/matej21/tmp/php-7.0.3/main/main.c:2484
#15 0x0000000000b1d368 in main (argc=4, argv=0x7fffbfa686c8) at
/home/matej21/tmp/php-7.0.3/sapi/fpm/fpm/fpm_main.c:1944



Program terminated with signal SIGSEGV, Segmentation fault.
#0  memset () at ../sysdeps/x86_64/memset.S:93
93      ../sysdeps/x86_64/memset.S: Adresář nebo soubor neexistuje.

(gdb) bt
#0  memset () at ../sysdeps/x86_64/memset.S:93
#1  0x0000000000aa83e6 in i_init_code_execute_data (execute_data=0x7f47a7814a50,
op_array=0x7f47a7873700, return_value=0x0) at /home/matej21/tmp/php-7.0.3/Zend/zend_execute.c:2200
#2  0x0000000000ae5790 in ZEND_INCLUDE_OR_EVAL_SPEC_CV_HANDLER () at
/home/matej21/tmp/php-7.0.3/Zend/zend_vm_execute.h:29164
#3  0x0000000000aa93ff in execute_ex (ex=0x7f47a7814930) at
/home/matej21/tmp/php-7.0.3/Zend/zend_vm_execute.h:414
#4  0x0000000000a36ce7 in zend_call_function (fci=0x7fffbfa64ad0, fci_cache=0x7fffbfa64aa0) at
/home/matej21/tmp/php-7.0.3/Zend/zend_execute_API.c:860
#5  0x0000000000a73f76 in zend_call_method (object=0x7f47a7802d28, obj_ce=0x7f47a7805380,
fn_proxy=0x7f47a7802d20, function_name=0x7f47a792fbe8
"composer\\autoload\\classloader::loadclass\001", function_name_len=44, 
    retval_ptr=0x0, param_count=1, arg1=0x7f47a7814920, arg2=0x0) at
/home/matej21/tmp/php-7.0.3/Zend/zend_interfaces.c:104
#6  0x000000000083e7fc in zif_spl_autoload_call (execute_data=0x7f47a78148c0,
return_value=0x7fffbfa64da0) at /home/matej21/tmp/php-7.0.3/ext/spl/php_spl.c:429
#7  0x0000000000a36e0e in zend_call_function (fci=0x7fffbfa64de0, fci_cache=0x7fffbfa64db0) at
/home/matej21/tmp/php-7.0.3/Zend/zend_execute_API.c:879
#8  0x0000000000a3758c in zend_lookup_class_ex (name=0x7f47a359b1d8, key=0x7f47a398ef20,
use_autoload=1) at /home/matej21/tmp/php-7.0.3/Zend/zend_execute_API.c:1041
#9  0x0000000000a380d5 in zend_fetch_class_by_name (class_name=0x7f47a359b1d8, key=0x7f47a398ef20,
fetch_type=6) at /home/matej21/tmp/php-7.0.3/Zend/zend_execute_API.c:1387
#10 0x0000000000aac681 in ZEND_ADD_TRAIT_SPEC_HANDLER () at
/home/matej21/tmp/php-7.0.3/Zend/zend_vm_execute.h:1449
#11 0x0000000000aa93ff in execute_ex (ex=0x7f47a7814730) at
/home/matej21/tmp/php-7.0.3/Zend/zend_vm_execute.h:414
#12 0x0000000000a36ce7 in zend_call_function (fci=0x7fffbfa65140, fci_cache=0x7fffbfa65110) at
/home/matej21/tmp/php-7.0.3/Zend/zend_execute_API.c:860
#13 0x0000000000a73f76 in zend_call_method (object=0x7f47a7802d28, obj_ce=0x7f47a7805380,
fn_proxy=0x7f47a7802d20, function_name=0x7f47a792fbe8
"composer\\autoload\\classloader::loadclass\001", function_name_len=44, 
    retval_ptr=0x0, param_count=1, arg1=0x7f47a7814720, arg2=0x0) at
/home/matej21/tmp/php-7.0.3/Zend/zend_interfaces.c:104
#14 0x000000000083e7fc in zif_spl_autoload_call (execute_data=0x7f47a78146c0,
return_value=0x7fffbfa65410) at /home/matej21/tmp/php-7.0.3/ext/spl/php_spl.c:429
#15 0x0000000000a36e0e in zend_call_function (fci=0x7fffbfa65450, fci_cache=0x7fffbfa65420) at
/home/matej21/tmp/php-7.0.3/Zend/zend_execute_API.c:879
#16 0x0000000000a3758c in zend_lookup_class_ex (name=0x7f47a359b5d8, key=0x0, use_autoload=1) at
/home/matej21/tmp/php-7.0.3/Zend/zend_execute_API.c:1041
#17 0x0000000000a6c0e3 in zif_class_alias (execute_data=0x7f47a7814640, return_value=0x7f47a7814620)
at /home/matej21/tmp/php-7.0.3/Zend/zend_builtin_functions.c:1585
#18 0x0000000000aa99d0 in ZEND_DO_ICALL_SPEC_HANDLER () at
/home/matej21/tmp/php-7.0.3/Zend/zend_vm_execute.h:586
#19 0x0000000000aa93ff in execute_ex (ex=0x7f47a7814590) at
/home/matej21/tmp/php-7.0.3/Zend/zend_vm_execute.h:414
#20 0x0000000000a36ce7 in zend_call_function (fci=0x7fffbfa657e0, fci_cache=0x7fffbfa657b0) at
/home/matej21/tmp/php-7.0.3/Zend/zend_execute_API.c:860
#21 0x0000000000a73f76 in zend_call_method (object=0x0, obj_ce=0x0, fn_proxy=0x7f47a78fe190,
function_name=0x7f47a7901bf8 "closure::__invoke\003", function_name_len=21,
retval_ptr=0x0, param_count=1, arg1=0x7f47a7814580, 
    arg2=0x0) at /home/matej21/tmp/php-7.0.3/Zend/zend_interfaces.c:104
#22 0x000000000083e7fc in zif_spl_autoload_call (execute_data=0x7f47a7814520,
return_value=0x7fffbfa65ab0) at /home/matej21/tmp/php-7.0.3/ext/spl/php_spl.c:429
#23 0x0000000000a36e0e in zend_call_function (fci=0x7fffbfa65af0, fci_cache=0x7fffbfa65ac0) at
/home/matej21/tmp/php-7.0.3/Zend/zend_execute_API.c:879
#24 0x0000000000a3758c in zend_lookup_class_ex (name=0x7f47a359bbc0, key=0x0, use_autoload=1) at
/home/matej21/tmp/php-7.0.3/Zend/zend_execute_API.c:1041
#25 0x0000000000a37685 in zend_lookup_class (name=0x7f47a359bbc0) at
/home/matej21/tmp/php-7.0.3/Zend/zend_execute_API.c:1062
#26 0x0000000000a6b557 in zif_class_exists (execute_data=0x7f47a78144b0,
return_value=0x7fffbfa65e50) at /home/matej21/tmp/php-7.0.3/Zend/zend_builtin_functions.c:1437
#27 0x0000000000a36e0e in zend_call_function (fci=0x7fffbfa65ea0, fci_cache=0x7fffbfa65e70) at
/home/matej21/tmp/php-7.0.3/Zend/zend_execute_API.c:879
#28 0x000000000088de93 in zif_array_map (execute_data=0x7f47a7814430, return_value=0x7f47a7814420)
at /home/matej21/tmp/php-7.0.3/ext/standard/array.c:5290
#29 0x0000000000aa99d0 in ZEND_DO_ICALL_SPEC_HANDLER () at
/home/matej21/tmp/php-7.0.3/Zend/zend_vm_execute.h:586
#30 0x0000000000aa93ff in execute_ex (ex=0x7f47a7814030) at
/home/matej21/tmp/php-7.0.3/Zend/zend_vm_execute.h:414
#31 0x0000000000aa9511 in zend_execute (op_array=0x7f47a7873000, return_value=0x0) at
/home/matej21/tmp/php-7.0.3/Zend/zend_vm_execute.h:458
#32 0x0000000000a4e394 in zend_execute_scripts (type=8, retval=0x0, file_count=3) at
/home/matej21/tmp/php-7.0.3/Zend/zend.c:1427
#33 0x00000000009bb7a1 in php_execute_script (primary_file=0x7fffbfa683d0) at
/home/matej21/tmp/php-7.0.3/main/main.c:2484
#34 0x0000000000b1d368 in main (argc=4, argv=0x7fffbfa686c8) at
/home/matej21/tmp/php-7.0.3/sapi/fpm/fpm/fpm_main.c:1944

------------------------------------------------------------------------


The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at

    https://bugs.php.net/bug.php?id=71135


--
Edit this bug report at https://bugs.php.net/bug.php?id=71135&edit=1


Thread (52 messages)

« previous php.bugs (#199606) next »