Bug #72179 [Fbk->Asn]: Segfault in gc_possible_root on CLI
| From: | webmaster at tom-geiger dot de | Date: | Thu, 12 May 2016 13:23:16 +0000 |
| Subject: | Bug #72179 [Fbk->Asn]: Segfault in gc_possible_root on CLI | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-201036@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=72179&edit=1
ID: 72179
User updated by: webmaster at tom-geiger dot de
Reported by: webmaster at tom-geiger dot de
Summary: Segfault in gc_possible_root on CLI
-Status: Feedback
+Status: Assigned
Type: Bug
Package: Reproducible crash
Operating System: Ubuntu 16.04
PHP Version: 7.0.6
Assigned To: laruence
Block user comment: N
Private report: N
New Comment:
Running valgrind gives me this: I'll check if I can get more information with different
valgrind parameters:
==3856== Invalid read of size 8
==3856== at 0x38F4BF: gc_possible_root (in /usr/bin/php7.0)
==3856== by 0x2F608F: var_destroy (in /usr/bin/php7.0)
==3856== by 0x2E8967: zif_unserialize (in /usr/bin/php7.0)
==3856== by 0x356679: dtrace_execute_internal (in /usr/bin/php7.0)
==3856== by 0x9AE1E7D: xdebug_execute_internal (xdebug.c:2035)
==3856== by 0x3EB46F: ??? (in /usr/bin/php7.0)
==3856== by 0x3A6ACA: execute_ex (in /usr/bin/php7.0)
==3856== by 0x356510: dtrace_execute_ex (in /usr/bin/php7.0)
==3856== by 0x9AE14EE: xdebug_execute_ex (xdebug.c:1890)
==3856== by 0x3EB5AC: ??? (in /usr/bin/php7.0)
==3856== by 0x3A6ACA: execute_ex (in /usr/bin/php7.0)
==3856== by 0x356510: dtrace_execute_ex (in /usr/bin/php7.0)
==3856== Address 0x20f901c0 is 16 bytes before a block of size 288 free'd
==3856== at 0x4C2EDEB: free (in /usr/lib/valgrind/vgpreload_memcheck-amd64-linux.so)
==3856== by 0x3778F1: zend_array_destroy (in /usr/bin/php7.0)
==3856== by 0x37795E: zend_array_destroy (in /usr/bin/php7.0)
==3856== by 0x364A58: _zval_dtor_func_for_ptr (in /usr/bin/php7.0)
==3856== by 0x3F90C2: ??? (in /usr/bin/php7.0)
==3856== by 0x3A6ACA: execute_ex (in /usr/bin/php7.0)
==3856== by 0x356510: dtrace_execute_ex (in /usr/bin/php7.0)
==3856== by 0x9AE14EE: xdebug_execute_ex (xdebug.c:1890)
==3856== by 0x3EB5AC: ??? (in /usr/bin/php7.0)
==3856== by 0x3A6ACA: execute_ex (in /usr/bin/php7.0)
==3856== by 0x356510: dtrace_execute_ex (in /usr/bin/php7.0)
==3856== by 0x9AE14EE: xdebug_execute_ex (xdebug.c:1890)
==3856== Block was alloc'd at
==3856== at 0x4C2DB8F: malloc (in /usr/lib/valgrind/vgpreload_memcheck-amd64-linux.so)
==3856== by 0x37422C: _zend_hash_str_update (in /usr/bin/php7.0)
==3856== by 0x3695BE: add_assoc_str_ex (in /usr/bin/php7.0)
==3856== by 0x380CFE: zend_fetch_debug_backtrace (in /usr/bin/php7.0)
==3856== by 0x3811FC: ??? (in /usr/bin/php7.0)
==3856== by 0x356679: dtrace_execute_internal (in /usr/bin/php7.0)
==3856== by 0x9AE1E7D: xdebug_execute_internal (xdebug.c:2035)
==3856== by 0x3EB46F: ??? (in /usr/bin/php7.0)
==3856== by 0x3A6ACA: execute_ex (in /usr/bin/php7.0)
==3856== by 0x356510: dtrace_execute_ex (in /usr/bin/php7.0)
==3856== by 0x9AE14EE: xdebug_execute_ex (xdebug.c:1890)
==3856== by 0x3EB5AC: ??? (in /usr/bin/php7.0)
==3856==
==3856== Invalid write of size 8
==3856== at 0x38F4DB: gc_possible_root (in /usr/bin/php7.0)
==3856== by 0x2F608F: var_destroy (in /usr/bin/php7.0)
==3856== by 0x2E8967: zif_unserialize (in /usr/bin/php7.0)
==3856== by 0x356679: dtrace_execute_internal (in /usr/bin/php7.0)
==3856== by 0x9AE1E7D: xdebug_execute_internal (xdebug.c:2035)
==3856== by 0x3EB46F: ??? (in /usr/bin/php7.0)
==3856== by 0x3A6ACA: execute_ex (in /usr/bin/php7.0)
==3856== by 0x356510: dtrace_execute_ex (in /usr/bin/php7.0)
==3856== by 0x9AE14EE: xdebug_execute_ex (xdebug.c:1890)
==3856== by 0x3EB5AC: ??? (in /usr/bin/php7.0)
==3856== by 0x3A6ACA: execute_ex (in /usr/bin/php7.0)
==3856== by 0x356510: dtrace_execute_ex (in /usr/bin/php7.0)
==3856== Address 0x20f901b0 is 32 bytes before a block of size 288 in arena "client"
==3856==
==3856== Invalid write of size 8
==3856== at 0x38F4E2: gc_possible_root (in /usr/bin/php7.0)
==3856== by 0x2F608F: var_destroy (in /usr/bin/php7.0)
==3856== by 0x2E8967: zif_unserialize (in /usr/bin/php7.0)
==3856== by 0x356679: dtrace_execute_internal (in /usr/bin/php7.0)
==3856== by 0x9AE1E7D: xdebug_execute_internal (xdebug.c:2035)
==3856== by 0x3EB46F: ??? (in /usr/bin/php7.0)
==3856== by 0x3A6ACA: execute_ex (in /usr/bin/php7.0)
==3856== by 0x356510: dtrace_execute_ex (in /usr/bin/php7.0)
==3856== by 0x9AE14EE: xdebug_execute_ex (xdebug.c:1890)
==3856== by 0x3EB5AC: ??? (in /usr/bin/php7.0)
==3856== by 0x3A6ACA: execute_ex (in /usr/bin/php7.0)
==3856== by 0x356510: dtrace_execute_ex (in /usr/bin/php7.0)
==3856== Address 0x20f901b8 is 24 bytes before a block of size 288 free'd
==3856== at 0x4C2EDEB: free (in /usr/lib/valgrind/vgpreload_memcheck-amd64-linux.so)
==3856== by 0x3778F1: zend_array_destroy (in /usr/bin/php7.0)
==3856== by 0x37795E: zend_array_destroy (in /usr/bin/php7.0)
==3856== by 0x364A58: _zval_dtor_func_for_ptr (in /usr/bin/php7.0)
==3856== by 0x3F90C2: ??? (in /usr/bin/php7.0)
==3856== by 0x3A6ACA: execute_ex (in /usr/bin/php7.0)
==3856== by 0x356510: dtrace_execute_ex (in /usr/bin/php7.0)
==3856== by 0x9AE14EE: xdebug_execute_ex (xdebug.c:1890)
==3856== by 0x3EB5AC: ??? (in /usr/bin/php7.0)
==3856== by 0x3A6ACA: execute_ex (in /usr/bin/php7.0)
==3856== by 0x356510: dtrace_execute_ex (in /usr/bin/php7.0)
==3856== by 0x9AE14EE: xdebug_execute_ex (xdebug.c:1890)
==3856== Block was alloc'd at
==3856== at 0x4C2DB8F: malloc (in /usr/lib/valgrind/vgpreload_memcheck-amd64-linux.so)
==3856== by 0x37422C: _zend_hash_str_update (in /usr/bin/php7.0)
==3856== by 0x3695BE: add_assoc_str_ex (in /usr/bin/php7.0)
==3856== by 0x380CFE: zend_fetch_debug_backtrace (in /usr/bin/php7.0)
==3856== by 0x3811FC: ??? (in /usr/bin/php7.0)
==3856== by 0x356679: dtrace_execute_internal (in /usr/bin/php7.0)
==3856== by 0x9AE1E7D: xdebug_execute_internal (xdebug.c:2035)
==3856== by 0x3EB46F: ??? (in /usr/bin/php7.0)
==3856== by 0x3A6ACA: execute_ex (in /usr/bin/php7.0)
==3856== by 0x356510: dtrace_execute_ex (in /usr/bin/php7.0)
==3856== by 0x9AE14EE: xdebug_execute_ex (xdebug.c:1890)
==3856== by 0x3EB5AC: ??? (in /usr/bin/php7.0)
==3856==
==3856== Invalid write of size 8
==3856== at 0x38F4EA: gc_possible_root (in /usr/bin/php7.0)
==3856== by 0x2F608F: var_destroy (in /usr/bin/php7.0)
==3856== by 0x2E8967: zif_unserialize (in /usr/bin/php7.0)
==3856== by 0x356679: dtrace_execute_internal (in /usr/bin/php7.0)
==3856== by 0x9AE1E7D: xdebug_execute_internal (xdebug.c:2035)
==3856== by 0x3EB46F: ??? (in /usr/bin/php7.0)
==3856== by 0x3A6ACA: execute_ex (in /usr/bin/php7.0)
==3856== by 0x356510: dtrace_execute_ex (in /usr/bin/php7.0)
==3856== by 0x9AE14EE: xdebug_execute_ex (xdebug.c:1890)
==3856== by 0x3EB5AC: ??? (in /usr/bin/php7.0)
==3856== by 0x3A6ACA: execute_ex (in /usr/bin/php7.0)
==3856== by 0x356510: dtrace_execute_ex (in /usr/bin/php7.0)
==3856== Address 0x20f901c0 is 16 bytes before a block of size 288 free'd
==3856== at 0x4C2EDEB: free (in /usr/lib/valgrind/vgpreload_memcheck-amd64-linux.so)
==3856== by 0x3778F1: zend_array_destroy (in /usr/bin/php7.0)
==3856== by 0x37795E: zend_array_destroy (in /usr/bin/php7.0)
==3856== by 0x364A58: _zval_dtor_func_for_ptr (in /usr/bin/php7.0)
==3856== by 0x3F90C2: ??? (in /usr/bin/php7.0)
==3856== by 0x3A6ACA: execute_ex (in /usr/bin/php7.0)
==3856== by 0x356510: dtrace_execute_ex (in /usr/bin/php7.0)
==3856== by 0x9AE14EE: xdebug_execute_ex (xdebug.c:1890)
==3856== by 0x3EB5AC: ??? (in /usr/bin/php7.0)
==3856== by 0x3A6ACA: execute_ex (in /usr/bin/php7.0)
==3856== by 0x356510: dtrace_execute_ex (in /usr/bin/php7.0)
==3856== by 0x9AE14EE: xdebug_execute_ex (xdebug.c:1890)
==3856== Block was alloc'd at
==3856== at 0x4C2DB8F: malloc (in /usr/lib/valgrind/vgpreload_memcheck-amd64-linux.so)
==3856== by 0x37422C: _zend_hash_str_update (in /usr/bin/php7.0)
==3856== by 0x3695BE: add_assoc_str_ex (in /usr/bin/php7.0)
==3856== by 0x380CFE: zend_fetch_debug_backtrace (in /usr/bin/php7.0)
==3856== by 0x3811FC: ??? (in /usr/bin/php7.0)
==3856== by 0x356679: dtrace_execute_internal (in /usr/bin/php7.0)
==3856== by 0x9AE1E7D: xdebug_execute_internal (xdebug.c:2035)
==3856== by 0x3EB46F: ??? (in /usr/bin/php7.0)
==3856== by 0x3A6ACA: execute_ex (in /usr/bin/php7.0)
==3856== by 0x356510: dtrace_execute_ex (in /usr/bin/php7.0)
==3856== by 0x9AE14EE: xdebug_execute_ex (xdebug.c:1890)
==3856== by 0x3EB5AC: ??? (in /usr/bin/php7.0)
==3856==
==3856==
==3856== Process terminating with default action of signal 11 (SIGSEGV)
==3856== Bad permissions for mapped region at address 0x706870
==3856== at 0x38F4DB: gc_possible_root (in /usr/bin/php7.0)
==3856== by 0x2F608F: var_destroy (in /usr/bin/php7.0)
==3856== by 0x2E8967: zif_unserialize (in /usr/bin/php7.0)
==3856== by 0x356679: dtrace_execute_internal (in /usr/bin/php7.0)
==3856== by 0x9AE1E7D: xdebug_execute_internal (xdebug.c:2035)
==3856== by 0x3EB46F: ??? (in /usr/bin/php7.0)
==3856== by 0x3A6ACA: execute_ex (in /usr/bin/php7.0)
==3856== by 0x356510: dtrace_execute_ex (in /usr/bin/php7.0)
==3856== by 0x9AE14EE: xdebug_execute_ex (xdebug.c:1890)
==3856== by 0x3EB5AC: ??? (in /usr/bin/php7.0)
==3856== by 0x3A6ACA: execute_ex (in /usr/bin/php7.0)
==3856== by 0x356510: dtrace_execute_ex (in /usr/bin/php7.0)
==3856==
==3856== HEAP SUMMARY:
==3856== in use at exit: 99,178,289 bytes in 499,578 blocks
==3856== total heap usage: 65,129,443 allocs, 64,629,865 frees, 6,570,319,776 bytes allocated
==3856==
==3856== LEAK SUMMARY:
==3856== definitely lost: 1,688 bytes in 31 blocks
==3856== indirectly lost: 8,352 bytes in 29 blocks
==3856== possibly lost: 85,691,756 bytes in 392,542 blocks
==3856== still reachable: 13,476,493 bytes in 106,976 blocks
==3856== suppressed: 0 bytes in 0 blocks
==3856== Rerun with --leak-check=full to see details of leaked memory
Previous Comments:
------------------------------------------------------------------------
[2016-05-09 14:48:25] laruence@php.net
please try with valgrind, and see if there is any info useful
USE_ZEND_ALLOC=0 valgrind php your-script.php
thanks
------------------------------------------------------------------------
[2016-05-09 14:06:19] webmaster at tom-geiger dot de
The Stacktrace says 7.0.4, but the problem persists using the 7.0.6 packages from Ondrejs PPA.
------------------------------------------------------------------------
[2016-05-09 14:04:33] webmaster at tom-geiger dot de
Description:
------------
PHP CLI segfaults during a loop handling events from a database. At some point the GC segfaults the
script.
Adding gc_disable() at the start of the script will let it run through without error.
gdb bt attached.
See filed Ubuntu Bug: https://bugs.launchpad.net/bugs/1559693
"Segmentation fault (core dumped) while running an CLI "daemon" script that does a
multitude of database operations onto a mysql database. (mysqli)
Happens randomly, and not always at the same position of test data after processing multiple
thousand different SQL queries (Select, insert, update, delete).
Restarting the script after crash will successfully complete all test data.
Test data sadly can't be published because of privacy concerns."
StacktraceTop:
gc_possible_root (ref=0x7f1599693620) at /build/php7.0-XlnpcA/php7.0-7.0.4/Zend/zend_gc.c:262
zend_assign_to_variable (value_type=16 '\020', value=0x7f15996f4980,
variable_ptr=0x7f15afc15b30) at /build/php7.0-XlnpcA/php7.0-7.0.4/Zend/zend_execute.h:109
ZEND_FE_FETCH_R_SPEC_VAR_HANDLER () at
/build/php7.0-XlnpcA/php7.0-7.0.4/Zend/zend_vm_execute.h:15938
execute_ex (ex=ex@entry=0x7f15afc15ab0) at
/build/php7.0-XlnpcA/php7.0-7.0.4/Zend/zend_vm_execute.h:414
dtrace_execute_ex (execute_data=0x7f15afc15ab0) at
/build/php7.0-XlnpcA/php7.0-7.0.4/Zend/zend_dtrace.c:83
Expected result:
----------------
No segfault.
Actual result:
--------------
0x000055c1fb3dcabf in execute_ex ()
(gdb) cont
Continuing.
Program received signal SIGSEGV, Segmentation fault.
0x000055c1fb3c54bf in gc_possible_root ()
(gdb) bt
#0 0x000055c1fb3c54bf in gc_possible_root ()
#1 0x000055c1fb3e3870 in ?? ()
#2 0x000055c1fb3dcacb in execute_ex ()
#3 0x000055c1fb38c511 in dtrace_execute_ex ()
#4 0x00007fe1ceb434ef in xdebug_execute_ex (execute_data=0x7fe1cf4168c0) at
/build/xdebug-QTCpEl/xdebug-2.4.0/build-7.0/xdebug.c:1890
#5 0x000055c1fb4215ad in ?? ()
#6 0x000055c1fb3dcacb in execute_ex ()
#7 0x000055c1fb38c511 in dtrace_execute_ex ()
#8 0x00007fe1ceb434ef in xdebug_execute_ex (execute_data=0x7fe1cf416580) at
/build/xdebug-QTCpEl/xdebug-2.4.0/build-7.0/xdebug.c:1890
#9 0x000055c1fb4215ad in ?? ()
#10 0x000055c1fb3dcacb in execute_ex ()
#11 0x000055c1fb38c511 in dtrace_execute_ex ()
#12 0x00007fe1ceb434ef in xdebug_execute_ex (execute_data=0x7fe1cf4164c0) at
/build/xdebug-QTCpEl/xdebug-2.4.0/build-7.0/xdebug.c:1890
#13 0x000055c1fb4215ad in ?? ()
#14 0x000055c1fb3dcacb in execute_ex ()
#15 0x000055c1fb38c511 in dtrace_execute_ex ()
#16 0x00007fe1ceb434ef in xdebug_execute_ex (execute_data=0x7fe1cf4163f0) at
/build/xdebug-QTCpEl/xdebug-2.4.0/build-7.0/xdebug.c:1890
#17 0x000055c1fb4215ad in ?? ()
#18 0x000055c1fb3dcacb in execute_ex ()
#19 0x000055c1fb38c511 in dtrace_execute_ex ()
#20 0x00007fe1ceb434ef in xdebug_execute_ex (execute_data=0x7fe1cf415db0) at
/build/xdebug-QTCpEl/xdebug-2.4.0/build-7.0/xdebug.c:1890
#21 0x000055c1fb4215ad in ?? ()
#22 0x000055c1fb3dcacb in execute_ex ()
#23 0x000055c1fb38c511 in dtrace_execute_ex ()
#24 0x00007fe1ceb434ef in xdebug_execute_ex (execute_data=0x7fe1cf415b60) at
/build/xdebug-QTCpEl/xdebug-2.4.0/build-7.0/xdebug.c:1890
#25 0x000055c1fb4215ad in ?? ()
#26 0x000055c1fb3dcacb in execute_ex ()
#27 0x000055c1fb38c511 in dtrace_execute_ex ()
#28 0x00007fe1ceb434ef in xdebug_execute_ex (execute_data=0x7fe1cf415280) at
/build/xdebug-QTCpEl/xdebug-2.4.0/build-7.0/xdebug.c:1890
#29 0x000055c1fb4215ad in ?? ()
#30 0x000055c1fb3dcacb in execute_ex ()
#31 0x000055c1fb38c511 in dtrace_execute_ex ()
#32 0x00007fe1ceb434ef in xdebug_execute_ex (execute_data=0x7fe1cf414ae0) at
/build/xdebug-QTCpEl/xdebug-2.4.0/build-7.0/xdebug.c:1890
#33 0x000055c1fb4215ad in ?? ()
#34 0x000055c1fb3dcacb in execute_ex ()
#35 0x000055c1fb38c511 in dtrace_execute_ex ()
#36 0x00007fe1ceb434ef in xdebug_execute_ex (execute_data=0x7fe1cf4149b0) at
/build/xdebug-QTCpEl/xdebug-2.4.0/build-7.0/xdebug.c:1890
#37 0x000055c1fb4215ad in ?? ()
#38 0x000055c1fb3dcacb in execute_ex ()
#39 0x000055c1fb38c511 in dtrace_execute_ex ()
#40 0x00007fe1ceb434ef in xdebug_execute_ex (execute_data=0x7fe1cf414650) at
/build/xdebug-QTCpEl/xdebug-2.4.0/build-7.0/xdebug.c:1890
#41 0x000055c1fb4215ad in ?? ()
#42 0x000055c1fb3dcacb in execute_ex ()
#43 0x000055c1fb38c511 in dtrace_execute_ex ()
#44 0x00007fe1ceb434ef in xdebug_execute_ex (execute_data=0x7fe1cf4144d0) at
/build/xdebug-QTCpEl/xdebug-2.4.0/build-7.0/xdebug.c:1890
#45 0x000055c1fb4215ad in ?? ()
#46 0x000055c1fb3dcacb in execute_ex ()
#47 0x000055c1fb38c511 in dtrace_execute_ex ()
#48 0x00007fe1ceb434ef in xdebug_execute_ex (execute_data=0x7fe1cf414030) at
/build/xdebug-QTCpEl/xdebug-2.4.0/build-7.0/xdebug.c:1890
#49 0x000055c1fb430537 in zend_execute ()
---Type <return> to continue, or q <return> to quit---bt
#50 0x000055c1fb39c713 in zend_execute_scripts ()
#51 0x000055c1fb33d130 in php_execute_script ()
#52 0x000055c1fb4321f7 in ?? ()
#53 0x000055c1fb221f64 in main ()
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=72179&edit=1