Bug #72179 [Fbk->Asn]: Segfault in gc_possible_root on CLI

From: Date: Thu, 12 May 2016 13:23:16 +0000
Subject: Bug #72179 [Fbk->Asn]: Segfault in gc_possible_root on CLI
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-201036@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=72179&edit=1 ID: 72179 User updated by: webmaster at tom-geiger dot de Reported by: webmaster at tom-geiger dot de Summary: Segfault in gc_possible_root on CLI -Status: Feedback +Status: Assigned Type: Bug Package: Reproducible crash Operating System: Ubuntu 16.04 PHP Version: 7.0.6 Assigned To: laruence Block user comment: N Private report: N New Comment: Running valgrind gives me this: I'll check if I can get more information with different valgrind parameters: ==3856== Invalid read of size 8 ==3856== at 0x38F4BF: gc_possible_root (in /usr/bin/php7.0) ==3856== by 0x2F608F: var_destroy (in /usr/bin/php7.0) ==3856== by 0x2E8967: zif_unserialize (in /usr/bin/php7.0) ==3856== by 0x356679: dtrace_execute_internal (in /usr/bin/php7.0) ==3856== by 0x9AE1E7D: xdebug_execute_internal (xdebug.c:2035) ==3856== by 0x3EB46F: ??? (in /usr/bin/php7.0) ==3856== by 0x3A6ACA: execute_ex (in /usr/bin/php7.0) ==3856== by 0x356510: dtrace_execute_ex (in /usr/bin/php7.0) ==3856== by 0x9AE14EE: xdebug_execute_ex (xdebug.c:1890) ==3856== by 0x3EB5AC: ??? (in /usr/bin/php7.0) ==3856== by 0x3A6ACA: execute_ex (in /usr/bin/php7.0) ==3856== by 0x356510: dtrace_execute_ex (in /usr/bin/php7.0) ==3856== Address 0x20f901c0 is 16 bytes before a block of size 288 free'd ==3856== at 0x4C2EDEB: free (in /usr/lib/valgrind/vgpreload_memcheck-amd64-linux.so) ==3856== by 0x3778F1: zend_array_destroy (in /usr/bin/php7.0) ==3856== by 0x37795E: zend_array_destroy (in /usr/bin/php7.0) ==3856== by 0x364A58: _zval_dtor_func_for_ptr (in /usr/bin/php7.0) ==3856== by 0x3F90C2: ??? (in /usr/bin/php7.0) ==3856== by 0x3A6ACA: execute_ex (in /usr/bin/php7.0) ==3856== by 0x356510: dtrace_execute_ex (in /usr/bin/php7.0) ==3856== by 0x9AE14EE: xdebug_execute_ex (xdebug.c:1890) ==3856== by 0x3EB5AC: ??? (in /usr/bin/php7.0) ==3856== by 0x3A6ACA: execute_ex (in /usr/bin/php7.0) ==3856== by 0x356510: dtrace_execute_ex (in /usr/bin/php7.0) ==3856== by 0x9AE14EE: xdebug_execute_ex (xdebug.c:1890) ==3856== Block was alloc'd at ==3856== at 0x4C2DB8F: malloc (in /usr/lib/valgrind/vgpreload_memcheck-amd64-linux.so) ==3856== by 0x37422C: _zend_hash_str_update (in /usr/bin/php7.0) ==3856== by 0x3695BE: add_assoc_str_ex (in /usr/bin/php7.0) ==3856== by 0x380CFE: zend_fetch_debug_backtrace (in /usr/bin/php7.0) ==3856== by 0x3811FC: ??? (in /usr/bin/php7.0) ==3856== by 0x356679: dtrace_execute_internal (in /usr/bin/php7.0) ==3856== by 0x9AE1E7D: xdebug_execute_internal (xdebug.c:2035) ==3856== by 0x3EB46F: ??? (in /usr/bin/php7.0) ==3856== by 0x3A6ACA: execute_ex (in /usr/bin/php7.0) ==3856== by 0x356510: dtrace_execute_ex (in /usr/bin/php7.0) ==3856== by 0x9AE14EE: xdebug_execute_ex (xdebug.c:1890) ==3856== by 0x3EB5AC: ??? (in /usr/bin/php7.0) ==3856== ==3856== Invalid write of size 8 ==3856== at 0x38F4DB: gc_possible_root (in /usr/bin/php7.0) ==3856== by 0x2F608F: var_destroy (in /usr/bin/php7.0) ==3856== by 0x2E8967: zif_unserialize (in /usr/bin/php7.0) ==3856== by 0x356679: dtrace_execute_internal (in /usr/bin/php7.0) ==3856== by 0x9AE1E7D: xdebug_execute_internal (xdebug.c:2035) ==3856== by 0x3EB46F: ??? (in /usr/bin/php7.0) ==3856== by 0x3A6ACA: execute_ex (in /usr/bin/php7.0) ==3856== by 0x356510: dtrace_execute_ex (in /usr/bin/php7.0) ==3856== by 0x9AE14EE: xdebug_execute_ex (xdebug.c:1890) ==3856== by 0x3EB5AC: ??? (in /usr/bin/php7.0) ==3856== by 0x3A6ACA: execute_ex (in /usr/bin/php7.0) ==3856== by 0x356510: dtrace_execute_ex (in /usr/bin/php7.0) ==3856== Address 0x20f901b0 is 32 bytes before a block of size 288 in arena "client" ==3856== ==3856== Invalid write of size 8 ==3856== at 0x38F4E2: gc_possible_root (in /usr/bin/php7.0) ==3856== by 0x2F608F: var_destroy (in /usr/bin/php7.0) ==3856== by 0x2E8967: zif_unserialize (in /usr/bin/php7.0) ==3856== by 0x356679: dtrace_execute_internal (in /usr/bin/php7.0) ==3856== by 0x9AE1E7D: xdebug_execute_internal (xdebug.c:2035) ==3856== by 0x3EB46F: ??? (in /usr/bin/php7.0) ==3856== by 0x3A6ACA: execute_ex (in /usr/bin/php7.0) ==3856== by 0x356510: dtrace_execute_ex (in /usr/bin/php7.0) ==3856== by 0x9AE14EE: xdebug_execute_ex (xdebug.c:1890) ==3856== by 0x3EB5AC: ??? (in /usr/bin/php7.0) ==3856== by 0x3A6ACA: execute_ex (in /usr/bin/php7.0) ==3856== by 0x356510: dtrace_execute_ex (in /usr/bin/php7.0) ==3856== Address 0x20f901b8 is 24 bytes before a block of size 288 free'd ==3856== at 0x4C2EDEB: free (in /usr/lib/valgrind/vgpreload_memcheck-amd64-linux.so) ==3856== by 0x3778F1: zend_array_destroy (in /usr/bin/php7.0) ==3856== by 0x37795E: zend_array_destroy (in /usr/bin/php7.0) ==3856== by 0x364A58: _zval_dtor_func_for_ptr (in /usr/bin/php7.0) ==3856== by 0x3F90C2: ??? (in /usr/bin/php7.0) ==3856== by 0x3A6ACA: execute_ex (in /usr/bin/php7.0) ==3856== by 0x356510: dtrace_execute_ex (in /usr/bin/php7.0) ==3856== by 0x9AE14EE: xdebug_execute_ex (xdebug.c:1890) ==3856== by 0x3EB5AC: ??? (in /usr/bin/php7.0) ==3856== by 0x3A6ACA: execute_ex (in /usr/bin/php7.0) ==3856== by 0x356510: dtrace_execute_ex (in /usr/bin/php7.0) ==3856== by 0x9AE14EE: xdebug_execute_ex (xdebug.c:1890) ==3856== Block was alloc'd at ==3856== at 0x4C2DB8F: malloc (in /usr/lib/valgrind/vgpreload_memcheck-amd64-linux.so) ==3856== by 0x37422C: _zend_hash_str_update (in /usr/bin/php7.0) ==3856== by 0x3695BE: add_assoc_str_ex (in /usr/bin/php7.0) ==3856== by 0x380CFE: zend_fetch_debug_backtrace (in /usr/bin/php7.0) ==3856== by 0x3811FC: ??? (in /usr/bin/php7.0) ==3856== by 0x356679: dtrace_execute_internal (in /usr/bin/php7.0) ==3856== by 0x9AE1E7D: xdebug_execute_internal (xdebug.c:2035) ==3856== by 0x3EB46F: ??? (in /usr/bin/php7.0) ==3856== by 0x3A6ACA: execute_ex (in /usr/bin/php7.0) ==3856== by 0x356510: dtrace_execute_ex (in /usr/bin/php7.0) ==3856== by 0x9AE14EE: xdebug_execute_ex (xdebug.c:1890) ==3856== by 0x3EB5AC: ??? (in /usr/bin/php7.0) ==3856== ==3856== Invalid write of size 8 ==3856== at 0x38F4EA: gc_possible_root (in /usr/bin/php7.0) ==3856== by 0x2F608F: var_destroy (in /usr/bin/php7.0) ==3856== by 0x2E8967: zif_unserialize (in /usr/bin/php7.0) ==3856== by 0x356679: dtrace_execute_internal (in /usr/bin/php7.0) ==3856== by 0x9AE1E7D: xdebug_execute_internal (xdebug.c:2035) ==3856== by 0x3EB46F: ??? (in /usr/bin/php7.0) ==3856== by 0x3A6ACA: execute_ex (in /usr/bin/php7.0) ==3856== by 0x356510: dtrace_execute_ex (in /usr/bin/php7.0) ==3856== by 0x9AE14EE: xdebug_execute_ex (xdebug.c:1890) ==3856== by 0x3EB5AC: ??? (in /usr/bin/php7.0) ==3856== by 0x3A6ACA: execute_ex (in /usr/bin/php7.0) ==3856== by 0x356510: dtrace_execute_ex (in /usr/bin/php7.0) ==3856== Address 0x20f901c0 is 16 bytes before a block of size 288 free'd ==3856== at 0x4C2EDEB: free (in /usr/lib/valgrind/vgpreload_memcheck-amd64-linux.so) ==3856== by 0x3778F1: zend_array_destroy (in /usr/bin/php7.0) ==3856== by 0x37795E: zend_array_destroy (in /usr/bin/php7.0) ==3856== by 0x364A58: _zval_dtor_func_for_ptr (in /usr/bin/php7.0) ==3856== by 0x3F90C2: ??? (in /usr/bin/php7.0) ==3856== by 0x3A6ACA: execute_ex (in /usr/bin/php7.0) ==3856== by 0x356510: dtrace_execute_ex (in /usr/bin/php7.0) ==3856== by 0x9AE14EE: xdebug_execute_ex (xdebug.c:1890) ==3856== by 0x3EB5AC: ??? (in /usr/bin/php7.0) ==3856== by 0x3A6ACA: execute_ex (in /usr/bin/php7.0) ==3856== by 0x356510: dtrace_execute_ex (in /usr/bin/php7.0) ==3856== by 0x9AE14EE: xdebug_execute_ex (xdebug.c:1890) ==3856== Block was alloc'd at ==3856== at 0x4C2DB8F: malloc (in /usr/lib/valgrind/vgpreload_memcheck-amd64-linux.so) ==3856== by 0x37422C: _zend_hash_str_update (in /usr/bin/php7.0) ==3856== by 0x3695BE: add_assoc_str_ex (in /usr/bin/php7.0) ==3856== by 0x380CFE: zend_fetch_debug_backtrace (in /usr/bin/php7.0) ==3856== by 0x3811FC: ??? (in /usr/bin/php7.0) ==3856== by 0x356679: dtrace_execute_internal (in /usr/bin/php7.0) ==3856== by 0x9AE1E7D: xdebug_execute_internal (xdebug.c:2035) ==3856== by 0x3EB46F: ??? (in /usr/bin/php7.0) ==3856== by 0x3A6ACA: execute_ex (in /usr/bin/php7.0) ==3856== by 0x356510: dtrace_execute_ex (in /usr/bin/php7.0) ==3856== by 0x9AE14EE: xdebug_execute_ex (xdebug.c:1890) ==3856== by 0x3EB5AC: ??? (in /usr/bin/php7.0) ==3856== ==3856== ==3856== Process terminating with default action of signal 11 (SIGSEGV) ==3856== Bad permissions for mapped region at address 0x706870 ==3856== at 0x38F4DB: gc_possible_root (in /usr/bin/php7.0) ==3856== by 0x2F608F: var_destroy (in /usr/bin/php7.0) ==3856== by 0x2E8967: zif_unserialize (in /usr/bin/php7.0) ==3856== by 0x356679: dtrace_execute_internal (in /usr/bin/php7.0) ==3856== by 0x9AE1E7D: xdebug_execute_internal (xdebug.c:2035) ==3856== by 0x3EB46F: ??? (in /usr/bin/php7.0) ==3856== by 0x3A6ACA: execute_ex (in /usr/bin/php7.0) ==3856== by 0x356510: dtrace_execute_ex (in /usr/bin/php7.0) ==3856== by 0x9AE14EE: xdebug_execute_ex (xdebug.c:1890) ==3856== by 0x3EB5AC: ??? (in /usr/bin/php7.0) ==3856== by 0x3A6ACA: execute_ex (in /usr/bin/php7.0) ==3856== by 0x356510: dtrace_execute_ex (in /usr/bin/php7.0) ==3856== ==3856== HEAP SUMMARY: ==3856== in use at exit: 99,178,289 bytes in 499,578 blocks ==3856== total heap usage: 65,129,443 allocs, 64,629,865 frees, 6,570,319,776 bytes allocated ==3856== ==3856== LEAK SUMMARY: ==3856== definitely lost: 1,688 bytes in 31 blocks ==3856== indirectly lost: 8,352 bytes in 29 blocks ==3856== possibly lost: 85,691,756 bytes in 392,542 blocks ==3856== still reachable: 13,476,493 bytes in 106,976 blocks ==3856== suppressed: 0 bytes in 0 blocks ==3856== Rerun with --leak-check=full to see details of leaked memory Previous Comments: ------------------------------------------------------------------------ [2016-05-09 14:48:25] laruence@php.net please try with valgrind, and see if there is any info useful USE_ZEND_ALLOC=0 valgrind php your-script.php thanks ------------------------------------------------------------------------ [2016-05-09 14:06:19] webmaster at tom-geiger dot de The Stacktrace says 7.0.4, but the problem persists using the 7.0.6 packages from Ondrejs PPA. ------------------------------------------------------------------------ [2016-05-09 14:04:33] webmaster at tom-geiger dot de Description: ------------ PHP CLI segfaults during a loop handling events from a database. At some point the GC segfaults the script. Adding gc_disable() at the start of the script will let it run through without error. gdb bt attached. See filed Ubuntu Bug: https://bugs.launchpad.net/bugs/1559693 "Segmentation fault (core dumped) while running an CLI "daemon" script that does a multitude of database operations onto a mysql database. (mysqli) Happens randomly, and not always at the same position of test data after processing multiple thousand different SQL queries (Select, insert, update, delete). Restarting the script after crash will successfully complete all test data. Test data sadly can't be published because of privacy concerns." StacktraceTop: gc_possible_root (ref=0x7f1599693620) at /build/php7.0-XlnpcA/php7.0-7.0.4/Zend/zend_gc.c:262 zend_assign_to_variable (value_type=16 '\020', value=0x7f15996f4980, variable_ptr=0x7f15afc15b30) at /build/php7.0-XlnpcA/php7.0-7.0.4/Zend/zend_execute.h:109 ZEND_FE_FETCH_R_SPEC_VAR_HANDLER () at /build/php7.0-XlnpcA/php7.0-7.0.4/Zend/zend_vm_execute.h:15938 execute_ex (ex=ex@entry=0x7f15afc15ab0) at /build/php7.0-XlnpcA/php7.0-7.0.4/Zend/zend_vm_execute.h:414 dtrace_execute_ex (execute_data=0x7f15afc15ab0) at /build/php7.0-XlnpcA/php7.0-7.0.4/Zend/zend_dtrace.c:83 Expected result: ---------------- No segfault. Actual result: -------------- 0x000055c1fb3dcabf in execute_ex () (gdb) cont Continuing. Program received signal SIGSEGV, Segmentation fault. 0x000055c1fb3c54bf in gc_possible_root () (gdb) bt #0 0x000055c1fb3c54bf in gc_possible_root () #1 0x000055c1fb3e3870 in ?? () #2 0x000055c1fb3dcacb in execute_ex () #3 0x000055c1fb38c511 in dtrace_execute_ex () #4 0x00007fe1ceb434ef in xdebug_execute_ex (execute_data=0x7fe1cf4168c0) at /build/xdebug-QTCpEl/xdebug-2.4.0/build-7.0/xdebug.c:1890 #5 0x000055c1fb4215ad in ?? () #6 0x000055c1fb3dcacb in execute_ex () #7 0x000055c1fb38c511 in dtrace_execute_ex () #8 0x00007fe1ceb434ef in xdebug_execute_ex (execute_data=0x7fe1cf416580) at /build/xdebug-QTCpEl/xdebug-2.4.0/build-7.0/xdebug.c:1890 #9 0x000055c1fb4215ad in ?? () #10 0x000055c1fb3dcacb in execute_ex () #11 0x000055c1fb38c511 in dtrace_execute_ex () #12 0x00007fe1ceb434ef in xdebug_execute_ex (execute_data=0x7fe1cf4164c0) at /build/xdebug-QTCpEl/xdebug-2.4.0/build-7.0/xdebug.c:1890 #13 0x000055c1fb4215ad in ?? () #14 0x000055c1fb3dcacb in execute_ex () #15 0x000055c1fb38c511 in dtrace_execute_ex () #16 0x00007fe1ceb434ef in xdebug_execute_ex (execute_data=0x7fe1cf4163f0) at /build/xdebug-QTCpEl/xdebug-2.4.0/build-7.0/xdebug.c:1890 #17 0x000055c1fb4215ad in ?? () #18 0x000055c1fb3dcacb in execute_ex () #19 0x000055c1fb38c511 in dtrace_execute_ex () #20 0x00007fe1ceb434ef in xdebug_execute_ex (execute_data=0x7fe1cf415db0) at /build/xdebug-QTCpEl/xdebug-2.4.0/build-7.0/xdebug.c:1890 #21 0x000055c1fb4215ad in ?? () #22 0x000055c1fb3dcacb in execute_ex () #23 0x000055c1fb38c511 in dtrace_execute_ex () #24 0x00007fe1ceb434ef in xdebug_execute_ex (execute_data=0x7fe1cf415b60) at /build/xdebug-QTCpEl/xdebug-2.4.0/build-7.0/xdebug.c:1890 #25 0x000055c1fb4215ad in ?? () #26 0x000055c1fb3dcacb in execute_ex () #27 0x000055c1fb38c511 in dtrace_execute_ex () #28 0x00007fe1ceb434ef in xdebug_execute_ex (execute_data=0x7fe1cf415280) at /build/xdebug-QTCpEl/xdebug-2.4.0/build-7.0/xdebug.c:1890 #29 0x000055c1fb4215ad in ?? () #30 0x000055c1fb3dcacb in execute_ex () #31 0x000055c1fb38c511 in dtrace_execute_ex () #32 0x00007fe1ceb434ef in xdebug_execute_ex (execute_data=0x7fe1cf414ae0) at /build/xdebug-QTCpEl/xdebug-2.4.0/build-7.0/xdebug.c:1890 #33 0x000055c1fb4215ad in ?? () #34 0x000055c1fb3dcacb in execute_ex () #35 0x000055c1fb38c511 in dtrace_execute_ex () #36 0x00007fe1ceb434ef in xdebug_execute_ex (execute_data=0x7fe1cf4149b0) at /build/xdebug-QTCpEl/xdebug-2.4.0/build-7.0/xdebug.c:1890 #37 0x000055c1fb4215ad in ?? () #38 0x000055c1fb3dcacb in execute_ex () #39 0x000055c1fb38c511 in dtrace_execute_ex () #40 0x00007fe1ceb434ef in xdebug_execute_ex (execute_data=0x7fe1cf414650) at /build/xdebug-QTCpEl/xdebug-2.4.0/build-7.0/xdebug.c:1890 #41 0x000055c1fb4215ad in ?? () #42 0x000055c1fb3dcacb in execute_ex () #43 0x000055c1fb38c511 in dtrace_execute_ex () #44 0x00007fe1ceb434ef in xdebug_execute_ex (execute_data=0x7fe1cf4144d0) at /build/xdebug-QTCpEl/xdebug-2.4.0/build-7.0/xdebug.c:1890 #45 0x000055c1fb4215ad in ?? () #46 0x000055c1fb3dcacb in execute_ex () #47 0x000055c1fb38c511 in dtrace_execute_ex () #48 0x00007fe1ceb434ef in xdebug_execute_ex (execute_data=0x7fe1cf414030) at /build/xdebug-QTCpEl/xdebug-2.4.0/build-7.0/xdebug.c:1890 #49 0x000055c1fb430537 in zend_execute () ---Type <return> to continue, or q <return> to quit---bt #50 0x000055c1fb39c713 in zend_execute_scripts () #51 0x000055c1fb33d130 in php_execute_script () #52 0x000055c1fb4321f7 in ?? () #53 0x000055c1fb221f64 in main () ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=72179&edit=1

« previous php.bugs (#201036) next »