Bug #72179 [Asn]: Segfault in gc_possible_root on CLI
| From: | webmaster at tom-geiger dot de | Date: | Thu, 19 May 2016 13:24:59 +0000 |
| Subject: | Bug #72179 [Asn]: Segfault in gc_possible_root on CLI | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-201194@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=72179&edit=1
ID: 72179
User updated by: webmaster at tom-geiger dot de
Reported by: webmaster at tom-geiger dot de
Summary: Segfault in gc_possible_root on CLI
Status: Assigned
Type: Bug
Package: Reproducible crash
Operating System: Ubuntu 16.04
PHP Version: 7.0.6
Assigned To: laruence
Block user comment: N
Private report: N
New Comment:
Compiled PHP myself from the GIT repository.
The segfault still persists, when running gdb I get this error:
Program received signal SIGSEGV, Segmentation fault.
0x000000000085cf75 in gc_possible_root (ref=0x7fffeafb02a0) at
/home/geiger/git/php/Zend/zend_gc.c:234
234 GC_G(unused) = newRoot->prev;
I have also during testing the compile had the same error in line 262 once,
both lines use GC_G(unused) = newRoot->prev;
Previous Comments:
------------------------------------------------------------------------
[2016-05-12 13:23:11] webmaster at tom-geiger dot de
Running valgrind gives me this: I'll check if I can get more information with different
valgrind parameters:
==3856== Invalid read of size 8
==3856== at 0x38F4BF: gc_possible_root (in /usr/bin/php7.0)
==3856== by 0x2F608F: var_destroy (in /usr/bin/php7.0)
==3856== by 0x2E8967: zif_unserialize (in /usr/bin/php7.0)
==3856== by 0x356679: dtrace_execute_internal (in /usr/bin/php7.0)
==3856== by 0x9AE1E7D: xdebug_execute_internal (xdebug.c:2035)
==3856== by 0x3EB46F: ??? (in /usr/bin/php7.0)
==3856== by 0x3A6ACA: execute_ex (in /usr/bin/php7.0)
==3856== by 0x356510: dtrace_execute_ex (in /usr/bin/php7.0)
==3856== by 0x9AE14EE: xdebug_execute_ex (xdebug.c:1890)
==3856== by 0x3EB5AC: ??? (in /usr/bin/php7.0)
==3856== by 0x3A6ACA: execute_ex (in /usr/bin/php7.0)
==3856== by 0x356510: dtrace_execute_ex (in /usr/bin/php7.0)
==3856== Address 0x20f901c0 is 16 bytes before a block of size 288 free'd
==3856== at 0x4C2EDEB: free (in /usr/lib/valgrind/vgpreload_memcheck-amd64-linux.so)
==3856== by 0x3778F1: zend_array_destroy (in /usr/bin/php7.0)
==3856== by 0x37795E: zend_array_destroy (in /usr/bin/php7.0)
==3856== by 0x364A58: _zval_dtor_func_for_ptr (in /usr/bin/php7.0)
==3856== by 0x3F90C2: ??? (in /usr/bin/php7.0)
==3856== by 0x3A6ACA: execute_ex (in /usr/bin/php7.0)
==3856== by 0x356510: dtrace_execute_ex (in /usr/bin/php7.0)
==3856== by 0x9AE14EE: xdebug_execute_ex (xdebug.c:1890)
==3856== by 0x3EB5AC: ??? (in /usr/bin/php7.0)
==3856== by 0x3A6ACA: execute_ex (in /usr/bin/php7.0)
==3856== by 0x356510: dtrace_execute_ex (in /usr/bin/php7.0)
==3856== by 0x9AE14EE: xdebug_execute_ex (xdebug.c:1890)
==3856== Block was alloc'd at
==3856== at 0x4C2DB8F: malloc (in /usr/lib/valgrind/vgpreload_memcheck-amd64-linux.so)
==3856== by 0x37422C: _zend_hash_str_update (in /usr/bin/php7.0)
==3856== by 0x3695BE: add_assoc_str_ex (in /usr/bin/php7.0)
==3856== by 0x380CFE: zend_fetch_debug_backtrace (in /usr/bin/php7.0)
==3856== by 0x3811FC: ??? (in /usr/bin/php7.0)
==3856== by 0x356679: dtrace_execute_internal (in /usr/bin/php7.0)
==3856== by 0x9AE1E7D: xdebug_execute_internal (xdebug.c:2035)
==3856== by 0x3EB46F: ??? (in /usr/bin/php7.0)
==3856== by 0x3A6ACA: execute_ex (in /usr/bin/php7.0)
==3856== by 0x356510: dtrace_execute_ex (in /usr/bin/php7.0)
==3856== by 0x9AE14EE: xdebug_execute_ex (xdebug.c:1890)
==3856== by 0x3EB5AC: ??? (in /usr/bin/php7.0)
==3856==
==3856== Invalid write of size 8
==3856== at 0x38F4DB: gc_possible_root (in /usr/bin/php7.0)
==3856== by 0x2F608F: var_destroy (in /usr/bin/php7.0)
==3856== by 0x2E8967: zif_unserialize (in /usr/bin/php7.0)
==3856== by 0x356679: dtrace_execute_internal (in /usr/bin/php7.0)
==3856== by 0x9AE1E7D: xdebug_execute_internal (xdebug.c:2035)
==3856== by 0x3EB46F: ??? (in /usr/bin/php7.0)
==3856== by 0x3A6ACA: execute_ex (in /usr/bin/php7.0)
==3856== by 0x356510: dtrace_execute_ex (in /usr/bin/php7.0)
==3856== by 0x9AE14EE: xdebug_execute_ex (xdebug.c:1890)
==3856== by 0x3EB5AC: ??? (in /usr/bin/php7.0)
==3856== by 0x3A6ACA: execute_ex (in /usr/bin/php7.0)
==3856== by 0x356510: dtrace_execute_ex (in /usr/bin/php7.0)
==3856== Address 0x20f901b0 is 32 bytes before a block of size 288 in arena "client"
==3856==
==3856== Invalid write of size 8
==3856== at 0x38F4E2: gc_possible_root (in /usr/bin/php7.0)
==3856== by 0x2F608F: var_destroy (in /usr/bin/php7.0)
==3856== by 0x2E8967: zif_unserialize (in /usr/bin/php7.0)
==3856== by 0x356679: dtrace_execute_internal (in /usr/bin/php7.0)
==3856== by 0x9AE1E7D: xdebug_execute_internal (xdebug.c:2035)
==3856== by 0x3EB46F: ??? (in /usr/bin/php7.0)
==3856== by 0x3A6ACA: execute_ex (in /usr/bin/php7.0)
==3856== by 0x356510: dtrace_execute_ex (in /usr/bin/php7.0)
==3856== by 0x9AE14EE: xdebug_execute_ex (xdebug.c:1890)
==3856== by 0x3EB5AC: ??? (in /usr/bin/php7.0)
==3856== by 0x3A6ACA: execute_ex (in /usr/bin/php7.0)
==3856== by 0x356510: dtrace_execute_ex (in /usr/bin/php7.0)
==3856== Address 0x20f901b8 is 24 bytes before a block of size 288 free'd
==3856== at 0x4C2EDEB: free (in /usr/lib/valgrind/vgpreload_memcheck-amd64-linux.so)
==3856== by 0x3778F1: zend_array_destroy (in /usr/bin/php7.0)
==3856== by 0x37795E: zend_array_destroy (in /usr/bin/php7.0)
==3856== by 0x364A58: _zval_dtor_func_for_ptr (in /usr/bin/php7.0)
==3856== by 0x3F90C2: ??? (in /usr/bin/php7.0)
==3856== by 0x3A6ACA: execute_ex (in /usr/bin/php7.0)
==3856== by 0x356510: dtrace_execute_ex (in /usr/bin/php7.0)
==3856== by 0x9AE14EE: xdebug_execute_ex (xdebug.c:1890)
==3856== by 0x3EB5AC: ??? (in /usr/bin/php7.0)
==3856== by 0x3A6ACA: execute_ex (in /usr/bin/php7.0)
==3856== by 0x356510: dtrace_execute_ex (in /usr/bin/php7.0)
==3856== by 0x9AE14EE: xdebug_execute_ex (xdebug.c:1890)
==3856== Block was alloc'd at
==3856== at 0x4C2DB8F: malloc (in /usr/lib/valgrind/vgpreload_memcheck-amd64-linux.so)
==3856== by 0x37422C: _zend_hash_str_update (in /usr/bin/php7.0)
==3856== by 0x3695BE: add_assoc_str_ex (in /usr/bin/php7.0)
==3856== by 0x380CFE: zend_fetch_debug_backtrace (in /usr/bin/php7.0)
==3856== by 0x3811FC: ??? (in /usr/bin/php7.0)
==3856== by 0x356679: dtrace_execute_internal (in /usr/bin/php7.0)
==3856== by 0x9AE1E7D: xdebug_execute_internal (xdebug.c:2035)
==3856== by 0x3EB46F: ??? (in /usr/bin/php7.0)
==3856== by 0x3A6ACA: execute_ex (in /usr/bin/php7.0)
==3856== by 0x356510: dtrace_execute_ex (in /usr/bin/php7.0)
==3856== by 0x9AE14EE: xdebug_execute_ex (xdebug.c:1890)
==3856== by 0x3EB5AC: ??? (in /usr/bin/php7.0)
==3856==
==3856== Invalid write of size 8
==3856== at 0x38F4EA: gc_possible_root (in /usr/bin/php7.0)
==3856== by 0x2F608F: var_destroy (in /usr/bin/php7.0)
==3856== by 0x2E8967: zif_unserialize (in /usr/bin/php7.0)
==3856== by 0x356679: dtrace_execute_internal (in /usr/bin/php7.0)
==3856== by 0x9AE1E7D: xdebug_execute_internal (xdebug.c:2035)
==3856== by 0x3EB46F: ??? (in /usr/bin/php7.0)
==3856== by 0x3A6ACA: execute_ex (in /usr/bin/php7.0)
==3856== by 0x356510: dtrace_execute_ex (in /usr/bin/php7.0)
==3856== by 0x9AE14EE: xdebug_execute_ex (xdebug.c:1890)
==3856== by 0x3EB5AC: ??? (in /usr/bin/php7.0)
==3856== by 0x3A6ACA: execute_ex (in /usr/bin/php7.0)
==3856== by 0x356510: dtrace_execute_ex (in /usr/bin/php7.0)
==3856== Address 0x20f901c0 is 16 bytes before a block of size 288 free'd
==3856== at 0x4C2EDEB: free (in /usr/lib/valgrind/vgpreload_memcheck-amd64-linux.so)
==3856== by 0x3778F1: zend_array_destroy (in /usr/bin/php7.0)
==3856== by 0x37795E: zend_array_destroy (in /usr/bin/php7.0)
==3856== by 0x364A58: _zval_dtor_func_for_ptr (in /usr/bin/php7.0)
==3856== by 0x3F90C2: ??? (in /usr/bin/php7.0)
==3856== by 0x3A6ACA: execute_ex (in /usr/bin/php7.0)
==3856== by 0x356510: dtrace_execute_ex (in /usr/bin/php7.0)
==3856== by 0x9AE14EE: xdebug_execute_ex (xdebug.c:1890)
==3856== by 0x3EB5AC: ??? (in /usr/bin/php7.0)
==3856== by 0x3A6ACA: execute_ex (in /usr/bin/php7.0)
==3856== by 0x356510: dtrace_execute_ex (in /usr/bin/php7.0)
==3856== by 0x9AE14EE: xdebug_execute_ex (xdebug.c:1890)
==3856== Block was alloc'd at
==3856== at 0x4C2DB8F: malloc (in /usr/lib/valgrind/vgpreload_memcheck-amd64-linux.so)
==3856== by 0x37422C: _zend_hash_str_update (in /usr/bin/php7.0)
==3856== by 0x3695BE: add_assoc_str_ex (in /usr/bin/php7.0)
==3856== by 0x380CFE: zend_fetch_debug_backtrace (in /usr/bin/php7.0)
==3856== by 0x3811FC: ??? (in /usr/bin/php7.0)
==3856== by 0x356679: dtrace_execute_internal (in /usr/bin/php7.0)
==3856== by 0x9AE1E7D: xdebug_execute_internal (xdebug.c:2035)
==3856== by 0x3EB46F: ??? (in /usr/bin/php7.0)
==3856== by 0x3A6ACA: execute_ex (in /usr/bin/php7.0)
==3856== by 0x356510: dtrace_execute_ex (in /usr/bin/php7.0)
==3856== by 0x9AE14EE: xdebug_execute_ex (xdebug.c:1890)
==3856== by 0x3EB5AC: ??? (in /usr/bin/php7.0)
==3856==
==3856==
==3856== Process terminating with default action of signal 11 (SIGSEGV)
==3856== Bad permissions for mapped region at address 0x706870
==3856== at 0x38F4DB: gc_possible_root (in /usr/bin/php7.0)
==3856== by 0x2F608F: var_destroy (in /usr/bin/php7.0)
==3856== by 0x2E8967: zif_unserialize (in /usr/bin/php7.0)
==3856== by 0x356679: dtrace_execute_internal (in /usr/bin/php7.0)
==3856== by 0x9AE1E7D: xdebug_execute_internal (xdebug.c:2035)
==3856== by 0x3EB46F: ??? (in /usr/bin/php7.0)
==3856== by 0x3A6ACA: execute_ex (in /usr/bin/php7.0)
==3856== by 0x356510: dtrace_execute_ex (in /usr/bin/php7.0)
==3856== by 0x9AE14EE: xdebug_execute_ex (xdebug.c:1890)
==3856== by 0x3EB5AC: ??? (in /usr/bin/php7.0)
==3856== by 0x3A6ACA: execute_ex (in /usr/bin/php7.0)
==3856== by 0x356510: dtrace_execute_ex (in /usr/bin/php7.0)
==3856==
==3856== HEAP SUMMARY:
==3856== in use at exit: 99,178,289 bytes in 499,578 blocks
==3856== total heap usage: 65,129,443 allocs, 64,629,865 frees, 6,570,319,776 bytes allocated
==3856==
==3856== LEAK SUMMARY:
==3856== definitely lost: 1,688 bytes in 31 blocks
==3856== indirectly lost: 8,352 bytes in 29 blocks
==3856== possibly lost: 85,691,756 bytes in 392,542 blocks
==3856== still reachable: 13,476,493 bytes in 106,976 blocks
==3856== suppressed: 0 bytes in 0 blocks
==3856== Rerun with --leak-check=full to see details of leaked memory
------------------------------------------------------------------------
[2016-05-09 14:48:25] laruence@php.net
please try with valgrind, and see if there is any info useful
USE_ZEND_ALLOC=0 valgrind php your-script.php
thanks
------------------------------------------------------------------------
[2016-05-09 14:06:19] webmaster at tom-geiger dot de
The Stacktrace says 7.0.4, but the problem persists using the 7.0.6 packages from Ondrejs PPA.
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=72179
--
Edit this bug report at https://bugs.php.net/bug.php?id=72179&edit=1