Bug #72179 [Asn]: Segfault in gc_possible_root on CLI

From: Date: Thu, 19 May 2016 13:24:59 +0000
Subject: Bug #72179 [Asn]: Segfault in gc_possible_root on CLI
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-201194@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=72179&edit=1 ID: 72179 User updated by: webmaster at tom-geiger dot de Reported by: webmaster at tom-geiger dot de Summary: Segfault in gc_possible_root on CLI Status: Assigned Type: Bug Package: Reproducible crash Operating System: Ubuntu 16.04 PHP Version: 7.0.6 Assigned To: laruence Block user comment: N Private report: N New Comment: Compiled PHP myself from the GIT repository. The segfault still persists, when running gdb I get this error: Program received signal SIGSEGV, Segmentation fault. 0x000000000085cf75 in gc_possible_root (ref=0x7fffeafb02a0) at /home/geiger/git/php/Zend/zend_gc.c:234 234 GC_G(unused) = newRoot->prev; I have also during testing the compile had the same error in line 262 once, both lines use GC_G(unused) = newRoot->prev; Previous Comments: ------------------------------------------------------------------------ [2016-05-12 13:23:11] webmaster at tom-geiger dot de Running valgrind gives me this: I'll check if I can get more information with different valgrind parameters: ==3856== Invalid read of size 8 ==3856== at 0x38F4BF: gc_possible_root (in /usr/bin/php7.0) ==3856== by 0x2F608F: var_destroy (in /usr/bin/php7.0) ==3856== by 0x2E8967: zif_unserialize (in /usr/bin/php7.0) ==3856== by 0x356679: dtrace_execute_internal (in /usr/bin/php7.0) ==3856== by 0x9AE1E7D: xdebug_execute_internal (xdebug.c:2035) ==3856== by 0x3EB46F: ??? (in /usr/bin/php7.0) ==3856== by 0x3A6ACA: execute_ex (in /usr/bin/php7.0) ==3856== by 0x356510: dtrace_execute_ex (in /usr/bin/php7.0) ==3856== by 0x9AE14EE: xdebug_execute_ex (xdebug.c:1890) ==3856== by 0x3EB5AC: ??? (in /usr/bin/php7.0) ==3856== by 0x3A6ACA: execute_ex (in /usr/bin/php7.0) ==3856== by 0x356510: dtrace_execute_ex (in /usr/bin/php7.0) ==3856== Address 0x20f901c0 is 16 bytes before a block of size 288 free'd ==3856== at 0x4C2EDEB: free (in /usr/lib/valgrind/vgpreload_memcheck-amd64-linux.so) ==3856== by 0x3778F1: zend_array_destroy (in /usr/bin/php7.0) ==3856== by 0x37795E: zend_array_destroy (in /usr/bin/php7.0) ==3856== by 0x364A58: _zval_dtor_func_for_ptr (in /usr/bin/php7.0) ==3856== by 0x3F90C2: ??? (in /usr/bin/php7.0) ==3856== by 0x3A6ACA: execute_ex (in /usr/bin/php7.0) ==3856== by 0x356510: dtrace_execute_ex (in /usr/bin/php7.0) ==3856== by 0x9AE14EE: xdebug_execute_ex (xdebug.c:1890) ==3856== by 0x3EB5AC: ??? (in /usr/bin/php7.0) ==3856== by 0x3A6ACA: execute_ex (in /usr/bin/php7.0) ==3856== by 0x356510: dtrace_execute_ex (in /usr/bin/php7.0) ==3856== by 0x9AE14EE: xdebug_execute_ex (xdebug.c:1890) ==3856== Block was alloc'd at ==3856== at 0x4C2DB8F: malloc (in /usr/lib/valgrind/vgpreload_memcheck-amd64-linux.so) ==3856== by 0x37422C: _zend_hash_str_update (in /usr/bin/php7.0) ==3856== by 0x3695BE: add_assoc_str_ex (in /usr/bin/php7.0) ==3856== by 0x380CFE: zend_fetch_debug_backtrace (in /usr/bin/php7.0) ==3856== by 0x3811FC: ??? (in /usr/bin/php7.0) ==3856== by 0x356679: dtrace_execute_internal (in /usr/bin/php7.0) ==3856== by 0x9AE1E7D: xdebug_execute_internal (xdebug.c:2035) ==3856== by 0x3EB46F: ??? (in /usr/bin/php7.0) ==3856== by 0x3A6ACA: execute_ex (in /usr/bin/php7.0) ==3856== by 0x356510: dtrace_execute_ex (in /usr/bin/php7.0) ==3856== by 0x9AE14EE: xdebug_execute_ex (xdebug.c:1890) ==3856== by 0x3EB5AC: ??? (in /usr/bin/php7.0) ==3856== ==3856== Invalid write of size 8 ==3856== at 0x38F4DB: gc_possible_root (in /usr/bin/php7.0) ==3856== by 0x2F608F: var_destroy (in /usr/bin/php7.0) ==3856== by 0x2E8967: zif_unserialize (in /usr/bin/php7.0) ==3856== by 0x356679: dtrace_execute_internal (in /usr/bin/php7.0) ==3856== by 0x9AE1E7D: xdebug_execute_internal (xdebug.c:2035) ==3856== by 0x3EB46F: ??? (in /usr/bin/php7.0) ==3856== by 0x3A6ACA: execute_ex (in /usr/bin/php7.0) ==3856== by 0x356510: dtrace_execute_ex (in /usr/bin/php7.0) ==3856== by 0x9AE14EE: xdebug_execute_ex (xdebug.c:1890) ==3856== by 0x3EB5AC: ??? (in /usr/bin/php7.0) ==3856== by 0x3A6ACA: execute_ex (in /usr/bin/php7.0) ==3856== by 0x356510: dtrace_execute_ex (in /usr/bin/php7.0) ==3856== Address 0x20f901b0 is 32 bytes before a block of size 288 in arena "client" ==3856== ==3856== Invalid write of size 8 ==3856== at 0x38F4E2: gc_possible_root (in /usr/bin/php7.0) ==3856== by 0x2F608F: var_destroy (in /usr/bin/php7.0) ==3856== by 0x2E8967: zif_unserialize (in /usr/bin/php7.0) ==3856== by 0x356679: dtrace_execute_internal (in /usr/bin/php7.0) ==3856== by 0x9AE1E7D: xdebug_execute_internal (xdebug.c:2035) ==3856== by 0x3EB46F: ??? (in /usr/bin/php7.0) ==3856== by 0x3A6ACA: execute_ex (in /usr/bin/php7.0) ==3856== by 0x356510: dtrace_execute_ex (in /usr/bin/php7.0) ==3856== by 0x9AE14EE: xdebug_execute_ex (xdebug.c:1890) ==3856== by 0x3EB5AC: ??? (in /usr/bin/php7.0) ==3856== by 0x3A6ACA: execute_ex (in /usr/bin/php7.0) ==3856== by 0x356510: dtrace_execute_ex (in /usr/bin/php7.0) ==3856== Address 0x20f901b8 is 24 bytes before a block of size 288 free'd ==3856== at 0x4C2EDEB: free (in /usr/lib/valgrind/vgpreload_memcheck-amd64-linux.so) ==3856== by 0x3778F1: zend_array_destroy (in /usr/bin/php7.0) ==3856== by 0x37795E: zend_array_destroy (in /usr/bin/php7.0) ==3856== by 0x364A58: _zval_dtor_func_for_ptr (in /usr/bin/php7.0) ==3856== by 0x3F90C2: ??? (in /usr/bin/php7.0) ==3856== by 0x3A6ACA: execute_ex (in /usr/bin/php7.0) ==3856== by 0x356510: dtrace_execute_ex (in /usr/bin/php7.0) ==3856== by 0x9AE14EE: xdebug_execute_ex (xdebug.c:1890) ==3856== by 0x3EB5AC: ??? (in /usr/bin/php7.0) ==3856== by 0x3A6ACA: execute_ex (in /usr/bin/php7.0) ==3856== by 0x356510: dtrace_execute_ex (in /usr/bin/php7.0) ==3856== by 0x9AE14EE: xdebug_execute_ex (xdebug.c:1890) ==3856== Block was alloc'd at ==3856== at 0x4C2DB8F: malloc (in /usr/lib/valgrind/vgpreload_memcheck-amd64-linux.so) ==3856== by 0x37422C: _zend_hash_str_update (in /usr/bin/php7.0) ==3856== by 0x3695BE: add_assoc_str_ex (in /usr/bin/php7.0) ==3856== by 0x380CFE: zend_fetch_debug_backtrace (in /usr/bin/php7.0) ==3856== by 0x3811FC: ??? (in /usr/bin/php7.0) ==3856== by 0x356679: dtrace_execute_internal (in /usr/bin/php7.0) ==3856== by 0x9AE1E7D: xdebug_execute_internal (xdebug.c:2035) ==3856== by 0x3EB46F: ??? (in /usr/bin/php7.0) ==3856== by 0x3A6ACA: execute_ex (in /usr/bin/php7.0) ==3856== by 0x356510: dtrace_execute_ex (in /usr/bin/php7.0) ==3856== by 0x9AE14EE: xdebug_execute_ex (xdebug.c:1890) ==3856== by 0x3EB5AC: ??? (in /usr/bin/php7.0) ==3856== ==3856== Invalid write of size 8 ==3856== at 0x38F4EA: gc_possible_root (in /usr/bin/php7.0) ==3856== by 0x2F608F: var_destroy (in /usr/bin/php7.0) ==3856== by 0x2E8967: zif_unserialize (in /usr/bin/php7.0) ==3856== by 0x356679: dtrace_execute_internal (in /usr/bin/php7.0) ==3856== by 0x9AE1E7D: xdebug_execute_internal (xdebug.c:2035) ==3856== by 0x3EB46F: ??? (in /usr/bin/php7.0) ==3856== by 0x3A6ACA: execute_ex (in /usr/bin/php7.0) ==3856== by 0x356510: dtrace_execute_ex (in /usr/bin/php7.0) ==3856== by 0x9AE14EE: xdebug_execute_ex (xdebug.c:1890) ==3856== by 0x3EB5AC: ??? (in /usr/bin/php7.0) ==3856== by 0x3A6ACA: execute_ex (in /usr/bin/php7.0) ==3856== by 0x356510: dtrace_execute_ex (in /usr/bin/php7.0) ==3856== Address 0x20f901c0 is 16 bytes before a block of size 288 free'd ==3856== at 0x4C2EDEB: free (in /usr/lib/valgrind/vgpreload_memcheck-amd64-linux.so) ==3856== by 0x3778F1: zend_array_destroy (in /usr/bin/php7.0) ==3856== by 0x37795E: zend_array_destroy (in /usr/bin/php7.0) ==3856== by 0x364A58: _zval_dtor_func_for_ptr (in /usr/bin/php7.0) ==3856== by 0x3F90C2: ??? (in /usr/bin/php7.0) ==3856== by 0x3A6ACA: execute_ex (in /usr/bin/php7.0) ==3856== by 0x356510: dtrace_execute_ex (in /usr/bin/php7.0) ==3856== by 0x9AE14EE: xdebug_execute_ex (xdebug.c:1890) ==3856== by 0x3EB5AC: ??? (in /usr/bin/php7.0) ==3856== by 0x3A6ACA: execute_ex (in /usr/bin/php7.0) ==3856== by 0x356510: dtrace_execute_ex (in /usr/bin/php7.0) ==3856== by 0x9AE14EE: xdebug_execute_ex (xdebug.c:1890) ==3856== Block was alloc'd at ==3856== at 0x4C2DB8F: malloc (in /usr/lib/valgrind/vgpreload_memcheck-amd64-linux.so) ==3856== by 0x37422C: _zend_hash_str_update (in /usr/bin/php7.0) ==3856== by 0x3695BE: add_assoc_str_ex (in /usr/bin/php7.0) ==3856== by 0x380CFE: zend_fetch_debug_backtrace (in /usr/bin/php7.0) ==3856== by 0x3811FC: ??? (in /usr/bin/php7.0) ==3856== by 0x356679: dtrace_execute_internal (in /usr/bin/php7.0) ==3856== by 0x9AE1E7D: xdebug_execute_internal (xdebug.c:2035) ==3856== by 0x3EB46F: ??? (in /usr/bin/php7.0) ==3856== by 0x3A6ACA: execute_ex (in /usr/bin/php7.0) ==3856== by 0x356510: dtrace_execute_ex (in /usr/bin/php7.0) ==3856== by 0x9AE14EE: xdebug_execute_ex (xdebug.c:1890) ==3856== by 0x3EB5AC: ??? (in /usr/bin/php7.0) ==3856== ==3856== ==3856== Process terminating with default action of signal 11 (SIGSEGV) ==3856== Bad permissions for mapped region at address 0x706870 ==3856== at 0x38F4DB: gc_possible_root (in /usr/bin/php7.0) ==3856== by 0x2F608F: var_destroy (in /usr/bin/php7.0) ==3856== by 0x2E8967: zif_unserialize (in /usr/bin/php7.0) ==3856== by 0x356679: dtrace_execute_internal (in /usr/bin/php7.0) ==3856== by 0x9AE1E7D: xdebug_execute_internal (xdebug.c:2035) ==3856== by 0x3EB46F: ??? (in /usr/bin/php7.0) ==3856== by 0x3A6ACA: execute_ex (in /usr/bin/php7.0) ==3856== by 0x356510: dtrace_execute_ex (in /usr/bin/php7.0) ==3856== by 0x9AE14EE: xdebug_execute_ex (xdebug.c:1890) ==3856== by 0x3EB5AC: ??? (in /usr/bin/php7.0) ==3856== by 0x3A6ACA: execute_ex (in /usr/bin/php7.0) ==3856== by 0x356510: dtrace_execute_ex (in /usr/bin/php7.0) ==3856== ==3856== HEAP SUMMARY: ==3856== in use at exit: 99,178,289 bytes in 499,578 blocks ==3856== total heap usage: 65,129,443 allocs, 64,629,865 frees, 6,570,319,776 bytes allocated ==3856== ==3856== LEAK SUMMARY: ==3856== definitely lost: 1,688 bytes in 31 blocks ==3856== indirectly lost: 8,352 bytes in 29 blocks ==3856== possibly lost: 85,691,756 bytes in 392,542 blocks ==3856== still reachable: 13,476,493 bytes in 106,976 blocks ==3856== suppressed: 0 bytes in 0 blocks ==3856== Rerun with --leak-check=full to see details of leaked memory ------------------------------------------------------------------------ [2016-05-09 14:48:25] laruence@php.net please try with valgrind, and see if there is any info useful USE_ZEND_ALLOC=0 valgrind php your-script.php thanks ------------------------------------------------------------------------ [2016-05-09 14:06:19] webmaster at tom-geiger dot de The Stacktrace says 7.0.4, but the problem persists using the 7.0.6 packages from Ondrejs PPA. ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=72179 -- Edit this bug report at https://bugs.php.net/bug.php?id=72179&edit=1

« previous php.bugs (#201194) next »