Bug #72179 [Asn]: Segfault in gc_possible_root on CLI

From: Date: Thu, 19 May 2016 13:40:43 +0000
Subject: Bug #72179 [Asn]: Segfault in gc_possible_root on CLI
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-201195@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=72179&edit=1

 ID:                 72179
 User updated by:    webmaster at tom-geiger dot de
 Reported by:        webmaster at tom-geiger dot de
 Summary:            Segfault in gc_possible_root on CLI
 Status:             Assigned
 Type:               Bug
 Package:            Reproducible crash
 Operating System:   Ubuntu 16.04
 PHP Version:        7.0.6
 Assigned To:        laruence
 Block user comment: N
 Private report:     N

 New Comment:

Also, another valgrind with the manually built version:

==14634== Invalid read of size 8
==14634==    at 0x85CF75: gc_possible_root (zend_gc.c:234)
==14634==    by 0x82429E: gc_check_possible_root (zend_gc.h:136)
==14634==    by 0x82434E: i_zval_ptr_dtor (zend_variables.h:50)
==14634==    by 0x824A29: _zval_ptr_dtor_wrapper (zend_variables.c:203)
==14634==    by 0x83CC1D: _zend_hash_del_el_ex (zend_hash.c:1026)
==14634==    by 0x83D411: zend_hash_index_del (zend_hash.c:1228)
==14634==    by 0x667ABD: zif_array_shift (array.c:2706)
==14634==    by 0x889F65: ZEND_DO_FCALL_BY_NAME_SPEC_RETVAL_UNUSED_HANDLER (zend_vm_execute.h:785)
==14634==    by 0x8891C4: execute_ex (zend_vm_execute.h:426)
==14634==    by 0x8892D5: zend_execute (zend_vm_execute.h:471)
==14634==    by 0x827C90: zend_execute_scripts (zend.c:1427)
==14634==    by 0x78EB25: php_execute_script (main.c:2492)
==14634==  Address 0x6364376232363742 is not stack'd, malloc'd or (recently) free'd
==14634== 
==14634== 
==14634== Process terminating with default action of signal 11 (SIGSEGV)
==14634==  General Protection Fault
==14634==    at 0x85CF75: gc_possible_root (zend_gc.c:234)
==14634==    by 0x82429E: gc_check_possible_root (zend_gc.h:136)
==14634==    by 0x82434E: i_zval_ptr_dtor (zend_variables.h:50)
==14634==    by 0x824A29: _zval_ptr_dtor_wrapper (zend_variables.c:203)
==14634==    by 0x83CC1D: _zend_hash_del_el_ex (zend_hash.c:1026)
==14634==    by 0x83D411: zend_hash_index_del (zend_hash.c:1228)
==14634==    by 0x667ABD: zif_array_shift (array.c:2706)
==14634==    by 0x889F65: ZEND_DO_FCALL_BY_NAME_SPEC_RETVAL_UNUSED_HANDLER (zend_vm_execute.h:785)
==14634==    by 0x8891C4: execute_ex (zend_vm_execute.h:426)
==14634==    by 0x8892D5: zend_execute (zend_vm_execute.h:471)
==14634==    by 0x827C90: zend_execute_scripts (zend.c:1427)
==14634==    by 0x78EB25: php_execute_script (main.c:2492)
==14634== 
==14634== HEAP SUMMARY:
==14634==     in use at exit: 99,412,531 bytes in 488,147 blocks
==14634==   total heap usage: 17,687,831 allocs, 17,199,684 frees, 3,341,087,194 bytes allocated
==14634== 
==14634== LEAK SUMMARY:
==14634==    definitely lost: 3,472 bytes in 62 blocks
==14634==    indirectly lost: 17,856 bytes in 62 blocks
==14634==      possibly lost: 88,267,081 bytes in 390,950 blocks
==14634==    still reachable: 11,124,122 bytes in 97,073 blocks
==14634==         suppressed: 0 bytes in 0 blocks


Previous Comments:
------------------------------------------------------------------------
[2016-05-19 13:24:56] webmaster at tom-geiger dot de

Compiled PHP myself from the GIT repository.

The segfault still persists, when running gdb I get this error:

Program received signal SIGSEGV, Segmentation fault.
0x000000000085cf75 in gc_possible_root (ref=0x7fffeafb02a0) at
/home/geiger/git/php/Zend/zend_gc.c:234
234			GC_G(unused) = newRoot->prev;

I have also during testing the compile had the same error in line 262 once,

both lines use GC_G(unused) = newRoot->prev;

------------------------------------------------------------------------
[2016-05-12 13:23:11] webmaster at tom-geiger dot de

Running valgrind gives me this: I'll check if I can get more information with different
valgrind parameters:

==3856== Invalid read of size 8
==3856==    at 0x38F4BF: gc_possible_root (in /usr/bin/php7.0)
==3856==    by 0x2F608F: var_destroy (in /usr/bin/php7.0)
==3856==    by 0x2E8967: zif_unserialize (in /usr/bin/php7.0)
==3856==    by 0x356679: dtrace_execute_internal (in /usr/bin/php7.0)
==3856==    by 0x9AE1E7D: xdebug_execute_internal (xdebug.c:2035)
==3856==    by 0x3EB46F: ??? (in /usr/bin/php7.0)
==3856==    by 0x3A6ACA: execute_ex (in /usr/bin/php7.0)
==3856==    by 0x356510: dtrace_execute_ex (in /usr/bin/php7.0)
==3856==    by 0x9AE14EE: xdebug_execute_ex (xdebug.c:1890)
==3856==    by 0x3EB5AC: ??? (in /usr/bin/php7.0)
==3856==    by 0x3A6ACA: execute_ex (in /usr/bin/php7.0)
==3856==    by 0x356510: dtrace_execute_ex (in /usr/bin/php7.0)
==3856==  Address 0x20f901c0 is 16 bytes before a block of size 288 free'd
==3856==    at 0x4C2EDEB: free (in /usr/lib/valgrind/vgpreload_memcheck-amd64-linux.so)
==3856==    by 0x3778F1: zend_array_destroy (in /usr/bin/php7.0)
==3856==    by 0x37795E: zend_array_destroy (in /usr/bin/php7.0)
==3856==    by 0x364A58: _zval_dtor_func_for_ptr (in /usr/bin/php7.0)
==3856==    by 0x3F90C2: ??? (in /usr/bin/php7.0)
==3856==    by 0x3A6ACA: execute_ex (in /usr/bin/php7.0)
==3856==    by 0x356510: dtrace_execute_ex (in /usr/bin/php7.0)
==3856==    by 0x9AE14EE: xdebug_execute_ex (xdebug.c:1890)
==3856==    by 0x3EB5AC: ??? (in /usr/bin/php7.0)
==3856==    by 0x3A6ACA: execute_ex (in /usr/bin/php7.0)
==3856==    by 0x356510: dtrace_execute_ex (in /usr/bin/php7.0)
==3856==    by 0x9AE14EE: xdebug_execute_ex (xdebug.c:1890)
==3856==  Block was alloc'd at
==3856==    at 0x4C2DB8F: malloc (in /usr/lib/valgrind/vgpreload_memcheck-amd64-linux.so)
==3856==    by 0x37422C: _zend_hash_str_update (in /usr/bin/php7.0)
==3856==    by 0x3695BE: add_assoc_str_ex (in /usr/bin/php7.0)
==3856==    by 0x380CFE: zend_fetch_debug_backtrace (in /usr/bin/php7.0)
==3856==    by 0x3811FC: ??? (in /usr/bin/php7.0)
==3856==    by 0x356679: dtrace_execute_internal (in /usr/bin/php7.0)
==3856==    by 0x9AE1E7D: xdebug_execute_internal (xdebug.c:2035)
==3856==    by 0x3EB46F: ??? (in /usr/bin/php7.0)
==3856==    by 0x3A6ACA: execute_ex (in /usr/bin/php7.0)
==3856==    by 0x356510: dtrace_execute_ex (in /usr/bin/php7.0)
==3856==    by 0x9AE14EE: xdebug_execute_ex (xdebug.c:1890)
==3856==    by 0x3EB5AC: ??? (in /usr/bin/php7.0)
==3856== 
==3856== Invalid write of size 8
==3856==    at 0x38F4DB: gc_possible_root (in /usr/bin/php7.0)
==3856==    by 0x2F608F: var_destroy (in /usr/bin/php7.0)
==3856==    by 0x2E8967: zif_unserialize (in /usr/bin/php7.0)
==3856==    by 0x356679: dtrace_execute_internal (in /usr/bin/php7.0)
==3856==    by 0x9AE1E7D: xdebug_execute_internal (xdebug.c:2035)
==3856==    by 0x3EB46F: ??? (in /usr/bin/php7.0)
==3856==    by 0x3A6ACA: execute_ex (in /usr/bin/php7.0)
==3856==    by 0x356510: dtrace_execute_ex (in /usr/bin/php7.0)
==3856==    by 0x9AE14EE: xdebug_execute_ex (xdebug.c:1890)
==3856==    by 0x3EB5AC: ??? (in /usr/bin/php7.0)
==3856==    by 0x3A6ACA: execute_ex (in /usr/bin/php7.0)
==3856==    by 0x356510: dtrace_execute_ex (in /usr/bin/php7.0)
==3856==  Address 0x20f901b0 is 32 bytes before a block of size 288 in arena "client"
==3856== 
==3856== Invalid write of size 8
==3856==    at 0x38F4E2: gc_possible_root (in /usr/bin/php7.0)
==3856==    by 0x2F608F: var_destroy (in /usr/bin/php7.0)
==3856==    by 0x2E8967: zif_unserialize (in /usr/bin/php7.0)
==3856==    by 0x356679: dtrace_execute_internal (in /usr/bin/php7.0)
==3856==    by 0x9AE1E7D: xdebug_execute_internal (xdebug.c:2035)
==3856==    by 0x3EB46F: ??? (in /usr/bin/php7.0)
==3856==    by 0x3A6ACA: execute_ex (in /usr/bin/php7.0)
==3856==    by 0x356510: dtrace_execute_ex (in /usr/bin/php7.0)
==3856==    by 0x9AE14EE: xdebug_execute_ex (xdebug.c:1890)
==3856==    by 0x3EB5AC: ??? (in /usr/bin/php7.0)
==3856==    by 0x3A6ACA: execute_ex (in /usr/bin/php7.0)
==3856==    by 0x356510: dtrace_execute_ex (in /usr/bin/php7.0)
==3856==  Address 0x20f901b8 is 24 bytes before a block of size 288 free'd
==3856==    at 0x4C2EDEB: free (in /usr/lib/valgrind/vgpreload_memcheck-amd64-linux.so)
==3856==    by 0x3778F1: zend_array_destroy (in /usr/bin/php7.0)
==3856==    by 0x37795E: zend_array_destroy (in /usr/bin/php7.0)
==3856==    by 0x364A58: _zval_dtor_func_for_ptr (in /usr/bin/php7.0)
==3856==    by 0x3F90C2: ??? (in /usr/bin/php7.0)
==3856==    by 0x3A6ACA: execute_ex (in /usr/bin/php7.0)
==3856==    by 0x356510: dtrace_execute_ex (in /usr/bin/php7.0)
==3856==    by 0x9AE14EE: xdebug_execute_ex (xdebug.c:1890)
==3856==    by 0x3EB5AC: ??? (in /usr/bin/php7.0)
==3856==    by 0x3A6ACA: execute_ex (in /usr/bin/php7.0)
==3856==    by 0x356510: dtrace_execute_ex (in /usr/bin/php7.0)
==3856==    by 0x9AE14EE: xdebug_execute_ex (xdebug.c:1890)
==3856==  Block was alloc'd at
==3856==    at 0x4C2DB8F: malloc (in /usr/lib/valgrind/vgpreload_memcheck-amd64-linux.so)
==3856==    by 0x37422C: _zend_hash_str_update (in /usr/bin/php7.0)
==3856==    by 0x3695BE: add_assoc_str_ex (in /usr/bin/php7.0)
==3856==    by 0x380CFE: zend_fetch_debug_backtrace (in /usr/bin/php7.0)
==3856==    by 0x3811FC: ??? (in /usr/bin/php7.0)
==3856==    by 0x356679: dtrace_execute_internal (in /usr/bin/php7.0)
==3856==    by 0x9AE1E7D: xdebug_execute_internal (xdebug.c:2035)
==3856==    by 0x3EB46F: ??? (in /usr/bin/php7.0)
==3856==    by 0x3A6ACA: execute_ex (in /usr/bin/php7.0)
==3856==    by 0x356510: dtrace_execute_ex (in /usr/bin/php7.0)
==3856==    by 0x9AE14EE: xdebug_execute_ex (xdebug.c:1890)
==3856==    by 0x3EB5AC: ??? (in /usr/bin/php7.0)
==3856== 
==3856== Invalid write of size 8
==3856==    at 0x38F4EA: gc_possible_root (in /usr/bin/php7.0)
==3856==    by 0x2F608F: var_destroy (in /usr/bin/php7.0)
==3856==    by 0x2E8967: zif_unserialize (in /usr/bin/php7.0)
==3856==    by 0x356679: dtrace_execute_internal (in /usr/bin/php7.0)
==3856==    by 0x9AE1E7D: xdebug_execute_internal (xdebug.c:2035)
==3856==    by 0x3EB46F: ??? (in /usr/bin/php7.0)
==3856==    by 0x3A6ACA: execute_ex (in /usr/bin/php7.0)
==3856==    by 0x356510: dtrace_execute_ex (in /usr/bin/php7.0)
==3856==    by 0x9AE14EE: xdebug_execute_ex (xdebug.c:1890)
==3856==    by 0x3EB5AC: ??? (in /usr/bin/php7.0)
==3856==    by 0x3A6ACA: execute_ex (in /usr/bin/php7.0)
==3856==    by 0x356510: dtrace_execute_ex (in /usr/bin/php7.0)
==3856==  Address 0x20f901c0 is 16 bytes before a block of size 288 free'd
==3856==    at 0x4C2EDEB: free (in /usr/lib/valgrind/vgpreload_memcheck-amd64-linux.so)
==3856==    by 0x3778F1: zend_array_destroy (in /usr/bin/php7.0)
==3856==    by 0x37795E: zend_array_destroy (in /usr/bin/php7.0)
==3856==    by 0x364A58: _zval_dtor_func_for_ptr (in /usr/bin/php7.0)
==3856==    by 0x3F90C2: ??? (in /usr/bin/php7.0)
==3856==    by 0x3A6ACA: execute_ex (in /usr/bin/php7.0)
==3856==    by 0x356510: dtrace_execute_ex (in /usr/bin/php7.0)
==3856==    by 0x9AE14EE: xdebug_execute_ex (xdebug.c:1890)
==3856==    by 0x3EB5AC: ??? (in /usr/bin/php7.0)
==3856==    by 0x3A6ACA: execute_ex (in /usr/bin/php7.0)
==3856==    by 0x356510: dtrace_execute_ex (in /usr/bin/php7.0)
==3856==    by 0x9AE14EE: xdebug_execute_ex (xdebug.c:1890)
==3856==  Block was alloc'd at
==3856==    at 0x4C2DB8F: malloc (in /usr/lib/valgrind/vgpreload_memcheck-amd64-linux.so)
==3856==    by 0x37422C: _zend_hash_str_update (in /usr/bin/php7.0)
==3856==    by 0x3695BE: add_assoc_str_ex (in /usr/bin/php7.0)
==3856==    by 0x380CFE: zend_fetch_debug_backtrace (in /usr/bin/php7.0)
==3856==    by 0x3811FC: ??? (in /usr/bin/php7.0)
==3856==    by 0x356679: dtrace_execute_internal (in /usr/bin/php7.0)
==3856==    by 0x9AE1E7D: xdebug_execute_internal (xdebug.c:2035)
==3856==    by 0x3EB46F: ??? (in /usr/bin/php7.0)
==3856==    by 0x3A6ACA: execute_ex (in /usr/bin/php7.0)
==3856==    by 0x356510: dtrace_execute_ex (in /usr/bin/php7.0)
==3856==    by 0x9AE14EE: xdebug_execute_ex (xdebug.c:1890)
==3856==    by 0x3EB5AC: ??? (in /usr/bin/php7.0)
==3856== 
==3856== 
==3856== Process terminating with default action of signal 11 (SIGSEGV)
==3856==  Bad permissions for mapped region at address 0x706870
==3856==    at 0x38F4DB: gc_possible_root (in /usr/bin/php7.0)
==3856==    by 0x2F608F: var_destroy (in /usr/bin/php7.0)
==3856==    by 0x2E8967: zif_unserialize (in /usr/bin/php7.0)
==3856==    by 0x356679: dtrace_execute_internal (in /usr/bin/php7.0)
==3856==    by 0x9AE1E7D: xdebug_execute_internal (xdebug.c:2035)
==3856==    by 0x3EB46F: ??? (in /usr/bin/php7.0)
==3856==    by 0x3A6ACA: execute_ex (in /usr/bin/php7.0)
==3856==    by 0x356510: dtrace_execute_ex (in /usr/bin/php7.0)
==3856==    by 0x9AE14EE: xdebug_execute_ex (xdebug.c:1890)
==3856==    by 0x3EB5AC: ??? (in /usr/bin/php7.0)
==3856==    by 0x3A6ACA: execute_ex (in /usr/bin/php7.0)
==3856==    by 0x356510: dtrace_execute_ex (in /usr/bin/php7.0)
==3856== 
==3856== HEAP SUMMARY:
==3856==     in use at exit: 99,178,289 bytes in 499,578 blocks
==3856==   total heap usage: 65,129,443 allocs, 64,629,865 frees, 6,570,319,776 bytes allocated
==3856== 
==3856== LEAK SUMMARY:
==3856==    definitely lost: 1,688 bytes in 31 blocks
==3856==    indirectly lost: 8,352 bytes in 29 blocks
==3856==      possibly lost: 85,691,756 bytes in 392,542 blocks
==3856==    still reachable: 13,476,493 bytes in 106,976 blocks
==3856==         suppressed: 0 bytes in 0 blocks
==3856== Rerun with --leak-check=full to see details of leaked memory

------------------------------------------------------------------------


The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at

    https://bugs.php.net/bug.php?id=72179


--
Edit this bug report at https://bugs.php.net/bug.php?id=72179&edit=1


Thread (10 messages)

« previous php.bugs (#201195) next »