Edit report at https://bugs.php.net/bug.php?id=72179&edit=1
ID: 72179
User updated by: webmaster at tom-geiger dot de
Reported by: webmaster at tom-geiger dot de
Summary: Segfault in gc_possible_root on CLI
Status: Assigned
Type: Bug
Package: Reproducible crash
Operating System: Ubuntu 16.04
PHP Version: 7.0.6
Assigned To: laruence
Block user comment: N
Private report: N
New Comment:
Also, another valgrind with the manually built version:
==14634== Invalid read of size 8
==14634== at 0x85CF75: gc_possible_root (zend_gc.c:234)
==14634== by 0x82429E: gc_check_possible_root (zend_gc.h:136)
==14634== by 0x82434E: i_zval_ptr_dtor (zend_variables.h:50)
==14634== by 0x824A29: _zval_ptr_dtor_wrapper (zend_variables.c:203)
==14634== by 0x83CC1D: _zend_hash_del_el_ex (zend_hash.c:1026)
==14634== by 0x83D411: zend_hash_index_del (zend_hash.c:1228)
==14634== by 0x667ABD: zif_array_shift (array.c:2706)
==14634== by 0x889F65: ZEND_DO_FCALL_BY_NAME_SPEC_RETVAL_UNUSED_HANDLER (zend_vm_execute.h:785)
==14634== by 0x8891C4: execute_ex (zend_vm_execute.h:426)
==14634== by 0x8892D5: zend_execute (zend_vm_execute.h:471)
==14634== by 0x827C90: zend_execute_scripts (zend.c:1427)
==14634== by 0x78EB25: php_execute_script (main.c:2492)
==14634== Address 0x6364376232363742 is not stack'd, malloc'd or (recently) free'd
==14634==
==14634==
==14634== Process terminating with default action of signal 11 (SIGSEGV)
==14634== General Protection Fault
==14634== at 0x85CF75: gc_possible_root (zend_gc.c:234)
==14634== by 0x82429E: gc_check_possible_root (zend_gc.h:136)
==14634== by 0x82434E: i_zval_ptr_dtor (zend_variables.h:50)
==14634== by 0x824A29: _zval_ptr_dtor_wrapper (zend_variables.c:203)
==14634== by 0x83CC1D: _zend_hash_del_el_ex (zend_hash.c:1026)
==14634== by 0x83D411: zend_hash_index_del (zend_hash.c:1228)
==14634== by 0x667ABD: zif_array_shift (array.c:2706)
==14634== by 0x889F65: ZEND_DO_FCALL_BY_NAME_SPEC_RETVAL_UNUSED_HANDLER (zend_vm_execute.h:785)
==14634== by 0x8891C4: execute_ex (zend_vm_execute.h:426)
==14634== by 0x8892D5: zend_execute (zend_vm_execute.h:471)
==14634== by 0x827C90: zend_execute_scripts (zend.c:1427)
==14634== by 0x78EB25: php_execute_script (main.c:2492)
==14634==
==14634== HEAP SUMMARY:
==14634== in use at exit: 99,412,531 bytes in 488,147 blocks
==14634== total heap usage: 17,687,831 allocs, 17,199,684 frees, 3,341,087,194 bytes allocated
==14634==
==14634== LEAK SUMMARY:
==14634== definitely lost: 3,472 bytes in 62 blocks
==14634== indirectly lost: 17,856 bytes in 62 blocks
==14634== possibly lost: 88,267,081 bytes in 390,950 blocks
==14634== still reachable: 11,124,122 bytes in 97,073 blocks
==14634== suppressed: 0 bytes in 0 blocks
Previous Comments:
------------------------------------------------------------------------
[2016-05-19 13:24:56] webmaster at tom-geiger dot de
Compiled PHP myself from the GIT repository.
The segfault still persists, when running gdb I get this error:
Program received signal SIGSEGV, Segmentation fault.
0x000000000085cf75 in gc_possible_root (ref=0x7fffeafb02a0) at
/home/geiger/git/php/Zend/zend_gc.c:234
234 GC_G(unused) = newRoot->prev;
I have also during testing the compile had the same error in line 262 once,
both lines use GC_G(unused) = newRoot->prev;
------------------------------------------------------------------------
[2016-05-12 13:23:11] webmaster at tom-geiger dot de
Running valgrind gives me this: I'll check if I can get more information with different
valgrind parameters:
==3856== Invalid read of size 8
==3856== at 0x38F4BF: gc_possible_root (in /usr/bin/php7.0)
==3856== by 0x2F608F: var_destroy (in /usr/bin/php7.0)
==3856== by 0x2E8967: zif_unserialize (in /usr/bin/php7.0)
==3856== by 0x356679: dtrace_execute_internal (in /usr/bin/php7.0)
==3856== by 0x9AE1E7D: xdebug_execute_internal (xdebug.c:2035)
==3856== by 0x3EB46F: ??? (in /usr/bin/php7.0)
==3856== by 0x3A6ACA: execute_ex (in /usr/bin/php7.0)
==3856== by 0x356510: dtrace_execute_ex (in /usr/bin/php7.0)
==3856== by 0x9AE14EE: xdebug_execute_ex (xdebug.c:1890)
==3856== by 0x3EB5AC: ??? (in /usr/bin/php7.0)
==3856== by 0x3A6ACA: execute_ex (in /usr/bin/php7.0)
==3856== by 0x356510: dtrace_execute_ex (in /usr/bin/php7.0)
==3856== Address 0x20f901c0 is 16 bytes before a block of size 288 free'd
==3856== at 0x4C2EDEB: free (in /usr/lib/valgrind/vgpreload_memcheck-amd64-linux.so)
==3856== by 0x3778F1: zend_array_destroy (in /usr/bin/php7.0)
==3856== by 0x37795E: zend_array_destroy (in /usr/bin/php7.0)
==3856== by 0x364A58: _zval_dtor_func_for_ptr (in /usr/bin/php7.0)
==3856== by 0x3F90C2: ??? (in /usr/bin/php7.0)
==3856== by 0x3A6ACA: execute_ex (in /usr/bin/php7.0)
==3856== by 0x356510: dtrace_execute_ex (in /usr/bin/php7.0)
==3856== by 0x9AE14EE: xdebug_execute_ex (xdebug.c:1890)
==3856== by 0x3EB5AC: ??? (in /usr/bin/php7.0)
==3856== by 0x3A6ACA: execute_ex (in /usr/bin/php7.0)
==3856== by 0x356510: dtrace_execute_ex (in /usr/bin/php7.0)
==3856== by 0x9AE14EE: xdebug_execute_ex (xdebug.c:1890)
==3856== Block was alloc'd at
==3856== at 0x4C2DB8F: malloc (in /usr/lib/valgrind/vgpreload_memcheck-amd64-linux.so)
==3856== by 0x37422C: _zend_hash_str_update (in /usr/bin/php7.0)
==3856== by 0x3695BE: add_assoc_str_ex (in /usr/bin/php7.0)
==3856== by 0x380CFE: zend_fetch_debug_backtrace (in /usr/bin/php7.0)
==3856== by 0x3811FC: ??? (in /usr/bin/php7.0)
==3856== by 0x356679: dtrace_execute_internal (in /usr/bin/php7.0)
==3856== by 0x9AE1E7D: xdebug_execute_internal (xdebug.c:2035)
==3856== by 0x3EB46F: ??? (in /usr/bin/php7.0)
==3856== by 0x3A6ACA: execute_ex (in /usr/bin/php7.0)
==3856== by 0x356510: dtrace_execute_ex (in /usr/bin/php7.0)
==3856== by 0x9AE14EE: xdebug_execute_ex (xdebug.c:1890)
==3856== by 0x3EB5AC: ??? (in /usr/bin/php7.0)
==3856==
==3856== Invalid write of size 8
==3856== at 0x38F4DB: gc_possible_root (in /usr/bin/php7.0)
==3856== by 0x2F608F: var_destroy (in /usr/bin/php7.0)
==3856== by 0x2E8967: zif_unserialize (in /usr/bin/php7.0)
==3856== by 0x356679: dtrace_execute_internal (in /usr/bin/php7.0)
==3856== by 0x9AE1E7D: xdebug_execute_internal (xdebug.c:2035)
==3856== by 0x3EB46F: ??? (in /usr/bin/php7.0)
==3856== by 0x3A6ACA: execute_ex (in /usr/bin/php7.0)
==3856== by 0x356510: dtrace_execute_ex (in /usr/bin/php7.0)
==3856== by 0x9AE14EE: xdebug_execute_ex (xdebug.c:1890)
==3856== by 0x3EB5AC: ??? (in /usr/bin/php7.0)
==3856== by 0x3A6ACA: execute_ex (in /usr/bin/php7.0)
==3856== by 0x356510: dtrace_execute_ex (in /usr/bin/php7.0)
==3856== Address 0x20f901b0 is 32 bytes before a block of size 288 in arena "client"
==3856==
==3856== Invalid write of size 8
==3856== at 0x38F4E2: gc_possible_root (in /usr/bin/php7.0)
==3856== by 0x2F608F: var_destroy (in /usr/bin/php7.0)
==3856== by 0x2E8967: zif_unserialize (in /usr/bin/php7.0)
==3856== by 0x356679: dtrace_execute_internal (in /usr/bin/php7.0)
==3856== by 0x9AE1E7D: xdebug_execute_internal (xdebug.c:2035)
==3856== by 0x3EB46F: ??? (in /usr/bin/php7.0)
==3856== by 0x3A6ACA: execute_ex (in /usr/bin/php7.0)
==3856== by 0x356510: dtrace_execute_ex (in /usr/bin/php7.0)
==3856== by 0x9AE14EE: xdebug_execute_ex (xdebug.c:1890)
==3856== by 0x3EB5AC: ??? (in /usr/bin/php7.0)
==3856== by 0x3A6ACA: execute_ex (in /usr/bin/php7.0)
==3856== by 0x356510: dtrace_execute_ex (in /usr/bin/php7.0)
==3856== Address 0x20f901b8 is 24 bytes before a block of size 288 free'd
==3856== at 0x4C2EDEB: free (in /usr/lib/valgrind/vgpreload_memcheck-amd64-linux.so)
==3856== by 0x3778F1: zend_array_destroy (in /usr/bin/php7.0)
==3856== by 0x37795E: zend_array_destroy (in /usr/bin/php7.0)
==3856== by 0x364A58: _zval_dtor_func_for_ptr (in /usr/bin/php7.0)
==3856== by 0x3F90C2: ??? (in /usr/bin/php7.0)
==3856== by 0x3A6ACA: execute_ex (in /usr/bin/php7.0)
==3856== by 0x356510: dtrace_execute_ex (in /usr/bin/php7.0)
==3856== by 0x9AE14EE: xdebug_execute_ex (xdebug.c:1890)
==3856== by 0x3EB5AC: ??? (in /usr/bin/php7.0)
==3856== by 0x3A6ACA: execute_ex (in /usr/bin/php7.0)
==3856== by 0x356510: dtrace_execute_ex (in /usr/bin/php7.0)
==3856== by 0x9AE14EE: xdebug_execute_ex (xdebug.c:1890)
==3856== Block was alloc'd at
==3856== at 0x4C2DB8F: malloc (in /usr/lib/valgrind/vgpreload_memcheck-amd64-linux.so)
==3856== by 0x37422C: _zend_hash_str_update (in /usr/bin/php7.0)
==3856== by 0x3695BE: add_assoc_str_ex (in /usr/bin/php7.0)
==3856== by 0x380CFE: zend_fetch_debug_backtrace (in /usr/bin/php7.0)
==3856== by 0x3811FC: ??? (in /usr/bin/php7.0)
==3856== by 0x356679: dtrace_execute_internal (in /usr/bin/php7.0)
==3856== by 0x9AE1E7D: xdebug_execute_internal (xdebug.c:2035)
==3856== by 0x3EB46F: ??? (in /usr/bin/php7.0)
==3856== by 0x3A6ACA: execute_ex (in /usr/bin/php7.0)
==3856== by 0x356510: dtrace_execute_ex (in /usr/bin/php7.0)
==3856== by 0x9AE14EE: xdebug_execute_ex (xdebug.c:1890)
==3856== by 0x3EB5AC: ??? (in /usr/bin/php7.0)
==3856==
==3856== Invalid write of size 8
==3856== at 0x38F4EA: gc_possible_root (in /usr/bin/php7.0)
==3856== by 0x2F608F: var_destroy (in /usr/bin/php7.0)
==3856== by 0x2E8967: zif_unserialize (in /usr/bin/php7.0)
==3856== by 0x356679: dtrace_execute_internal (in /usr/bin/php7.0)
==3856== by 0x9AE1E7D: xdebug_execute_internal (xdebug.c:2035)
==3856== by 0x3EB46F: ??? (in /usr/bin/php7.0)
==3856== by 0x3A6ACA: execute_ex (in /usr/bin/php7.0)
==3856== by 0x356510: dtrace_execute_ex (in /usr/bin/php7.0)
==3856== by 0x9AE14EE: xdebug_execute_ex (xdebug.c:1890)
==3856== by 0x3EB5AC: ??? (in /usr/bin/php7.0)
==3856== by 0x3A6ACA: execute_ex (in /usr/bin/php7.0)
==3856== by 0x356510: dtrace_execute_ex (in /usr/bin/php7.0)
==3856== Address 0x20f901c0 is 16 bytes before a block of size 288 free'd
==3856== at 0x4C2EDEB: free (in /usr/lib/valgrind/vgpreload_memcheck-amd64-linux.so)
==3856== by 0x3778F1: zend_array_destroy (in /usr/bin/php7.0)
==3856== by 0x37795E: zend_array_destroy (in /usr/bin/php7.0)
==3856== by 0x364A58: _zval_dtor_func_for_ptr (in /usr/bin/php7.0)
==3856== by 0x3F90C2: ??? (in /usr/bin/php7.0)
==3856== by 0x3A6ACA: execute_ex (in /usr/bin/php7.0)
==3856== by 0x356510: dtrace_execute_ex (in /usr/bin/php7.0)
==3856== by 0x9AE14EE: xdebug_execute_ex (xdebug.c:1890)
==3856== by 0x3EB5AC: ??? (in /usr/bin/php7.0)
==3856== by 0x3A6ACA: execute_ex (in /usr/bin/php7.0)
==3856== by 0x356510: dtrace_execute_ex (in /usr/bin/php7.0)
==3856== by 0x9AE14EE: xdebug_execute_ex (xdebug.c:1890)
==3856== Block was alloc'd at
==3856== at 0x4C2DB8F: malloc (in /usr/lib/valgrind/vgpreload_memcheck-amd64-linux.so)
==3856== by 0x37422C: _zend_hash_str_update (in /usr/bin/php7.0)
==3856== by 0x3695BE: add_assoc_str_ex (in /usr/bin/php7.0)
==3856== by 0x380CFE: zend_fetch_debug_backtrace (in /usr/bin/php7.0)
==3856== by 0x3811FC: ??? (in /usr/bin/php7.0)
==3856== by 0x356679: dtrace_execute_internal (in /usr/bin/php7.0)
==3856== by 0x9AE1E7D: xdebug_execute_internal (xdebug.c:2035)
==3856== by 0x3EB46F: ??? (in /usr/bin/php7.0)
==3856== by 0x3A6ACA: execute_ex (in /usr/bin/php7.0)
==3856== by 0x356510: dtrace_execute_ex (in /usr/bin/php7.0)
==3856== by 0x9AE14EE: xdebug_execute_ex (xdebug.c:1890)
==3856== by 0x3EB5AC: ??? (in /usr/bin/php7.0)
==3856==
==3856==
==3856== Process terminating with default action of signal 11 (SIGSEGV)
==3856== Bad permissions for mapped region at address 0x706870
==3856== at 0x38F4DB: gc_possible_root (in /usr/bin/php7.0)
==3856== by 0x2F608F: var_destroy (in /usr/bin/php7.0)
==3856== by 0x2E8967: zif_unserialize (in /usr/bin/php7.0)
==3856== by 0x356679: dtrace_execute_internal (in /usr/bin/php7.0)
==3856== by 0x9AE1E7D: xdebug_execute_internal (xdebug.c:2035)
==3856== by 0x3EB46F: ??? (in /usr/bin/php7.0)
==3856== by 0x3A6ACA: execute_ex (in /usr/bin/php7.0)
==3856== by 0x356510: dtrace_execute_ex (in /usr/bin/php7.0)
==3856== by 0x9AE14EE: xdebug_execute_ex (xdebug.c:1890)
==3856== by 0x3EB5AC: ??? (in /usr/bin/php7.0)
==3856== by 0x3A6ACA: execute_ex (in /usr/bin/php7.0)
==3856== by 0x356510: dtrace_execute_ex (in /usr/bin/php7.0)
==3856==
==3856== HEAP SUMMARY:
==3856== in use at exit: 99,178,289 bytes in 499,578 blocks
==3856== total heap usage: 65,129,443 allocs, 64,629,865 frees, 6,570,319,776 bytes allocated
==3856==
==3856== LEAK SUMMARY:
==3856== definitely lost: 1,688 bytes in 31 blocks
==3856== indirectly lost: 8,352 bytes in 29 blocks
==3856== possibly lost: 85,691,756 bytes in 392,542 blocks
==3856== still reachable: 13,476,493 bytes in 106,976 blocks
==3856== suppressed: 0 bytes in 0 blocks
==3856== Rerun with --leak-check=full to see details of leaked memory
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=72179
--
Edit this bug report at https://bugs.php.net/bug.php?id=72179&edit=1