Bug #72286 [NEW]: Segmentation fault (segfault) During Garbage Collection

From: Date: Mon, 30 May 2016 02:49:17 +0000
Subject: Bug #72286 [NEW]: Segmentation fault (segfault) During Garbage Collection
Groups: php.bugs 
Request: Send a blank email to php-bugs+get-201328@lists.php.net to get a copy of this message
From:             php at mattlight dot biz
Operating system: CentOS Linux release 7.2.1511
PHP version:      5.6.22
Package:          Reproducible crash
Bug Type:         Bug
Bug description:Segmentation fault (segfault) During Garbage Collection

Description:
------------
A segmentation fault occurs during garbage collection when the following
criteria are all met:
 - Object "A" stores a reference to itself in an instance variable
 - Object "A" also stores another object, Object "B" in another instance
variable (instance of stdClass is fine)
 - The destructor of object "A" attempts to reference object "B" only
after check that object "B" is still set
 - Object "A" is instantiated from some other object

The issue affects PHP 5.6 and 5.5 (and 5.4), but not 7.0. I have set the
test case up in Travis CI:
https://travis-ci.org/lightster/php-circular-reference-segfault

The scenario I presented is a simplified scenario of an issue I
encountered when using phpamqplib. Other people have reported this issue
to phpamqplib but since the library is written purely in PHP it cannot
be responsible for preventing a segmentation fault:
https://github.com/php-amqplib/php-amqplib/issues/261

My bug report might be the same issue that was reported in
https://bugs.php.net/bug.php?id=71958 but I was
unable to confirm one
way or another.

Test script:
---------------
https://raw.githubusercontent.com/lightster/php-circular-reference-segfault/master/segfault.php

Expected result:
----------------
I would expect either "the object exists" or "will not get here" to be
output. I know the order that destructors is called is documented to be
undefined, so either output is probably acceptable.

Actual result:
--------------
PHP exits with a segmentation fault:

Array
(
    [0] => Core
    [1] => date
    [2] => ereg
    [3] => libxml
    [4] => openssl
    [5] => pcre
    [6] => zlib
    [7] => filter
    [8] => hash
    [9] => pcntl
    [10] => readline
    [11] => Reflection
    [12] => SPL
    [13] => session
    [14] => standard
    [15] => mhash
)
string(24) "we are about to segfault"
string(15) "segfaults here:"
Segmentation fault (core dumped)

-- 
Edit bug report at https://bugs.php.net/bug.php?id=72286&edit=1
-- 
Try a snapshot (PHP 5.4):   https://bugs.php.net/fix.php?id=72286&r=trysnapshot54
Try a snapshot (PHP 5.5):   https://bugs.php.net/fix.php?id=72286&r=trysnapshot55
Try a snapshot (trunk):     https://bugs.php.net/fix.php?id=72286&r=trysnapshottrunk
Fixed in SVN:               https://bugs.php.net/fix.php?id=72286&r=fixed
Fixed in release:           https://bugs.php.net/fix.php?id=72286&r=alreadyfixed
Need backtrace:             https://bugs.php.net/fix.php?id=72286&r=needtrace
Need Reproduce Script:      https://bugs.php.net/fix.php?id=72286&r=needscript
Try newer version:          https://bugs.php.net/fix.php?id=72286&r=oldversion
Not developer issue:        https://bugs.php.net/fix.php?id=72286&r=support
Expected behavior:          https://bugs.php.net/fix.php?id=72286&r=notwrong
Not enough info:            https://bugs.php.net/fix.php?id=72286&r=notenoughinfo
Submitted twice:            https://bugs.php.net/fix.php?id=72286&r=submittedtwice
register_globals:           https://bugs.php.net/fix.php?id=72286&r=globals
PHP 4 support discontinued: https://bugs.php.net/fix.php?id=72286&r=php4
Daylight Savings:           https://bugs.php.net/fix.php?id=72286&r=dst
IIS Stability:              https://bugs.php.net/fix.php?id=72286&r=isapi
Install GNU Sed:            https://bugs.php.net/fix.php?id=72286&r=gnused
Floating point limitations: https://bugs.php.net/fix.php?id=72286&r=float
No Zend Extensions:         https://bugs.php.net/fix.php?id=72286&r=nozend
MySQL Configuration Error:  https://bugs.php.net/fix.php?id=72286&r=mysqlcfg



Thread (12 messages)

« previous php.bugs (#201328) next »