Bug #72286 [Com]: Segmentation fault (segfault) During Garbage Collection

From: Date: Mon, 30 May 2016 03:05:12 +0000
Subject: Bug #72286 [Com]: Segmentation fault (segfault) During Garbage Collection
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-201330@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=72286&edit=1

 ID:                 72286
 Comment by:         php at mattlight dot biz
 Reported by:        php at mattlight dot biz
 Summary:            Segmentation fault (segfault) During Garbage
                     Collection
 Status:             Open
 Type:               Bug
 Package:            Reproducible crash
 Operating System:   CentOS Linux release 7.2.1511
 PHP Version:        5.6.22
 Block user comment: N
 Private report:     N

 New Comment:

In case it might be useful, here is the gdb output:

(gdb) bt
#0  0x00007f5966ac5e98 in zend_std_object_get_class ()
#1  0x00007f5966ac5ec5 in zend_std_get_debug_info ()
#2  0x00007f5966a16e83 in php_var_dump ()
#3  0x00007f5966a1730a in zif_var_dump ()
#4  0x00007f5966a8ce1b in dtrace_execute_internal ()
#5  0x00007f5966b468e4 in zend_do_fcall_common_helper_SPEC ()
#6  0x00007f5966adac28 in execute_ex ()
#7  0x00007f5966a8ccf9 in dtrace_execute_ex ()
#8  0x00007f5966a8eaf3 in zend_call_function ()
#9  0x00007f5966ab6838 in zend_call_method ()
#10 0x00007f5966ac5929 in zend_objects_destroy_object ()
#11 0x00007f5966abf04a in gc_collect_cycles ()
#12 0x00007f5966aaf889 in zif_gc_collect_cycles ()
#13 0x00007f5966a8ce1b in dtrace_execute_internal ()
#14 0x00007f5966b468e4 in zend_do_fcall_common_helper_SPEC ()
#15 0x00007f5966adac28 in execute_ex ()
#16 0x00007f5966a8ccf9 in dtrace_execute_ex ()
#17 0x00007f5966a9fa6b in zend_execute_scripts ()
#18 0x00007f5966a3aea2 in php_execute_script ()
#19 0x00007f5966b487e8 in do_cli ()
#20 0x00007f5966918f6a in main ()


Previous Comments:
------------------------------------------------------------------------
[2016-05-30 02:49:14] php at mattlight dot biz

Description:
------------
A segmentation fault occurs during garbage collection when the following criteria are all met:
 - Object "A" stores a reference to itself in an instance variable
 - Object "A" also stores another object, Object "B" in another instance
variable (instance of stdClass is fine)
 - The destructor of object "A" attempts to reference object "B" only after
check that object "B" is still set
 - Object "A" is instantiated from some other object

The issue affects PHP 5.6 and 5.5 (and 5.4), but not 7.0. I have set the test case up in Travis CI:
https://travis-ci.org/lightster/php-circular-reference-segfault

The scenario I presented is a simplified scenario of an issue I encountered when using phpamqplib.
Other people have reported this issue to phpamqplib but since the library is written purely in PHP
it cannot be responsible for preventing a segmentation fault: https://github.com/php-amqplib/php-amqplib/issues/261

My bug report might be the same issue that was reported in https://bugs.php.net/bug.php?id=71958 but I was
unable to confirm one way or another.

Test script:
---------------
https://raw.githubusercontent.com/lightster/php-circular-reference-segfault/master/segfault.php

Expected result:
----------------
I would expect either "the object exists" or "will not get here" to be output. I
know the order that destructors is called is documented to be undefined, so either output is
probably acceptable.

Actual result:
--------------
PHP exits with a segmentation fault:

Array
(
    [0] => Core
    [1] => date
    [2] => ereg
    [3] => libxml
    [4] => openssl
    [5] => pcre
    [6] => zlib
    [7] => filter
    [8] => hash
    [9] => pcntl
    [10] => readline
    [11] => Reflection
    [12] => SPL
    [13] => session
    [14] => standard
    [15] => mhash
)
string(24) "we are about to segfault"
string(15) "segfaults here:"
Segmentation fault (core dumped)


------------------------------------------------------------------------



--
Edit this bug report at https://bugs.php.net/bug.php?id=72286&edit=1


Thread (12 messages)

« previous php.bugs (#201330) next »