Bug #72257 [Fbk->Opn]: "get_defined_constants(true)" core dump

From: Date: Mon, 30 May 2016 05:56:54 +0000
Subject: Bug #72257 [Fbk->Opn]: "get_defined_constants(true)" core dump
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-201332@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=72257&edit=1

 ID:                 72257
 User updated by:    jccgls001 at 126 dot com
 Reported by:        jccgls001 at 126 dot com
 Summary:            "get_defined_constants(true)" core dump
-Status:             Feedback
+Status:             Open
 Type:               Bug
 Package:            Scripting Engine problem
 Operating System:   linux 2.6
 PHP Version:        7.0.6
 Block user comment: N
 Private report:     N

 New Comment:

I find when i add USE_ZEND_ALLOC=0 the function run successful

--------------------------------------------
these info are created by command without USE_ZEND_ALLOC=0:
gdb --args ./php -n -r "var_dump(get_defined_constants(true));"


(gdb) bt full
#0  0x000000302af6ff40 in ?? ()
No symbol table info available.
#1  0x0000000000a652b6 in zif_get_defined_constants (execute_data=0x7ffff7612120,
return_value=0x7ffff7612090)
    at /home/users/lvshun/php7/trunk/php/.tmp/build/php-7.0.6/Zend/zend_builtin_functions.c:2227
        _z = 0x1901690
        _p = 0x1901690
        _end = 0x190f2b0
        val = 0x17ec910
        modules = 0x7ffff7676000
        const_val = {value = {lval = 2, dval = 9.8813129168249309e-324, counted = 0x2, str = 0x2,
arr = 0x2, obj = 0x2, res = 0x2, 
            ref = 0x2, ast = 0x2, zv = 0x2, ptr = 0x2, ce = 0x2, func = 0x2, ww = {w1 = 2, w2 = 0}},
u1 = {v = {type = 1 '\001', 
              type_flags = 0 '\000', const_flags = 0 '\000', reserved = 0
'\000'}, type_info = 1}, u2 = {var_flags = 0, next = 0, 
            cache_slot = 0, lineno = 0, num_args = 0, fe_pos = 0, fe_iter_idx = 0}}
        module = 0x17df330
        i = 41
        module_number = 1
        module_names = 0x7ffff7679000
        categorize = 1 '\001'
#2  0x0000000000ab1781 in ZEND_DO_ICALL_SPEC_HANDLER (execute_data=0x7ffff7612030)
    at /home/users/lvshun/php7/trunk/php/.tmp/build/php-7.0.6/Zend/zend_vm_execute.h:586
        opline = 0x7ffff7662220
        call = 0x7ffff7612120
        fbc = 0x17e9700
        ret = 0x7ffff7612090
#3  0x0000000000ab04bc in execute_ex (ex=0x7ffff7612030)
    at /home/users/lvshun/php7/trunk/php/.tmp/build/php-7.0.6/Zend/zend_vm_execute.h:417
        ret = 0
        execute_data = 0x7ffff7612030
#4  0x0000000000ab0c66 in zend_execute (op_array=0x7ffff76620e0, return_value=0x7fffffffcdf0)
    at /home/users/lvshun/php7/trunk/php/.tmp/build/php-7.0.6/Zend/zend_vm_execute.h:458
        execute_data = 0x7ffff7612030
#5  0x0000000000a18f78 in zend_eval_stringl (str=0x17d4d90
"var_dump(get_defined_constants(true));", str_len=38, retval_ptr=0x0, 
    string_name=0x1353fcc "Command line code")
    at /home/users/lvshun/php7/trunk/php/.tmp/build/php-7.0.6/Zend/zend_execute_API.c:1135
        __orig_bailout = 0x7fffffffe050
        __bailout = {{__jmpbuf = {0, 140737488342688, 14558992, 140737488348272, 0, 0,
140737488342256, 10587994}, 
            __mask_was_saved = 0, __saved_mask = {__val = {140737488342432, 14558992, 10461214, 0,
26465744, 0, 140737488342608, 
                140737488342800, 11965133, 18446744073565204544, 1125281431552, 26465744, 26465744,
1129432048064, 26465696, 
                26465696}}}}
        local_retval = {value = {lval = 26465648, dval = 1.3075767471727095e-316, counted =
0x193d570, str = 0x193d570, 
            arr = 0x193d570, obj = 0x193d570, res = 0x193d570, ref = 0x193d570, ast = 0x193d570, zv
= 0x193d570, ptr = 0x193d570, 
            ce = 0x193d570, func = 0x193d570, ww = {w1 = 26465648, w2 = 0}}, u1 = {v = {type = 0
'\000', type_flags = 0 '\000', 
              const_flags = 0 '\000', reserved = 0 '\000'}, type_info = 0}, u2 =
{var_flags = 0, next = 0, cache_slot = 0, 
            lineno = 0, num_args = 0, fe_pos = 0, fe_iter_idx = 0}}
        pv = {value = {lval = 140737343656320, dval = 6.9533486587541203e-310, counted =
0x7ffff7601180, str = 0x7ffff7601180, 
            arr = 0x7ffff7601180, obj = 0x7ffff7601180, res = 0x7ffff7601180, ref = 0x7ffff7601180,
ast = 0x7ffff7601180, 
            zv = 0x7ffff7601180, ptr = 0x7ffff7601180, ce = 0x7ffff7601180, func = 0x7ffff7601180,
ww = {w1 = 4150268288, 
              w2 = 32767}}, u1 = {v = {type = 6 '\006', type_flags = 20 '\024',
const_flags = 0 '\000', reserved = 0 '\000'}, 
            type_info = 5126}, u2 = {var_flags = 0, next = 0, cache_slot = 0, lineno = 0, num_args =
0, fe_pos = 0, 
            fe_iter_idx = 0}}
        new_op_array = 0x7ffff76620e0
        original_compiler_options = 2
        retval = 26465744
#6  0x0000000000a19135 in zend_eval_stringl_ex (str=0x17d4d90
"var_dump(get_defined_constants(true));", str_len=38, retval_ptr=0x0, 
    string_name=0x1353fcc "Command line code", handle_exceptions=1)
    at /home/users/lvshun/php7/trunk/php/.tmp/build/php-7.0.6/Zend/zend_execute_API.c:1176
        result = 0
#7  0x0000000000a191ad in zend_eval_string_ex (str=0x17d4d90
"var_dump(get_defined_constants(true));", retval_ptr=0x0, 
    string_name=0x1353fcc "Command line code", handle_exceptions=1)
    at /home/users/lvshun/php7/trunk/php/.tmp/build/php-7.0.6/Zend/zend_execute_API.c:1187
No locals.
#8  0x0000000000b6a05c in do_cli (argc=4, argv=0x17d4cd0)
    at /home/users/lvshun/php7/trunk/php/.tmp/build/php-7.0.6/sapi/cli/php_cli.c:1005
        __orig_bailout = 0x7fffffffe270
        __bailout = {{__jmpbuf = {0, 140737488347712, 14558992, 140737488348272, 0, 0,
140737488342816, 11965745}, 
            __mask_was_saved = 0, __saved_mask = {__val = {16, 20146392, 20146440, 20146471,
20146480, 20146504, 20146517, 
                20146534, 20146555, 20146575, 20146592, 20146613, 20146623, 20146637, 20146659,
20146678}}}}
        c = -1
        file_handle = {handle = {fd = 722660096, fp = 0x302b12eb00, stream = {handle = 0x302b12eb00,
isatty = 10040959, mmap = {
                len = 10135242, pos = 10041794, map = 0x993470 <php_stream_open_for_zend>, 
                buf = 0x99b7b9 <vspprintf>
"UH\211\345H\203\354PH\211}\370H\211u\360H\211U\350H\211M\340H\215}\300", <incomplete
sequence \374\272>, old_handle = 0x99b970 <vstrpprintf>, old_closer = 0x9a282f
<sapi_getenv>}, 
              reader = 0x993657 <php_resolve_path_for_zend>, fsizer = 0x302b130620, closer =
0x70}}, filename = 0x1353f76 "-", 
          opened_path = 0x0, type = ZEND_HANDLE_FP, free_filename = 0 '\000'}
        behavior = 6
        reflection_what = 0x0
        request_started = 1
        exit_status = 0
        php_optarg = 0x17d4d90 "var_dump(get_defined_constants(true));"
        orig_optarg = 0x0
        php_optind = 4
        orig_optind = 1
        exec_direct = 0x17d4d90 "var_dump(get_defined_constants(true));"
        exec_run = 0x0
        exec_begin = 0x0
        exec_end = 0x0
        arg_free = 0x17d4d90 "var_dump(get_defined_constants(true));"
        arg_excp = 0x17d4ce8
        script_file = 0x0
        translated_path = 0x0
        interactive = 0
        param_error = 0x0
        hide_argv = 0
#9  0x0000000000b6b0f5 in main (argc=4, argv=0x17d4cd0)
    at /home/users/lvshun/php7/trunk/php/.tmp/build/php-7.0.6/sapi/cli/php_cli.c:1344
        __orig_bailout = 0x0
        __bailout = {{__jmpbuf = {0, 140737488348064, 14558992, 140737488348272, 0, 0,
140737488347728, 11972824}, 
            __mask_was_saved = 0, __saved_mask = {__val = {23437640, 22686360, 140737488348272, 0,
0, 270766525504, 270765434426, 
                206158430209, 0, 140737346091280, 206878818672, 0, 270765434114, 0, 32, 0}}}}
        c = -1
        exit_status = 0
        module_started = 1
        sapi_started = 1
        php_optarg = 0x17d4d90 "var_dump(get_defined_constants(true));"
        php_optind = 4
        use_extended_info = 0
        ini_path_override = 0x0
        ini_entries = 0x17d4fe0
"html_errors=0\nregister_argc_argv=1\nimplicit_flush=1\noutput_buffering=0\nmax_execution_time=0\nmax_input_time=-1\n"
        ini_entries_len = 110
        ini_ignore = 1
        sapi_module = 0x1672d60 <cli_sapi_module>


Previous Comments:
------------------------------------------------------------------------
[2016-05-30 05:36:45] krakjoe@php.net

I can't reproduce either.

Can you post "bt full" ?

------------------------------------------------------------------------
[2016-05-30 03:02:59] jccgls001 at 126 dot com

thanks for you apply~ this problem really troubles me a lot ...

I use this command:
USE_ZEND_ALLOC valgrind -r -n "var_dump(get_defined_constants(true));"

valgrind show these infos:
==25809== Memcheck, a memory error detector
==25809== Copyright (C) 2002-2012, and GNU GPL'd, by Julian Seward et al.
==25809== Using Valgrind-3.8.1 and LibVEX; rerun with -h for copyright info
==25809== Command: install/php/bin/php -n -r var_dump(get_defined_constants(true));
==25809== 
==25809== Use of uninitialised value of size 8
==25809==    at 0x49095B2: strlen (mc_replace_strmem.c:399)
==25809==    by 0xA652B5: zif_get_defined_constants (zend_builtin_functions.c:2227)
==25809==    by 0xAB1780: ZEND_DO_ICALL_SPEC_HANDLER (zend_vm_execute.h:586)
==25809==    by 0xAB04BB: execute_ex (zend_vm_execute.h:417)
==25809==    by 0xAB0C65: zend_execute (zend_vm_execute.h:458)
==25809==    by 0xA18F77: zend_eval_stringl (zend_execute_API.c:1135)
==25809==    by 0xA19134: zend_eval_stringl_ex (zend_execute_API.c:1176)
==25809==    by 0xA191AC: zend_eval_string_ex (zend_execute_API.c:1187)
==25809==    by 0xB6A05B: do_cli (php_cli.c:1005)
==25809==    by 0xB6B0F4: main (php_cli.c:1344)
==25809== 
==25809== Invalid read of size 1
==25809==    at 0x49095B2: strlen (mc_replace_strmem.c:399)
==25809==    by 0xA652B5: zif_get_defined_constants (zend_builtin_functions.c:2227)
==25809==    by 0xAB1780: ZEND_DO_ICALL_SPEC_HANDLER (zend_vm_execute.h:586)
==25809==    by 0xAB04BB: execute_ex (zend_vm_execute.h:417)
==25809==    by 0xAB0C65: zend_execute (zend_vm_execute.h:458)
==25809==    by 0xA18F77: zend_eval_stringl (zend_execute_API.c:1135)
==25809==    by 0xA19134: zend_eval_stringl_ex (zend_execute_API.c:1176)
==25809==    by 0xA191AC: zend_eval_string_ex (zend_execute_API.c:1187)
==25809==    by 0xB6A05B: do_cli (php_cli.c:1005)
==25809==    by 0xB6B0F4: main (php_cli.c:1344)
==25809==  Address 0x0 is not stack'd, malloc'd or (recently) free'd
==25809== 
==25809== 
==25809== Process terminating with default action of signal 11 (SIGSEGV)
==25809==  Access not within mapped region at address 0x0
==25809==    at 0x49095B2: strlen (mc_replace_strmem.c:399)
==25809==    by 0xA652B5: zif_get_defined_constants (zend_builtin_functions.c:2227)
==25809==    by 0xAB1780: ZEND_DO_ICALL_SPEC_HANDLER (zend_vm_execute.h:586)
==25809==    by 0xAB04BB: execute_ex (zend_vm_execute.h:417)
==25809==    by 0xAB0C65: zend_execute (zend_vm_execute.h:458)
==25809==    by 0xA18F77: zend_eval_stringl (zend_execute_API.c:1135)
==25809==    by 0xA19134: zend_eval_stringl_ex (zend_execute_API.c:1176)
==25809==    by 0xA191AC: zend_eval_string_ex (zend_execute_API.c:1187)
==25809==    by 0xB6A05B: do_cli (php_cli.c:1005)
==25809==    by 0xB6B0F4: main (php_cli.c:1344)
==25809==  If you believe this happened as a result of a stack
==25809==  overflow in your program's main thread (unlikely but
==25809==  possible), you can try to increase the size of the
==25809==  main thread stack using the --main-stacksize= flag.
==25809==  The main thread stack size used in this run was 10485760.
==25809== 
==25809== HEAP SUMMARY:
==25809==     in use at exit: 2,092,430 bytes in 16,256 blocks
==25809==   total heap usage: 19,987 allocs, 3,731 frees, 2,593,732 bytes allocated
==25809== 
==25809== LEAK SUMMARY:
==25809==    definitely lost: 923 bytes in 13 blocks
==25809==    indirectly lost: 0 bytes in 0 blocks
==25809==      possibly lost: 1,213,506 bytes in 12,245 blocks
==25809==    still reachable: 878,001 bytes in 3,998 blocks
==25809==         suppressed: 0 bytes in 0 blocks
==25809== Rerun with --leak-check=full to see details of leaked memory
==25809== 
==25809== For counts of detected and suppressed errors, rerun with: -v
==25809== Use --track-origins=yes to see where uninitialised values come from
==25809== ERROR SUMMARY: 2 errors from 2 contexts (suppressed: 7 from 7)

it seems like strlen() used a uninitialised char*(size of 8)

i think this problem maybe caused by:
module_names in zend_builtin_functions.c(2203), it should assign "Core" to
module_names[1], but actually assign to module_names[0], which will lead to error when call
"strlen(module_names[1])" in line 2227.


----------------------
by the way, "php -m" show:
[PHP Modules]
bcmath
Core
ctype
curl
date
dom
fileinfo
filter
gd
hash
iconv
json
libxml
mbstring
mcrypt
openssl
pcntl
pcre
PDO
pdo_mysql
pdo_sqlite
Phar
posix
Reflection
session
shmop
SimpleXML
soap
sockets
SPL
sqlite3
standard
sysvsem
tokenizer
xml
xmlreader
xmlrpc
xmlwriter
zip
zlib

[Zend Modules]

------------------------------------------------------------------------
[2016-05-29 12:12:44] bwoebi@php.net

The only way this code could crash is if module->name is invalid.

Try:
USE_ZEND_ALLOC=0 valgrind php -n -r "var_dump(get_define_constants(true));"

Perhaps this finds something, but locally I cannot reproduce it either.

Also, what does php -m tell you?

------------------------------------------------------------------------
[2016-05-23 12:39:02] jccgls001 at 126 dot com

Following your advise, I use php -n -r "var_dump(get_define_constants(true);" command but
segmentation fault again. the backtrace info is same as before.

I have removed all third-party extensions when build source and before run code.

------------------------------------------------------------------------
[2016-05-23 12:13:26] laruence@php.net

try again after you disable any third-part extension.

like: php -n -r "var_dump(get_define_constants(true);", then add them one by one to check
which extension cause this.

------------------------------------------------------------------------


The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at

    https://bugs.php.net/bug.php?id=72257


--
Edit this bug report at https://bugs.php.net/bug.php?id=72257&edit=1


Thread (16 messages)

« previous php.bugs (#201332) next »