Bug #72257 [Fbk->Opn]: "get_defined_constants(true)" core dump

From: Date: Mon, 30 May 2016 13:02:58 +0000
Subject: Bug #72257 [Fbk->Opn]: "get_defined_constants(true)" core dump
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-201347@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=72257&edit=1 ID: 72257 User updated by: jccgls001 at 126 dot com Reported by: jccgls001 at 126 dot com Summary: "get_defined_constants(true)" core dump -Status: Feedback +Status: Open Type: Bug Package: Scripting Engine problem Operating System: linux 2.6 PHP Version: 7.0.6 Block user comment: N Private report: N New Comment: ok and i find module_names[1] is uninitailized value... (gdb) p (char*)module_names[0] <------- this may ‘internal’ ? $1 = 0x134d795 "Core" (gdb) p (char*)module_names[1] <------- problem module, may 'Core' but null $2 = 0x0 (gdb) p (char*)module_names[2] $3 = 0xde2964 "date" (gdb) p (char*)module_number $4 = 0x1 <error: Cannot access memory at address 0x1> (gdb) p (char*)val->name->val $5 = 0x17ecc08 "PHP_VERSION" Previous Comments: ------------------------------------------------------------------------ [2016-05-30 12:46:52] bwoebi@php.net Well, module_number 1 should be unused. Can you please give us the faulty constant name with the bad module number? f 1 p (char*)val->name->val ------------------------------------------------------------------------ [2016-05-30 05:56:47] jccgls001 at 126 dot com I find when i add USE_ZEND_ALLOC=0 the function run successful -------------------------------------------- these info are created by command without USE_ZEND_ALLOC=0: gdb --args ./php -n -r "var_dump(get_defined_constants(true));" (gdb) bt full #0 0x000000302af6ff40 in ?? () No symbol table info available. #1 0x0000000000a652b6 in zif_get_defined_constants (execute_data=0x7ffff7612120, return_value=0x7ffff7612090) at /home/users/lvshun/php7/trunk/php/.tmp/build/php-7.0.6/Zend/zend_builtin_functions.c:2227 _z = 0x1901690 _p = 0x1901690 _end = 0x190f2b0 val = 0x17ec910 modules = 0x7ffff7676000 const_val = {value = {lval = 2, dval = 9.8813129168249309e-324, counted = 0x2, str = 0x2, arr = 0x2, obj = 0x2, res = 0x2, ref = 0x2, ast = 0x2, zv = 0x2, ptr = 0x2, ce = 0x2, func = 0x2, ww = {w1 = 2, w2 = 0}}, u1 = {v = {type = 1 '\001', type_flags = 0 '\000', const_flags = 0 '\000', reserved = 0 '\000'}, type_info = 1}, u2 = {var_flags = 0, next = 0, cache_slot = 0, lineno = 0, num_args = 0, fe_pos = 0, fe_iter_idx = 0}} module = 0x17df330 i = 41 module_number = 1 module_names = 0x7ffff7679000 categorize = 1 '\001' #2 0x0000000000ab1781 in ZEND_DO_ICALL_SPEC_HANDLER (execute_data=0x7ffff7612030) at /home/users/lvshun/php7/trunk/php/.tmp/build/php-7.0.6/Zend/zend_vm_execute.h:586 opline = 0x7ffff7662220 call = 0x7ffff7612120 fbc = 0x17e9700 ret = 0x7ffff7612090 #3 0x0000000000ab04bc in execute_ex (ex=0x7ffff7612030) at /home/users/lvshun/php7/trunk/php/.tmp/build/php-7.0.6/Zend/zend_vm_execute.h:417 ret = 0 execute_data = 0x7ffff7612030 #4 0x0000000000ab0c66 in zend_execute (op_array=0x7ffff76620e0, return_value=0x7fffffffcdf0) at /home/users/lvshun/php7/trunk/php/.tmp/build/php-7.0.6/Zend/zend_vm_execute.h:458 execute_data = 0x7ffff7612030 #5 0x0000000000a18f78 in zend_eval_stringl (str=0x17d4d90 "var_dump(get_defined_constants(true));", str_len=38, retval_ptr=0x0, string_name=0x1353fcc "Command line code") at /home/users/lvshun/php7/trunk/php/.tmp/build/php-7.0.6/Zend/zend_execute_API.c:1135 __orig_bailout = 0x7fffffffe050 __bailout = {{__jmpbuf = {0, 140737488342688, 14558992, 140737488348272, 0, 0, 140737488342256, 10587994}, __mask_was_saved = 0, __saved_mask = {__val = {140737488342432, 14558992, 10461214, 0, 26465744, 0, 140737488342608, 140737488342800, 11965133, 18446744073565204544, 1125281431552, 26465744, 26465744, 1129432048064, 26465696, 26465696}}}} local_retval = {value = {lval = 26465648, dval = 1.3075767471727095e-316, counted = 0x193d570, str = 0x193d570, arr = 0x193d570, obj = 0x193d570, res = 0x193d570, ref = 0x193d570, ast = 0x193d570, zv = 0x193d570, ptr = 0x193d570, ce = 0x193d570, func = 0x193d570, ww = {w1 = 26465648, w2 = 0}}, u1 = {v = {type = 0 '\000', type_flags = 0 '\000', const_flags = 0 '\000', reserved = 0 '\000'}, type_info = 0}, u2 = {var_flags = 0, next = 0, cache_slot = 0, lineno = 0, num_args = 0, fe_pos = 0, fe_iter_idx = 0}} pv = {value = {lval = 140737343656320, dval = 6.9533486587541203e-310, counted = 0x7ffff7601180, str = 0x7ffff7601180, arr = 0x7ffff7601180, obj = 0x7ffff7601180, res = 0x7ffff7601180, ref = 0x7ffff7601180, ast = 0x7ffff7601180, zv = 0x7ffff7601180, ptr = 0x7ffff7601180, ce = 0x7ffff7601180, func = 0x7ffff7601180, ww = {w1 = 4150268288, w2 = 32767}}, u1 = {v = {type = 6 '\006', type_flags = 20 '\024', const_flags = 0 '\000', reserved = 0 '\000'}, type_info = 5126}, u2 = {var_flags = 0, next = 0, cache_slot = 0, lineno = 0, num_args = 0, fe_pos = 0, fe_iter_idx = 0}} new_op_array = 0x7ffff76620e0 original_compiler_options = 2 retval = 26465744 #6 0x0000000000a19135 in zend_eval_stringl_ex (str=0x17d4d90 "var_dump(get_defined_constants(true));", str_len=38, retval_ptr=0x0, string_name=0x1353fcc "Command line code", handle_exceptions=1) at /home/users/lvshun/php7/trunk/php/.tmp/build/php-7.0.6/Zend/zend_execute_API.c:1176 result = 0 #7 0x0000000000a191ad in zend_eval_string_ex (str=0x17d4d90 "var_dump(get_defined_constants(true));", retval_ptr=0x0, string_name=0x1353fcc "Command line code", handle_exceptions=1) at /home/users/lvshun/php7/trunk/php/.tmp/build/php-7.0.6/Zend/zend_execute_API.c:1187 No locals. #8 0x0000000000b6a05c in do_cli (argc=4, argv=0x17d4cd0) at /home/users/lvshun/php7/trunk/php/.tmp/build/php-7.0.6/sapi/cli/php_cli.c:1005 __orig_bailout = 0x7fffffffe270 __bailout = {{__jmpbuf = {0, 140737488347712, 14558992, 140737488348272, 0, 0, 140737488342816, 11965745}, __mask_was_saved = 0, __saved_mask = {__val = {16, 20146392, 20146440, 20146471, 20146480, 20146504, 20146517, 20146534, 20146555, 20146575, 20146592, 20146613, 20146623, 20146637, 20146659, 20146678}}}} c = -1 file_handle = {handle = {fd = 722660096, fp = 0x302b12eb00, stream = {handle = 0x302b12eb00, isatty = 10040959, mmap = { len = 10135242, pos = 10041794, map = 0x993470 <php_stream_open_for_zend>, buf = 0x99b7b9 <vspprintf> "UH\211\345H\203\354PH\211}\370H\211u\360H\211U\350H\211M\340H\215}\300", <incomplete sequence \374\272>, old_handle = 0x99b970 <vstrpprintf>, old_closer = 0x9a282f <sapi_getenv>}, reader = 0x993657 <php_resolve_path_for_zend>, fsizer = 0x302b130620, closer = 0x70}}, filename = 0x1353f76 "-", opened_path = 0x0, type = ZEND_HANDLE_FP, free_filename = 0 '\000'} behavior = 6 reflection_what = 0x0 request_started = 1 exit_status = 0 php_optarg = 0x17d4d90 "var_dump(get_defined_constants(true));" orig_optarg = 0x0 php_optind = 4 orig_optind = 1 exec_direct = 0x17d4d90 "var_dump(get_defined_constants(true));" exec_run = 0x0 exec_begin = 0x0 exec_end = 0x0 arg_free = 0x17d4d90 "var_dump(get_defined_constants(true));" arg_excp = 0x17d4ce8 script_file = 0x0 translated_path = 0x0 interactive = 0 param_error = 0x0 hide_argv = 0 #9 0x0000000000b6b0f5 in main (argc=4, argv=0x17d4cd0) at /home/users/lvshun/php7/trunk/php/.tmp/build/php-7.0.6/sapi/cli/php_cli.c:1344 __orig_bailout = 0x0 __bailout = {{__jmpbuf = {0, 140737488348064, 14558992, 140737488348272, 0, 0, 140737488347728, 11972824}, __mask_was_saved = 0, __saved_mask = {__val = {23437640, 22686360, 140737488348272, 0, 0, 270766525504, 270765434426, 206158430209, 0, 140737346091280, 206878818672, 0, 270765434114, 0, 32, 0}}}} c = -1 exit_status = 0 module_started = 1 sapi_started = 1 php_optarg = 0x17d4d90 "var_dump(get_defined_constants(true));" php_optind = 4 use_extended_info = 0 ini_path_override = 0x0 ini_entries = 0x17d4fe0 "html_errors=0\nregister_argc_argv=1\nimplicit_flush=1\noutput_buffering=0\nmax_execution_time=0\nmax_input_time=-1\n" ini_entries_len = 110 ini_ignore = 1 sapi_module = 0x1672d60 <cli_sapi_module> ------------------------------------------------------------------------ [2016-05-30 05:36:45] krakjoe@php.net I can't reproduce either. Can you post "bt full" ? ------------------------------------------------------------------------ [2016-05-30 03:02:59] jccgls001 at 126 dot com thanks for you apply~ this problem really troubles me a lot ... I use this command: USE_ZEND_ALLOC valgrind -r -n "var_dump(get_defined_constants(true));" valgrind show these infos: ==25809== Memcheck, a memory error detector ==25809== Copyright (C) 2002-2012, and GNU GPL'd, by Julian Seward et al. ==25809== Using Valgrind-3.8.1 and LibVEX; rerun with -h for copyright info ==25809== Command: install/php/bin/php -n -r var_dump(get_defined_constants(true)); ==25809== ==25809== Use of uninitialised value of size 8 ==25809== at 0x49095B2: strlen (mc_replace_strmem.c:399) ==25809== by 0xA652B5: zif_get_defined_constants (zend_builtin_functions.c:2227) ==25809== by 0xAB1780: ZEND_DO_ICALL_SPEC_HANDLER (zend_vm_execute.h:586) ==25809== by 0xAB04BB: execute_ex (zend_vm_execute.h:417) ==25809== by 0xAB0C65: zend_execute (zend_vm_execute.h:458) ==25809== by 0xA18F77: zend_eval_stringl (zend_execute_API.c:1135) ==25809== by 0xA19134: zend_eval_stringl_ex (zend_execute_API.c:1176) ==25809== by 0xA191AC: zend_eval_string_ex (zend_execute_API.c:1187) ==25809== by 0xB6A05B: do_cli (php_cli.c:1005) ==25809== by 0xB6B0F4: main (php_cli.c:1344) ==25809== ==25809== Invalid read of size 1 ==25809== at 0x49095B2: strlen (mc_replace_strmem.c:399) ==25809== by 0xA652B5: zif_get_defined_constants (zend_builtin_functions.c:2227) ==25809== by 0xAB1780: ZEND_DO_ICALL_SPEC_HANDLER (zend_vm_execute.h:586) ==25809== by 0xAB04BB: execute_ex (zend_vm_execute.h:417) ==25809== by 0xAB0C65: zend_execute (zend_vm_execute.h:458) ==25809== by 0xA18F77: zend_eval_stringl (zend_execute_API.c:1135) ==25809== by 0xA19134: zend_eval_stringl_ex (zend_execute_API.c:1176) ==25809== by 0xA191AC: zend_eval_string_ex (zend_execute_API.c:1187) ==25809== by 0xB6A05B: do_cli (php_cli.c:1005) ==25809== by 0xB6B0F4: main (php_cli.c:1344) ==25809== Address 0x0 is not stack'd, malloc'd or (recently) free'd ==25809== ==25809== ==25809== Process terminating with default action of signal 11 (SIGSEGV) ==25809== Access not within mapped region at address 0x0 ==25809== at 0x49095B2: strlen (mc_replace_strmem.c:399) ==25809== by 0xA652B5: zif_get_defined_constants (zend_builtin_functions.c:2227) ==25809== by 0xAB1780: ZEND_DO_ICALL_SPEC_HANDLER (zend_vm_execute.h:586) ==25809== by 0xAB04BB: execute_ex (zend_vm_execute.h:417) ==25809== by 0xAB0C65: zend_execute (zend_vm_execute.h:458) ==25809== by 0xA18F77: zend_eval_stringl (zend_execute_API.c:1135) ==25809== by 0xA19134: zend_eval_stringl_ex (zend_execute_API.c:1176) ==25809== by 0xA191AC: zend_eval_string_ex (zend_execute_API.c:1187) ==25809== by 0xB6A05B: do_cli (php_cli.c:1005) ==25809== by 0xB6B0F4: main (php_cli.c:1344) ==25809== If you believe this happened as a result of a stack ==25809== overflow in your program's main thread (unlikely but ==25809== possible), you can try to increase the size of the ==25809== main thread stack using the --main-stacksize= flag. ==25809== The main thread stack size used in this run was 10485760. ==25809== ==25809== HEAP SUMMARY: ==25809== in use at exit: 2,092,430 bytes in 16,256 blocks ==25809== total heap usage: 19,987 allocs, 3,731 frees, 2,593,732 bytes allocated ==25809== ==25809== LEAK SUMMARY: ==25809== definitely lost: 923 bytes in 13 blocks ==25809== indirectly lost: 0 bytes in 0 blocks ==25809== possibly lost: 1,213,506 bytes in 12,245 blocks ==25809== still reachable: 878,001 bytes in 3,998 blocks ==25809== suppressed: 0 bytes in 0 blocks ==25809== Rerun with --leak-check=full to see details of leaked memory ==25809== ==25809== For counts of detected and suppressed errors, rerun with: -v ==25809== Use --track-origins=yes to see where uninitialised values come from ==25809== ERROR SUMMARY: 2 errors from 2 contexts (suppressed: 7 from 7) it seems like strlen() used a uninitialised char*(size of 8) i think this problem maybe caused by: module_names in zend_builtin_functions.c(2203), it should assign "Core" to module_names[1], but actually assign to module_names[0], which will lead to error when call "strlen(module_names[1])" in line 2227. ---------------------- by the way, "php -m" show: [PHP Modules] bcmath Core ctype curl date dom fileinfo filter gd hash iconv json libxml mbstring mcrypt openssl pcntl pcre PDO pdo_mysql pdo_sqlite Phar posix Reflection session shmop SimpleXML soap sockets SPL sqlite3 standard sysvsem tokenizer xml xmlreader xmlrpc xmlwriter zip zlib [Zend Modules] ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=72257 -- Edit this bug report at https://bugs.php.net/bug.php?id=72257&edit=1

« previous php.bugs (#201347) next »