Bug #72286 [Csd->ReO]: Segmentation fault (segfault) During Garbage Collection

From: Date: Sat, 16 Jul 2016 21:04:17 +0000
Subject: Bug #72286 [Csd->ReO]: Segmentation fault (segfault) During Garbage Collection
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-202366@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=72286&edit=1 ID: 72286 Updated by: nikic@php.net Reported by: php at mattlight dot biz Summary: Segmentation fault (segfault) During Garbage Collection -Status: Closed +Status: Re-Opened Type: Bug Package: Reproducible crash Operating System: CentOS Linux release 7.2.1511 PHP Version: 5.6.23 Assigned To: dmitry Block user comment: N Private report: N New Comment: Commit reverted due to segfaults. Previous Comments: ------------------------------------------------------------------------ [2016-07-16 21:03:33] nikic@php.net Automatic comment on behalf of nikic Revision: http://git.php.net/?p=php-src.git;a=commit;h=171c759d791f809ebc31711fd0b0b5bb632cd2cc Log: Revert "Fixed bug #72286 (Segmentation fault During Garbage Collection)" ------------------------------------------------------------------------ [2016-07-14 19:42:23] dmitry@php.net Fixed in PHP-5.6. http://git.php.net/?p=php-src.git;a=commitdiff;h=1c84b55adea936b065a20102202bea3d1d243225 PHP-7.0 is not affected. ------------------------------------------------------------------------ [2016-07-14 19:40:48] dmitry@php.net Automatic comment on behalf of dmitry@zend.com Revision: http://git.php.net/?p=php-src.git;a=commit;h=1c84b55adea936b065a20102202bea3d1d243225 Log: Fixed bug #72286 (Segmentation fault During Garbage Collection) ------------------------------------------------------------------------ [2016-07-14 15:56:06] dmitry@php.net Got it. it's reproducible on PHP-5.* with opcache disabled. $ USE_ZEND_ALLOC=0 valgrind php5.6/CGI-DEBUG/sapi/cli/php -n bug72286.php ==9892== Invalid read of size 4 ==9892== at 0x8642AC4: zend_std_object_get_class (zend_object_handlers.c:1528) ==9892== by 0x86159DD: zend_get_class_entry (zend_API.c:238) ==9892== by 0x863E671: zend_std_get_debug_info (zend_object_handlers.c:140) ==9892== by 0x84D26C7: php_var_dump (var.c:129) ==9892== by 0x84D29EA: zif_var_dump (var.c:183) ==9892== by 0x8649A92: zend_do_fcall_common_helper_SPEC (zend_vm_execute.h:558) ==9892== by 0x864E037: ZEND_DO_FCALL_SPEC_CONST_HANDLER (zend_vm_execute.h:2602) ==9892== by 0x864936C: execute_ex (zend_vm_execute.h:363) ==9892== by 0x86493CD: zend_execute (zend_vm_execute.h:388) ==9892== by 0x86048E1: zend_call_function (zend_execute_API.c:829) ==9892== by 0x862CD3F: zend_call_method (zend_interfaces.c:97) ==9892== by 0x863DBDA: zend_objects_destroy_object (zend_objects.c:123) ==9892== Address 0xffffffff is not stack'd, malloc'd or (recently) free'd PHP-7.0 works fine. ------------------------------------------------------------------------ [2016-07-14 15:34:59] php at mattlight dot biz This error is still reproducible on my end with the latest version of PHP 5.6 (5.6.23). Here is the output I produced as of a few minutes ago: [boxkeeper@macaroon-dev php-circular-reference-segfault]$ php segfault.php Array ( [0] => Core [1] => date [2] => ereg [3] => libxml [4] => openssl [5] => pcre [6] => zlib [7] => filter [8] => hash [9] => pcntl [10] => readline [11] => Reflection [12] => SPL [13] => session [14] => standard [15] => mhash ) string(24) "we are about to segfault" string(15) "segfaults here:" Segmentation fault [boxkeeper@macaroon-dev php-circular-reference-segfault]$ echo $? 139 [boxkeeper@macaroon-dev php-circular-reference-segfault]$ php --version PHP 5.6.23 (cli) (built: Jun 22 2016 08:56:52) Copyright (c) 1997-2016 The PHP Group Zend Engine v2.6.0, Copyright (c) 1998-2016 Zend Technologies [boxkeeper@macaroon-dev php-circular-reference-segfault]$ ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=72286 -- Edit this bug report at https://bugs.php.net/bug.php?id=72286&edit=1

« previous php.bugs (#202366) next »