Bug #72286 [Csd->ReO]: Segmentation fault (segfault) During Garbage Collection
| From: | nikic@php.net | Date: | Sat, 16 Jul 2016 21:04:17 +0000 |
| Subject: | Bug #72286 [Csd->ReO]: Segmentation fault (segfault) During Garbage Collection | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-202366@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=72286&edit=1
ID: 72286
Updated by: nikic@php.net
Reported by: php at mattlight dot biz
Summary: Segmentation fault (segfault) During Garbage
Collection
-Status: Closed
+Status: Re-Opened
Type: Bug
Package: Reproducible crash
Operating System: CentOS Linux release 7.2.1511
PHP Version: 5.6.23
Assigned To: dmitry
Block user comment: N
Private report: N
New Comment:
Commit reverted due to segfaults.
Previous Comments:
------------------------------------------------------------------------
[2016-07-16 21:03:33] nikic@php.net
Automatic comment on behalf of nikic
Revision: http://git.php.net/?p=php-src.git;a=commit;h=171c759d791f809ebc31711fd0b0b5bb632cd2cc
Log: Revert "Fixed bug #72286 (Segmentation fault During Garbage Collection)"
------------------------------------------------------------------------
[2016-07-14 19:42:23] dmitry@php.net
Fixed in PHP-5.6.
http://git.php.net/?p=php-src.git;a=commitdiff;h=1c84b55adea936b065a20102202bea3d1d243225
PHP-7.0 is not affected.
------------------------------------------------------------------------
[2016-07-14 19:40:48] dmitry@php.net
Automatic comment on behalf of dmitry@zend.com
Revision: http://git.php.net/?p=php-src.git;a=commit;h=1c84b55adea936b065a20102202bea3d1d243225
Log: Fixed bug #72286 (Segmentation fault During Garbage Collection)
------------------------------------------------------------------------
[2016-07-14 15:56:06] dmitry@php.net
Got it. it's reproducible on PHP-5.* with opcache disabled.
$ USE_ZEND_ALLOC=0 valgrind php5.6/CGI-DEBUG/sapi/cli/php -n bug72286.php
==9892== Invalid read of size 4
==9892== at 0x8642AC4: zend_std_object_get_class (zend_object_handlers.c:1528)
==9892== by 0x86159DD: zend_get_class_entry (zend_API.c:238)
==9892== by 0x863E671: zend_std_get_debug_info (zend_object_handlers.c:140)
==9892== by 0x84D26C7: php_var_dump (var.c:129)
==9892== by 0x84D29EA: zif_var_dump (var.c:183)
==9892== by 0x8649A92: zend_do_fcall_common_helper_SPEC (zend_vm_execute.h:558)
==9892== by 0x864E037: ZEND_DO_FCALL_SPEC_CONST_HANDLER (zend_vm_execute.h:2602)
==9892== by 0x864936C: execute_ex (zend_vm_execute.h:363)
==9892== by 0x86493CD: zend_execute (zend_vm_execute.h:388)
==9892== by 0x86048E1: zend_call_function (zend_execute_API.c:829)
==9892== by 0x862CD3F: zend_call_method (zend_interfaces.c:97)
==9892== by 0x863DBDA: zend_objects_destroy_object (zend_objects.c:123)
==9892== Address 0xffffffff is not stack'd, malloc'd or (recently) free'd
PHP-7.0 works fine.
------------------------------------------------------------------------
[2016-07-14 15:34:59] php at mattlight dot biz
This error is still reproducible on my end with the latest version of PHP 5.6 (5.6.23).
Here is the output I produced as of a few minutes ago:
[boxkeeper@macaroon-dev php-circular-reference-segfault]$ php segfault.php
Array
(
[0] => Core
[1] => date
[2] => ereg
[3] => libxml
[4] => openssl
[5] => pcre
[6] => zlib
[7] => filter
[8] => hash
[9] => pcntl
[10] => readline
[11] => Reflection
[12] => SPL
[13] => session
[14] => standard
[15] => mhash
)
string(24) "we are about to segfault"
string(15) "segfaults here:"
Segmentation fault
[boxkeeper@macaroon-dev php-circular-reference-segfault]$ echo $?
139
[boxkeeper@macaroon-dev php-circular-reference-segfault]$ php --version
PHP 5.6.23 (cli) (built: Jun 22 2016 08:56:52)
Copyright (c) 1997-2016 The PHP Group
Zend Engine v2.6.0, Copyright (c) 1998-2016 Zend Technologies
[boxkeeper@macaroon-dev php-circular-reference-segfault]$
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=72286
--
Edit this bug report at https://bugs.php.net/bug.php?id=72286&edit=1