Bug #74543 [NEW]: SIGSEGV in _zend_hash_find_bucket with opcache enabled
| From: | zinigor+php at gmail dot com | Date: | Thu, 04 May 2017 21:09:47 +0000 |
| Subject: | Bug #74543 [NEW]: SIGSEGV in _zend_hash_find_bucket with opcache enabled | ||
| Groups: | php.bugs | ||
| Request: | Send a blank email to php-bugs+get-208955@lists.php.net to get a copy of this message | ||
From: zinigor+php at gmail dot com
Operating system: Ubuntu 16.10
PHP version: 7.1.4
Package: FPM related
Bug Type: Bug
Bug description:SIGSEGV in _zend_hash_find_bucket with opcache enabled
Description:
------------
I have a web server running PHP under FPM with PHP version
7.1.4-1+deb.sury.org~yakkety+1_amd64. Here is the full info if you're
interested: http://dev71.lousy.site/info.php
I get a segfault in the same place when I enable opcache (default
settings, nothing fancy). I'm running WordPress with Jetpack, and here's
the line that causes the error:
https://github.com/Automattic/jetpack/blob/master/json-endpoints.php#L141
I don't know why, but if I remove that line completely, execution
happens right until;
https://github.com/Automattic/jetpack/blob/master/json-endpoints.php#L612
where it segfaults again.
I have been trying to figure out a small script that would illustrate
the problem, but I can't - I know what lines in the PHP code are the
last to get executed, but I don't know why and I can't reproduce the
same thing in an isolated file.
I have been able to get a stack trace with debug symbols, here it is:
Reading symbols from /usr/sbin/php-fpm7.1...Reading symbols from
/usr/lib/debug/.build-id/6d/1b8d73ab820b0d911a4252da9febf10aa54f2d.debug...done.
done.
[New LWP 4945]
[Thread debugging using libthread_db enabled]
Using host libthread_db library
"/lib/x86_64-linux-gnu/libthread_db.so.1".
Core was generated by `php-fpm: pool www
'.
Program terminated with signal SIGSEGV, Segmentation fault.
#0 0x0000564573545c0f in zend_hash_find_bucket (key=0x7fef4eab4f68,
ht=0x7fef4d03fa00) at ./Zend/zend_hash.c:481
481 ./Zend/zend_hash.c: No such file or directory.
(gdb) bt
#0 0x0000564573545c0f in zend_hash_find_bucket (key=0x7fef4eab4f68,
ht=0x7fef4d03fa00) at ./Zend/zend_hash.c:481
#1 _zend_hash_add_or_update_i (flag=1, pData=0x7fef504bdd40,
key=0x7fef4eab4f68, ht=0x7fef4d03fa00) at ./Zend/zend_hash.c:556
#2 _zend_hash_update (ht=0x7fef4d03fa00, key=0x7fef4eab4f68,
pData=0x7fef504bdd40) at ./Zend/zend_hash.c:627
#3 0x0000564573581efc in
ZEND_ADD_ARRAY_ELEMENT_SPEC_CONST_CONST_HANDLER () at
./Zend/zend_vm_execute.h:5886
#4 0x000056457358273b in execute_ex (ex=<optimized out>) at
./Zend/zend_vm_execute.h:429
#5 0x00005645735dd888 in zend_execute
(op_array=op_array@entry=0x7fef5b279000,
return_value=return_value@entry=0x7fef504d8cf0) at
./Zend/zend_vm_execute.h:474
#6 0x0000564573538b53 in zend_execute_scripts (type=1528907680,
type@entry=8, retval=0x7fef504d8cf0, retval@entry=0x0,
file_count=file_count@entry=3) at ./Zend/zend.c:1476
#7 0x00005645734d4ca0 in php_execute_script
(primary_file=0x7fffce0ad610) at ./main/main.c:2537
#8 0x00005645733b1efa in main (argc=<optimized out>, argv=<optimized
out>) at ./sapi/fpm/fpm/fpm_main.c:1966
Here's what it says about frame 0:
(gdb) frame 0
#0 0x0000564573545c0f in zend_hash_find_bucket (key=0x7fef4eab4f68,
ht=0x7fef4d03fa00) at ./Zend/zend_hash.c:481
481 in ./Zend/zend_hash.c
Please let me know what more I can provide.
P,S. this looks kinda similar to https://bugs.php.net/bug.php?id=70428,
but the stack trace is different, so I thought I'd create a new bug
anyway. Sorry if it's a duplicate.
Test script:
---------------
None, but if you have a WordPress site installed, you can:
1. Install Jetpack.
2. Activate Jetpack by connecting to WordPress.com
3. Go to https://wordpress.com/settings/discussion/your.site.url.com
This is enough to trigger a request that fails with a segfault.
--
Edit bug report at https://bugs.php.net/bug.php?id=74543&edit=1
--
Try a snapshot (PHP 5.4): https://bugs.php.net/fix.php?id=74543&r=trysnapshot54
Try a snapshot (PHP 5.5): https://bugs.php.net/fix.php?id=74543&r=trysnapshot55
Try a snapshot (trunk): https://bugs.php.net/fix.php?id=74543&r=trysnapshottrunk
Fixed in SVN: https://bugs.php.net/fix.php?id=74543&r=fixed
Fixed in release: https://bugs.php.net/fix.php?id=74543&r=alreadyfixed
Need backtrace: https://bugs.php.net/fix.php?id=74543&r=needtrace
Need Reproduce Script: https://bugs.php.net/fix.php?id=74543&r=needscript
Try newer version: https://bugs.php.net/fix.php?id=74543&r=oldversion
Not developer issue: https://bugs.php.net/fix.php?id=74543&r=support
Expected behavior: https://bugs.php.net/fix.php?id=74543&r=notwrong
Not enough info: https://bugs.php.net/fix.php?id=74543&r=notenoughinfo
Submitted twice: https://bugs.php.net/fix.php?id=74543&r=submittedtwice
register_globals: https://bugs.php.net/fix.php?id=74543&r=globals
PHP 4 support discontinued: https://bugs.php.net/fix.php?id=74543&r=php4
Daylight Savings: https://bugs.php.net/fix.php?id=74543&r=dst
IIS Stability: https://bugs.php.net/fix.php?id=74543&r=isapi
Install GNU Sed: https://bugs.php.net/fix.php?id=74543&r=gnused
Floating point limitations: https://bugs.php.net/fix.php?id=74543&r=float
No Zend Extensions: https://bugs.php.net/fix.php?id=74543&r=nozend
MySQL Configuration Error: https://bugs.php.net/fix.php?id=74543&r=mysqlcfg