Bug #52752 [Ver]: Crash when lexing

From: Date: Sun, 14 May 2017 17:16:30 +0000
Subject: Bug #52752 [Ver]: Crash when lexing
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-209107@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=52752&edit=1 ID: 52752 Updated by: pollita@php.net Reported by: paulgao at yeah dot net Summary: Crash when lexing Status: Verified Type: Bug Package: Scripting Engine problem Operating System: Centos 5 32bit PHP Version: 5.3SVN-2010-08-31 (SVN) Block user comment: N Private report: N New Comment: Wouldn't acquiring a shared lock work here? We only lex when including an uncached file, so the extra flock() hit would be negligible over time (except for scripts like this which void assumptions about file permanence, obviously). Previous Comments: ------------------------------------------------------------------------ [2017-02-22 13:44:46] ironsmile at gmail dot com You can actually hit this bug when you are not in a position to do anything about it. For example, my organisation is using Codeception and Paracept for running our tests. Every now and then a testing process would fail because of this bug. Save for abandoning the whole testing framework one cannot do anything about it and have to accept false negatives. And this because PHP is indeterministic and its processes fail from time to time. Surely, this can be easily fixed! For what is worth, here is a back trace from a failure in our environment, which is 64bit CentOS 7.3.1611: #0 0x00007f2097dd86ed in lex_scan () #1 0x00007f2097df7062 in zendlex () #2 0x00007f2097dd1956 in zendparse () #3 0x00007f2097dd6f5b in compile_file () #4 0x00007f2097dfd12a in dtrace_compile_file () #5 0x00007f2085d7bc9a in phar_compile_file () from /usr/lib64/php/modules/phar.so #6 0x00007f2097ec08b3 in ZEND_INCLUDE_OR_EVAL_SPEC_CV_HANDLER () #7 0x00007f2097e39e68 in execute_ex () #8 0x00007f2097dfd1a9 in dtrace_execute_ex () #9 0x00007f2097ec27cb in zend_do_fcall_common_helper_SPEC () #10 0x00007f2097e39e68 in execute_ex () #11 0x00007f2097dfd1a9 in dtrace_execute_ex () #12 0x00007f2097ec27cb in zend_do_fcall_common_helper_SPEC () #13 0x00007f2097e39e68 in execute_ex () #14 0x00007f2097dfd1a9 in dtrace_execute_ex () #15 0x00007f2097ec27cb in zend_do_fcall_common_helper_SPEC () #16 0x00007f2097e39e68 in execute_ex () #17 0x00007f2097dfd1a9 in dtrace_execute_ex () #18 0x00007f2097dff571 in zend_call_function () #19 0x00007f2097e261a8 in zend_call_method () #20 0x00007f2097d0e3aa in zif_spl_autoload_call () #21 0x00007f2097dfd2cb in dtrace_execute_internal () #22 0x00007f2097dff710 in zend_call_function () #23 0x00007f2097dffe92 in zend_lookup_class_ex () #24 0x00007f2097e005f0 in zend_fetch_class_by_name () #25 0x00007f2097e48362 in ZEND_ADD_TRAIT_SPEC_HANDLER () #26 0x00007f2097e39e68 in execute_ex () #27 0x00007f2097dfd1a9 in dtrace_execute_ex () #28 0x00007f2097ec0980 in ZEND_INCLUDE_OR_EVAL_SPEC_CV_HANDLER () #29 0x00007f2097e39e68 in execute_ex () #30 0x00007f2097dfd1a9 in dtrace_execute_ex () #31 0x00007f2097ec27cb in zend_do_fcall_common_helper_SPEC () #32 0x00007f2097e39e68 in execute_ex () #33 0x00007f2097dfd1a9 in dtrace_execute_ex () #34 0x00007f2097ec27cb in zend_do_fcall_common_helper_SPEC () #35 0x00007f2097e39e68 in execute_ex () #36 0x00007f2097dfd1a9 in dtrace_execute_ex () #37 0x00007f2097ec27cb in zend_do_fcall_common_helper_SPEC () #38 0x00007f2097e39e68 in execute_ex () #39 0x00007f2097dfd1a9 in dtrace_execute_ex () #40 0x00007f2097dff571 in zend_call_function () #41 0x00007f2097e261a8 in zend_call_method () #42 0x00007f2097d0e3aa in zif_spl_autoload_call () #43 0x00007f2097dfd2cb in dtrace_execute_internal () #44 0x00007f2097dff710 in zend_call_function () #45 0x00007f2097dffe92 in zend_lookup_class_ex () #46 0x00007f2097e20c48 in zif_get_class_methods () #47 0x00007f2097dfd2cb in dtrace_execute_internal () #48 0x00007f2097ec2160 in zend_do_fcall_common_helper_SPEC () #49 0x00007f2097e39e68 in execute_ex () #50 0x00007f2097dfd1a9 in dtrace_execute_ex () #51 0x00007f2097ec27cb in zend_do_fcall_common_helper_SPEC () #52 0x00007f2097e39e68 in execute_ex () #53 0x00007f2097dfd1a9 in dtrace_execute_ex () #54 0x00007f2097ec27cb in zend_do_fcall_common_helper_SPEC () #55 0x00007f2097e39e68 in execute_ex () #56 0x00007f2097dfd1a9 in dtrace_execute_ex () ---Type <return> to continue, or q <return> to quit--- #57 0x00007f2097ec27cb in zend_do_fcall_common_helper_SPEC () #58 0x00007f2097e39e68 in execute_ex () #59 0x00007f2097dfd1a9 in dtrace_execute_ex () #60 0x00007f2097ec27cb in zend_do_fcall_common_helper_SPEC () #61 0x00007f2097e39e68 in execute_ex () #62 0x00007f2097dfd1a9 in dtrace_execute_ex () #63 0x00007f2097ec27cb in zend_do_fcall_common_helper_SPEC () #64 0x00007f2097e39e68 in execute_ex () #65 0x00007f2097dfd1a9 in dtrace_execute_ex () #66 0x00007f2097ec27cb in zend_do_fcall_common_helper_SPEC () #67 0x00007f2097e39e68 in execute_ex () #68 0x00007f2097dfd1a9 in dtrace_execute_ex () #69 0x00007f2097ec27cb in zend_do_fcall_common_helper_SPEC () #70 0x00007f2097e39e68 in execute_ex () #71 0x00007f2097dfd1a9 in dtrace_execute_ex () #72 0x00007f2097ec27cb in zend_do_fcall_common_helper_SPEC () #73 0x00007f2097e39e68 in execute_ex () #74 0x00007f2097dfd1a9 in dtrace_execute_ex () #75 0x00007f2097ec27cb in zend_do_fcall_common_helper_SPEC () #76 0x00007f2097e39e68 in execute_ex () #77 0x00007f2097dfd1a9 in dtrace_execute_ex () #78 0x00007f2097ec27cb in zend_do_fcall_common_helper_SPEC () #79 0x00007f2097e39e68 in execute_ex () #80 0x00007f2097dfd1a9 in dtrace_execute_ex () #81 0x00007f2097ec27cb in zend_do_fcall_common_helper_SPEC () #82 0x00007f2097e39e68 in execute_ex () #83 0x00007f2097dfd1a9 in dtrace_execute_ex () #84 0x00007f2097ec27cb in zend_do_fcall_common_helper_SPEC () #85 0x00007f2097e39e68 in execute_ex () #86 0x00007f2097dfd1a9 in dtrace_execute_ex () #87 0x00007f2097ec27cb in zend_do_fcall_common_helper_SPEC () #88 0x00007f2097e39e68 in execute_ex () #89 0x00007f2097dfd1a9 in dtrace_execute_ex () #90 0x00007f2097ec27cb in zend_do_fcall_common_helper_SPEC () #91 0x00007f2097e39e68 in execute_ex () #92 0x00007f2097dfd1a9 in dtrace_execute_ex () #93 0x00007f2097e0f45b in zend_execute_scripts () #94 0x00007f2097dacb02 in php_execute_script () #95 0x00007f2097ec4198 in do_cli () #96 0x00007f2097c437ea in main () ------------------------------------------------------------------------ [2016-12-16 21:41:28] nikic@php.net I can repro using the script provided by paulgao <?php file_put_contents(__DIR__ . '/test.tpl', 'AAA<?php $string = "'. str_repeat('A', mt_rand(1, 256 * 1024)) .'"; ?>BBB' . "\r\n"); require_once __DIR__ . '/test.tpl'; together with for ((n=0;n<100;n++)); do sapi/cli/php test.php & done A few of the PHP processes will trigger a SIGBUS. The issue here seems pretty clear. We are mmap()ing the file. While the file is mapped, it is modified, resulting in an effective ftruncate(). Here is what the man page for ftruncate() has to say on the topic: > If the effect of ftruncate() is to decrease the size of a shared memory object or memory mapped > file and whole pages beyond the new end were previously mapped, then the whole pages beyond the new > end shall be discarded. > > If the Memory Protection option is supported, references to discarded pages shall result in the > generation of a SIGBUS signal; otherwise, the result of such references is undefined. This is precisely what we are observing here. I don't think there is any good way of fixing this short of dropping the mmap() and reading the file into memory instead (which we already do in the fallback code). ------------------------------------------------------------------------ [2016-02-24 11:10:53] bwoebi@php.net This had been marked as duplicate of itself … reopening. ------------------------------------------------------------------------ [2015-12-21 11:39:35] mfractal at gmail dot com I am seeing similar behaviour in PHP 7.0.1 as well : [New LWP 30950] [Thread debugging using libthread_db enabled] Using host libthread_db library "/lib/x86_64-linux-gnu/libthread_db.so.1". Core was generated by `php-fpm: pool www '. Program terminated with signal SIGBUS, Bus error. #0 0x0000000000746e13 in lex_scan () (gdb) bt #0 0x0000000000746e13 in lex_scan () #1 0x000000000075958b in zendlex () #2 0x000000000073dd5e in zendparse () #3 0x000000000074181b in compile_file () #4 0x00000000007673c2 in dtrace_compile_file () #5 0x00000000005d3b83 in ?? () #6 0x0000000000741a05 in compile_filename () #7 0x00000000007f7c37 in ?? () #8 0x00000000007b205b in execute_ex () #9 0x0000000000767439 in dtrace_execute_ex () #10 0x00000000007eed70 in ?? () #11 0x00000000007b205b in execute_ex () #12 0x0000000000767439 in dtrace_execute_ex () #13 0x00000000007eed70 in ?? () #14 0x00000000007b205b in execute_ex () #15 0x0000000000767439 in dtrace_execute_ex () #16 0x00000000007eed70 in ?? () #17 0x00000000007b205b in execute_ex () #18 0x0000000000767439 in dtrace_execute_ex () #19 0x0000000000768d2c in zend_call_function () #20 0x0000000000792124 in zend_call_method () #21 0x00000000007ac0d2 in ?? () #22 0x00000000007b2292 in ?? () #23 0x00000000007b205b in execute_ex () ---Type <return> to continue, or q <return> to quit--- #24 0x0000000000767439 in dtrace_execute_ex () #25 0x0000000000768d2c in zend_call_function () #26 0x0000000000792124 in zend_call_method () #27 0x00000000007aa37c in ?? () #28 0x00000000007ab804 in zend_std_read_property () #29 0x00000000007b52e1 in ?? () #30 0x00000000007b205b in execute_ex () #31 0x0000000000767439 in dtrace_execute_ex () #32 0x00000000007eed70 in ?? () #33 0x00000000007b205b in execute_ex () #34 0x0000000000767439 in dtrace_execute_ex () #35 0x00000000007eed70 in ?? () #36 0x00000000007b205b in execute_ex () #37 0x0000000000767439 in dtrace_execute_ex () #38 0x00000000007eed70 in ?? () #39 0x00000000007b205b in execute_ex () #40 0x0000000000767439 in dtrace_execute_ex () #41 0x00000000007facdf in zend_execute () #42 0x0000000000776a74 in zend_execute_scripts () #43 0x000000000071a9e8 in php_execute_script () #44 0x00000000004789bc in main () ------------------------------------------------------------------------ [2015-05-06 20:16:58] fbastani at perennate dot com I am still encountering this bug with PHP 5.5.9, using php5-fpm without opcache/APC. Backtrace: #0 lex_scan (zendlval=zendlval@entry=0x7fffefa33e58) at Zend/zend_language_scanner.c:2271 #1 0x00000000006d7772 in zendlex (zendlval=zendlval@entry=0x7fffefa33e50) at /build/buildd/php5-5.5.9+dfsg/Zend/zend_compile.c:6749 #2 0x00000000006b2766 in zendparse () at /build/buildd/php5-5.5.9+dfsg/Zend/zend_language_parser.c:3438 #3 0x00000000006b7d18 in compile_file (file_handle=file_handle@entry=0x7fffefa36330, type=8) at Zend/zend_language_scanner.l:588 #4 0x00000000006dd4ea in dtrace_compile_file (file_handle=0x7fffefa36330, type=<optimized out>) at /build/buildd/php5-5.5.9+dfsg/Zend/zend_dtrace.c:40 #5 0x0000000000566674 in phar_compile_file (file_handle=<optimized out>, type=<optimized out>) at /build/buildd/php5-5.5.9+dfsg/ext/phar/phar.c:3379 #6 0x000000000079cb9d in ZEND_INCLUDE_OR_EVAL_SPEC_TMP_HANDLER (execute_data=0x7fc1d68e6688) at /build/buildd/php5-5.5.9+dfsg/Zend/zend_vm_execute.h:7994 #7 0x00000000007173e8 in execute_ex (execute_data=0x7fc1d68e6688) at /build/buildd/php5-5.5.9+dfsg/Zend/zend_vm_execute.h:363 #8 0x00000000006dd559 in dtrace_execute_ex (execute_data=<optimized out>) at /build/buildd/php5-5.5.9+dfsg/Zend/zend_dtrace.c:73 #9 0x000000000079d1bf in ZEND_INCLUDE_OR_EVAL_SPEC_CONST_HANDLER (execute_data=0x7fc1d68e60f8) at /build/buildd/php5-5.5.9+dfsg/Zend/zend_vm_execute.h:2748 #10 0x00000000007173e8 in execute_ex (execute_data=0x7fc1d68e60f8) at /build/buildd/php5-5.5.9+dfsg/Zend/zend_vm_execute.h:363 #11 0x00000000006dd559 in dtrace_execute_ex (execute_data=<optimized out>) at /build/buildd/php5-5.5.9+dfsg/Zend/zend_dtrace.c:73 #12 0x00000000006eefe0 in zend_execute_scripts (type=type@entry=8, retval=retval@entry=0x0, file_count=file_count@entry=3) at /build/buildd/php5-5.5.9+dfsg/Zend/zend.c:1316 #13 0x000000000068eec5 in php_execute_script (primary_file=primary_file@entry=0x7fffefa38ad0) at /build/buildd/php5-5.5.9+dfsg/main/main.c:2506 #14 0x0000000000463b00 in main (argc=<optimized out>, argv=<optimized out>) at /build/buildd/php5-5.5.9+dfsg/sapi/fpm/fpm/fpm_main.c:1933 Line 2271 is this switch statement: YYDEBUG(121, *YYCURSOR); YYFILL(16); yych = *YYCURSOR; YYDEBUG(-1, yych); 2271 switch (yych) { case 0x00: case 0x01: case 0x02: case 0x03: This bug is marked duplicate, but all of the references bugs also appear to be marked duplicate. The error does not happen on every request, but occurs several ten or so times a day on our webserver. The file being compiled is "/var/www/include/include.php", which is included on every request, so there does not appear to be anything special about the requests that are failing (usually it is just a GET request for a static page that's parsed through PHP). ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=52752 -- Edit this bug report at https://bugs.php.net/bug.php?id=52752&edit=1

« previous php.bugs (#209107) next »