Bug #74632 [NEW]: Segmentation fault on php_request_shutdown

From: Date: Mon, 22 May 2017 14:01:35 +0000
Subject: Bug #74632 [NEW]: Segmentation fault on php_request_shutdown
Groups: php.bugs 
Request: Send a blank email to php-bugs+get-209225@lists.php.net to get a copy of this message
From: adam dot rosadzinski at home dot net dot pl Operating system: Arch Linux, kernel 4.0.6 x86_64 PHP version: 5.6.30 Package: Reproducible crash Bug Type: Bug Bug description:Segmentation fault on php_request_shutdown Description: ------------ PHP version: 5.6.30 Configure line: ./configure --disable-rpath --with-layout=GNU --with-pic --enable-static=no --prefix=/usr --with-pear=/usr/lib/pear --datarootdir=/usr/share --with-config-file-path=/usr/etc --with-config-file-scan-dir=/usr/etc/conf.d I'd like to report possible bug in Zend MM, which causes crash on request shutdown. This issue is easily reproducible if you try to allocate more memory than specified in memory_limit directive. Tested also on Mac OS X 10.12.4 (Sierra) with same result. Test script: --------------- <?php error_reporting(E_ALL); ini_set('display_errors', 0); ini_set('memory_limit', '512M'); for($x=0;$x<100000000;$x++) $array[$x]=$x; ?> Expected result: ---------------- No output on stdout Script exited with code 0 Actual result: -------------- Output on stdout: Segmentation fault Script exited with code 139 Valgrind output: ==28140== Invalid read of size 4 ==28140== at 0xA8C634: zval_delref_p (zend.h:411) ==28140== by 0xA8C634: i_zval_ptr_dtor (zend_execute.h:76) ==28140== by 0xA8C634: _zval_ptr_dtor (zend_execute_API.c:424) ==28140== by 0xAAFB4F: i_zend_hash_bucket_delete (zend_hash.c:182) ==28140== by 0xAAFB4F: zend_hash_bucket_delete (zend_hash.c:192) ==28140== by 0xAAFB4F: zend_hash_graceful_reverse_destroy (zend_hash.c:613) ==28140== by 0xA8CC55: shutdown_executor (zend_execute_API.c:244) ==28140== by 0xA9EE55: zend_deactivate (zend.c:960) ==28140== by 0xA2EB6F: php_request_shutdown (main.c:1899) ==28140== by 0xB5807E: do_cli (php_cli.c:1181) ==28140== by 0x463542: main (php_cli.c:1382) ==28140== Address 0x2a1ec220 is 261,984 bytes inside a block of size 262,144 free'd ==28140== at 0x4C2C14B: free (in /usr/lib/valgrind/vgpreload_memcheck-amd64-linux.so) ==28140== by 0xA71740: zend_mm_del_segment (zend_alloc.c:928) ==28140== by 0xA71740: _zend_mm_free_int (zend_alloc.c:2115) ==28140== by 0xA71740: _efree (zend_alloc.c:2440) ==28140== by 0xAAF7FD: zend_hash_destroy (zend_hash.c:553) ==28140== by 0xA9DD8A: _zval_dtor_func (zend_variables.c:45) ==28140== by 0xA8C67F: _zval_dtor (zend_variables.h:35) ==28140== by 0xA8C67F: i_zval_ptr_dtor (zend_execute.h:79) ==28140== by 0xA8C67F: _zval_ptr_dtor (zend_execute_API.c:424) ==28140== by 0xAAFB4F: i_zend_hash_bucket_delete (zend_hash.c:182) ==28140== by 0xAAFB4F: zend_hash_bucket_delete (zend_hash.c:192) ==28140== by 0xAAFB4F: zend_hash_graceful_reverse_destroy (zend_hash.c:613) ==28140== by 0xA8CC55: shutdown_executor (zend_execute_API.c:244) ==28140== by 0xA9EE55: zend_deactivate (zend.c:960) ==28140== by 0xA2EB6F: php_request_shutdown (main.c:1899) ==28140== by 0xB5807E: do_cli (php_cli.c:1181) ==28140== by 0x463542: main (php_cli.c:1382) ==28140== Block was alloc'd at ==28140== at 0x4C2AF1F: malloc (in /usr/lib/valgrind/vgpreload_memcheck-amd64-linux.so) ==28140== by 0xA6E8FF: _zend_mm_alloc_int (zend_alloc.c:1982) ==28140== by 0xAE7DDA: ZEND_POST_INC_SPEC_CV_HANDLER (zend_vm_execute.h:30867) ==28140== by 0xADFA1D: execute_ex (zend_vm_execute.h:363) ==28140== by 0x167162E6: zend_oe (in /usr/local/php56/modules/ZendGuardLoader.so) ==28140== by 0x164B3BEB: ??? (in /usr/local/php56/modules/ioncube_loader_lin_5.6.so) ==28140== by 0xAA0770: zend_execute_scripts (zend.c:1341) ==28140== by 0xA2FFF2: php_execute_script (main.c:2613) ==28140== by 0xB58D2E: do_cli (php_cli.c:998) ==28140== by 0x463542: main (php_cli.c:1382) ==28140== ==28140== Invalid write of size 4 ==28140== at 0xA8C63C: zval_delref_p (zend.h:411) ==28140== by 0xA8C63C: i_zval_ptr_dtor (zend_execute.h:76) ==28140== by 0xA8C63C: _zval_ptr_dtor (zend_execute_API.c:424) ==28140== by 0xAAFB4F: i_zend_hash_bucket_delete (zend_hash.c:182) ==28140== by 0xAAFB4F: zend_hash_bucket_delete (zend_hash.c:192) ==28140== by 0xAAFB4F: zend_hash_graceful_reverse_destroy (zend_hash.c:613) ==28140== by 0xA8CC55: shutdown_executor (zend_execute_API.c:244) ==28140== by 0xA9EE55: zend_deactivate (zend.c:960) ==28140== by 0xA2EB6F: php_request_shutdown (main.c:1899) ==28140== by 0xB5807E: do_cli (php_cli.c:1181) ==28140== by 0x463542: main (php_cli.c:1382) ==28140== Address 0x2a1ec220 is 261,984 bytes inside a block of size 262,144 free'd ==28140== at 0x4C2C14B: free (in /usr/lib/valgrind/vgpreload_memcheck-amd64-linux.so) ==28140== by 0xA71740: zend_mm_del_segment (zend_alloc.c:928) ==28140== by 0xA71740: _zend_mm_free_int (zend_alloc.c:2115) ==28140== by 0xA71740: _efree (zend_alloc.c:2440) ==28140== by 0xAAF7FD: zend_hash_destroy (zend_hash.c:553) ==28140== by 0xA9DD8A: _zval_dtor_func (zend_variables.c:45) ==28140== by 0xA8C67F: _zval_dtor (zend_variables.h:35) ==28140== by 0xA8C67F: i_zval_ptr_dtor (zend_execute.h:79) ==28140== by 0xA8C67F: _zval_ptr_dtor (zend_execute_API.c:424) ==28140== by 0xAAFB4F: i_zend_hash_bucket_delete (zend_hash.c:182) ==28140== by 0xAAFB4F: zend_hash_bucket_delete (zend_hash.c:192) ==28140== by 0xAAFB4F: zend_hash_graceful_reverse_destroy (zend_hash.c:613) ==28140== by 0xA8CC55: shutdown_executor (zend_execute_API.c:244) ==28140== by 0xA9EE55: zend_deactivate (zend.c:960) ==28140== by 0xA2EB6F: php_request_shutdown (main.c:1899) ==28140== by 0xB5807E: do_cli (php_cli.c:1181) ==28140== by 0x463542: main (php_cli.c:1382) ==28140== Block was alloc'd at ==28140== at 0x4C2AF1F: malloc (in /usr/lib/valgrind/vgpreload_memcheck-amd64-linux.so) ==28140== by 0xA6E8FF: _zend_mm_alloc_int (zend_alloc.c:1982) ==28140== by 0xAE7DDA: ZEND_POST_INC_SPEC_CV_HANDLER (zend_vm_execute.h:30867) ==28140== by 0xADFA1D: execute_ex (zend_vm_execute.h:363) ==28140== by 0x167162E6: zend_oe (in /usr/local/php56/modules/ZendGuardLoader.so) ==28140== by 0x164B3BEB: ??? (in /usr/local/php56/modules/ioncube_loader_lin_5.6.so) ==28140== by 0xAA0770: zend_execute_scripts (zend.c:1341) ==28140== by 0xA2FFF2: php_execute_script (main.c:2613) ==28140== by 0xB58D2E: do_cli (php_cli.c:998) ==28140== by 0x463542: main (php_cli.c:1382) ==28140== ==28140== Invalid read of size 1 ==28140== at 0xA8C665: gc_zval_check_possible_root (zend_gc.h:182) ==28140== by 0xA8C665: i_zval_ptr_dtor (zend_execute.h:86) ==28140== by 0xA8C665: _zval_ptr_dtor (zend_execute_API.c:424) ==28140== by 0xAAFB4F: i_zend_hash_bucket_delete (zend_hash.c:182) ==28140== by 0xAAFB4F: zend_hash_bucket_delete (zend_hash.c:192) ==28140== by 0xAAFB4F: zend_hash_graceful_reverse_destroy (zend_hash.c:613) ==28140== by 0xA8CC55: shutdown_executor (zend_execute_API.c:244) ==28140== by 0xA9EE55: zend_deactivate (zend.c:960) ==28140== by 0xA2EB6F: php_request_shutdown (main.c:1899) ==28140== by 0xB5807E: do_cli (php_cli.c:1181) ==28140== by 0x463542: main (php_cli.c:1382) ==28140== Address 0x2a1ec224 is 261,988 bytes inside a block of size 262,144 free'd ==28140== at 0x4C2C14B: free (in /usr/lib/valgrind/vgpreload_memcheck-amd64-linux.so) ==28140== by 0xA71740: zend_mm_del_segment (zend_alloc.c:928) ==28140== by 0xA71740: _zend_mm_free_int (zend_alloc.c:2115) ==28140== by 0xA71740: _efree (zend_alloc.c:2440) ==28140== by 0xAAF7FD: zend_hash_destroy (zend_hash.c:553) ==28140== by 0xA9DD8A: _zval_dtor_func (zend_variables.c:45) ==28140== by 0xA8C67F: _zval_dtor (zend_variables.h:35) ==28140== by 0xA8C67F: i_zval_ptr_dtor (zend_execute.h:79) ==28140== by 0xA8C67F: _zval_ptr_dtor (zend_execute_API.c:424) ==28140== by 0xAAFB4F: i_zend_hash_bucket_delete (zend_hash.c:182) ==28140== by 0xAAFB4F: zend_hash_bucket_delete (zend_hash.c:192) ==28140== by 0xAAFB4F: zend_hash_graceful_reverse_destroy (zend_hash.c:613) ==28140== by 0xA8CC55: shutdown_executor (zend_execute_API.c:244) ==28140== by 0xA9EE55: zend_deactivate (zend.c:960) ==28140== by 0xA2EB6F: php_request_shutdown (main.c:1899) ==28140== by 0xB5807E: do_cli (php_cli.c:1181) ==28140== by 0x463542: main (php_cli.c:1382) ==28140== Block was alloc'd at ==28140== at 0x4C2AF1F: malloc (in /usr/lib/valgrind/vgpreload_memcheck-amd64-linux.so) ==28140== by 0xA6E8FF: _zend_mm_alloc_int (zend_alloc.c:1982) ==28140== by 0xAE7DDA: ZEND_POST_INC_SPEC_CV_HANDLER (zend_vm_execute.h:30867) ==28140== by 0xADFA1D: execute_ex (zend_vm_execute.h:363) ==28140== by 0x167162E6: zend_oe (in /usr/local/php56/modules/ZendGuardLoader.so) ==28140== by 0x164B3BEB: ??? (in /usr/local/php56/modules/ioncube_loader_lin_5.6.so) ==28140== by 0xAA0770: zend_execute_scripts (zend.c:1341) ==28140== by 0xA2FFF2: php_execute_script (main.c:2613) ==28140== by 0xB58D2E: do_cli (php_cli.c:998) ==28140== by 0x463542: main (php_cli.c:1382) -- Edit bug report at https://bugs.php.net/bug.php?id=74632&edit=1 -- Try a snapshot (PHP 5.4): https://bugs.php.net/fix.php?id=74632&r=trysnapshot54 Try a snapshot (PHP 5.5): https://bugs.php.net/fix.php?id=74632&r=trysnapshot55 Try a snapshot (trunk): https://bugs.php.net/fix.php?id=74632&r=trysnapshottrunk Fixed in SVN: https://bugs.php.net/fix.php?id=74632&r=fixed Fixed in release: https://bugs.php.net/fix.php?id=74632&r=alreadyfixed Need backtrace: https://bugs.php.net/fix.php?id=74632&r=needtrace Need Reproduce Script: https://bugs.php.net/fix.php?id=74632&r=needscript Try newer version: https://bugs.php.net/fix.php?id=74632&r=oldversion Not developer issue: https://bugs.php.net/fix.php?id=74632&r=support Expected behavior: https://bugs.php.net/fix.php?id=74632&r=notwrong Not enough info: https://bugs.php.net/fix.php?id=74632&r=notenoughinfo Submitted twice: https://bugs.php.net/fix.php?id=74632&r=submittedtwice register_globals: https://bugs.php.net/fix.php?id=74632&r=globals PHP 4 support discontinued: https://bugs.php.net/fix.php?id=74632&r=php4 Daylight Savings: https://bugs.php.net/fix.php?id=74632&r=dst IIS Stability: https://bugs.php.net/fix.php?id=74632&r=isapi Install GNU Sed: https://bugs.php.net/fix.php?id=74632&r=gnused Floating point limitations: https://bugs.php.net/fix.php?id=74632&r=float No Zend Extensions: https://bugs.php.net/fix.php?id=74632&r=nozend MySQL Configuration Error: https://bugs.php.net/fix.php?id=74632&r=mysqlcfg

« previous php.bugs (#209225) next »