Bug #74632 [NEW]: Segmentation fault on php_request_shutdown
| From: | adam dot rosadzinski at home dot net dot pl | Date: | Mon, 22 May 2017 14:01:35 +0000 |
| Subject: | Bug #74632 [NEW]: Segmentation fault on php_request_shutdown | ||
| Groups: | php.bugs | ||
| Request: | Send a blank email to php-bugs+get-209225@lists.php.net to get a copy of this message | ||
From: adam dot rosadzinski at home dot net dot pl
Operating system: Arch Linux, kernel 4.0.6 x86_64
PHP version: 5.6.30
Package: Reproducible crash
Bug Type: Bug
Bug description:Segmentation fault on php_request_shutdown
Description:
------------
PHP version: 5.6.30
Configure line: ./configure --disable-rpath --with-layout=GNU --with-pic
--enable-static=no --prefix=/usr --with-pear=/usr/lib/pear
--datarootdir=/usr/share --with-config-file-path=/usr/etc
--with-config-file-scan-dir=/usr/etc/conf.d
I'd like to report possible bug in Zend MM, which causes crash on
request shutdown.
This issue is easily reproducible if you try to allocate more memory
than specified in memory_limit directive.
Tested also on Mac OS X 10.12.4 (Sierra) with same result.
Test script:
---------------
<?php
error_reporting(E_ALL);
ini_set('display_errors', 0);
ini_set('memory_limit', '512M');
for($x=0;$x<100000000;$x++)
$array[$x]=$x;
?>
Expected result:
----------------
No output on stdout
Script exited with code 0
Actual result:
--------------
Output on stdout: Segmentation fault
Script exited with code 139
Valgrind output:
==28140== Invalid read of size 4
==28140== at 0xA8C634: zval_delref_p (zend.h:411)
==28140== by 0xA8C634: i_zval_ptr_dtor (zend_execute.h:76)
==28140== by 0xA8C634: _zval_ptr_dtor (zend_execute_API.c:424)
==28140== by 0xAAFB4F: i_zend_hash_bucket_delete (zend_hash.c:182)
==28140== by 0xAAFB4F: zend_hash_bucket_delete (zend_hash.c:192)
==28140== by 0xAAFB4F: zend_hash_graceful_reverse_destroy
(zend_hash.c:613)
==28140== by 0xA8CC55: shutdown_executor (zend_execute_API.c:244)
==28140== by 0xA9EE55: zend_deactivate (zend.c:960)
==28140== by 0xA2EB6F: php_request_shutdown (main.c:1899)
==28140== by 0xB5807E: do_cli (php_cli.c:1181)
==28140== by 0x463542: main (php_cli.c:1382)
==28140== Address 0x2a1ec220 is 261,984 bytes inside a block of size
262,144 free'd
==28140== at 0x4C2C14B: free (in
/usr/lib/valgrind/vgpreload_memcheck-amd64-linux.so)
==28140== by 0xA71740: zend_mm_del_segment (zend_alloc.c:928)
==28140== by 0xA71740: _zend_mm_free_int (zend_alloc.c:2115)
==28140== by 0xA71740: _efree (zend_alloc.c:2440)
==28140== by 0xAAF7FD: zend_hash_destroy (zend_hash.c:553)
==28140== by 0xA9DD8A: _zval_dtor_func (zend_variables.c:45)
==28140== by 0xA8C67F: _zval_dtor (zend_variables.h:35)
==28140== by 0xA8C67F: i_zval_ptr_dtor (zend_execute.h:79)
==28140== by 0xA8C67F: _zval_ptr_dtor (zend_execute_API.c:424)
==28140== by 0xAAFB4F: i_zend_hash_bucket_delete (zend_hash.c:182)
==28140== by 0xAAFB4F: zend_hash_bucket_delete (zend_hash.c:192)
==28140== by 0xAAFB4F: zend_hash_graceful_reverse_destroy
(zend_hash.c:613)
==28140== by 0xA8CC55: shutdown_executor (zend_execute_API.c:244)
==28140== by 0xA9EE55: zend_deactivate (zend.c:960)
==28140== by 0xA2EB6F: php_request_shutdown (main.c:1899)
==28140== by 0xB5807E: do_cli (php_cli.c:1181)
==28140== by 0x463542: main (php_cli.c:1382)
==28140== Block was alloc'd at
==28140== at 0x4C2AF1F: malloc (in
/usr/lib/valgrind/vgpreload_memcheck-amd64-linux.so)
==28140== by 0xA6E8FF: _zend_mm_alloc_int (zend_alloc.c:1982)
==28140== by 0xAE7DDA: ZEND_POST_INC_SPEC_CV_HANDLER
(zend_vm_execute.h:30867)
==28140== by 0xADFA1D: execute_ex (zend_vm_execute.h:363)
==28140== by 0x167162E6: zend_oe (in
/usr/local/php56/modules/ZendGuardLoader.so)
==28140== by 0x164B3BEB: ??? (in
/usr/local/php56/modules/ioncube_loader_lin_5.6.so)
==28140== by 0xAA0770: zend_execute_scripts (zend.c:1341)
==28140== by 0xA2FFF2: php_execute_script (main.c:2613)
==28140== by 0xB58D2E: do_cli (php_cli.c:998)
==28140== by 0x463542: main (php_cli.c:1382)
==28140==
==28140== Invalid write of size 4
==28140== at 0xA8C63C: zval_delref_p (zend.h:411)
==28140== by 0xA8C63C: i_zval_ptr_dtor (zend_execute.h:76)
==28140== by 0xA8C63C: _zval_ptr_dtor (zend_execute_API.c:424)
==28140== by 0xAAFB4F: i_zend_hash_bucket_delete (zend_hash.c:182)
==28140== by 0xAAFB4F: zend_hash_bucket_delete (zend_hash.c:192)
==28140== by 0xAAFB4F: zend_hash_graceful_reverse_destroy
(zend_hash.c:613)
==28140== by 0xA8CC55: shutdown_executor (zend_execute_API.c:244)
==28140== by 0xA9EE55: zend_deactivate (zend.c:960)
==28140== by 0xA2EB6F: php_request_shutdown (main.c:1899)
==28140== by 0xB5807E: do_cli (php_cli.c:1181)
==28140== by 0x463542: main (php_cli.c:1382)
==28140== Address 0x2a1ec220 is 261,984 bytes inside a block of size
262,144 free'd
==28140== at 0x4C2C14B: free (in
/usr/lib/valgrind/vgpreload_memcheck-amd64-linux.so)
==28140== by 0xA71740: zend_mm_del_segment (zend_alloc.c:928)
==28140== by 0xA71740: _zend_mm_free_int (zend_alloc.c:2115)
==28140== by 0xA71740: _efree (zend_alloc.c:2440)
==28140== by 0xAAF7FD: zend_hash_destroy (zend_hash.c:553)
==28140== by 0xA9DD8A: _zval_dtor_func (zend_variables.c:45)
==28140== by 0xA8C67F: _zval_dtor (zend_variables.h:35)
==28140== by 0xA8C67F: i_zval_ptr_dtor (zend_execute.h:79)
==28140== by 0xA8C67F: _zval_ptr_dtor (zend_execute_API.c:424)
==28140== by 0xAAFB4F: i_zend_hash_bucket_delete (zend_hash.c:182)
==28140== by 0xAAFB4F: zend_hash_bucket_delete (zend_hash.c:192)
==28140== by 0xAAFB4F: zend_hash_graceful_reverse_destroy
(zend_hash.c:613)
==28140== by 0xA8CC55: shutdown_executor (zend_execute_API.c:244)
==28140== by 0xA9EE55: zend_deactivate (zend.c:960)
==28140== by 0xA2EB6F: php_request_shutdown (main.c:1899)
==28140== by 0xB5807E: do_cli (php_cli.c:1181)
==28140== by 0x463542: main (php_cli.c:1382)
==28140== Block was alloc'd at
==28140== at 0x4C2AF1F: malloc (in
/usr/lib/valgrind/vgpreload_memcheck-amd64-linux.so)
==28140== by 0xA6E8FF: _zend_mm_alloc_int (zend_alloc.c:1982)
==28140== by 0xAE7DDA: ZEND_POST_INC_SPEC_CV_HANDLER
(zend_vm_execute.h:30867)
==28140== by 0xADFA1D: execute_ex (zend_vm_execute.h:363)
==28140== by 0x167162E6: zend_oe (in
/usr/local/php56/modules/ZendGuardLoader.so)
==28140== by 0x164B3BEB: ??? (in
/usr/local/php56/modules/ioncube_loader_lin_5.6.so)
==28140== by 0xAA0770: zend_execute_scripts (zend.c:1341)
==28140== by 0xA2FFF2: php_execute_script (main.c:2613)
==28140== by 0xB58D2E: do_cli (php_cli.c:998)
==28140== by 0x463542: main (php_cli.c:1382)
==28140==
==28140== Invalid read of size 1
==28140== at 0xA8C665: gc_zval_check_possible_root (zend_gc.h:182)
==28140== by 0xA8C665: i_zval_ptr_dtor (zend_execute.h:86)
==28140== by 0xA8C665: _zval_ptr_dtor (zend_execute_API.c:424)
==28140== by 0xAAFB4F: i_zend_hash_bucket_delete (zend_hash.c:182)
==28140== by 0xAAFB4F: zend_hash_bucket_delete (zend_hash.c:192)
==28140== by 0xAAFB4F: zend_hash_graceful_reverse_destroy
(zend_hash.c:613)
==28140== by 0xA8CC55: shutdown_executor (zend_execute_API.c:244)
==28140== by 0xA9EE55: zend_deactivate (zend.c:960)
==28140== by 0xA2EB6F: php_request_shutdown (main.c:1899)
==28140== by 0xB5807E: do_cli (php_cli.c:1181)
==28140== by 0x463542: main (php_cli.c:1382)
==28140== Address 0x2a1ec224 is 261,988 bytes inside a block of size
262,144 free'd
==28140== at 0x4C2C14B: free (in
/usr/lib/valgrind/vgpreload_memcheck-amd64-linux.so)
==28140== by 0xA71740: zend_mm_del_segment (zend_alloc.c:928)
==28140== by 0xA71740: _zend_mm_free_int (zend_alloc.c:2115)
==28140== by 0xA71740: _efree (zend_alloc.c:2440)
==28140== by 0xAAF7FD: zend_hash_destroy (zend_hash.c:553)
==28140== by 0xA9DD8A: _zval_dtor_func (zend_variables.c:45)
==28140== by 0xA8C67F: _zval_dtor (zend_variables.h:35)
==28140== by 0xA8C67F: i_zval_ptr_dtor (zend_execute.h:79)
==28140== by 0xA8C67F: _zval_ptr_dtor (zend_execute_API.c:424)
==28140== by 0xAAFB4F: i_zend_hash_bucket_delete (zend_hash.c:182)
==28140== by 0xAAFB4F: zend_hash_bucket_delete (zend_hash.c:192)
==28140== by 0xAAFB4F: zend_hash_graceful_reverse_destroy
(zend_hash.c:613)
==28140== by 0xA8CC55: shutdown_executor (zend_execute_API.c:244)
==28140== by 0xA9EE55: zend_deactivate (zend.c:960)
==28140== by 0xA2EB6F: php_request_shutdown (main.c:1899)
==28140== by 0xB5807E: do_cli (php_cli.c:1181)
==28140== by 0x463542: main (php_cli.c:1382)
==28140== Block was alloc'd at
==28140== at 0x4C2AF1F: malloc (in
/usr/lib/valgrind/vgpreload_memcheck-amd64-linux.so)
==28140== by 0xA6E8FF: _zend_mm_alloc_int (zend_alloc.c:1982)
==28140== by 0xAE7DDA: ZEND_POST_INC_SPEC_CV_HANDLER
(zend_vm_execute.h:30867)
==28140== by 0xADFA1D: execute_ex (zend_vm_execute.h:363)
==28140== by 0x167162E6: zend_oe (in
/usr/local/php56/modules/ZendGuardLoader.so)
==28140== by 0x164B3BEB: ??? (in
/usr/local/php56/modules/ioncube_loader_lin_5.6.so)
==28140== by 0xAA0770: zend_execute_scripts (zend.c:1341)
==28140== by 0xA2FFF2: php_execute_script (main.c:2613)
==28140== by 0xB58D2E: do_cli (php_cli.c:998)
==28140== by 0x463542: main (php_cli.c:1382)
--
Edit bug report at https://bugs.php.net/bug.php?id=74632&edit=1
--
Try a snapshot (PHP 5.4): https://bugs.php.net/fix.php?id=74632&r=trysnapshot54
Try a snapshot (PHP 5.5): https://bugs.php.net/fix.php?id=74632&r=trysnapshot55
Try a snapshot (trunk): https://bugs.php.net/fix.php?id=74632&r=trysnapshottrunk
Fixed in SVN: https://bugs.php.net/fix.php?id=74632&r=fixed
Fixed in release: https://bugs.php.net/fix.php?id=74632&r=alreadyfixed
Need backtrace: https://bugs.php.net/fix.php?id=74632&r=needtrace
Need Reproduce Script: https://bugs.php.net/fix.php?id=74632&r=needscript
Try newer version: https://bugs.php.net/fix.php?id=74632&r=oldversion
Not developer issue: https://bugs.php.net/fix.php?id=74632&r=support
Expected behavior: https://bugs.php.net/fix.php?id=74632&r=notwrong
Not enough info: https://bugs.php.net/fix.php?id=74632&r=notenoughinfo
Submitted twice: https://bugs.php.net/fix.php?id=74632&r=submittedtwice
register_globals: https://bugs.php.net/fix.php?id=74632&r=globals
PHP 4 support discontinued: https://bugs.php.net/fix.php?id=74632&r=php4
Daylight Savings: https://bugs.php.net/fix.php?id=74632&r=dst
IIS Stability: https://bugs.php.net/fix.php?id=74632&r=isapi
Install GNU Sed: https://bugs.php.net/fix.php?id=74632&r=gnused
Floating point limitations: https://bugs.php.net/fix.php?id=74632&r=float
No Zend Extensions: https://bugs.php.net/fix.php?id=74632&r=nozend
MySQL Configuration Error: https://bugs.php.net/fix.php?id=74632&r=mysqlcfg