Bug #74804 [Opn]: Segfault when instantiating object in array

From: Date: Fri, 23 Jun 2017 14:31:46 +0000
Subject: Bug #74804 [Opn]: Segfault when instantiating object in array
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-209650@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=74804&edit=1

 ID:                 74804
 Updated by:         nikic@php.net
 Reported by:        steve dot hall+bugs dot php dot net at rg456 dot co
                     dot uk
 Summary:            Segfault when instantiating object in array
 Status:             Open
 Type:               Bug
 Package:            Reproducible crash
 Operating System:   Alpine 3.4 & Windows 10
 PHP Version:        7.1.6
 Block user comment: N
 Private report:     N

 New Comment:

The last valgrind output looks pretty good. This seems to be some kind of GC issue involving
destructors and nested GCs. From the valgrind output, what seems to be happening:
 1. During the outer GC, while running a destructor and object is created.
 2. During the inner GC that object is freed.
 3. During the outer GC, there is an attempt to free the object again.

Not sure how we could actually end up in that situation though. It might help to find out which
__destruct() method is involved here. (From the trace, the __destruct() might be calling __invoke()
on a closure, though it's not clear if that's a direct call.)


Previous Comments:
------------------------------------------------------------------------
[2017-06-23 13:55:50] steve dot hall+bugs dot php dot net at rg456 dot co dot uk

New valgrind here with "export USE_ZEND_ALLOC=0" and ZEND_DONT_UNLOAD_MODULES=1 and a
couple of Invalid reads/writes:
https://gist.github.com/sh41/2dd25967ec598f4f48bbdf049df2e462#file-valgrind-L7126

I will try to eliminate un-needed extensions with -n and provide another one as soon as I can.

------------------------------------------------------------------------
[2017-06-23 11:20:43] nikic@php.net

It's okay if you don't get a segfault, the important part is whether you get invalid
reads/writes in valgrind. I would suggest to:

 * Try running under php -n and only enable those extensions that are necessary to reproduce this.
In particular running with openssl adds a lot of noise to valgrind output, because openssl
developers have some very peculiar views on reading uninitialized data from memory.
 * Try setting ZEND_DONT_UNLOAD_MODULES=1 to avoid some of the ???s in the output.
 * Try running with USE_ZEND_ALLOC=0 again and see if there are still invalid read/writes, even if
there is no segfault. (Disregard the ones caused by "invalid file descriptor", those
don't seem related.)

------------------------------------------------------------------------
[2017-06-23 10:49:21] steve dot hall+bugs dot php dot net at rg456 dot co dot uk

With 
export USE_ZEND_ALLOC=0
I cannot cause the segfault in valgrind, but as soon as I do
export USE_ZEND_ALLOC=1
The segfault reappears.
New file here: 
https://gist.github.com/sh41/df3d2b8e3695d67ef59653b83e5604d0

------------------------------------------------------------------------
[2017-06-23 10:39:52] steve dot hall+bugs dot php dot net at rg456 dot co dot uk

Apologies, I spoke to soon. The segfault is happening again. I am attempting to capture a new
valgrind without the igbinary extension, but the segfault goes away when I'm running in
valgrind.

------------------------------------------------------------------------
[2017-06-23 10:10:45] steve dot hall+bugs dot php dot net at rg456 dot co dot uk

I may have stumbled over the problem. We had the https://github.com/igbinary/igbinary extension
enabled, but weren't deliberately using anywhere. I have now removed it from the configuration 
and cannot cause the seg fault anymore.

------------------------------------------------------------------------


The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at

    https://bugs.php.net/bug.php?id=74804


--
Edit this bug report at https://bugs.php.net/bug.php?id=74804&edit=1


Thread (13 messages)

« previous php.bugs (#209650) next »