Bug #74877 [Opn]: Segmentation fault in zend_mm_alloc_small

From: Date: Mon, 24 Jul 2017 08:24:20 +0000
Subject: Bug #74877 [Opn]: Segmentation fault in zend_mm_alloc_small
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-210256@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=74877&edit=1

 ID:                 74877
 User updated by:    mcfedr at gmail dot com
 Reported by:        mcfedr at gmail dot com
 Summary:            Segmentation fault in zend_mm_alloc_small
 Status:             Open
 Type:               Bug
 Package:            Reproducible crash
 Operating System:   linux/macos
 PHP Version:        7.2.0-beta1
 Block user comment: N
 Private report:     N

 New Comment:

Ran with USE_ZEND_ALLOC=0 - Using php 7.2 the crash is more random now, happening in different
places

With valgrind and USE_ZEND_ALLOC=0 doesnt crash, reports lots of 

==440== Conditional jump or move depends on uninitialised value(s)
==440==    at 0x4082CB7: ???
==440==    by 0xEEEB977: ???
==440==    by 0xEEEB977: ???
==440==    by 0xEEEB97B: ???
==440==    by 0xFFEFFCA9F: ???
==440==    by 0x3804FEEF: ??? (mc_malloc_wrappers.c:483)
==440==
==440== Conditional jump or move depends on uninitialised value(s)
==440==    at 0x4082CE8: ???
==440==    by 0x10C0C087: ???
==440==    by 0x10C0C087: ???
==440==    by 0x10C0C0B6: ???
==440==    by 0xFFEFFCA9F: ???
==440==    by 0x27: ???

With valgrind and without USE_ZEND_ALLOC=0

Lots of these:

==431== Conditional jump or move depends on uninitialised value(s)
==431==    at 0x40AD424: ???
==431==    by 0x22E82B7F: ???
==431==    by 0x22E82B7F: ???
==431==    by 0x22E82B8B: ???
==431==    by 0xFFEFFC6DF: ???
==431==    by 0x95015708B26750FF: ???
==431==
==431== Conditional jump or move depends on uninitialised value(s)
==431==    at 0x40AAD5C: ???
==431==    by 0x232FFE27: ???
==431==    by 0x232FFE27: ???
==431==    by 0x232FFE30: ???
==431==    by 0xFFEFFC83F: ???
==431==

Then finishes with the segfault

==431== Invalid read of size 8
==431==    at 0x58AA40: _emalloc (in /usr/local/bin/php)
==431==    by 0x643899: ZEND_CONCAT_SPEC_TMPVAR_CV_HANDLER (in /usr/local/bin/php)
==431==    by 0x659291: execute_ex (in /usr/local/bin/php)
==431==    by 0x5A203B: zend_call_function (in /usr/local/bin/php)
==431==    by 0x45D6A8: reflection_method_invoke (in /usr/local/bin/php)
==431==    by 0x65F15A: execute_ex (in /usr/local/bin/php)
==431==    by 0x65F7C3: zend_execute (in /usr/local/bin/php)
==431==    by 0x5B21A2: zend_execute_scripts (in /usr/local/bin/php)
==431==    by 0x54DB27: php_execute_script (in /usr/local/bin/php)
==431==    by 0x661ABE: do_cli (in /usr/local/bin/php)
==431==    by 0x261118: main (in /usr/local/bin/php)
==431==  Address 0x2b1d018000 is not stack'd, malloc'd or (recently) free'd
==431==
==431==
==431== Process terminating with default action of signal 11 (SIGSEGV)
==431==  Access not within mapped region at address 0x2B1D018000
==431==    at 0x58AA40: _emalloc (in /usr/local/bin/php)
==431==    by 0x643899: ZEND_CONCAT_SPEC_TMPVAR_CV_HANDLER (in /usr/local/bin/php)
==431==    by 0x659291: execute_ex (in /usr/local/bin/php)
==431==    by 0x5A203B: zend_call_function (in /usr/local/bin/php)
==431==    by 0x45D6A8: reflection_method_invoke (in /usr/local/bin/php)
==431==    by 0x65F15A: execute_ex (in /usr/local/bin/php)
==431==    by 0x65F7C3: zend_execute (in /usr/local/bin/php)
==431==    by 0x5B21A2: zend_execute_scripts (in /usr/local/bin/php)
==431==    by 0x54DB27: php_execute_script (in /usr/local/bin/php)
==431==    by 0x661ABE: do_cli (in /usr/local/bin/php)
==431==    by 0x261118: main (in /usr/local/bin/php)
==431==  If you believe this happened as a result of a stack
==431==  overflow in your program's main thread (unlikely but
==431==  possible), you can try to increase the size of the
==431==  main thread stack using the --main-stacksize= flag.
==431==  The main thread stack size used in this run was 8388608
==431==
==431== HEAP SUMMARY:
==431==     in use at exit: 26,448,791 bytes in 459,135 blocks
==431==   total heap usage: 4,214,628 allocs, 3,755,493 frees, 730,515,583 bytes allocated
==431==
==431== LEAK SUMMARY:
==431==    definitely lost: 0 bytes in 0 blocks
==431==    indirectly lost: 0 bytes in 0 blocks
==431==      possibly lost: 1,635,452 bytes in 10,610 blocks
==431==    still reachable: 24,813,339 bytes in 448,525 blocks
==431==         suppressed: 0 bytes in 0 blocks
==431== Rerun with --leak-check=full to see details of leaked memory
==431==
==431== For counts of detected and suppressed errors, rerun with: -v
==431== Use --track-origins=yes to see where uninitialised values come from
==431== ERROR SUMMARY: 135 errors from 27 contexts (suppressed: 0 from 0)
Segmentation fault


Previous Comments:
------------------------------------------------------------------------
[2017-07-23 14:19:32] mcfedr at gmail dot com

Still reproduces with 7.2.0-beta1

------------------------------------------------------------------------
[2017-07-18 14:43:37] mcfedr at gmail dot com

Interesting idea that I meant to try, and now have. Exactly the same result. Seg fault in the same
place in the same test.

Clearly and issue with memory management, gc_disable and memory_limit=2G and all is fine

------------------------------------------------------------------------
[2017-07-18 13:32:55] schacht at kaliber5 dot de

Had exatly the same issue. Updating PHPUnit 4.x to 6.x (and dependent packages) solved this for me.

------------------------------------------------------------------------
[2017-07-10 10:44:06] mcfedr at gmail dot com

There were no third party extensions installed. I have tried again, with only pdo_sqlite extension
installed (its required to run the tests) and the result is exactly the same. Crashes on the same
line of php code, the php backtrace is the same

Having disabled all other extensions the c backtrace is slightly different, but the top is the same,
crashes on a access-after-free in zend_mm_alloc_small

New result
----------

Core was generated by `php ./vendor/bin/phpunit'.
Program terminated with signal SIGSEGV, Segmentation fault.
#0  0x0000564c35fdd6ae in zend_mm_alloc_small (heap=0x7f4d7ae00040, size=200, bin_num=14,
__zend_filename=0x564c3662df28 "/usr/src/php/Zend/zend_string.h", __zend_lineno=122,
__zend_orig_filename=0x0, __zend_orig_lineno=0)
    at /usr/src/php/Zend/zend_alloc.c:1261
1261			heap->free_slot[bin_num] = p->next_free_slot;
(gdb) bt
#0  0x0000564c35fdd6ae in zend_mm_alloc_small (heap=0x7f4d7ae00040, size=200, bin_num=14,
__zend_filename=0x564c3662df28 "/usr/src/php/Zend/zend_string.h", __zend_lineno=122,
__zend_orig_filename=0x0, __zend_orig_lineno=0)
    at /usr/src/php/Zend/zend_alloc.c:1261
#1  0x0000564c35fdd950 in zend_mm_alloc_heap (heap=0x7f4d7ae00040, size=200,
__zend_filename=0x564c3662df28 "/usr/src/php/Zend/zend_string.h", __zend_lineno=122,
__zend_orig_filename=0x0, __zend_orig_lineno=0)
    at /usr/src/php/Zend/zend_alloc.c:1332
#2  0x0000564c35fe0397 in _emalloc (size=168, __zend_filename=0x564c3662df28
"/usr/src/php/Zend/zend_string.h", __zend_lineno=122, __zend_orig_filename=0x0,
__zend_orig_lineno=0) at /usr/src/php/Zend/zend_alloc.c:2417
#3  0x0000564c35e7ee0c in zend_string_alloc (len=137, persistent=0) at
/usr/src/php/Zend/zend_string.h:122
#4  0x0000564c35e7ee75 in zend_string_init (str=0x7f4d75384780
"%255B%255BC%255DKidslox%255CDevice%255CProfileBundle%255CEntity%255CWebFilterCategoryGroup%2524count%2540%255BAnnot%255D%255D%255B1%255D\n",
len=137, persistent=0)
    at /usr/src/php/Zend/zend_string.h:158
#5  0x0000564c35e82db1 in zif_fgets (execute_data=0x7f4d7ae1f990, return_value=0x7f4d7ae1f830) at
/usr/src/php/ext/standard/file.c:1018
#6  0x0000564c3607d1ec in ZEND_DO_FCALL_BY_NAME_SPEC_RETVAL_USED_HANDLER () at
/usr/src/php/Zend/zend_vm_execute.h:876
#7  0x0000564c3607bfd2 in execute_ex (ex=0x7f4d7ae18c60) at /usr/src/php/Zend/zend_vm_execute.h:429
#8  0x0000564c35fff80c in zend_call_function (fci=0x7ffcb65fe4d0, fci_cache=0x7ffcb65fe4a0) at
/usr/src/php/Zend/zend_execute_API.c:855
#9  0x0000564c35df1599 in reflection_method_invoke (execute_data=0x7f4d7ae18bf0,
return_value=0x7f4d7ae18880, variadic=0) at /usr/src/php/ext/reflection/php_reflection.c:3331
#10 0x0000564c35df1762 in zim_reflection_method_invokeArgs (execute_data=0x7f4d7ae18bf0,
return_value=0x7f4d7ae18880) at /usr/src/php/ext/reflection/php_reflection.c:3367
#11 0x0000564c3607dc2e in ZEND_DO_FCALL_SPEC_RETVAL_USED_HANDLER () at
/usr/src/php/Zend/zend_vm_execute.h:1097
#12 0x0000564c3607bfd2 in execute_ex (ex=0x7f4d7ae14030) at /usr/src/php/Zend/zend_vm_execute.h:429
#13 0x0000564c3607c0e7 in zend_execute (op_array=0x7f4d7ae7e000, return_value=0x0) at
/usr/src/php/Zend/zend_vm_execute.h:474
#14 0x0000564c36019368 in zend_execute_scripts (type=8, retval=0x0, file_count=3) at
/usr/src/php/Zend/zend.c:1476
#15 0x0000564c35f7dfbb in php_execute_script (primary_file=0x7ffcb6600c20) at
/usr/src/php/main/main.c:2537
#16 0x0000564c36102c03 in do_cli (argc=2, argv=0x564c388bd090) at
/usr/src/php/sapi/cli/php_cli.c:993
#17 0x0000564c36103db8 in main (argc=2, argv=0x564c388bd090) at /usr/src/php/sapi/cli/php_cli.c:1381

------------------------------------------------------------------------
[2017-07-10 10:13:05] laruence@php.net

do you use any third-part extensions?

to me, this backtrace seems like a write-after-free side-affect.


thanks

------------------------------------------------------------------------


The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at

    https://bugs.php.net/bug.php?id=74877


--
Edit this bug report at https://bugs.php.net/bug.php?id=74877&edit=1


Thread (14 messages)

« previous php.bugs (#210256) next »