Bug #75969 [Ver->Csd]: Assertion failure in live range DCE due to block pass misoptimization
| From: | nikic@php.net | Date: | Fri, 16 Feb 2018 19:31:33 +0000 |
| Subject: | Bug #75969 [Ver->Csd]: Assertion failure in live range DCE due to block pass misoptimization | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-213995@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=75969&edit=1
ID: 75969
Updated by: nikic@php.net
Reported by: alex at buayacorp dot com
Summary: Assertion failure in live range DCE due to block
pass misoptimization
-Status: Verified
+Status: Closed
Type: Bug
Package: opcache
Operating System: Linux (debian)
PHP Version: 7.2.2
Block user comment: N
Private report: N
New Comment:
Automatic comment on behalf of nikita.ppv@gmail.com
Revision: http://git.php.net/?p=php-src.git;a=commit;h=372bf8a9231a58ef8d1d2f0d9b560167495e215e
Log: Fixed bug #75969
Previous Comments:
------------------------------------------------------------------------
[2018-02-16 18:13:08] alex at buayacorp dot com
It looks like this commit introduced this problem https://github.com/php/php-src/commit/8e5b139732893d2a5f6ba3ae0a0b2b5cf6dba09f.
The test script doesn't seem to cause a segfault in previous revisions.
------------------------------------------------------------------------
[2018-02-16 15:58:41] danack@php.net
Yep, that crashes it.
------------------------------------------------------------------------
[2018-02-16 15:45:47] alex at buayacorp dot com
Description:
------------
While preparing for a migration of our applications from PHP 7.0 to PHP 7.2, we noticed segmentation
faults in our php-fpm processes. The test script below is a simplified example of what we are
currently running in different debian based servers. I'm able to consistently reproduce it on a
debian stretch vm too.
alex@atoq-builder:~/src/php-7.2.2$ uname -a
Linux atoq-builder 4.9.0-3-amd64 #1 SMP Debian 4.9.30-2+deb9u5 (2017-09-19) x86_64 GNU/Linux
alex@atoq-builder:~/src/php-7.2.2$ sapi/cli/php -v
PHP 7.2.2 (cli) (built: Feb 16 2018 15:01:07) ( NTS DEBUG )
Copyright (c) 1997-2018 The PHP Group
Zend Engine v3.2.0, Copyright (c) 1998-2018 Zend Technologies
alex@atoq-builder:~/src/php-7.2.2$ sapi/cli/php -i | grep conf
Configure Command => './configure' '--disable-all'
'--enable-opcache' '--enable-debug'
Test script:
---------------
<?php
// This is required for the segfault
md5('foo');
class Extended_Class {};
$response = array(
'a' => 'b'
);
new Extended_Class( array(
'foo' => $response,
'foo2' => 'bar2'
) );
new Extended_Class( array(
'foo' => $response,
'foo3' => $response,
) );
Expected result:
----------------
No segfault
Actual result:
--------------
with a PHP cli debug build
alex@atoq-builder:~/src/php-7.2.2$ sapi/cli/php -dextension_dir=./modules/
-dzend_extension=opcache.so -dopcache.enable_cli=true segfault.php
php: /home/alex/src/php-7.2.2/ext/opcache/Optimizer/dce.c:588: dce_live_ranges: Assertion
`op_array->opcodes[def].result_type & ((1<<1)|(1<<2))' failed.
Aborted
It also fails on standard PHP-FPM and PHP cli (with opcache.enable_cli=true) builds.
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=75969&edit=1