Bug #75969 [Ver->Csd]: Assertion failure in live range DCE due to block pass misoptimization

From: Date: Fri, 16 Feb 2018 19:31:33 +0000
Subject: Bug #75969 [Ver->Csd]: Assertion failure in live range DCE due to block pass misoptimization
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-213995@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=75969&edit=1 ID: 75969 Updated by: nikic@php.net Reported by: alex at buayacorp dot com Summary: Assertion failure in live range DCE due to block pass misoptimization -Status: Verified +Status: Closed Type: Bug Package: opcache Operating System: Linux (debian) PHP Version: 7.2.2 Block user comment: N Private report: N New Comment: Automatic comment on behalf of nikita.ppv@gmail.com Revision: http://git.php.net/?p=php-src.git;a=commit;h=372bf8a9231a58ef8d1d2f0d9b560167495e215e Log: Fixed bug #75969 Previous Comments: ------------------------------------------------------------------------ [2018-02-16 18:13:08] alex at buayacorp dot com It looks like this commit introduced this problem https://github.com/php/php-src/commit/8e5b139732893d2a5f6ba3ae0a0b2b5cf6dba09f. The test script doesn't seem to cause a segfault in previous revisions. ------------------------------------------------------------------------ [2018-02-16 15:58:41] danack@php.net Yep, that crashes it. ------------------------------------------------------------------------ [2018-02-16 15:45:47] alex at buayacorp dot com Description: ------------ While preparing for a migration of our applications from PHP 7.0 to PHP 7.2, we noticed segmentation faults in our php-fpm processes. The test script below is a simplified example of what we are currently running in different debian based servers. I'm able to consistently reproduce it on a debian stretch vm too. alex@atoq-builder:~/src/php-7.2.2$ uname -a Linux atoq-builder 4.9.0-3-amd64 #1 SMP Debian 4.9.30-2+deb9u5 (2017-09-19) x86_64 GNU/Linux alex@atoq-builder:~/src/php-7.2.2$ sapi/cli/php -v PHP 7.2.2 (cli) (built: Feb 16 2018 15:01:07) ( NTS DEBUG ) Copyright (c) 1997-2018 The PHP Group Zend Engine v3.2.0, Copyright (c) 1998-2018 Zend Technologies alex@atoq-builder:~/src/php-7.2.2$ sapi/cli/php -i | grep conf Configure Command => './configure' '--disable-all' '--enable-opcache' '--enable-debug' Test script: --------------- <?php // This is required for the segfault md5('foo'); class Extended_Class {}; $response = array( 'a' => 'b' ); new Extended_Class( array( 'foo' => $response, 'foo2' => 'bar2' ) ); new Extended_Class( array( 'foo' => $response, 'foo3' => $response, ) ); Expected result: ---------------- No segfault Actual result: -------------- with a PHP cli debug build alex@atoq-builder:~/src/php-7.2.2$ sapi/cli/php -dextension_dir=./modules/ -dzend_extension=opcache.so -dopcache.enable_cli=true segfault.php php: /home/alex/src/php-7.2.2/ext/opcache/Optimizer/dce.c:588: dce_live_ranges: Assertion `op_array->opcodes[def].result_type & ((1<<1)|(1<<2))' failed. Aborted It also fails on standard PHP-FPM and PHP cli (with opcache.enable_cli=true) builds. ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=75969&edit=1

« previous php.bugs (#213995) next »