Bug #76205 [Opn]: PHP-FPM sporadic crash when running Infinitewp

From: Date: Thu, 26 Apr 2018 20:37:43 +0000
Subject: Bug #76205 [Opn]: PHP-FPM sporadic crash when running Infinitewp
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-214912@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=76205&edit=1 ID: 76205 Updated by: nikic@php.net Reported by: post at minhost dot no Summary: PHP-FPM sporadic crash when running Infinitewp Status: Open Type: Bug Package: opcache Operating System: CentOS 7.4 PHP Version: 7.1.16 Block user comment: N Private report: N New Comment: I can reproduce this issue using the following test file: <?php class Foo { public $prop; } class Bar extends Foo {} and then running PHP twice as follows: $ sapi/cli/php -c php.ini -d opcache.file_cache=/tmp/opcache t171.php $ sapi/cli/php -c php.ini -d opcache.file_cache=/tmp/opcache -d opcache.file_cache_only=1 t171.php Yielding: php: /home/nikic/php-src/ext/opcache/zend_file_cache.c:1184: zend_file_cache_unserialize_prop_info: Assertion `((char*)(prop->name) < (char*)script->size)' failed. Aborted (core dumped) The important bit is that we run first with file_cache_only=0 (so interned strings are used) and then with file_cache_only=1 (so they aren't). This isn't quite your situation, but the root cause should be the same. The second bug report also has the assertion failure in the same place, so it's very likely that it's also the same issue. Previous Comments: ------------------------------------------------------------------------ [2018-04-26 20:28:11] post at minhost dot no Thank you for looking into this! All I can say is that we have never yet seen it crash right after a php-fpm reload, so right after opcache is emptied, it does not seem to happen. Also the bactrace on the test server, when the crash happen on test server, opcache memory limit whas all used. However that does not make sence on produtction servers wich never reaches opcache memory limit. If my guess is right, you might be able to trigger the bug of you set opcache memory limit to for example 1 MB (or 0 if that is possible), and visit a WordPress site? But remember you need to have file cache as secondary fallback cache in place. Also, did you look at the bactrace on the similar bug report I created for Drupal?: https://bugs.php.net/bug.php?id=76258 - I was wondering if it seems to be the same bug or a different one? ------------------------------------------------------------------------ [2018-04-26 20:20:31] nikic@php.net The issue here is that the IS_UNSERIALIZED() macro checks for the pointer being either in script->mem or being an accel interned string. This does not account for the third possibility, where the string is in the arena allocated string memory region (when unserializing into non-shm). ------------------------------------------------------------------------ [2018-04-26 19:01:29] nikic@php.net > Please confirm if the commit is added in 7.1.17 or not? The commit is indeed part of the 7.1.17 release. > Also I am hoping someone soon will work on the bugs I reported, wich has bactrace in the > comment above. And also this bug wich could be related: > https://bugs.php.net/bug.php?id=76258 Thanks for providing the backtrace. An assertion failure occurs on line https://github.com/php/php-src/blob/PHP-7.1/ext/opcache/zend_file_cache.c#L1149, with the assertion presumably being https://github.com/php/php-src/blob/PHP-7.1/ext/opcache/zend_file_cache.c#L136. I'll have to think further on the circumstances that could cause this. ------------------------------------------------------------------------ [2018-04-26 17:37:59] post at minhost dot no @nikic@php.net, you said in your comment that this commit https://github.com/php/php-src/commit/b6a41ad5ba2f853d44e6184375968a86c8167f1e "missed the 7.1.16 cut". Now that PHP 7.1.17 is released, I do not find any entry in the changelog regarding opcache: http://www.php.net/ChangeLog-7.php#7.1.17 Please confirm if the commit is added in 7.1.17 or not? Also I am hoping someone soon will work on the bugs I reported, wich has bactrace in the comment above. And also this bug wich could be related: https://bugs.php.net/bug.php?id=76258 ------------------------------------------------------------------------ [2018-04-24 07:17:32] post at minhost dot no Related bug: https://bugs.php.net/bug.php?id=76258 ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=76205 -- Edit this bug report at https://bugs.php.net/bug.php?id=76205&edit=1

« previous php.bugs (#214912) next »