Bug #76339 [Opn]: segfault during shutdown

From: Date: Wed, 16 May 2018 07:43:11 +0000
Subject: Bug #76339 [Opn]: segfault during shutdown
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-215282@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=76339&edit=1 ID: 76339 Updated by: nikic@php.net Reported by: ray dot ward at bigcommerce dot com Summary: segfault during shutdown Status: Open Type: Bug Package: opcache Operating System: Debian 8.10 PHP Version: 7.2.5 Block user comment: N Private report: N New Comment: Can you tell me which version of APCu you are using? The issues you are experiencing are most likely caused by some extension performing incorrect refcounting and it manifesting during GC and shutdown. Unfortunately it doesn't really tell us much about the root cause, which is why a valgrind trace would be useful. When you say it does not reproduce under valgrind, does this refer only to the segfault, or is the valgrind output completely clean (no "invalid read" or similar warnings)? Previous Comments: ------------------------------------------------------------------------ [2018-05-16 05:00:42] ray dot ward at bigcommerce dot com The zbacktrace provided some insights. We have a shutdown function that is interacting with an object that itself calls gc_collect_cycles. (gdb) zbacktrace [0x7f44baa13260] gc_collect_cycles() [internal function] [0x7f44baa131e0] <redacted>\BatchIndexStrategy->flushUpdateQueue() [0x7f44baa13170] <redacted>\BatchIndexStrategy->flushQueues() [0x7f44baa13100] <redacted>\BatchIndexStrategy->cleanup() [0x7f44baa13030] {closure}() <redacted>:1903 [0x7ffc2eabe640] ??? The object queues updates to be sent to a 3rd party system and flushes them in batches when it reaches a preset size. We also invoke the flush on shutdown to push any remaining/pending updates. We use gc_collect_cycles() as an attempt to force GC and free up memory. Is calling gc_collect_cycles() from php code while php itself is shutting down and GC'ing a bad idea and could lead to these sorts of issues? ------------------------------------------------------------------------ [2018-05-16 04:32:03] ray dot ward at bigcommerce dot com Also seeing similar segfaults on the PHP 7.0 boxes we haven't upgraded #0 gc_mark_grey (ref=0x0) at ./Zend/zend_gc.c:521 #1 0x00000000005eabd8 in gc_mark_roots () at ./Zend/zend_gc.c:548 #2 zend_gc_collect_cycles () at ./Zend/zend_gc.c:1025 #3 0x00000000005d73bd in zif_gc_collect_cycles (execute_data=<optimized out>, return_value=0x7f44baa13240) at ./Zend/zend_builtin_functions.c:413 #4 0x0000000000646b1d in ZEND_DO_FCALL_BY_NAME_SPEC_HANDLER () at ./Zend/zend_vm_execute.h:714 #5 0x000000000060205b in execute_ex (ex=<optimized out>) at ./Zend/zend_vm_execute.h:414 #6 0x00000000005b21f5 in zend_call_function (fci=fci@entry=0x7ffc2eabe6e0, fci_cache=0x7f444687b340, fci_cache@entry=0x0) at ./Zend/zend_execute_API.c:867 #7 0x00000000005b2629 in call_user_function_ex (function_table=<optimized out>, object=object@entry=0x0, function_name=<optimized out>, retval_ptr=retval_ptr@entry=0x7ffc2eabe770, param_count=<optimized out>, params=<optimized out>, no_separation=1, symbol_table=0x0) at ./Zend/zend_execute_API.c:675 #8 0x00000000005b265d in call_user_function (function_table=<optimized out>, object=object@entry=0x0, function_name=<optimized out>, retval_ptr=retval_ptr@entry=0x7ffc2eabe770, param_count=<optimized out>, params=<optimized out>) at ./Zend/zend_execute_API.c:657 #9 0x00000000004feaf0 in user_shutdown_function_call (zv=<optimized out>) at ./ext/standard/basic_functions.c:4921 #10 0x00000000005d3a0c in zend_hash_apply (ht=0x7f44baa862a0, apply_func=apply_func@entry=0x4fea10 <user_shutdown_function_call>) at ./Zend/zend_hash.c:1537 #11 0x0000000000501f86 in php_call_shutdown_functions () at ./ext/standard/basic_functions.c:5005 #12 0x000000000055f9e5 in php_request_shutdown (dummy=<optimized out>) at ./main/main.c:1796 #13 0x0000000000444cf3 in main (argc=27158462, argv=0x19e6775) at ./sapi/fpm/fpm/fpm_main.c:1995 ------------------------------------------------------------------------ [2018-05-16 00:06:57] ray dot ward at bigcommerce dot com I wasn't able to reproduce the segfault while using valgrind. opcache config: opcache.enable=1 opcache.enable_cli=0 opcache.memory_consumption=1024M opcache.interned_strings_buffer=64 opcache.max_accelerated_files=40000 opcache.revalidate_path=1 opcache.force_restart_timeout=45 opcache.error_log=/var/log/php/opcache.log opcache.log_verbosity_level=2 extensions: apcu apcu_bc bcmath calendar ctype curl dom exif fileinfo ftp gd gettext gmp iconv imagick imap intl json mbstring mysqli mysqlnd newrelic opcache pdo pdo_mysql phar posix pspell readline realpath_turbo shmop simplexml soap sockets sysvmsg sysvsem sysvshm tokenizer wddx xml xmlreader xmlrpc xmlwriter xsl zip We also had the grpc extension installed previously and found it was contributing to a substantial number of segaults and have since removed that. We are still getting some segfaults but with a slightly different trace: #0 gc_mark_grey (ref=0x0) at ./Zend/zend_gc.c:562 #1 0x0000000000606ce8 in gc_mark_roots () at ./Zend/zend_gc.c:583 #2 zend_gc_collect_cycles () at ./Zend/zend_gc.c:1057 #3 0x0000000000606921 in gc_possible_root (ref=0x0) at ./Zend/zend_gc.c:286 #4 0x00000000005eebfd in gc_check_possible_root (ref=<optimized out>) at ./Zend/zend_gc.h:158 #5 i_zval_ptr_dtor (zval_ptr=0x7fe022eec2c0, zval_ptr=0x7fe022eec2c0) at ./Zend/zend_variables.h:51 #6 zend_array_destroy (ht=0x7fe022ee4968) at ./Zend/zend_hash.c:1304 #7 0x000000000061ba8b in zend_objects_store_free_object_storage (objects=0x0, objects@entry=0xa0e0b8 <executor_globals+824>, fast_shutdown=8 '\b', fast_shutdown@entry=1 '\001') at ./Zend/zend_objects_API.c:105 #8 0x00000000005cb034 in shutdown_executor () at ./Zend/zend_execute_API.c:265 #9 0x00000000005dccbb in zend_deactivate () at ./Zend/zend.c:1036 #10 0x0000000000576e0a in php_request_shutdown (dummy=<optimized out>) at ./main/main.c:1904 #11 0x000000000042dd78 in main (argc=37669494, argv=0x23eca33) at ./sapi/fpm/fpm/fpm_main.c:1994 Common theme seems to be ref=0x0 coming from gc_check_possible_root or i_zval_ptr_dtor, both which are inlined functions which makes it harder to debug. ------------------------------------------------------------------------ [2018-05-14 08:58:03] nikic@php.net Can you please try running PHP under valgrind using "USE_ZEND_ALLOC=0 valgrind php script.php" and post the resulting log? If you you can only reproduce under FPM, it should be possible to run FPM using "USE_ZEND_ALLOC=0 valgrind --trace-children=yes php-fpm". Also, can you provide your opcache configuration (e.g. do you use file cache?) and which extensions you have enabled? ------------------------------------------------------------------------ [2018-05-14 07:28:31] ray dot ward at bigcommerce dot com disabling either of these flags for opcache.optimization_level makes the segfault go away ZEND_OPTIMIZER_PASS_1 (1<<0) /* CSE, STRING construction */ ZEND_OPTIMIZER_PASS_11 (1<<10) /* Merge equal constants */ ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=76339 -- Edit this bug report at https://bugs.php.net/bug.php?id=76339&edit=1

« previous php.bugs (#215282) next »