Bug #76446 [Com]: zend_variables.c:73: zend_string_destroy: Assertion `!(zval_gc_flags((str)->gc.
| From: | spam2 at rhsoft dot net | Date: | Tue, 12 Jun 2018 06:36:00 +0000 |
| Subject: | Bug #76446 [Com]: zend_variables.c:73: zend_string_destroy: Assertion `!(zval_gc_flags((str)->gc. | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-215636@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=76446&edit=1
ID: 76446
Comment by: spam2 at rhsoft dot net
Reported by: spam2 at rhsoft dot net
Summary: zend_variables.c:73: zend_string_destroy: Assertion
`!(zval_gc_flags((str)->gc.
Status: Analyzed
Type: Bug
Package: Reproducible crash
PHP Version: master-Git-2018-06-11 (Git)
Block user comment: N
Private report: N
New Comment:
sorry, no, way too much stuff on the machine nad i also don't see a way to isolate the affected
code for now but that's something i will try sooner or later (currently at vacation and made
the mistake "hey let's look if our codebase triggers any php-warning with the current
master")
Previous Comments:
------------------------------------------------------------------------
[2018-06-12 04:01:25] laruence@php.net
is that possible that you could grant me a ssh access to your box to debugging it? (vid mail)
that will be much helpful :)
------------------------------------------------------------------------
[2018-06-11 20:46:58] spam2 at rhsoft dot net
https://git.php.net/?p=php-src.git;a=commit;h=e4e334effb9d8b6945e045fa97133f5a65d45ea6
(Remove dead code for ADD_STRING/ADD_CHAR optimization) still don't fix that
* OK: cl_api->navigation_base_internal->test(0.023)
zend_mm_heap corrupted
php: /home/builduser/rpmbuild/BUILD/php-7.3.0/Zend/zend_variables.c:73: zend_string_destroy:
Assertion `!(zval_gc_flags((str)->gc.u.type_info) & (1<<6))' failed.
Program received signal SIGABRT, Aborted.
0x00007ffff68e2660 in raise () from /lib64/libc.so.6
Missing separate debuginfos, use: dnf debuginfo-install bzip2-libs-1.0.6-24.fc27.x86_64
cyrus-sasl-lib-2.1.26-34.fc27.x86_64 expat-2.2.5-1.fc27.x86_64 fontconfig-2.12.6-4.fc27.x86_64
freetype-2.8-8.fc27.x86_64 gd-2.2.5-3.fc27.x86_64 jbigkit-libs-2.1-8.fc27.x86_64
keyutils-libs-1.5.10-3.fc27.x86_64 krb5-libs-1.15.2-9.fc27.x86_64 libX11-1.6.5-4.fc27.x86_64
libXau-1.0.8-9.fc27.x86_64 libXpm-3.5.12-4.fc27.x86_64 libcom_err-1.43.5-2.fc27.x86_64
libcrypt-nss-2.26-28.fc27.x86_64 libcurl-7.55.1-12.fc27.x86_64 libgcc-7.3.1-5.fc27.x86_64
libgomp-7.3.1-5.fc27.x86_64 libicu-57.1-9.fc27.x86_64 libidn2-2.0.5-1.fc27.x86_64
libjpeg-turbo-1.5.3-1.fc27.x86_64 libnghttp2-1.31.1-1.fc27.x86_64 libpng-1.6.31-1.fc27.x86_64
libpsl-0.18.0-3.fc27.x86_64 libselinux-2.7-3.fc27.x86_64 libssh2-1.8.0-5.fc27.x86_64
libstdc++-7.3.1-5.fc27.x86_64 libtidy-5.4.0-3.fc27.x86_64 libtiff-4.0.9-10.fc27.x86_64
libunistring-0.9.10-1.fc27.x86_64 libwebp-1.0.0-1.fc27.x86_64 libxcb-1.12-5.fc27.x86_64
libxml2-2.9.7-1.fc2!
7.x86_64 libzip-1.3.2-1.fc27.x86_64 nspr-4.19.0-1.fc27.x86_64 nss-3.37.3-1.0.fc27.x86_64
nss-softokn-freebl-3.37.3-1.0.fc27.x86_64 nss-util-3.37.3-1.0.fc27.x86_64
openldap-2.4.45-4.fc27.x86_64 openssl-libs-1.1.0h-3.fc27.x86_64 pcre2-10.31-4.fc27.x86_64
systemd-libs-234-11.git5f8984e.fc27.x86_64 xz-libs-5.2.3-4.fc27.x86_64
(gdb) f 4
#4 0x000055555588a52e in zend_string_destroy (str=0x7fffe3d08b18, __zend_filename=0x5555559ce4a8
"/home/builduser/rpmbuild/BUILD/php-7.3.0/Zend/zend_vm_execute.h",
__zend_lineno=12424) at /home/builduser/rpmbuild/BUILD/php-7.3.0/Zend/zend_variables.c:73
73 ZEND_ASSERT(!ZSTR_IS_INTERNED(str));
(gdb) p (char*)str->val
$1 = 0x7fffe3d08b30 "&openmenu="
------------------------------------------------------------------------
[2018-06-11 13:48:58] nikic@php.net
Can't say if it's *the* issue, but at least an issue is this:
<?php
"x{$a}y";
Crashes under opcache. Reason is that the ROPE_END is optimized away as dead code, leading to a FREE
on ROPE_ADD, which is illegal. I think something similar to this would also cause your case.
------------------------------------------------------------------------
[2018-06-11 13:33:15] spam2 at rhsoft dot net
there a 3 codelines in the whole codebase containing "&openmenu=" from the last
gdb-output which are basically "use rope instead of concat"
$openstr = "&openmenu={$local_row['hid']}{$addlang}";
$openstr2 = "&openmenu={$openmenu}{$addlang}";
$open_part = "&openmenu={$sid}{$langadd}";
Program received signal SIGABRT, Aborted.
0x00007ffff68e2660 in raise () from /lib64/libc.so.6
Missing separate debuginfos, use: dnf debuginfo-install bzip2-libs-1.0.6-24.fc27.x86_64
cyrus-sasl-lib-2.1.26-34.fc27.x86_64 expat-2.2.5-1.fc27.x86_64 fontconfig-2.12.6-4.fc27.x86_64
freetype-2.8-8.fc27.x86_64 gd-2.2.5-3.fc27.x86_64 jbigkit-libs-2.1-8.fc27.x86_64
keyutils-libs-1.5.10-3.fc27.x86_64 krb5-libs-1.15.2-9.fc27.x86_64 libX11-1.6.5-4.fc27.x86_64
libXau-1.0.8-9.fc27.x86_64 libXpm-3.5.12-4.fc27.x86_64 libcom_err-1.43.5-2.fc27.x86_64
libcrypt-nss-2.26-28.fc27.x86_64 libcurl-7.55.1-12.fc27.x86_64 libgcc-7.3.1-5.fc27.x86_64
libgomp-7.3.1-5.fc27.x86_64 libicu-57.1-9.fc27.x86_64 libidn2-2.0.5-1.fc27.x86_64
libjpeg-turbo-1.5.3-1.fc27.x86_64 libnghttp2-1.31.1-1.fc27.x86_64 libpng-1.6.31-1.fc27.x86_64
libpsl-0.18.0-3.fc27.x86_64 libselinux-2.7-3.fc27.x86_64 libssh2-1.8.0-5.fc27.x86_64
libstdc++-7.3.1-5.fc27.x86_64 libtidy-5.4.0-3.fc27.x86_64 libtiff-4.0.9-10.fc27.x86_64
libunistring-0.9.10-1.fc27.x86_64 libwebp-1.0.0-1.fc27.x86_64 libxcb-1.12-5.fc27.x86_64
libxml2-2.9.7-1.fc2!
7.x86_64 libzip-1.3.2-1.fc27.x86_64 nspr-4.19.0-1.fc27.x86_64 nss-3.37.3-1.0.fc27.x86_64
nss-softokn-freebl-3.37.3-1.0.fc27.x86_64 nss-util-3.37.3-1.0.fc27.x86_64
openldap-2.4.45-4.fc27.x86_64 openssl-libs-1.1.0h-3.fc27.x86_64 pcre2-10.31-4.fc27.x86_64
systemd-libs-234-11.git5f8984e.fc27.x86_64 xz-libs-5.2.3-4.fc27.x86_64
(gdb) f 4
#4 0x000055555588a52e in zend_string_destroy (str=0x7fffe3d08b18, __zend_filename=0x5555559ce468
"/home/builduser/rpmbuild/BUILD/php-7.3.0/Zend/zend_vm_execute.h",
__zend_lineno=12424) at /home/builduser/rpmbuild/BUILD/php-7.3.0/Zend/zend_variables.c:73
73 ZEND_ASSERT(!ZSTR_IS_INTERNED(str));
(gdb) p (char*)str->val
$1 = 0x7fffe3d08b30 "&openmenu="
------------------------------------------------------------------------
[2018-06-11 13:19:26] nikic@php.net
Thanks for the backtrace. What is happening is that we're trying to destroy an interned string,
which means that at some point we did not mark a zval as !refcounted when storing the string into
it.
However, the backtrace is extremely generic, so it's hard to say where the string came from.
Can you please run "f 4" followed by "p (char*)str->val" when the assertion
occurs? This will print the contents of the string and may help in tracking down where it is coming
from (e.g. class name, method name or similar).
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=76446
--
Edit this bug report at https://bugs.php.net/bug.php?id=76446&edit=1