Bug #76446 [Com]: zend_variables.c:73: zend_string_destroy: Assertion `!(zval_gc_flags((str)->gc.
| From: | spam2 at rhsoft dot net | Date: | Tue, 12 Jun 2018 06:59:18 +0000 |
| Subject: | Bug #76446 [Com]: zend_variables.c:73: zend_string_destroy: Assertion `!(zval_gc_flags((str)->gc. | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-215638@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=76446&edit=1
ID: 76446
Comment by: spam2 at rhsoft dot net
Reported by: spam2 at rhsoft dot net
Summary: zend_variables.c:73: zend_string_destroy: Assertion
`!(zval_gc_flags((str)->gc.
Status: Analyzed
Type: Bug
Package: Reproducible crash
PHP Version: master-Git-2018-06-11 (Git)
Block user comment: N
Private report: N
New Comment:
https://access.thelounge.net/harry/bug76446_php.txt
is the affected function which is basically the navigation on the left at https://www.rhsoft.net/
probably you are faster to create a way smaller and database independent reproducer with the
interals of the zendengine in mind, basicly the lines with "&openmenu" seems to be
the trigger for hwatever reson given that i work that way on thousands of other places
Previous Comments:
------------------------------------------------------------------------
[2018-06-12 06:53:52] nikic@php.net
@rhsoft: That commit was just some drive-by cleanup, it wasn't supposed to fix anything :)
I think we should first fix the DCE issue and see if it also resolves your problem. If not
we'll have to debug further...
------------------------------------------------------------------------
[2018-06-12 06:35:57] spam2 at rhsoft dot net
sorry, no, way too much stuff on the machine nad i also don't see a way to isolate the affected
code for now but that's something i will try sooner or later (currently at vacation and made
the mistake "hey let's look if our codebase triggers any php-warning with the current
master")
------------------------------------------------------------------------
[2018-06-12 04:01:25] laruence@php.net
is that possible that you could grant me a ssh access to your box to debugging it? (vid mail)
that will be much helpful :)
------------------------------------------------------------------------
[2018-06-11 20:46:58] spam2 at rhsoft dot net
https://git.php.net/?p=php-src.git;a=commit;h=e4e334effb9d8b6945e045fa97133f5a65d45ea6
(Remove dead code for ADD_STRING/ADD_CHAR optimization) still don't fix that
* OK: cl_api->navigation_base_internal->test(0.023)
zend_mm_heap corrupted
php: /home/builduser/rpmbuild/BUILD/php-7.3.0/Zend/zend_variables.c:73: zend_string_destroy:
Assertion `!(zval_gc_flags((str)->gc.u.type_info) & (1<<6))' failed.
Program received signal SIGABRT, Aborted.
0x00007ffff68e2660 in raise () from /lib64/libc.so.6
Missing separate debuginfos, use: dnf debuginfo-install bzip2-libs-1.0.6-24.fc27.x86_64
cyrus-sasl-lib-2.1.26-34.fc27.x86_64 expat-2.2.5-1.fc27.x86_64 fontconfig-2.12.6-4.fc27.x86_64
freetype-2.8-8.fc27.x86_64 gd-2.2.5-3.fc27.x86_64 jbigkit-libs-2.1-8.fc27.x86_64
keyutils-libs-1.5.10-3.fc27.x86_64 krb5-libs-1.15.2-9.fc27.x86_64 libX11-1.6.5-4.fc27.x86_64
libXau-1.0.8-9.fc27.x86_64 libXpm-3.5.12-4.fc27.x86_64 libcom_err-1.43.5-2.fc27.x86_64
libcrypt-nss-2.26-28.fc27.x86_64 libcurl-7.55.1-12.fc27.x86_64 libgcc-7.3.1-5.fc27.x86_64
libgomp-7.3.1-5.fc27.x86_64 libicu-57.1-9.fc27.x86_64 libidn2-2.0.5-1.fc27.x86_64
libjpeg-turbo-1.5.3-1.fc27.x86_64 libnghttp2-1.31.1-1.fc27.x86_64 libpng-1.6.31-1.fc27.x86_64
libpsl-0.18.0-3.fc27.x86_64 libselinux-2.7-3.fc27.x86_64 libssh2-1.8.0-5.fc27.x86_64
libstdc++-7.3.1-5.fc27.x86_64 libtidy-5.4.0-3.fc27.x86_64 libtiff-4.0.9-10.fc27.x86_64
libunistring-0.9.10-1.fc27.x86_64 libwebp-1.0.0-1.fc27.x86_64 libxcb-1.12-5.fc27.x86_64
libxml2-2.9.7-1.fc2!
7.x86_64 libzip-1.3.2-1.fc27.x86_64 nspr-4.19.0-1.fc27.x86_64 nss-3.37.3-1.0.fc27.x86_64
nss-softokn-freebl-3.37.3-1.0.fc27.x86_64 nss-util-3.37.3-1.0.fc27.x86_64
openldap-2.4.45-4.fc27.x86_64 openssl-libs-1.1.0h-3.fc27.x86_64 pcre2-10.31-4.fc27.x86_64
systemd-libs-234-11.git5f8984e.fc27.x86_64 xz-libs-5.2.3-4.fc27.x86_64
(gdb) f 4
#4 0x000055555588a52e in zend_string_destroy (str=0x7fffe3d08b18, __zend_filename=0x5555559ce4a8
"/home/builduser/rpmbuild/BUILD/php-7.3.0/Zend/zend_vm_execute.h",
__zend_lineno=12424) at /home/builduser/rpmbuild/BUILD/php-7.3.0/Zend/zend_variables.c:73
73 ZEND_ASSERT(!ZSTR_IS_INTERNED(str));
(gdb) p (char*)str->val
$1 = 0x7fffe3d08b30 "&openmenu="
------------------------------------------------------------------------
[2018-06-11 13:48:58] nikic@php.net
Can't say if it's *the* issue, but at least an issue is this:
<?php
"x{$a}y";
Crashes under opcache. Reason is that the ROPE_END is optimized away as dead code, leading to a FREE
on ROPE_ADD, which is illegal. I think something similar to this would also cause your case.
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=76446
--
Edit this bug report at https://bugs.php.net/bug.php?id=76446&edit=1