Bug #76446 [Ana]: zend_variables.c:73: zend_string_destroy: Assertion `!(zval_gc_flags((str)->gc.

From: Date: Tue, 12 Jun 2018 22:27:43 +0000
Subject: Bug #76446 [Ana]: zend_variables.c:73: zend_string_destroy: Assertion `!(zval_gc_flags((str)->gc.
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-215669@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=76446&edit=1 ID: 76446 Updated by: cmb@php.net Reported by: spam2 at rhsoft dot net Summary: zend_variables.c:73: zend_string_destroy: Assertion `!(zval_gc_flags((str)->gc. Status: Analyzed Type: Bug Package: Reproducible crash PHP Version: master-Git-2018-06-11 (Git) Block user comment: N Private report: N New Comment: > "just mark ROPE_END as having side-effects with a FIXME that > this may be improved" don't help anybody […] Please try “disable-ROPE_END-dce.patch”. Previous Comments: ------------------------------------------------------------------------ [2018-06-12 22:27:06] cmb@php.net The following patch has been added/updated: Patch Name: disable-ROPE_END-dce Revision: 1528842426 URL: https://bugs.php.net/patch-display.php?bug=76446&patch=disable-ROPE_END-dce&revision=1528842426 ------------------------------------------------------------------------ [2018-06-12 21:47:39] spam2 at rhsoft dot net whatever optimization it was - it's not worth the trouble - frankly half of my codebase segfaults without the slightest chance to make any workarounds because it segfaults long before any code is executed and so even trigger_error(__FILE__ . ' ' . __LINE__) spread around source files don't help becaus eit never get executed "just mark ROPE_END as having side-effects with a FIXME that this may be improved" don't help anybody - i can't even build a binary because as long as the test-suite crashes the rpmbuild is stopped for good reasons and all my gdb-stuff was with the intermediate binary after the build crashed ------------------------------------------------------------------------ [2018-06-12 21:39:56] cmb@php.net > I think for now we should just mark ROPE_END as having > side-effects with a FIXME that this may be improved. I'd very much appreciate to have *some* fix for this nasty *abort* in 7.3.0alpha2, if possible; otherwise we might hamper further testing of other stuff. Your suggestion seems to be rather innocuous – to my knowledge, it would just mean to move a single line, and to loose a somwehat rare and minor optimization. ------------------------------------------------------------------------ [2018-06-12 20:19:43] nikic@php.net > about the original problem, a simple fix is make ROPE_END as side-affect instrction, however I > am still thinking maybe we should remove the whole ROPE_INIT/ADD/END all-togther We already do that is we can. However, in this case we are not able to prove that the ROPE_ADD will not generate an error (e.g. array to string conversion warning). As such, in this case we can only determine that the ROPE_END is dead, but not the ROPE_ADD. Our options are to either a) just don't DCE ropes, b) only DCE them if they are dead in their entirety, or c) DCE as much dead suffix as we can, but making sure to terminate with ROPE_END+FREE if the rope does not become empty through this. I think for now we should just mark ROPE_END as having side-effects with a FIXME that this may be improved. ------------------------------------------------------------------------ [2018-06-12 13:08:57] spam2 at rhsoft dot net BTW: would it be possible to extend the "zend_variables.c:73: zend_string_destroy: Assertion `!(zval_gc_flags((str)->gc" at least with the path to the script/include and if possible method/function/line strace, gdb, valgrind - no chance to find out where it is triggered and besides the bug i would like to remove the dead code anyways ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=76446 -- Edit this bug report at https://bugs.php.net/bug.php?id=76446&edit=1

« previous php.bugs (#215669) next »