Bug #76518 [Opn]: segfault when opcache enabled + extensions like apcu/imagick

From: Date: Fri, 22 Jun 2018 17:23:21 +0000
Subject: Bug #76518 [Opn]: segfault when opcache enabled + extensions like apcu/imagick
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-215873@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=76518&edit=1 ID: 76518 Updated by: nikic@php.net Reported by: lists at iezzi dot ch Summary: segfault when opcache enabled + extensions like apcu/imagick Status: Open Type: Bug Package: opcache Operating System: Linux (Debian Stretch) PHP Version: 7.2.7 Block user comment: N Private report: N New Comment: Can you please set opcache.protect_memory=1 and see if this changes the crash location? ce->name should never be NULL, so I'm assuming something is corrupting SHM. Previous Comments: ------------------------------------------------------------------------ [2018-06-22 09:51:44] lists at iezzi dot ch Description: ------------ I am getting the following segfaults in syslog: ``` php-fpm[15221]: [WARNING] [pool web447-php72] child 24117 exited on signal 11 (SIGSEGV - core dumped) after 11.003968 seconds from start ``` This only seems to happen on fpm pools with both enabled OPcache and either one of PECL apcu 5.1.11 (http://pecl.php.net/package/APCu) or imagick 3.4.3 (http://pecl.php.net/package/imagick) extensions. The problem does not seem to be directly related to these extensions. It more looks like #76337 (https://bugs.php.net/bug.php?id=76337) is not fully fixed in PHP 7.2.7. Such segfaults don't occur on latest PHP 7.0 / 7.1, only on PHP 7.2 (all compiled from sources). gdb backtrace: ``` $ gdb /opt/php/php72/sbin/php-fpm /tmp/coredump-php-fpm.24117 GNU gdb (Debian 7.12-6) 7.12.0.20161007-git Copyright (C) 2016 Free Software Foundation, Inc. License GPLv3+: GNU GPL version 3 or later <http://gnu.org/licenses/gpl.html> This is free software: you are free to change and redistribute it. There is NO WARRANTY, to the extent permitted by law. Type "show copying" and "show warranty" for details. This GDB was configured as "x86_64-linux-gnu". Type "show configuration" for configuration details. For bug reporting instructions, please see: <http://www.gnu.org/software/gdb/bugs/>. Find the GDB manual and other documentation resources online at: <http://www.gnu.org/software/gdb/documentation/>. For help, type "help". Type "apropos word" to search for commands related to "word"... Reading symbols from /opt/php/php72/sbin/php-fpm...done. [New LWP 24117] [Thread debugging using libthread_db enabled] Using host libthread_db library "/lib/x86_64-linux-gnu/libthread_db.so.1". Core was generated by `php-fpm: pool web447-php72 '. Program terminated with signal SIGSEGV, Segmentation fault. #0 zend_string_release (s=0x0) at /usr/src/php-7.2.7/Zend/zend_string.h:289 289 if (!ZSTR_IS_INTERNED(s)) { (gdb) bt #0 zend_string_release (s=0x0) at /usr/src/php-7.2.7/Zend/zend_string.h:289 #1 destroy_zend_class (zv=<optimized out>) at /usr/src/php-7.2.7/Zend/zend_opcode.c:334 #2 0x000055af43e9c586 in zend_hash_destroy (ht=0x55af45461160) at /usr/src/php-7.2.7/Zend/zend_hash.c:1245 #3 0x000055af43e8b8f1 in zend_shutdown () at /usr/src/php-7.2.7/Zend/zend.c:911 #4 0x000055af43e2a5fb in php_module_shutdown () at /usr/src/php-7.2.7/main/main.c:2453 #5 0x000055af43a0835e in main (argc=<optimized out>, argv=<optimized out>) at /usr/src/php-7.2.7/sapi/fpm/fpm/fpm_main.c:2020 (gdb) frame 5 #5 0x000055af43a0835e in main (argc=<optimized out>, argv=<optimized out>) at /usr/src/php-7.2.7/sapi/fpm/fpm/fpm_main.c:2020 2020 php_module_shutdown(); (gdb) frame 4 #4 0x000055af43e2a5fb in php_module_shutdown () at /usr/src/php-7.2.7/main/main.c:2453 2453 zend_shutdown(); (gdb) frame 3 #3 0x000055af43e8b8f1 in zend_shutdown () at /usr/src/php-7.2.7/Zend/zend.c:911 911 zend_hash_destroy(GLOBAL_CLASS_TABLE); (gdb) frame 2 #2 0x000055af43e9c586 in zend_hash_destroy (ht=0x55af45461160) at /usr/src/php-7.2.7/Zend/zend_hash.c:1245 1245 ht->pDestructor(&p->val); (gdb) frame 1 #1 destroy_zend_class (zv=<optimized out>) at /usr/src/php-7.2.7/Zend/zend_opcode.c:334 334 zend_string_release(ce->name); ``` ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=76518&edit=1

« previous php.bugs (#215873) next »