Bug #76518 [Opn]: segfault when opcache enabled + extensions like apcu/imagick
| From: | nikic@php.net | Date: | Fri, 22 Jun 2018 17:23:21 +0000 |
| Subject: | Bug #76518 [Opn]: segfault when opcache enabled + extensions like apcu/imagick | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-215873@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=76518&edit=1
ID: 76518
Updated by: nikic@php.net
Reported by: lists at iezzi dot ch
Summary: segfault when opcache enabled + extensions like
apcu/imagick
Status: Open
Type: Bug
Package: opcache
Operating System: Linux (Debian Stretch)
PHP Version: 7.2.7
Block user comment: N
Private report: N
New Comment:
Can you please set opcache.protect_memory=1 and see if this changes the crash location?
ce->name should never be NULL, so I'm assuming something is corrupting SHM.
Previous Comments:
------------------------------------------------------------------------
[2018-06-22 09:51:44] lists at iezzi dot ch
Description:
------------
I am getting the following segfaults in syslog:
```
php-fpm[15221]: [WARNING] [pool web447-php72] child 24117 exited on signal 11 (SIGSEGV - core
dumped) after 11.003968 seconds from start
```
This only seems to happen on fpm pools with both enabled OPcache and either one of PECL apcu 5.1.11
(http://pecl.php.net/package/APCu) or imagick 3.4.3 (http://pecl.php.net/package/imagick)
extensions.
The problem does not seem to be directly related to these extensions. It more looks like #76337
(https://bugs.php.net/bug.php?id=76337) is not fully fixed in PHP 7.2.7.
Such segfaults don't occur on latest PHP 7.0 / 7.1, only on PHP 7.2 (all compiled from
sources).
gdb backtrace:
```
$ gdb /opt/php/php72/sbin/php-fpm /tmp/coredump-php-fpm.24117
GNU gdb (Debian 7.12-6) 7.12.0.20161007-git
Copyright (C) 2016 Free Software Foundation, Inc.
License GPLv3+: GNU GPL version 3 or later <http://gnu.org/licenses/gpl.html>
This is free software: you are free to change and redistribute it.
There is NO WARRANTY, to the extent permitted by law. Type "show copying"
and "show warranty" for details.
This GDB was configured as "x86_64-linux-gnu".
Type "show configuration" for configuration details.
For bug reporting instructions, please see:
<http://www.gnu.org/software/gdb/bugs/>.
Find the GDB manual and other documentation resources online at:
<http://www.gnu.org/software/gdb/documentation/>.
For help, type "help".
Type "apropos word" to search for commands related to "word"...
Reading symbols from /opt/php/php72/sbin/php-fpm...done.
[New LWP 24117]
[Thread debugging using libthread_db enabled]
Using host libthread_db library "/lib/x86_64-linux-gnu/libthread_db.so.1".
Core was generated by `php-fpm: pool web447-php72
'.
Program terminated with signal SIGSEGV, Segmentation fault.
#0 zend_string_release (s=0x0) at /usr/src/php-7.2.7/Zend/zend_string.h:289
289 if (!ZSTR_IS_INTERNED(s)) {
(gdb) bt
#0 zend_string_release (s=0x0) at /usr/src/php-7.2.7/Zend/zend_string.h:289
#1 destroy_zend_class (zv=<optimized out>) at /usr/src/php-7.2.7/Zend/zend_opcode.c:334
#2 0x000055af43e9c586 in zend_hash_destroy (ht=0x55af45461160) at
/usr/src/php-7.2.7/Zend/zend_hash.c:1245
#3 0x000055af43e8b8f1 in zend_shutdown () at /usr/src/php-7.2.7/Zend/zend.c:911
#4 0x000055af43e2a5fb in php_module_shutdown () at /usr/src/php-7.2.7/main/main.c:2453
#5 0x000055af43a0835e in main (argc=<optimized out>, argv=<optimized out>) at
/usr/src/php-7.2.7/sapi/fpm/fpm/fpm_main.c:2020
(gdb) frame 5
#5 0x000055af43a0835e in main (argc=<optimized out>, argv=<optimized out>) at
/usr/src/php-7.2.7/sapi/fpm/fpm/fpm_main.c:2020
2020 php_module_shutdown();
(gdb) frame 4
#4 0x000055af43e2a5fb in php_module_shutdown () at /usr/src/php-7.2.7/main/main.c:2453
2453 zend_shutdown();
(gdb) frame 3
#3 0x000055af43e8b8f1 in zend_shutdown () at /usr/src/php-7.2.7/Zend/zend.c:911
911 zend_hash_destroy(GLOBAL_CLASS_TABLE);
(gdb) frame 2
#2 0x000055af43e9c586 in zend_hash_destroy (ht=0x55af45461160) at
/usr/src/php-7.2.7/Zend/zend_hash.c:1245
1245 ht->pDestructor(&p->val);
(gdb) frame 1
#1 destroy_zend_class (zv=<optimized out>) at /usr/src/php-7.2.7/Zend/zend_opcode.c:334
334 zend_string_release(ce->name);
```
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=76518&edit=1