Bug #76713 [NEW]: Segmentation fault caused by property corruption
| From: | shiranai7 at hotmail dot com | Date: | Mon, 06 Aug 2018 21:20:26 +0000 |
| Subject: | Bug #76713 [NEW]: Segmentation fault caused by property corruption | ||
| Groups: | php.bugs | ||
| Request: | Send a blank email to php-bugs+get-216644@lists.php.net to get a copy of this message | ||
From: shiranai7 at hotmail dot com
Operating system: Linux, Windows
PHP version: 7.3.0beta1
Package: Reproducible crash
Bug Type: Bug
Bug description:Segmentation fault caused by property corruption
Description:
------------
I'm getting a segmentation fault while running PHPUnit tests of one of
my libraries, both on Linux and Windows.
I've traced it to an array_column() call in
./tests/EventEmitterTest.php@642
Dumping $actualListeners reveals that some of the object properties are
corrupted just before the crash occurs. This seems to change randomly
depending on which code is added or commented-out.
Test script:
---------------
Unfortunately, I haven't been able to reproduce this crash in isolation.
I've prepared a ZIP archive with all the necessary PHP files:
(1.75 MB)
https://github.com/kuria/event/raw/segfault-repr/segfault-repr.zip
The following command can be used to run the test:
php ./vendor/phpunit/phpunit/phpunit
Expected result:
----------------
No segfault
Actual result:
--------------
Program received signal SIGSEGV, Segmentation fault.
zend_mm_alloc_small (bin_num=<optimized out>, size=140737287172912,
heap=0x7ffff4000040)
at /home/user/Downloads/php-7.3.0beta1/Zend/zend_alloc.c:1283
1283 heap->free_slot[bin_num] = p->next_free_slot;
(gdb) bt
#0 zend_mm_alloc_small (bin_num=<optimized out>, size=140737287172912,
heap=0x7ffff4000040)
at /home/user/Downloads/php-7.3.0beta1/Zend/zend_alloc.c:1283
#1 zend_mm_realloc_heap (copy_size=140737287172912, use_copy_size=0
'\000', size=<optimized out>,
ptr=0x7ffff3416100, heap=0x7ffff4000040) at
/home/user/Downloads/php-7.3.0beta1/Zend/zend_alloc.c:1598
#2 _erealloc (ptr=ptr@entry=0x7ffff3416100, size=size@entry=72)
at /home/user/Downloads/php-7.3.0beta1/Zend/zend_alloc.c:2523
#3 0x00005555559e1c5f in zend_string_extend (persistent=0,
len=<optimized out>, s=0x7ffff3416100)
at /home/user/Downloads/php-7.3.0beta1/Zend/zend_string.h:205
#4 ZEND_CONCAT_SPEC_TMPVAR_CV_HANDLER ()
at /home/user/Downloads/php-7.3.0beta1/Zend/zend_vm_execute.h:16985
#5 0x00005555559f99e5 in execute_ex (ex=0x7ffff3416100)
at /home/user/Downloads/php-7.3.0beta1/Zend/zend_vm_execute.h:57284
#6 0x0000555555a007de in zend_execute
(op_array=op_array@entry=0x7ffff407d2a0, return_value=0x0,
return_value@entry=0x7ffff41810e0) at
/home/user/Downloads/php-7.3.0beta1/Zend/zend_vm_execute.h:60882
#7 0x0000555555973092 in zend_execute_scripts (type=type@entry=8,
retval=0x7ffff41810e0, retval@entry=0x0,
file_count=-201182608, file_count@entry=3) at
/home/user/Downloads/php-7.3.0beta1/Zend/zend.c:1562
#8 0x0000555555913c40 in php_execute_script
(primary_file=0x7fffffffcdc0)
at /home/user/Downloads/php-7.3.0beta1/main/main.c:2630
#9 0x0000555555a02c7c in do_cli (argc=2, argv=0x555556396fa0)
at /home/user/Downloads/php-7.3.0beta1/sapi/cli/php_cli.c:997
#10 0x000055555565ce9b in main (argc=2, argv=0x555556396fa0)
at /home/user/Downloads/php-7.3.0beta1/sapi/cli/php_cli.c:1390
--
Edit bug report at https://bugs.php.net/bug.php?id=76713&edit=1
--
Try a snapshot (PHP 5.4): https://bugs.php.net/fix.php?id=76713&r=trysnapshot54
Try a snapshot (PHP 5.5): https://bugs.php.net/fix.php?id=76713&r=trysnapshot55
Try a snapshot (trunk): https://bugs.php.net/fix.php?id=76713&r=trysnapshottrunk
Fixed in SVN: https://bugs.php.net/fix.php?id=76713&r=fixed
Fixed in release: https://bugs.php.net/fix.php?id=76713&r=alreadyfixed
Need backtrace: https://bugs.php.net/fix.php?id=76713&r=needtrace
Need Reproduce Script: https://bugs.php.net/fix.php?id=76713&r=needscript
Try newer version: https://bugs.php.net/fix.php?id=76713&r=oldversion
Not developer issue: https://bugs.php.net/fix.php?id=76713&r=support
Expected behavior: https://bugs.php.net/fix.php?id=76713&r=notwrong
Not enough info: https://bugs.php.net/fix.php?id=76713&r=notenoughinfo
Submitted twice: https://bugs.php.net/fix.php?id=76713&r=submittedtwice
register_globals: https://bugs.php.net/fix.php?id=76713&r=globals
PHP 4 support discontinued: https://bugs.php.net/fix.php?id=76713&r=php4
Daylight Savings: https://bugs.php.net/fix.php?id=76713&r=dst
IIS Stability: https://bugs.php.net/fix.php?id=76713&r=isapi
Install GNU Sed: https://bugs.php.net/fix.php?id=76713&r=gnused
Floating point limitations: https://bugs.php.net/fix.php?id=76713&r=float
No Zend Extensions: https://bugs.php.net/fix.php?id=76713&r=nozend
MySQL Configuration Error: https://bugs.php.net/fix.php?id=76713&r=mysqlcfg