Bug #76711 [Ver]: OPcache enabled triggers false-positive "Illegal string offset"
| From: | nikic@php.net | Date: | Thu, 20 Sep 2018 07:56:10 +0000 |
| Subject: | Bug #76711 [Ver]: OPcache enabled triggers false-positive "Illegal string offset" | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-217148@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=76711&edit=1
ID: 76711
Updated by: nikic@php.net
Reported by: nicolas dot grekas+php at gmail dot com
Summary: OPcache enabled triggers false-positive "Illegal
string offset"
Status: Verified
Type: Bug
Package: opcache
PHP Version: 7.3Git-2018-08-06 (Git)
Block user comment: N
Private report: N
New Comment:
Valgrind says:
==5806== Conditional jump or move depends on uninitialised value(s)
==5806== at 0xA652CA: ZEND_FETCH_DIM_R_INDEX_SPEC_CV_CONST_HANDLER (zend_vm_execute.h:41973)
==5806== by 0xA7D01D: execute_ex (zend_vm_execute.h:59659)
==5806== by 0xA7E0D5: zend_execute (zend_vm_execute.h:60703)
==5806== by 0x9A3D55: zend_execute_scripts (zend.c:1562)
==5806== by 0x90A5A8: php_execute_script (main.c:2636)
==5806== by 0xA80E2A: do_cli (php_cli.c:997)
==5806== by 0xA81FA0: main (php_cli.c:1390)
This is likely a bug in literal compaction. It probably combines two integer literals, one with
Z_EXTRA=0 and one with unspecified Z_EXTRA. The unspecified Z_EXTRA is then used in
FETCH_DIM_R_INDEX.
Previous Comments:
------------------------------------------------------------------------
[2018-09-20 06:47:25] nicolas dot grekas+php at gmail dot com
This issue still exists in 7.3.0RC1, see failures at
https://travis-ci.org/nicolas-grekas/symfony/builds/430883587
------------------------------------------------------------------------
[2018-08-07 07:28:57] laruence@php.net
I can not reproduce this, what I got is:
$ /home/huixinchen/local/php73/bin/php -d opcache.enable_cli=1 -d error_reporting=-1 -d
display_errors=1 ./phpunit src/Symfony/Component/BrowserKit
#!/usr/bin/env php
PHPUnit 6.5.10 by Sebastian Bergmann and contributors.
Testing src/Symfony/Component/BrowserKit
.............................................F................. 63 / 136 ( 46%)
............................................................... 126 / 136 ( 92%)
.......... 136 / 136 (100%)
Time: 691 ms, Memory: 4.00MB
There was 1 failure:
1) Symfony\Component\BrowserKit\Tests\ClientTest::testFollowMetaRefresh with data set #7
('<html><head><noscript><meta h.../html>', 'http://www.example.com/redirected')
Failed asserting that two strings are equal.
--- Expected
+++ Actual
@@ @@
-'http://www.example.com/redirected'
+'http://www.example.com/foo/foobar'
/home/huixinchen/opensource/github/symfony/src/Symfony/Component/BrowserKit/Tests/ClientTest.php:669
/home/huixinchen/opensource/github/symfony/.phpunit/phpunit-6.5/phpunit:5
FAILURES!
Tests: 136, Assertions: 312, Failures: 1.
------------------------------------------------------------------------
[2018-08-06 14:08:38] nicolas dot grekas+php at gmail dot com
Description:
------------
when running the Symfony test suite on PHP 7.3 with opcache.enable_cli=1, some tests fail with
"Illegal string offset '...'" errors, which make no sense:
Example build is:
https://travis-ci.org/nicolas-grekas/symfony/builds/411802579#L2508
The reported line reads as such:
> if (!$uri || '#' == $uri[0] || '?' == $uri[0]) {
See https://github.com/symfony/symfony/blob/master/src/Symfony/Component/BrowserKit/Client.php#L668
It looks like there is a leak from L649 to L668:
https://github.com/symfony/symfony/blob/master/src/Symfony/Component/BrowserKit/Client.php#L649
Test script:
---------------
No better reproducer sorry:
git clone https://github.com/symfony/symfony
cd symfony
composer install
./phpunit install
php -dopcache.enable_cli=1 ./phpunit src/Symfony/Component/BrowserKit
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=76711&edit=1