Bug #77194 [Opn]: php7ts.dll crashing when running embed
| From: | svbussww at 126 dot com | Date: | Tue, 27 Nov 2018 13:41:27 +0000 |
| Subject: | Bug #77194 [Opn]: php7ts.dll crashing when running embed | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-218164@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=77194&edit=1
ID: 77194
User updated by: svbussww at 126 dot com
Reported by: svbussww at 126 dot com
Summary: php7ts.dll crashing when running embed
Status: Open
Type: Bug
Package: Reproducible crash
Operating System: Windows 7
PHP Version: 7.2.12
Block user comment: N
Private report: N
New Comment:
Fix the temporary plan
static void *zend_mm_chunk_alloc_int(size_t size, size_t alignment)
{
void *ptr = zend_mm_mmap(size);
if (ptr == NULL) {
return NULL;
} else if (ZEND_MM_ALIGNED_OFFSET(ptr, alignment) == 0) {
#ifdef MADV_HUGEPAGE
madvise(ptr, size, MADV_HUGEPAGE);
#endif
return ptr;
} else {
size_t offset;
/* chunk has to be aligned */
zend_mm_munmap(ptr, size);
LOOP:;
ptr = zend_mm_mmap(size + alignment - REAL_PAGE_SIZE);
if (ptr == NULL) return NULL;
#ifdef _WIN32
offset = ZEND_MM_ALIGNED_OFFSET(ptr, alignment);
zend_mm_munmap(ptr, size + alignment - REAL_PAGE_SIZE);
ptr = zend_mm_mmap_fixed((void*)((char*)ptr + (alignment - offset)), size);
if(ptr == NULL) goto LOOP;
offset = ZEND_MM_ALIGNED_OFFSET(ptr, alignment);
if (offset != 0) {
zend_mm_munmap(ptr, size);
return NULL;
}
return ptr;
#else
offset = ZEND_MM_ALIGNED_OFFSET(ptr, alignment);
if (offset != 0) {
offset = alignment - offset;
zend_mm_munmap(ptr, offset);
ptr = (char*)ptr + offset;
alignment -= offset;
}
if (alignment > REAL_PAGE_SIZE) {
zend_mm_munmap((char*)ptr + size, alignment - REAL_PAGE_SIZE);
}
# ifdef MADV_HUGEPAGE
madvise(ptr, size, MADV_HUGEPAGE);
# endif
#endif
return ptr;
}
}
Previous Comments:
------------------------------------------------------------------------
[2018-11-27 12:46:17] svbussww at 126 dot com
The bug has been found
file Zend/zend_alloc.c
function zend_mm_chunk_alloc_int
zend_mm_mmap After not aligned
zend_mm_mmap_fixed Call failed is return 0
The cause of the bug
zend_mm_mmap The allocated memory address is released. In the case of multithreading, it may be
preempted by other threads.
This causes the subsequent zend_mm_mmap_fixed function to allocate memory and cause the program to
crash.
Temporary solution
static void *zend_mm_chunk_alloc_int(size_t size, size_t alignment)
{
LOOP:;
void *ptr = zend_mm_mmap(size);
if (ptr == NULL) {
return NULL;
} else if (ZEND_MM_ALIGNED_OFFSET(ptr, alignment) == 0) {
#ifdef MADV_HUGEPAGE
madvise(ptr, size, MADV_HUGEPAGE);
#endif
return ptr;
} else {
size_t offset;
/* chunk has to be aligned */
zend_mm_munmap(ptr, size);
ptr = zend_mm_mmap(size + alignment - REAL_PAGE_SIZE);
#ifdef _WIN32
offset = ZEND_MM_ALIGNED_OFFSET(ptr, alignment);
zend_mm_munmap(ptr, size + alignment - REAL_PAGE_SIZE);
ptr = zend_mm_mmap_fixed((void*)((char*)ptr + (alignment - offset)), size);
if(ptr == NULL) goto LOOP;
offset = ZEND_MM_ALIGNED_OFFSET(ptr, alignment);
if (offset != 0) {
zend_mm_munmap(ptr, size);
return NULL;
}
return ptr;
#else
offset = ZEND_MM_ALIGNED_OFFSET(ptr, alignment);
if (offset != 0) {
offset = alignment - offset;
zend_mm_munmap(ptr, offset);
ptr = (char*)ptr + offset;
alignment -= offset;
}
if (alignment > REAL_PAGE_SIZE) {
zend_mm_munmap((char*)ptr + size, alignment - REAL_PAGE_SIZE);
}
# ifdef MADV_HUGEPAGE
madvise(ptr, size, MADV_HUGEPAGE);
# endif
#endif
return ptr;
}
}
I hope the development team can solve this bug as soon as possible.
------------------------------------------------------------------------
[2018-11-27 12:03:08] svbussww at 126 dot com
Can't initialize heap: [0x000001e7] Attempt to access invalid address.
Tracking source code is generated from zend_alloc.c
in zend_mm_mmap_fixed
VirtualAlloc Error return NULL
------------------------------------------------------------------------
[2018-11-26 22:16:52] svbussww at 126 dot com
The problem persists after using the standard method
Environment is Windows 7 SP1 + VS2017 Enterprise
Test code
DWORD WINAPI ThreadProc(LPVOID lpParameter) {
ts_resource(0);
ts_free_thread();
return 0;
}
int main(){
php_embed_init(0, NULL);
for (;;){
HANDLE Thread = CreateThread(NULL, 0, ThreadProc, NULL, 0, NULL);
if (Thread != NULL) CloseHandle(Thread);
}
php_embed_shutdown();
return 0;
}
Debug
Problem event name: APPCRASH
Application Name: Test.exe
Application version: 0.0.0.0
Application timestamp: 5bfc6f7c
Fault module name: php7ts.dll
Fault module version: 7.2.12.0
Fault module timestamp: 5be3d4fd
Exception code: c0000005
Abnormal offset: 000000000001f648
OS version: 6.1.7601.2.1.0.256.1
Locale ID: 2052
Other information 1:e3c7
Additional information 2:e3c7d0ab13feedaa62f1ab674aea779c
Other information 3: db03
Other information 4: db03925cc4db17c3dff9789e6103f141
Can't initialize heap: [0x000001e7] Attempt to access invalid address.
Exception thrown at 0x000007FEEAD5F648 (in php7ts.dll) (in Test.exe): 0xC0000005: An access
violation occurred while reading location 0x0000000000000000.
Stack
php7ts.dll!_emalloc(unsigned __int64 size) Line 2425
php7ts.dll!cwd_globals_ctor(_virtual_cwd_globals * cwd_g) Line 391
php7ts.dll!allocate_new_resource(_tsrm_tls_entry * * thread_resources_ptr, unsigned long thread_id)
Line 315
php7ts.dll!ts_resource_ex(int id, unsigned long * th_id) Line 395
Test.exe!ThreadProc(void * lpParameter) Line 9
------------------------------------------------------------------------
[2018-11-26 21:21:01] svbussww at 126 dot com
Since my test code is completely from php_embed.c and checked correctly
So in theory, using php7embed.lib should also have this problem.
I will go through the standard usage test, but I still hope that I can pay attention to it.
If the standard method still exists, I will follow up the feedback.
------------------------------------------------------------------------
[2018-11-26 15:39:09] ab@php.net
Thanks for the further info. Please realize, that you're not using the embed SAPI, but are
developing your own. To use embed SAPI, you should link with php7embed.lib and include
sapi/embed/php_embed.h. It is fine to develop a custom SAPI as you do, but in that case no bug
report against the embed SAPI should be filed.
The code you've posted looks OK at first glance. If you indeed were intended to use the embed
SAPI, please check a worky example here https://gist.github.com/paresy/3cbd4c6a469511ac7479aa0e7c42fea7,
linked from bug #74011. Unfortunately I don't come to debug your code in near days, so
can't tell yet whether it uncovers a bug in PHP.
Thanks.
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=77194
--
Edit this bug report at https://bugs.php.net/bug.php?id=77194&edit=1