Bug #77275 [Com]: OPcache optimization problem for ArrayAccess->offsetGet(string)

From: Date: Sun, 16 Dec 2018 11:54:49 +0000
Subject: Bug #77275 [Com]: OPcache optimization problem for ArrayAccess->offsetGet(string)
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-218466@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=77275&edit=1 ID: 77275 Comment by: greenreaper at hotmail dot com Reported by: kentaro at ranvis dot com Summary: OPcache optimization problem for ArrayAccess->offsetGet(string) Status: Closed Type: Bug Package: opcache Operating System: Windows 10 PHP Version: 7.3.0 Block user comment: N Private report: N New Comment: I think we have been running into this problem (or the integer version of it) on a busy custom website (no framework) with FPM and opcache, that was experiencing sudden crashes and termination of all processes (leading to 502 errors). We set in php.ini: opcache.optimization_level=0x7FFFBBFF The second 'B' represents the removal of 0x400, or ZEND_OPTIMIZER_PASS_11 (1<<10) /* Merge equal constants */ So far the issue has not reoccurred. Previous Comments: ------------------------------------------------------------------------ [2018-12-10 12:37:21] nikic@php.net Automatic comment on behalf of nikita.ppv@gmail.com Revision: http://git.php.net/?p=php-src.git;a=commit;h=93aabf1533bd3af673bb59cf283e6599ced3ab9a Log: Fixed bug #77275 ------------------------------------------------------------------------ [2018-12-10 11:33:17] nikic@php.net The problem is that we're merging a Z_EXTRA=0 literal with a Z_EXTRA=undefined literal. This is basically the same as bug #76711, but that one only fixed the case of integer literals, while here it's a string :/ ------------------------------------------------------------------------ [2018-12-10 11:29:35] chris at xenforo dot com We have been looking into this issue in our own code as of last week while trying to ensure PHP compatibility with our application. I can tell you, if it helps, that the issue does not exist in 7.3 RC3, so it was introduced some time after that. ------------------------------------------------------------------------ [2018-12-10 11:12:41] nikic@php.net Can reproduce under valgrind: ==23813== Conditional jump or move depends on uninitialised value(s) ==23813== at 0x91B2F8: ZEND_FETCH_DIM_R_SPEC_CV_CONST_HANDLER (zend_vm_execute.h:39179) ==23813== by 0x93A255: execute_ex (zend_vm_execute.h:59027) ==23813== by 0x93B63D: zend_execute (zend_vm_execute.h:60215) ==23813== by 0x84E2D7: zend_execute_scripts (zend.c:1615) ==23813== by 0x789D5C: php_execute_script (main.c:2641) ==23813== by 0x93E6BA: do_cli (php_cli.c:997) ==23813== by 0x93FB05: main (php_cli.c:1389) ------------------------------------------------------------------------ [2018-12-10 11:06:38] nikic@php.net Can't repro on Ubuntu, though the issue is certainly plausible. At a guess the second literal for the the offset lookup is not being preserved and being overwritten. ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=77275 -- Edit this bug report at https://bugs.php.net/bug.php?id=77275&edit=1

« previous php.bugs (#218466) next »