Bug #77434 [Csd]: php-fpm workers are segfaulting in zend_gc_addref
| From: | nikic@php.net | Date: | Thu, 10 Jan 2019 09:29:31 +0000 |
| Subject: | Bug #77434 [Csd]: php-fpm workers are segfaulting in zend_gc_addref | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-218878@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=77434&edit=1
ID: 77434
Updated by: nikic@php.net
Reported by: bugs dot php dot net at mundpropaganda dot net
Summary: php-fpm workers are segfaulting in zend_gc_addref
Status: Closed
Type: Bug
Package: opcache
Operating System: Archlinux
PHP Version: 7.3Git-2019-01-09 (Git)
Assigned To: nikic
Block user comment: N
Private report: N
New Comment:
Can you please confirm whether this fixes the issue you're seeing? I've fixed *something*
here, but I'm not sure if this is also what was causing the problem, or just an unrelated
problem.
Previous Comments:
------------------------------------------------------------------------
[2019-01-10 09:28:19] nikic@php.net
Automatic comment on behalf of nikita.ppv@gmail.com
Revision: http://git.php.net/?p=php-src.git;a=commit;h=ade702a0d299f0c8967720fb4887cd1447419cd9
Log: Fixed bug #77434
------------------------------------------------------------------------
[2019-01-10 09:10:06] nikic@php.net
Two possible ways to fix: Either we can check recursively for partial arrays when replacing
constants, or we can mark arrays as partial if they contain partial arrays. Not totally sure, but I
think the latter is required for correctness in other cases as well. In particular we assume that
for non-partial arrays a constant lattice value can only lower to overdetermined, while in the case
where it contains a partial array it could lower to another, different constant value.
------------------------------------------------------------------------
[2019-01-10 09:00:30] nikic@php.net
I believe the issue is not in the template, but the code generating the data: https://github.com/vanilla/vanilla/blob/818e6a6dc387dd47a0a9fa78c6899aebf6ba7ecb/plugins/editor/class.editor.plugin.php#L323
For now I have this test case causing memory leaks in opcache:
<?php
function test(int $x) {
$a = ['a' => 0, 'b' => $x];
$b = [];
$b[0] = $a;
$c = $b[0];
}
SCCP value dump:
#5.X4 = null
#6.X4 = partial ["a" => int(0)]
#7.CV1($a) = partial ["a" => int(0)]
#8.CV2($b) = []
#9.CV2($b) = [0 => zval(type=253)]
#10.X4 = partial ["a" => int(0)]
#11.CV3($c) = partial ["a" => int(0)]
And importantly, we end up embedding #9.CV2($b) as a literal -- but of course nothing will be able
to handle the partial array it contains, as this is an SCCP only concept.
------------------------------------------------------------------------
[2019-01-09 14:50:41] bugs dot php dot net at mundpropaganda dot net
I meant the problem goes away when I set "opcache.optimization_level=0" (checked twice ,
sorry again)
------------------------------------------------------------------------
[2019-01-09 14:48:37] bugs dot php dot net at mundpropaganda dot net
Oh, I'm sorryâ¦Â The problem indeed goes away after I set
"opcache.protect_memory=1". I hadn't reloaded php-fpm correctly before.
The backtrace I get with opcache.protect_memory=1 follows:
#0 0x00007f7ddb598d7f in raise () from /usr/lib/libc.so.6
#1 0x00007f7ddb583672 in abort () from /usr/lib/libc.so.6
#2 0x00007f7ddb583548 in __assert_fail_base.cold.0 () from /usr/lib/libc.so.6
#3 0x00007f7ddb591396 in __assert_fail () from /usr/lib/libc.so.6
#4 0x000055a2619614f0 in rc_dtor_func (p=0x7f7ddad66d80) at
/home/krist/tmp/php-7.3.2/Zend/zend_variables.c:64
#5 0x000055a261977277 in i_zval_ptr_dtor (zval_ptr=0x7f7dd20e0060,
__zend_filename=0x55a2621cc210 "/home/krist/tmp/php-7.3.2/Zend/zend_hash.c",
__zend_lineno=1491)
at /home/krist/tmp/php-7.3.2/Zend/zend_variables.h:44
#6 0x000055a26197c072 in zend_array_destroy (ht=0x7f7dd213b480)
at /home/krist/tmp/php-7.3.2/Zend/zend_hash.c:1491
#7 0x000055a261961694 in zend_array_destroy_wrapper (arr=0x7f7dd213b480)
at /home/krist/tmp/php-7.3.2/Zend/zend_variables.c:90
#8 0x000055a26196151f in rc_dtor_func (p=0x7f7dd213b480) at
/home/krist/tmp/php-7.3.2/Zend/zend_variables.c:65
#9 0x000055a261977277 in i_zval_ptr_dtor (zval_ptr=0x7f7ddad6c788,
__zend_filename=0x55a2621cc210 "/home/krist/tmp/php-7.3.2/Zend/zend_hash.c",
__zend_lineno=1487)
at /home/krist/tmp/php-7.3.2/Zend/zend_variables.h:44
#10 0x000055a26197c034 in zend_array_destroy (ht=0x7f7dd213b5a0)
at /home/krist/tmp/php-7.3.2/Zend/zend_hash.c:1487
#11 0x000055a261961694 in zend_array_destroy_wrapper (arr=0x7f7dd213b5a0)
at /home/krist/tmp/php-7.3.2/Zend/zend_variables.c:90
#12 0x000055a26196151f in rc_dtor_func (p=0x7f7dd213b5a0) at
/home/krist/tmp/php-7.3.2/Zend/zend_variables.c:65
#13 0x000055a261977277 in i_zval_ptr_dtor (zval_ptr=0x7f7dd213a620,
__zend_filename=0x55a2621cc210 "/home/krist/tmp/php-7.3.2/Zend/zend_hash.c",
__zend_lineno=1487)
at /home/krist/tmp/php-7.3.2/Zend/zend_variables.h:44
#14 0x000055a26197c034 in zend_array_destroy (ht=0x7f7dd213b540)
at /home/krist/tmp/php-7.3.2/Zend/zend_hash.c:1487
#15 0x000055a261961694 in zend_array_destroy_wrapper (arr=0x7f7dd213b540)
at /home/krist/tmp/php-7.3.2/Zend/zend_variables.c:90
#16 0x000055a26196151f in rc_dtor_func (p=0x7f7dd213b540) at
/home/krist/tmp/php-7.3.2/Zend/zend_variables.c:65
#17 0x000055a261977277 in i_zval_ptr_dtor (zval_ptr=0x7f7dd2131408,
__zend_filename=0x55a2621cc210 "/home/krist/tmp/php-7.3.2/Zend/zend_hash.c",
__zend_lineno=1487)
at /home/krist/tmp/php-7.3.2/Zend/zend_variables.h:44
#18 0x000055a26197c034 in zend_array_destroy (ht=0x7f7dd213b4e0)
at /home/krist/tmp/php-7.3.2/Zend/zend_hash.c:1487
#19 0x000055a261961694 in zend_array_destroy_wrapper (arr=0x7f7dd213b4e0)
at /home/krist/tmp/php-7.3.2/Zend/zend_variables.c:90
#20 0x000055a26196151f in rc_dtor_func (p=0x7f7dd213b4e0) at
/home/krist/tmp/php-7.3.2/Zend/zend_variables.c:65
#21 0x000055a2619b28e1 in i_zval_ptr_dtor (zval_ptr=0x7f7dd2136238,
__zend_filename=0x55a2621d13c0 "/home/krist/tmp/php-7.3.2/Zend/zend_objects.c",
__zend_lineno=55)
at /home/krist/tmp/php-7.3.2/Zend/zend_variables.h:44
#22 0x000055a2619b2bbe in zend_object_std_dtor (object=0x7f7dd21361c0)
at /home/krist/tmp/php-7.3.2/Zend/zend_objects.c:55
#23 0x000055a2619b9b0d in zend_objects_store_free_object_storage (objects=0x55a26237e568
<executor_globals+840>,
fast_shutdown=0 '\000') at /home/krist/tmp/php-7.3.2/Zend/zend_objects_API.c:118
#24 0x000055a26194ba71 in shutdown_executor () at
/home/krist/tmp/php-7.3.2/Zend/zend_execute_API.c:268
#25 0x000055a261963f7d in zend_deactivate () at /home/krist/tmp/php-7.3.2/Zend/zend.c:1104
#26 0x000055a2618ca496 in php_request_shutdown (dummy=0x0) at
/home/krist/tmp/php-7.3.2/main/main.c:1926
#27 0x000055a261a52f3b in main (argc=3, argv=0x7ffdbd24e6e8)
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=77434
--
Edit this bug report at https://bugs.php.net/bug.php?id=77434&edit=1