Bug #77312 [Com]: accel_replace_string_by_process_permanent: Assertion `0' failed

From: Date: Wed, 16 Jan 2019 09:07:08 +0000
Subject: Bug #77312 [Com]: accel_replace_string_by_process_permanent: Assertion `0' failed
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-218979@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=77312&edit=1

 ID:                 77312
 Comment by:         mnikulin at plesk dot com
 Reported by:        sjon at hortensius dot net
 Summary:            accel_replace_string_by_process_permanent: Assertion
                     `0' failed
 Status:             Assigned
 Type:               Bug
 Package:            FPM related
 Operating System:   archlinux
 PHP Version:        7.3.1
 Assigned To:        bukka
 Block user comment: N
 Private report:     N

 New Comment:

The bug can be reproduced by accessing any php file even just

    <?php echo 10; ?>

Certainly, OpCache must be enabled in php.ini

    zend_extension=opcache.so
    opcache.enable=1

It happens during child exit, so simple way to reproduce
is to set short timeout for on-demand manager in a pool .conf file

    pm = ondemand
    pm.process_idle_timeout = 2s
    catch_workers_output = yes
    php_value[error_reporting] = 22519

Unsure which bits of error_reporting should be set.

The pool name in log messages after "child 9958 said into stderr" may be truncated.


Previous Comments:
------------------------------------------------------------------------
[2019-01-15 14:13:31] nikic@php.net

This might do it: https://gist.github.com/nikic/c4c4ac241da02af410ce4f720c31d628

But fpm is really not my area... Maybe bukka could take a look?

------------------------------------------------------------------------
[2019-01-15 13:54:21] nikic@php.net

Okay, so I guess the problem here is that fpm alters the ini entry, but does not restore the old
value. Right now PHP_ADMIN_VALUE ends up calling fpm_php_zend_ini_alter_master which directly
touches ini directives, while it probably should go through the normal zend_alter_ini_entry API,
which will also register it in modified_ini_directives, so that it will be restored after the
request.

------------------------------------------------------------------------
[2019-01-15 13:12:48] sjon at hortensius dot net

Thanks - I found in frame-1 that this is indeed an ini-setting - namely one that is pushed by nginx
to fpm as PHP_ADMIN_VALUE (in our case upload_max_filesize)

------------------------------------------------------------------------
[2019-01-15 13:00:11] nikic@php.net

https://github.com/php/php-src/blob/PHP-7.3.1/ext/opcache/ZendAccelerator.c#L689

Failing to replace value of an ini directive.

In your core dump, can you please "f 2" and "p (char*)entry->key->val" and
"p (char*)entry->value->val"? That should narrow down where this is happening.

------------------------------------------------------------------------
[2019-01-15 12:08:47] sjon at hortensius dot net

Turns out FPM needed process.dumpable=true set as well to actually generate a coredump. Here is the
backtrace after replacing the assert with a segfault:

#0  accel_replace_string_by_process_permanent (str=0x56100556b3c0) at
ext/opcache/ZendAccelerator.c:737
#1  0x00007f2c06511144 in accel_copy_permanent_strings (new_interned_string=0x7f2c06511431
<accel_replace_string_by_process_permanent>) at ext/opcache/ZendAccelerator.c:689
#2  0x00007f2c06511540 in accel_use_permanent_interned_strings () at
ext/opcache/ZendAccelerator.c:765
#3  0x00005610031b7bff in zend_interned_strings_switch_storage (request=0 '\000') at
Zend/zend_string.c:322
#4  0x00005610030e0d1f in php_module_shutdown () at main/main.c:2473
#5  0x0000561003268912 in main (argc=4, argv=0x7ffdd655b968) at sapi/fpm/fpm/fpm_main.c:2004

This happens pretty frequently

------------------------------------------------------------------------


The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at

    https://bugs.php.net/bug.php?id=77312


--
Edit this bug report at https://bugs.php.net/bug.php?id=77312&edit=1


Thread (26 messages)

« previous php.bugs (#218979) next »