Bug #77647 [Opn]: preload: Access violation in zend_mm_shutdown

From: Date: Sat, 23 Mar 2019 10:31:15 +0000
Subject: Bug #77647 [Opn]: preload: Access violation in zend_mm_shutdown
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-220148@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=77647&edit=1

 ID:                 77647
 Updated by:         nikic@php.net
 Reported by:        mberchtold at gmail dot com
 Summary:            preload: Access violation in zend_mm_shutdown
 Status:             Open
 Type:               Bug
 Package:            opcache
 Operating System:   Windows 10 x64
 PHP Version:        master-Git-2019-02-21 (snap)
 Block user comment: N
 Private report:     N

 New Comment:

Thanks for checking! Unfortunately it's hard to do anything here, as a segfault during memory
manager shutdown just indicates that memory manager data structures were corrupted at some point,
but doesn't really tell us where.

This is the point where I'd usually suggest to set opcache.protect_memory=1, but after checking
the code this functionality is currently implemented using mprotect() only and has no
VirtualProtect() support, so it won't actually do anything on Windows. We should probably add
that to make debugging opcache issues easier on Windows...


Previous Comments:
------------------------------------------------------------------------
[2019-03-23 01:04:58] mberchtold at gmail dot com

The stack trace:
>	VCRUNTIME140.dll!memset_repmovs() Line 67	Unknown
 	php8.dll!00007ffc60cabd45()	Unknown
 	php-cgi.exe!00007ff77d6a1763()	Unknown
 	php-cgi.exe!00007ff77d6a40f8()	Unknown
 	kernel32.dll!BaseThreadInitThunk()	Unknown
 	ntdll.dll!RtlUserThreadStart()	Unknown


But for some reason, the debug symbols (in the debug-pack) aren't matching the binaries.

------------------------------------------------------------------------
[2019-03-23 00:42:55] mberchtold at gmail dot com

Yes, the issue still exists with the latest master build:
Revision: r598175e (March 22 2019, 18:25:00)

------------------------------------------------------------------------
[2019-03-18 10:58:15] nikic@php.net

Just want to check back if this issue still exists. A lot of preloading issues have been fixed since
this bug report, so maybe the issue is already resolved?

------------------------------------------------------------------------
[2019-02-21 19:48:45] mberchtold at gmail dot com

Description:
------------
With preloading (preloading of zend framework 3, others) enabled, visiting certain urls of the
website crashes php-cgi.exe
When preloading is disabled, or when no classes are preloaded it does not crash.

php master: r82d6759

>	php8.dll!zend_mm_shutdown(_zend_mm_heap * heap, int full, int silent) Line 2269	C
 	[Inline Frame] php8.dll!shutdown_memory_manager(int)	C
 	php8.dll!php_module_startup(_sapi_module_struct * sf, _zend_module_entry * additional_modules,
unsigned int num_additional_modules) Line 2405	C
 	php-cgi.exe!php_cgi_startup(_sapi_module_struct * sapi_module) Line 973	C
 	php-cgi.exe!main(int argc, char * * argv) Line 1921	C
 	[Inline Frame] php-cgi.exe!invoke_main() Line 78	C++
 	php-cgi.exe!__scrt_common_main_seh() Line 288	C++
 	kernel32.dll!00007ff81f3b81f4()	Unknown
 	ntdll.dll!00007ff82174a251()	Unknown


zend_mm_shutdown
...

Code:
	/* move all chunks except of the first one into the cache */
	p = heap->main_chunk->next;
	while (p != heap->main_chunk) {
--->		zend_mm_chunk *q = p->next;
   // p is null
   
		p->next = heap->cached_chunks;
		heap->cached_chunks = p;
		p = q;
		heap->chunks_count--;
		heap->cached_chunks_count++;
	}


Locals:
+		heap	0x0000026899200040 {use_custom_heap=0x00000000 storage=0x0000000000000000 <NULL>
size=0x0000000000000000 ...}	_zend_mm_heap *
+		heap->main_chunk	0x0000026899200000 {heap=0x0000026899200040 {use_custom_heap=0x00000000
storage=0x0000000000000000 <NULL> ...} ...}	_zend_mm_chunk *
+		heap->main_chunk->next	0x0000000000000000 <NULL>	_zend_mm_chunk *
+		p	0x0000000000000000 <NULL>	_zend_mm_chunk *

For some reason, heap->main_chunk->next is NULL which looks unexpected (heap corruption?).


Test script:
---------------
I don't have a reproducible case other than that it always crashes when accessing a certain url
on an internal website.

Expected result:
----------------
no crash

Actual result:
--------------
Unhandled exception thrown: read access violation.


------------------------------------------------------------------------



--
Edit this bug report at https://bugs.php.net/bug.php?id=77647&edit=1


Thread (11 messages)

« previous php.bugs (#220148) next »