Edit report at https://bugs.php.net/bug.php?id=77922&edit=1
ID: 77922
Comment by: enumag at gmail dot com
Reported by: enumag at gmail dot com
Summary: Segmentation fault in PHP 7.3.4 when running phpunit
Status: Open
Type: Bug
Package: Unknown/Other Function
Operating System: Ubuntu
PHP Version: 7.3.4
Block user comment: N
Private report: N
New Comment:
How do we fix it then? Is there anything else I can do to help? This is currently blocking us from
upgrading to PHP 7.3.
Previous Comments:
------------------------------------------------------------------------
[2019-04-24 13:46:08] nikic@php.net
Thanks! The first non-spurious warning is:
==32207== Invalid read of size 4
==32207== at 0x3C7A2E: gc_mark_grey (zend_gc.c:901)
==32207== by 0x3C7A2E: gc_mark_roots (zend_gc.c:960)
==32207== by 0x3C7A2E: zend_gc_collect_cycles (zend_gc.c:1443)
==32207== by 0x3C68B7: gc_possible_root_when_full (zend_gc.c:577)
==32207== by 0x42C233: zend_object_release (zend_objects_API.h:79)
==32207== by 0x42C233: execute_ex (zend_vm_execute.h:55359)
==32207== by 0x42FCB2: zend_execute (zend_vm_execute.h:60881)
==32207== by 0x3A0E21: zend_execute_scripts (zend.c:1568)
==32207== by 0x340E6F: php_execute_script (main.c:2630)
==32207== by 0x43218B: do_cli (php_cli.c:997)
==32207== by 0x1F890A: main (php_cli.c:1389)
==32207== Address 0x1d757ae4 is 4 bytes inside a block of size 40 free'd
==32207== at 0x4C30D3B: free (in /usr/lib/valgrind/vgpreload_memcheck-amd64-linux.so)
==32207== by 0x3CA5F0: zend_string_release (zend_string.h:277)
==32207== by 0x3CA5F0: zend_new_interned_string_request (zend_string.c:232)
==32207== by 0x3827D1: zend_begin_method_decl (zend_compile.c:5817)
==32207== by 0x38F3B5: zend_compile_func_decl (zend_compile.c:6037)
==32207== by 0x38D109: zend_compile_stmt (zend_compile.c:8277)
==32207== by 0x38E326: zend_compile_stmt_list (zend_compile.c:5434)
==32207== by 0x38CFF1: zend_compile_stmt (zend_compile.c:8221)
==32207== by 0x38E681: zend_compile_class_decl (zend_compile.c:6491)
==32207== by 0x38D117: zend_compile_stmt (zend_compile.c:8289)
==32207== by 0x38FED4: zend_compile_top_stmt (zend_compile.c:8195)
==32207== by 0x38FEC0: zend_compile_top_stmt (zend_compile.c:8190)
==32207== by 0x368558: zend_compile (zend_language_scanner.l:602)
==32207== Block was alloc'd at
==32207== at 0x4C2FB0F: malloc (in /usr/lib/valgrind/vgpreload_memcheck-amd64-linux.so)
==32207== by 0x377168: __zend_malloc (zend_alloc.c:2903)
==32207== by 0x398444: zend_string_alloc (zend_string.h:133)
==32207== by 0x398444: zend_string_tolower_ex (zend_operators.c:2677)
==32207== by 0x3827C5: zend_begin_method_decl (zend_compile.c:5816)
==32207== by 0x38F3B5: zend_compile_func_decl (zend_compile.c:6037)
==32207== by 0x38D109: zend_compile_stmt (zend_compile.c:8277)
==32207== by 0x38E326: zend_compile_stmt_list (zend_compile.c:5434)
==32207== by 0x38CFF1: zend_compile_stmt (zend_compile.c:8221)
==32207== by 0x38E681: zend_compile_class_decl (zend_compile.c:6491)
==32207== by 0x38D117: zend_compile_stmt (zend_compile.c:8289)
==32207== by 0x38FED4: zend_compile_top_stmt (zend_compile.c:8195)
==32207== by 0x38FEC0: zend_compile_top_stmt (zend_compile.c:8190)
The warning indicates a use-after-free of https://github.com/php/php-src/blob/191e15309fce3df7839e52b1f488b0be83fa8561/Zend/zend_compile.c#L5816.
That seems rather unlikely, so it's probably hitting that piece of memory by coincidence :/
------------------------------------------------------------------------
[2019-04-24 13:31:11] enumag at gmail dot com
Here you go: https://gist.github.com/enumag/639017e964036e5a5576962ce0934a8b
------------------------------------------------------------------------
[2019-04-23 09:19:47] nikic@php.net
Would it be possible for you to run the test suite under "USE_ZEND_ALLOC=0 valgrind php"
and post the resulting log?
------------------------------------------------------------------------
[2019-04-19 06:34:37] enumag at gmail dot com
Description:
------------
Since we upgraded to PHP 7.3 our phpunit tests crash with segfault. It's not one specific test
though, it only happens when running the whole suite.
I tried to generate the backtrace (https://bugs.php.net/bugs-generating-backtrace.php) and I'm
posting it below. Hopefully I did it correctly but it's the first time I did something like
that. Let me know if it's not enough.
Actual result:
--------------
[Thread debugging using libthread_db enabled]
Using host libthread_db library "/lib/x86_64-linux-gnu/libthread_db.so.1".
PHPUnit 7.5.8 by Sebastian Bergmann and contributors.
............................................................. 61 / 1036 ( 5%)
............................................................. 122 / 1036 ( 11%)
............................................................. 183 / 1036 ( 17%)
............................................................. 244 / 1036 ( 23%)
............................................................. 305 / 1036 ( 29%)
.....
Program received signal SIGSEGV, Segmentation fault.
zend_mm_alloc_small (bin_num=<optimized out>, size=56, heap=0x7ffff3000040) at
./Zend/zend_alloc.c:1289
1289 ./Zend/zend_alloc.c: No such file or directory.
(gdb) bt
#0 zend_mm_alloc_small (bin_num=<optimized out>, size=56, heap=0x7ffff3000040) at
./Zend/zend_alloc.c:1289
#1 zend_mm_alloc_heap (size=56, heap=0x7ffff3000040) at ./Zend/zend_alloc.c:1360
#2 _emalloc (size=size@entry=56) at ./Zend/zend_alloc.c:2500
#3 0x00005555557e4445 in zend_string_alloc (persistent=0, len=28) at ./Zend/zend_string.h:133
#4 zend_string_tolower_ex (str=0x7fffe06bb000, persistent=persistent@entry=0) at
./Zend/zend_operators.c:2677
#5 0x00005555557df85f in zend_lookup_class_ex (name=name@entry=0x7fffe06bb000, key=key@entry=0x0,
use_autoload=use_autoload@entry=1) at ./Zend/zend_execute_API.c:851
#6 0x00005555557ed333 in zend_is_callable_check_class (name=<optimized out>,
scope=0x7ffff30c3428, fcc=fcc@entry=0x7fffffffa2e0, strict_class=strict_class@entry=0x7fffffffa2d8,
error=error@entry=0x0)
at ./Zend/zend_API.c:2957
#7 0x00005555557f3982 in zend_is_callable_impl (error=0x0, fcc=0x7fffffffa2e0,
check_flags=<optimized out>, object=0x0, callable=0x7ffff3025c90) at ./Zend/zend_API.c:3406
#8 zend_is_callable_ex (callable=0x7ffff3025c90, object=0x0, check_flags=<optimized out>,
callable_name=0x0, fcc=<optimized out>, error=0x0) at ./Zend/zend_API.c:3460
#9 0x00005555558793b0 in zend_check_type (is_return_type=<optimized out>, scope=<optimized
out>, default_value=<optimized out>, cache_slot=<optimized out>, ce=<optimized
out>, arg=0x7ffff3000070,
type=<optimized out>) at ./Zend/zend_execute.c:929
#10 zend_verify_arg_type (cache_slot=<optimized out>, default_value=<optimized out>,
arg=<optimized out>, arg_num=<optimized out>, zf=<optimized out>) at
./Zend/zend_execute.c:958
#11 ZEND_RECV_INIT_SPEC_CONST_HANDLER () at ./Zend/zend_vm_execute.h:2251
#12 execute_ex (ex=0x2c04b90) at ./Zend/zend_vm_execute.h:55601
#13 0x000055555587bcb3 in zend_execute (op_array=op_array@entry=0x7ffff30822a0, return_value=0x0,
return_value@entry=0x7ffff30b1d20) at ./Zend/zend_vm_execute.h:60881
#14 0x00005555557ece22 in zend_execute_scripts (type=type@entry=8, retval=0x7ffff30b1d20,
retval@entry=0x0, file_count=-217949136, file_count@entry=3) at ./Zend/zend.c:1568
#15 0x000055555578ce70 in php_execute_script (primary_file=0x7fffffffc9a0) at ./main/main.c:2630
#16 0x000055555587e18c in do_cli (argc=6, argv=0x555555bfa570) at ./sapi/cli/php_cli.c:997
#17 0x000055555564490b in main (argc=6, argv=0x555555bfa570) at ./sapi/cli/php_cli.c:1389
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=77922&edit=1