Bug #77922 [Com]: Segmentation fault in PHP 7.3.4 when running phpunit

From: Date: Sat, 04 May 2019 09:21:39 +0000
Subject: Bug #77922 [Com]: Segmentation fault in PHP 7.3.4 when running phpunit
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-220698@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=77922&edit=1 ID: 77922 Comment by: enumag at gmail dot com Reported by: enumag at gmail dot com Summary: Segmentation fault in PHP 7.3.4 when running phpunit Status: Open Type: Bug Package: Unknown/Other Function Operating System: Ubuntu PHP Version: 7.3.4 Block user comment: N Private report: N New Comment: Note: This bug still exists in PHP 7.3.5. Previous Comments: ------------------------------------------------------------------------ [2019-04-24 18:59:02] enumag at gmail dot com How do we fix it then? Is there anything else I can do to help? This is currently blocking us from upgrading to PHP 7.3. ------------------------------------------------------------------------ [2019-04-24 13:46:08] nikic@php.net Thanks! The first non-spurious warning is: ==32207== Invalid read of size 4 ==32207== at 0x3C7A2E: gc_mark_grey (zend_gc.c:901) ==32207== by 0x3C7A2E: gc_mark_roots (zend_gc.c:960) ==32207== by 0x3C7A2E: zend_gc_collect_cycles (zend_gc.c:1443) ==32207== by 0x3C68B7: gc_possible_root_when_full (zend_gc.c:577) ==32207== by 0x42C233: zend_object_release (zend_objects_API.h:79) ==32207== by 0x42C233: execute_ex (zend_vm_execute.h:55359) ==32207== by 0x42FCB2: zend_execute (zend_vm_execute.h:60881) ==32207== by 0x3A0E21: zend_execute_scripts (zend.c:1568) ==32207== by 0x340E6F: php_execute_script (main.c:2630) ==32207== by 0x43218B: do_cli (php_cli.c:997) ==32207== by 0x1F890A: main (php_cli.c:1389) ==32207== Address 0x1d757ae4 is 4 bytes inside a block of size 40 free'd ==32207== at 0x4C30D3B: free (in /usr/lib/valgrind/vgpreload_memcheck-amd64-linux.so) ==32207== by 0x3CA5F0: zend_string_release (zend_string.h:277) ==32207== by 0x3CA5F0: zend_new_interned_string_request (zend_string.c:232) ==32207== by 0x3827D1: zend_begin_method_decl (zend_compile.c:5817) ==32207== by 0x38F3B5: zend_compile_func_decl (zend_compile.c:6037) ==32207== by 0x38D109: zend_compile_stmt (zend_compile.c:8277) ==32207== by 0x38E326: zend_compile_stmt_list (zend_compile.c:5434) ==32207== by 0x38CFF1: zend_compile_stmt (zend_compile.c:8221) ==32207== by 0x38E681: zend_compile_class_decl (zend_compile.c:6491) ==32207== by 0x38D117: zend_compile_stmt (zend_compile.c:8289) ==32207== by 0x38FED4: zend_compile_top_stmt (zend_compile.c:8195) ==32207== by 0x38FEC0: zend_compile_top_stmt (zend_compile.c:8190) ==32207== by 0x368558: zend_compile (zend_language_scanner.l:602) ==32207== Block was alloc'd at ==32207== at 0x4C2FB0F: malloc (in /usr/lib/valgrind/vgpreload_memcheck-amd64-linux.so) ==32207== by 0x377168: __zend_malloc (zend_alloc.c:2903) ==32207== by 0x398444: zend_string_alloc (zend_string.h:133) ==32207== by 0x398444: zend_string_tolower_ex (zend_operators.c:2677) ==32207== by 0x3827C5: zend_begin_method_decl (zend_compile.c:5816) ==32207== by 0x38F3B5: zend_compile_func_decl (zend_compile.c:6037) ==32207== by 0x38D109: zend_compile_stmt (zend_compile.c:8277) ==32207== by 0x38E326: zend_compile_stmt_list (zend_compile.c:5434) ==32207== by 0x38CFF1: zend_compile_stmt (zend_compile.c:8221) ==32207== by 0x38E681: zend_compile_class_decl (zend_compile.c:6491) ==32207== by 0x38D117: zend_compile_stmt (zend_compile.c:8289) ==32207== by 0x38FED4: zend_compile_top_stmt (zend_compile.c:8195) ==32207== by 0x38FEC0: zend_compile_top_stmt (zend_compile.c:8190) The warning indicates a use-after-free of https://github.com/php/php-src/blob/191e15309fce3df7839e52b1f488b0be83fa8561/Zend/zend_compile.c#L5816. That seems rather unlikely, so it's probably hitting that piece of memory by coincidence :/ ------------------------------------------------------------------------ [2019-04-24 13:31:11] enumag at gmail dot com Here you go: https://gist.github.com/enumag/639017e964036e5a5576962ce0934a8b ------------------------------------------------------------------------ [2019-04-23 09:19:47] nikic@php.net Would it be possible for you to run the test suite under "USE_ZEND_ALLOC=0 valgrind php" and post the resulting log? ------------------------------------------------------------------------ [2019-04-19 06:34:37] enumag at gmail dot com Description: ------------ Since we upgraded to PHP 7.3 our phpunit tests crash with segfault. It's not one specific test though, it only happens when running the whole suite. I tried to generate the backtrace (https://bugs.php.net/bugs-generating-backtrace.php) and I'm posting it below. Hopefully I did it correctly but it's the first time I did something like that. Let me know if it's not enough. Actual result: -------------- [Thread debugging using libthread_db enabled] Using host libthread_db library "/lib/x86_64-linux-gnu/libthread_db.so.1". PHPUnit 7.5.8 by Sebastian Bergmann and contributors. ............................................................. 61 / 1036 ( 5%) ............................................................. 122 / 1036 ( 11%) ............................................................. 183 / 1036 ( 17%) ............................................................. 244 / 1036 ( 23%) ............................................................. 305 / 1036 ( 29%) ..... Program received signal SIGSEGV, Segmentation fault. zend_mm_alloc_small (bin_num=<optimized out>, size=56, heap=0x7ffff3000040) at ./Zend/zend_alloc.c:1289 1289 ./Zend/zend_alloc.c: No such file or directory. (gdb) bt #0 zend_mm_alloc_small (bin_num=<optimized out>, size=56, heap=0x7ffff3000040) at ./Zend/zend_alloc.c:1289 #1 zend_mm_alloc_heap (size=56, heap=0x7ffff3000040) at ./Zend/zend_alloc.c:1360 #2 _emalloc (size=size@entry=56) at ./Zend/zend_alloc.c:2500 #3 0x00005555557e4445 in zend_string_alloc (persistent=0, len=28) at ./Zend/zend_string.h:133 #4 zend_string_tolower_ex (str=0x7fffe06bb000, persistent=persistent@entry=0) at ./Zend/zend_operators.c:2677 #5 0x00005555557df85f in zend_lookup_class_ex (name=name@entry=0x7fffe06bb000, key=key@entry=0x0, use_autoload=use_autoload@entry=1) at ./Zend/zend_execute_API.c:851 #6 0x00005555557ed333 in zend_is_callable_check_class (name=<optimized out>, scope=0x7ffff30c3428, fcc=fcc@entry=0x7fffffffa2e0, strict_class=strict_class@entry=0x7fffffffa2d8, error=error@entry=0x0) at ./Zend/zend_API.c:2957 #7 0x00005555557f3982 in zend_is_callable_impl (error=0x0, fcc=0x7fffffffa2e0, check_flags=<optimized out>, object=0x0, callable=0x7ffff3025c90) at ./Zend/zend_API.c:3406 #8 zend_is_callable_ex (callable=0x7ffff3025c90, object=0x0, check_flags=<optimized out>, callable_name=0x0, fcc=<optimized out>, error=0x0) at ./Zend/zend_API.c:3460 #9 0x00005555558793b0 in zend_check_type (is_return_type=<optimized out>, scope=<optimized out>, default_value=<optimized out>, cache_slot=<optimized out>, ce=<optimized out>, arg=0x7ffff3000070, type=<optimized out>) at ./Zend/zend_execute.c:929 #10 zend_verify_arg_type (cache_slot=<optimized out>, default_value=<optimized out>, arg=<optimized out>, arg_num=<optimized out>, zf=<optimized out>) at ./Zend/zend_execute.c:958 #11 ZEND_RECV_INIT_SPEC_CONST_HANDLER () at ./Zend/zend_vm_execute.h:2251 #12 execute_ex (ex=0x2c04b90) at ./Zend/zend_vm_execute.h:55601 #13 0x000055555587bcb3 in zend_execute (op_array=op_array@entry=0x7ffff30822a0, return_value=0x0, return_value@entry=0x7ffff30b1d20) at ./Zend/zend_vm_execute.h:60881 #14 0x00005555557ece22 in zend_execute_scripts (type=type@entry=8, retval=0x7ffff30b1d20, retval@entry=0x0, file_count=-217949136, file_count@entry=3) at ./Zend/zend.c:1568 #15 0x000055555578ce70 in php_execute_script (primary_file=0x7fffffffc9a0) at ./main/main.c:2630 #16 0x000055555587e18c in do_cli (argc=6, argv=0x555555bfa570) at ./sapi/cli/php_cli.c:997 #17 0x000055555564490b in main (argc=6, argv=0x555555bfa570) at ./sapi/cli/php_cli.c:1389 ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=77922&edit=1

« previous php.bugs (#220698) next »