Edit report at https://bugs.php.net/bug.php?id=77922&edit=1
ID: 77922
Comment by: wskorodecki at gmail dot com
Reported by: enumag at gmail dot com
Summary: Segmentation fault in PHP 7.3.4 when running phpunit
Status: Open
Type: Bug
Package: Unknown/Other Function
Operating System: Ubuntu
PHP Version: 7.3.4
Block user comment: N
Private report: N
New Comment:
I'm facing the same problem on PHP 7.3.5 on Archlinux but my stacktrace is different.
Interesting here is that the error does not occur when I execute "phpunit -v" outside our
Symfony-based project, that has a "tests" directory containing several tests based on
PHPUnit.
$ php -v
PHP 7.3.5 (cli) (built: Apr 30 2019 21:05:09) ( NTS )
Copyright (c) 1997-2018 The PHP Group
Zend Engine v3.3.5, Copyright (c) 1998-2018 Zend Technologies
with Zend OPcache v7.3.5, Copyright (c) 1999-2018, by Zend Technologies
$ phpunit --version
PHPUnit 8.0.1 by Sebastian Bergmann and contributors.
$ php -m
[PHP Modules]
Core
ctype
curl
date
dom
ds
fileinfo
filter
ftp
gd
hash
iconv
igbinary
intl
json
libxml
mbstring
mysqlnd
odbc
openssl
pcntl
pcre
PDO
pdo_mysql
pdo_sqlite
Phar
posix
readline
redis
Reflection
session
SimpleXML
soap
SPL
standard
tokenizer
xml
xmlreader
xmlwriter
Zend OPcache
zip
zlib
[Zend Modules]
Zend OPcache
$ phpunit -v
Segmentation fault (core dumped)
$ coredumpctl info 20528
PID: 20528 (php)
UID: 1000 (wojtek)
GID: 985 (users)
Signal: 11 (SEGV)
Timestamp: Tue 2019-05-21 08:26:09 CEST (42s ago)
Command Line: php /usr/local/bin/phpunit -v
Executable: /usr/bin/php
Control Group: /user.slice/user-1000.slice/session-2.scope
Unit: session-2.scope
Slice: user-1000.slice
Session: 2
Owner UID: 1000 (wojtek)
Boot ID: 526298d71d1a4cb6bf2294d12eea5611
Machine ID: f372dea6fef44dc1ad344b6b92e63878
Hostname: archlinux-ws
Storage:
/var/lib/systemd/coredump/core.php.1000.526298d71d1a4cb6bf2294d12eea5611.20528.1558419969000000.lz4
Message: Process 20528 (php) of user 1000 dumped core.
Stack trace of thread 20528:
#0 0x000055e6a0409bd0 n/a (php)
#1 0x000055e6a05857c5 execute_ex (php)
#2 0x000055e6a058b836 zend_execute (php)
#3 0x000055e6a050455a zend_execute_scripts (php)
#4 0x000055e6a04a4489 php_execute_script (php)
#5 0x000055e6a058de36 n/a (php)
#6 0x000055e6a028f067 n/a (php)
#7 0x00007f51c5576ce3 __libc_start_main (libc.so.6)
#8 0x000055e6a028f74e _start (php)
Previous Comments:
------------------------------------------------------------------------
[2019-05-04 09:21:39] enumag at gmail dot com
Note: This bug still exists in PHP 7.3.5.
------------------------------------------------------------------------
[2019-04-24 18:59:02] enumag at gmail dot com
How do we fix it then? Is there anything else I can do to help? This is currently blocking us from
upgrading to PHP 7.3.
------------------------------------------------------------------------
[2019-04-24 13:46:08] nikic@php.net
Thanks! The first non-spurious warning is:
==32207== Invalid read of size 4
==32207== at 0x3C7A2E: gc_mark_grey (zend_gc.c:901)
==32207== by 0x3C7A2E: gc_mark_roots (zend_gc.c:960)
==32207== by 0x3C7A2E: zend_gc_collect_cycles (zend_gc.c:1443)
==32207== by 0x3C68B7: gc_possible_root_when_full (zend_gc.c:577)
==32207== by 0x42C233: zend_object_release (zend_objects_API.h:79)
==32207== by 0x42C233: execute_ex (zend_vm_execute.h:55359)
==32207== by 0x42FCB2: zend_execute (zend_vm_execute.h:60881)
==32207== by 0x3A0E21: zend_execute_scripts (zend.c:1568)
==32207== by 0x340E6F: php_execute_script (main.c:2630)
==32207== by 0x43218B: do_cli (php_cli.c:997)
==32207== by 0x1F890A: main (php_cli.c:1389)
==32207== Address 0x1d757ae4 is 4 bytes inside a block of size 40 free'd
==32207== at 0x4C30D3B: free (in /usr/lib/valgrind/vgpreload_memcheck-amd64-linux.so)
==32207== by 0x3CA5F0: zend_string_release (zend_string.h:277)
==32207== by 0x3CA5F0: zend_new_interned_string_request (zend_string.c:232)
==32207== by 0x3827D1: zend_begin_method_decl (zend_compile.c:5817)
==32207== by 0x38F3B5: zend_compile_func_decl (zend_compile.c:6037)
==32207== by 0x38D109: zend_compile_stmt (zend_compile.c:8277)
==32207== by 0x38E326: zend_compile_stmt_list (zend_compile.c:5434)
==32207== by 0x38CFF1: zend_compile_stmt (zend_compile.c:8221)
==32207== by 0x38E681: zend_compile_class_decl (zend_compile.c:6491)
==32207== by 0x38D117: zend_compile_stmt (zend_compile.c:8289)
==32207== by 0x38FED4: zend_compile_top_stmt (zend_compile.c:8195)
==32207== by 0x38FEC0: zend_compile_top_stmt (zend_compile.c:8190)
==32207== by 0x368558: zend_compile (zend_language_scanner.l:602)
==32207== Block was alloc'd at
==32207== at 0x4C2FB0F: malloc (in /usr/lib/valgrind/vgpreload_memcheck-amd64-linux.so)
==32207== by 0x377168: __zend_malloc (zend_alloc.c:2903)
==32207== by 0x398444: zend_string_alloc (zend_string.h:133)
==32207== by 0x398444: zend_string_tolower_ex (zend_operators.c:2677)
==32207== by 0x3827C5: zend_begin_method_decl (zend_compile.c:5816)
==32207== by 0x38F3B5: zend_compile_func_decl (zend_compile.c:6037)
==32207== by 0x38D109: zend_compile_stmt (zend_compile.c:8277)
==32207== by 0x38E326: zend_compile_stmt_list (zend_compile.c:5434)
==32207== by 0x38CFF1: zend_compile_stmt (zend_compile.c:8221)
==32207== by 0x38E681: zend_compile_class_decl (zend_compile.c:6491)
==32207== by 0x38D117: zend_compile_stmt (zend_compile.c:8289)
==32207== by 0x38FED4: zend_compile_top_stmt (zend_compile.c:8195)
==32207== by 0x38FEC0: zend_compile_top_stmt (zend_compile.c:8190)
The warning indicates a use-after-free of https://github.com/php/php-src/blob/191e15309fce3df7839e52b1f488b0be83fa8561/Zend/zend_compile.c#L5816.
That seems rather unlikely, so it's probably hitting that piece of memory by coincidence :/
------------------------------------------------------------------------
[2019-04-24 13:31:11] enumag at gmail dot com
Here you go: https://gist.github.com/enumag/639017e964036e5a5576962ce0934a8b
------------------------------------------------------------------------
[2019-04-23 09:19:47] nikic@php.net
Would it be possible for you to run the test suite under "USE_ZEND_ALLOC=0 valgrind php"
and post the resulting log?
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=77922
--
Edit this bug report at https://bugs.php.net/bug.php?id=77922&edit=1