Bug #78343 [NEW]: Test ext/phar/tests/bug71488.php core dump (segmentation fault)
| From: | rainer dot jung at kippdata dot de | Date: | Sun, 28 Jul 2019 20:11:02 +0000 |
| Subject: | Bug #78343 [NEW]: Test ext/phar/tests/bug71488.php core dump (segmentation fault) | ||
| Groups: | php.bugs | ||
| Request: | Send a blank email to php-bugs+get-221962@lists.php.net to get a copy of this message | ||
From: rainer dot jung at kippdata dot de
Operating system: Solaris 10 Sparc
PHP version: 7.4.0beta1
Package: PHAR related
Bug Type: Bug
Bug description:Test ext/phar/tests/bug71488.php core dump (segmentation fault)
Description:
------------
Test ext/phar/tests/bug71488.php dumps core (segmentation fault) during
clean up. The test passes, but of course creating a core indicates a
serious problem not just in the case but in the phar cleanup
implementation.
Here's the stack:
#0 zend_hash_apply (ht=0xfe66762c, apply_func=0xfe838aa8
<phar_tmpclose_apply>) at /path/to/my/Zend/zend_types.h:442
idx = 0
p = 0x5f303231
result = <optimized out>
#1 0xfe83aa18 in destroy_phar_data (zv=0xfe667558) at
/path/to/my/ext/phar/phar.c:357
phar_data = 0xfe667600
#2 0xfee798b0 in zend_hash_destroy (ht=0xfe8710fc <phar_globals+44>) at
/path/to/my/Zend/zend_hash.c:1552
p = 0xfe667558
end = 0xfe667570
#3 0xfe83a38c in zm_deactivate_phar (type=1, module_number=12) at
/path/to/my/ext/phar/phar.c:3478
i = <optimized out>
#4 0xfee6ecfc in zend_deactivate_modules () at
/path/to/my/Zend/zend_API.c:2619
module = <optimized out>
p = 0xf8b74
__orig_bailout = <optimized out>
__bailout = {2, -4200664, -18420712, -4200480, -18888536, 0,
1731670324, 943206000, 1752170728, -13041640, 114306127, 1299,
-13037944, 2, -20578536, 263, -12582912,
8388608, 0}
#5 0xfedfc8b0 in php_request_shutdown (dummy=0x0) at
/path/to/my/main/main.c:1892
report_memleaks = 1 '\001'
#6 0x00013658 in do_cli (argc=<optimized out>, argv=<optimized out>) at
/path/to/my/sapi/cli/php_cli.c:1130
c = <optimized out>
file_handle = {handle = {fp = 0xfe9b554c <_iob+48>, stream =
{handle = 0xfe9b554c <_iob+48>, isatty = 0, reader = 0xfee86810
<zend_stream_stdio_reader>,
fsizer = 0xfee868e0 <zend_stream_stdio_fsizer>, closer =
0xfee867c4 <zend_stream_stdio_closer>}},
filename = 0x3d7a8 "/path/to/my/ext/phar/tests/bug71488.php",
opened_path = 0x0, type = ZEND_HANDLE_STREAM,
buf = 0xfe676180 "¦\t¦¦gR@", len = 91}
behavior = <optimized out>
reflection_what = <optimized out>
request_started = 1
exit_status = 255
php_optarg = 0x3d7a8 "/path/to/my/ext/phar/tests/bug71488.php"
php_optind = 59
exec_direct = <optimized out>
exec_run = <optimized out>
exec_begin = <optimized out>
exec_end = <optimized out>
arg_free = <optimized out>
arg_excp = <optimized out>
script_file = <optimized out>
translated_path = 0xffed8
"/path/to/my/ext/phar/tests/bug71488.php"
interactive = <optimized out>
param_error = <optimized out>
hide_argv = <optimized out>
#7 0x0001e394 in main (argc=<optimized out>, argv=0x3d240) at
/path/to/my/sapi/cli/php_cli.c:1353
__orig_bailout = 0x0
__bailout = {2, -4198016, 123232, -4197792, 76492, 0, 0, 0, 0,
0, 0, 3, -4197692, 4, -4197452, 5, -12582912, 8388608, 0}
c = <optimized out>
exit_status = 0
module_started = 1
sapi_started = 1
php_optarg = 0x3d7a8 "/path/to/my/ext/phar/tests/bug71488.php"
php_optind = 59
use_extended_info = 0
ini_path_override = 0x0
ini_entries = 0x3dba8
"html_errors=0\nregister_argc_argv=1\nimplicit_flush=1\noutput_buffering=0\nmax_execution_time=0\nmax_input_time=-1\noutput_handler=\nopen_basedir=\ndisable_functions=\noutput_buffering=Off\nerror_reporting=3276"...
ini_entries_len = 540
ini_ignore = 0
and here's some data:
(gdb) print phar_data
$20 = (phar_archive_data *) 0xfe667600
(gdb) print *phar_data
$21 = {fname = 0xfe667900 "¦fw", fname_len = 1634476133, ext =
0x72726f72 <error: Cannot access memory at address 0x72726f72>, ext_len
= 975175812,
alias = 0x2330202f <error: Cannot access memory at address
0x2330202f>, alias_len = 1936220530, version = "ed/build/aut",
internal_file_start = 1868723561,
halt_offset = 1818505079, manifest = {gc = {refcount = 1869769572, u =
{type_info = 1769108271}}, u = {v = {_unused2 = 50 '2', nIteratorsCount
= 48 '0', _unused = 49 '1',
flags = 57 '9'}, flags = 842019129}, nTableMask = 808923702,
arData = 0x5f303231, nNumUsed = 842346799, nNumOfElements = 1651270703,
nTableSize = 1885892663,
nInternalPointer = 875521400, nNextFreeElement = 1949266024,
pDestructor = 0x61722f74}, virtual_dirs = {gc = {refcount = 1702065267,
u = {type_info = 794981735}}, u = {
v = {_unused2 = 55 '7', nIteratorsCount = 49 '1', _unused = 52
'4', flags = 56 '8'}, flags = 925971512}, nTableMask = 942567528, arData
= 0x70283329,
nNumUsed = 975196264, nNumOfElements = 1634878561, nTableSize =
1952525630, nInternalPointer = 1684366191, nNextFreeElement =
1836085861, pDestructor = 0x73732827},
mounted_dirs = {gc = {refcount = 1952805748, u = {type_info =
657000995}}, u = {v = {_unused2 = 49 '1', nIteratorsCount = 32 ' ',
_unused = 123 '{', flags = 109 'm'},
flags = 824212333}, nTableMask = 1634299517, arData = 0x47218,
nNumUsed = 0, nNumOfElements = 0, nTableSize = 8, nInternalPointer = 0,
nNextFreeElement = 0,
pDestructor = 0x0}, flags = 0, min_timestamp = 0, max_timestamp = 0,
fp = 0xfe676300, ufp = 0x0, refcount = 0, sig_flags = 0, sig_len = 0,
signature = 0x0, metadata = {
value = {lval = 0, dval = 0, counted = 0x0, str = 0x0, arr = 0x0,
obj = 0x0, res = 0x0, ref = 0x0, ast = 0x0, zv = 0x0, ptr = 0x0, ce =
0x0, func = 0x0, ww = {w1 = 0,
w2 = 0}}, u1 = {v = {u = {extra = 0}, type_flags = 0 '\000',
type = 0 '\000'}, type_info = 0}, u2 = {next = 0, cache_slot = 0,
opline_num = 0, lineno = 0,
num_args = 0, fe_pos = 0, fe_iter_idx = 0, access_flags = 0,
property_guard = 0, constant_flags = 0, extra = 0}}, metadata_len = 0,
phar_pos = 0, is_temporary_alias = 1,
is_modified = 0, is_writeable = 0, is_brandnew = 0, donotflush = 0,
is_zip = 0, is_tar = 1, is_data = 1, is_persistent = 0}
(gdb) print zv
$22 = (zval *) 0xfe667558
(gdb) print *zv
$23 = {value = {lval = -26839552, dval = -7.5209700351807801e+300,
counted = 0xfe667600, str = 0xfe667600, arr = 0xfe667600, obj =
0xfe667600, res = 0xfe667600,
ref = 0xfe667600, ast = 0xfe667600, zv = 0xfe667600, ptr =
0xfe667600, ce = 0xfe667600, func = 0xfe667600, ww = {w1 = 4268127744,
w2 = 4270256508}}, u1 = {v = {u = {
extra = 0}, type_flags = 0 '\000', type = 14 '\016'}, type_info
= 14}, u2 = {next = 4294967295, cache_slot = 4294967295, opline_num =
4294967295, lineno = 4294967295,
num_args = 4294967295, fe_pos = 4294967295, fe_iter_idx =
4294967295, access_flags = 4294967295, property_guard = 4294967295,
constant_flags = 4294967295,
extra = 4294967295}}
It is not a regression in 7.4, teh same happens at least as far back as
7.2, probably even older.
--
Edit bug report at https://bugs.php.net/bug.php?id=78343&edit=1
--
Try a snapshot (PHP 5.4): https://bugs.php.net/fix.php?id=78343&r=trysnapshot54
Try a snapshot (PHP 5.5): https://bugs.php.net/fix.php?id=78343&r=trysnapshot55
Try a snapshot (trunk): https://bugs.php.net/fix.php?id=78343&r=trysnapshottrunk
Fixed in SVN: https://bugs.php.net/fix.php?id=78343&r=fixed
Fixed in release: https://bugs.php.net/fix.php?id=78343&r=alreadyfixed
Need backtrace: https://bugs.php.net/fix.php?id=78343&r=needtrace
Need Reproduce Script: https://bugs.php.net/fix.php?id=78343&r=needscript
Try newer version: https://bugs.php.net/fix.php?id=78343&r=oldversion
Not developer issue: https://bugs.php.net/fix.php?id=78343&r=support
Expected behavior: https://bugs.php.net/fix.php?id=78343&r=notwrong
Not enough info: https://bugs.php.net/fix.php?id=78343&r=notenoughinfo
Submitted twice: https://bugs.php.net/fix.php?id=78343&r=submittedtwice
register_globals: https://bugs.php.net/fix.php?id=78343&r=globals
PHP 4 support discontinued: https://bugs.php.net/fix.php?id=78343&r=php4
Daylight Savings: https://bugs.php.net/fix.php?id=78343&r=dst
IIS Stability: https://bugs.php.net/fix.php?id=78343&r=isapi
Install GNU Sed: https://bugs.php.net/fix.php?id=78343&r=gnused
Floating point limitations: https://bugs.php.net/fix.php?id=78343&r=float
No Zend Extensions: https://bugs.php.net/fix.php?id=78343&r=nozend
MySQL Configuration Error: https://bugs.php.net/fix.php?id=78343&r=mysqlcfg