Bug #78343 [Opn->Ver]: Test ext/phar/tests/bug71488.php core dump (segmentation fault)

From: Date: Mon, 29 Jul 2019 09:46:14 +0000
Subject: Bug #78343 [Opn->Ver]: Test ext/phar/tests/bug71488.php core dump (segmentation fault)
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-221976@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=78343&edit=1 ID: 78343 Updated by: nikic@php.net Reported by: rainer dot jung at kippdata dot de Summary: Test ext/phar/tests/bug71488.php core dump (segmentation fault) -Status: Open +Status: Verified Type: Bug Package: PHAR related Operating System: Solaris 10 Sparc PHP Version: 7.4.0beta1 Block user comment: N Private report: N New Comment: Huh, looks like we missed this because the test has an %A match at the end. Valgrind: ==25600== Invalid read of size 4 ==25600== at 0x9476EC: _zend_is_inconsistent (zend_hash.c:54) ==25600== by 0x94D66F: zend_hash_apply (zend_hash.c:1807) ==25600== by 0x601A9F: destroy_phar_data (phar.c:357) ==25600== by 0x94C6E7: zend_hash_destroy (zend_hash.c:1552) ==25600== by 0x60D842: zm_deactivate_phar (phar.c:3479) ==25600== by 0x93FE41: zend_deactivate_modules (zend_API.c:2619) ==25600== by 0x895C3C: php_request_shutdown (main.c:1891) ==25600== by 0xA12F96: do_cli (php_cli.c:1129) ==25600== by 0xA13805: main (php_cli.c:1352) ==25600== Address 0x12368ae0 is 80 bytes inside a block of size 328 free&apos;d ==25600== at 0x4C30D3B: free (in /usr/lib/valgrind/vgpreload_memcheck-amd64-linux.so) ==25600== by 0x8F9F07: _efree_custom (zend_alloc.c:2411) ==25600== by 0x8FA048: _efree (zend_alloc.c:2531) ==25600== by 0x616A5D: phar_convert_to_other (phar_object.c:2354) ==25600== by 0x61983A: zim_Phar_decompress (phar_object.c:3296) ==25600== by 0x9A83BF: ZEND_DO_FCALL_SPEC_RETVAL_USED_HANDLER (zend_vm_execute.h:1714) ==25600== by 0xA0B9E4: execute_ex (zend_vm_execute.h:53477) ==25600== by 0xA0FA90: zend_execute (zend_vm_execute.h:57553) ==25600== by 0x934E5E: zend_execute_scripts (zend.c:1663) ==25600== by 0x897261: php_execute_script (main.c:2606) ==25600== by 0xA1269C: do_cli (php_cli.c:962) ==25600== by 0xA13805: main (php_cli.c:1352) ==25600== Block was alloc&apos;d at ==25600== at 0x4C2FB0F: malloc (in /usr/lib/valgrind/vgpreload_memcheck-amd64-linux.so) ==25600== by 0x8FAF48: __zend_malloc (zend_alloc.c:2961) ==25600== by 0x8F9EA0: _malloc_custom (zend_alloc.c:2402) ==25600== by 0x8F9FCE: _emalloc (zend_alloc.c:2521) ==25600== by 0x8FA389: _ecalloc (zend_alloc.c:2593) ==25600== by 0x616285: phar_convert_to_other (phar_object.c:2257) ==25600== by 0x61983A: zim_Phar_decompress (phar_object.c:3296) ==25600== by 0x9A83BF: ZEND_DO_FCALL_SPEC_RETVAL_USED_HANDLER (zend_vm_execute.h:1714) ==25600== by 0xA0B9E4: execute_ex (zend_vm_execute.h:53477) ==25600== by 0xA0FA90: zend_execute (zend_vm_execute.h:57553) ==25600== by 0x934E5E: zend_execute_scripts (zend.c:1663) ==25600== by 0x897261: php_execute_script (main.c:2606) Previous Comments: ------------------------------------------------------------------------ [2019-07-28 20:11:02] rainer dot jung at kippdata dot de Description: ------------ Test ext/phar/tests/bug71488.php dumps core (segmentation fault) during clean up. The test passes, but of course creating a core indicates a serious problem not just in the case but in the phar cleanup implementation. Here's the stack: #0 zend_hash_apply (ht=0xfe66762c, apply_func=0xfe838aa8 <phar_tmpclose_apply>) at /path/to/my/Zend/zend_types.h:442 idx = 0 p = 0x5f303231 result = <optimized out> #1 0xfe83aa18 in destroy_phar_data (zv=0xfe667558) at /path/to/my/ext/phar/phar.c:357 phar_data = 0xfe667600 #2 0xfee798b0 in zend_hash_destroy (ht=0xfe8710fc <phar_globals+44>) at /path/to/my/Zend/zend_hash.c:1552 p = 0xfe667558 end = 0xfe667570 #3 0xfe83a38c in zm_deactivate_phar (type=1, module_number=12) at /path/to/my/ext/phar/phar.c:3478 i = <optimized out> #4 0xfee6ecfc in zend_deactivate_modules () at /path/to/my/Zend/zend_API.c:2619 module = <optimized out> p = 0xf8b74 __orig_bailout = <optimized out> __bailout = {2, -4200664, -18420712, -4200480, -18888536, 0, 1731670324, 943206000, 1752170728, -13041640, 114306127, 1299, -13037944, 2, -20578536, 263, -12582912, 8388608, 0} #5 0xfedfc8b0 in php_request_shutdown (dummy=0x0) at /path/to/my/main/main.c:1892 report_memleaks = 1 '\001' #6 0x00013658 in do_cli (argc=<optimized out>, argv=<optimized out>) at /path/to/my/sapi/cli/php_cli.c:1130 c = <optimized out> file_handle = {handle = {fp = 0xfe9b554c <_iob+48>, stream = {handle = 0xfe9b554c <_iob+48>, isatty = 0, reader = 0xfee86810 <zend_stream_stdio_reader>, fsizer = 0xfee868e0 <zend_stream_stdio_fsizer>, closer = 0xfee867c4 <zend_stream_stdio_closer>}}, filename = 0x3d7a8 "/path/to/my/ext/phar/tests/bug71488.php", opened_path = 0x0, type = ZEND_HANDLE_STREAM, buf = 0xfe676180 "¦\t¦¦gR@", len = 91} behavior = <optimized out> reflection_what = <optimized out> request_started = 1 exit_status = 255 php_optarg = 0x3d7a8 "/path/to/my/ext/phar/tests/bug71488.php" php_optind = 59 exec_direct = <optimized out> exec_run = <optimized out> exec_begin = <optimized out> exec_end = <optimized out> arg_free = <optimized out> arg_excp = <optimized out> script_file = <optimized out> translated_path = 0xffed8 "/path/to/my/ext/phar/tests/bug71488.php" interactive = <optimized out> param_error = <optimized out> hide_argv = <optimized out> #7 0x0001e394 in main (argc=<optimized out>, argv=0x3d240) at /path/to/my/sapi/cli/php_cli.c:1353 __orig_bailout = 0x0 __bailout = {2, -4198016, 123232, -4197792, 76492, 0, 0, 0, 0, 0, 0, 3, -4197692, 4, -4197452, 5, -12582912, 8388608, 0} c = <optimized out> exit_status = 0 module_started = 1 sapi_started = 1 php_optarg = 0x3d7a8 "/path/to/my/ext/phar/tests/bug71488.php" php_optind = 59 use_extended_info = 0 ini_path_override = 0x0 ini_entries = 0x3dba8 "html_errors=0\nregister_argc_argv=1\nimplicit_flush=1\noutput_buffering=0\nmax_execution_time=0\nmax_input_time=-1\noutput_handler=\nopen_basedir=\ndisable_functions=\noutput_buffering=Off\nerror_reporting=3276"... ini_entries_len = 540 ini_ignore = 0 and here's some data: (gdb) print phar_data $20 = (phar_archive_data *) 0xfe667600 (gdb) print *phar_data $21 = {fname = 0xfe667900 "¦fw", fname_len = 1634476133, ext = 0x72726f72 <error: Cannot access memory at address 0x72726f72>, ext_len = 975175812, alias = 0x2330202f <error: Cannot access memory at address 0x2330202f>, alias_len = 1936220530, version = "ed/build/aut", internal_file_start = 1868723561, halt_offset = 1818505079, manifest = {gc = {refcount = 1869769572, u = {type_info = 1769108271}}, u = {v = {_unused2 = 50 '2', nIteratorsCount = 48 '0', _unused = 49 '1', flags = 57 '9'}, flags = 842019129}, nTableMask = 808923702, arData = 0x5f303231, nNumUsed = 842346799, nNumOfElements = 1651270703, nTableSize = 1885892663, nInternalPointer = 875521400, nNextFreeElement = 1949266024, pDestructor = 0x61722f74}, virtual_dirs = {gc = {refcount = 1702065267, u = {type_info = 794981735}}, u = { v = {_unused2 = 55 '7', nIteratorsCount = 49 '1', _unused = 52 '4', flags = 56 '8'}, flags = 925971512}, nTableMask = 942567528, arData = 0x70283329, nNumUsed = 975196264, nNumOfElements = 1634878561, nTableSize = 1952525630, nInternalPointer = 1684366191, nNextFreeElement = 1836085861, pDestructor = 0x73732827}, mounted_dirs = {gc = {refcount = 1952805748, u = {type_info = 657000995}}, u = {v = {_unused2 = 49 '1', nIteratorsCount = 32 ' ', _unused = 123 '{', flags = 109 'm'}, flags = 824212333}, nTableMask = 1634299517, arData = 0x47218, nNumUsed = 0, nNumOfElements = 0, nTableSize = 8, nInternalPointer = 0, nNextFreeElement = 0, pDestructor = 0x0}, flags = 0, min_timestamp = 0, max_timestamp = 0, fp = 0xfe676300, ufp = 0x0, refcount = 0, sig_flags = 0, sig_len = 0, signature = 0x0, metadata = { value = {lval = 0, dval = 0, counted = 0x0, str = 0x0, arr = 0x0, obj = 0x0, res = 0x0, ref = 0x0, ast = 0x0, zv = 0x0, ptr = 0x0, ce = 0x0, func = 0x0, ww = {w1 = 0, w2 = 0}}, u1 = {v = {u = {extra = 0}, type_flags = 0 '\000', type = 0 '\000'}, type_info = 0}, u2 = {next = 0, cache_slot = 0, opline_num = 0, lineno = 0, num_args = 0, fe_pos = 0, fe_iter_idx = 0, access_flags = 0, property_guard = 0, constant_flags = 0, extra = 0}}, metadata_len = 0, phar_pos = 0, is_temporary_alias = 1, is_modified = 0, is_writeable = 0, is_brandnew = 0, donotflush = 0, is_zip = 0, is_tar = 1, is_data = 1, is_persistent = 0} (gdb) print zv $22 = (zval *) 0xfe667558 (gdb) print *zv $23 = {value = {lval = -26839552, dval = -7.5209700351807801e+300, counted = 0xfe667600, str = 0xfe667600, arr = 0xfe667600, obj = 0xfe667600, res = 0xfe667600, ref = 0xfe667600, ast = 0xfe667600, zv = 0xfe667600, ptr = 0xfe667600, ce = 0xfe667600, func = 0xfe667600, ww = {w1 = 4268127744, w2 = 4270256508}}, u1 = {v = {u = { extra = 0}, type_flags = 0 '\000', type = 14 '\016'}, type_info = 14}, u2 = {next = 4294967295, cache_slot = 4294967295, opline_num = 4294967295, lineno = 4294967295, num_args = 4294967295, fe_pos = 4294967295, fe_iter_idx = 4294967295, access_flags = 4294967295, property_guard = 4294967295, constant_flags = 4294967295, extra = 4294967295}} It is not a regression in 7.4, teh same happens at least as far back as 7.2, probably even older. ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=78343&edit=1

« previous php.bugs (#221976) next »