Bug #78343 [Opn->Ver]: Test ext/phar/tests/bug71488.php core dump (segmentation fault)
| From: | nikic@php.net | Date: | Mon, 29 Jul 2019 09:46:14 +0000 |
| Subject: | Bug #78343 [Opn->Ver]: Test ext/phar/tests/bug71488.php core dump (segmentation fault) | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-221976@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=78343&edit=1
ID: 78343
Updated by: nikic@php.net
Reported by: rainer dot jung at kippdata dot de
Summary: Test ext/phar/tests/bug71488.php core dump
(segmentation fault)
-Status: Open
+Status: Verified
Type: Bug
Package: PHAR related
Operating System: Solaris 10 Sparc
PHP Version: 7.4.0beta1
Block user comment: N
Private report: N
New Comment:
Huh, looks like we missed this because the test has an %A match at the end.
Valgrind:
==25600== Invalid read of size 4
==25600== at 0x9476EC: _zend_is_inconsistent (zend_hash.c:54)
==25600== by 0x94D66F: zend_hash_apply (zend_hash.c:1807)
==25600== by 0x601A9F: destroy_phar_data (phar.c:357)
==25600== by 0x94C6E7: zend_hash_destroy (zend_hash.c:1552)
==25600== by 0x60D842: zm_deactivate_phar (phar.c:3479)
==25600== by 0x93FE41: zend_deactivate_modules (zend_API.c:2619)
==25600== by 0x895C3C: php_request_shutdown (main.c:1891)
==25600== by 0xA12F96: do_cli (php_cli.c:1129)
==25600== by 0xA13805: main (php_cli.c:1352)
==25600== Address 0x12368ae0 is 80 bytes inside a block of size 328 free'd
==25600== at 0x4C30D3B: free (in /usr/lib/valgrind/vgpreload_memcheck-amd64-linux.so)
==25600== by 0x8F9F07: _efree_custom (zend_alloc.c:2411)
==25600== by 0x8FA048: _efree (zend_alloc.c:2531)
==25600== by 0x616A5D: phar_convert_to_other (phar_object.c:2354)
==25600== by 0x61983A: zim_Phar_decompress (phar_object.c:3296)
==25600== by 0x9A83BF: ZEND_DO_FCALL_SPEC_RETVAL_USED_HANDLER (zend_vm_execute.h:1714)
==25600== by 0xA0B9E4: execute_ex (zend_vm_execute.h:53477)
==25600== by 0xA0FA90: zend_execute (zend_vm_execute.h:57553)
==25600== by 0x934E5E: zend_execute_scripts (zend.c:1663)
==25600== by 0x897261: php_execute_script (main.c:2606)
==25600== by 0xA1269C: do_cli (php_cli.c:962)
==25600== by 0xA13805: main (php_cli.c:1352)
==25600== Block was alloc'd at
==25600== at 0x4C2FB0F: malloc (in /usr/lib/valgrind/vgpreload_memcheck-amd64-linux.so)
==25600== by 0x8FAF48: __zend_malloc (zend_alloc.c:2961)
==25600== by 0x8F9EA0: _malloc_custom (zend_alloc.c:2402)
==25600== by 0x8F9FCE: _emalloc (zend_alloc.c:2521)
==25600== by 0x8FA389: _ecalloc (zend_alloc.c:2593)
==25600== by 0x616285: phar_convert_to_other (phar_object.c:2257)
==25600== by 0x61983A: zim_Phar_decompress (phar_object.c:3296)
==25600== by 0x9A83BF: ZEND_DO_FCALL_SPEC_RETVAL_USED_HANDLER (zend_vm_execute.h:1714)
==25600== by 0xA0B9E4: execute_ex (zend_vm_execute.h:53477)
==25600== by 0xA0FA90: zend_execute (zend_vm_execute.h:57553)
==25600== by 0x934E5E: zend_execute_scripts (zend.c:1663)
==25600== by 0x897261: php_execute_script (main.c:2606)
Previous Comments:
------------------------------------------------------------------------
[2019-07-28 20:11:02] rainer dot jung at kippdata dot de
Description:
------------
Test ext/phar/tests/bug71488.php dumps core (segmentation fault) during clean up. The test passes,
but of course creating a core indicates a serious problem not just in the case but in the phar
cleanup implementation.
Here's the stack:
#0 zend_hash_apply (ht=0xfe66762c, apply_func=0xfe838aa8 <phar_tmpclose_apply>) at
/path/to/my/Zend/zend_types.h:442
idx = 0
p = 0x5f303231
result = <optimized out>
#1 0xfe83aa18 in destroy_phar_data (zv=0xfe667558) at /path/to/my/ext/phar/phar.c:357
phar_data = 0xfe667600
#2 0xfee798b0 in zend_hash_destroy (ht=0xfe8710fc <phar_globals+44>) at
/path/to/my/Zend/zend_hash.c:1552
p = 0xfe667558
end = 0xfe667570
#3 0xfe83a38c in zm_deactivate_phar (type=1, module_number=12) at /path/to/my/ext/phar/phar.c:3478
i = <optimized out>
#4 0xfee6ecfc in zend_deactivate_modules () at /path/to/my/Zend/zend_API.c:2619
module = <optimized out>
p = 0xf8b74
__orig_bailout = <optimized out>
__bailout = {2, -4200664, -18420712, -4200480, -18888536, 0, 1731670324, 943206000,
1752170728, -13041640, 114306127, 1299, -13037944, 2, -20578536, 263, -12582912,
8388608, 0}
#5 0xfedfc8b0 in php_request_shutdown (dummy=0x0) at /path/to/my/main/main.c:1892
report_memleaks = 1 '\001'
#6 0x00013658 in do_cli (argc=<optimized out>, argv=<optimized out>) at
/path/to/my/sapi/cli/php_cli.c:1130
c = <optimized out>
file_handle = {handle = {fp = 0xfe9b554c <_iob+48>, stream = {handle = 0xfe9b554c
<_iob+48>, isatty = 0, reader = 0xfee86810 <zend_stream_stdio_reader>,
fsizer = 0xfee868e0 <zend_stream_stdio_fsizer>, closer = 0xfee867c4
<zend_stream_stdio_closer>}},
filename = 0x3d7a8 "/path/to/my/ext/phar/tests/bug71488.php", opened_path = 0x0,
type = ZEND_HANDLE_STREAM,
buf = 0xfe676180 "¦\t¦¦gR@", len = 91}
behavior = <optimized out>
reflection_what = <optimized out>
request_started = 1
exit_status = 255
php_optarg = 0x3d7a8 "/path/to/my/ext/phar/tests/bug71488.php"
php_optind = 59
exec_direct = <optimized out>
exec_run = <optimized out>
exec_begin = <optimized out>
exec_end = <optimized out>
arg_free = <optimized out>
arg_excp = <optimized out>
script_file = <optimized out>
translated_path = 0xffed8 "/path/to/my/ext/phar/tests/bug71488.php"
interactive = <optimized out>
param_error = <optimized out>
hide_argv = <optimized out>
#7 0x0001e394 in main (argc=<optimized out>, argv=0x3d240) at
/path/to/my/sapi/cli/php_cli.c:1353
__orig_bailout = 0x0
__bailout = {2, -4198016, 123232, -4197792, 76492, 0, 0, 0, 0, 0, 0, 3, -4197692, 4,
-4197452, 5, -12582912, 8388608, 0}
c = <optimized out>
exit_status = 0
module_started = 1
sapi_started = 1
php_optarg = 0x3d7a8 "/path/to/my/ext/phar/tests/bug71488.php"
php_optind = 59
use_extended_info = 0
ini_path_override = 0x0
ini_entries = 0x3dba8
"html_errors=0\nregister_argc_argv=1\nimplicit_flush=1\noutput_buffering=0\nmax_execution_time=0\nmax_input_time=-1\noutput_handler=\nopen_basedir=\ndisable_functions=\noutput_buffering=Off\nerror_reporting=3276"...
ini_entries_len = 540
ini_ignore = 0
and here's some data:
(gdb) print phar_data
$20 = (phar_archive_data *) 0xfe667600
(gdb) print *phar_data
$21 = {fname = 0xfe667900 "¦fw", fname_len = 1634476133, ext = 0x72726f72 <error:
Cannot access memory at address 0x72726f72>, ext_len = 975175812,
alias = 0x2330202f <error: Cannot access memory at address 0x2330202f>, alias_len =
1936220530, version = "ed/build/aut", internal_file_start = 1868723561,
halt_offset = 1818505079, manifest = {gc = {refcount = 1869769572, u = {type_info = 1769108271}},
u = {v = {_unused2 = 50 '2', nIteratorsCount = 48 '0', _unused = 49
'1',
flags = 57 '9'}, flags = 842019129}, nTableMask = 808923702, arData = 0x5f303231,
nNumUsed = 842346799, nNumOfElements = 1651270703, nTableSize = 1885892663,
nInternalPointer = 875521400, nNextFreeElement = 1949266024, pDestructor = 0x61722f74},
virtual_dirs = {gc = {refcount = 1702065267, u = {type_info = 794981735}}, u = {
v = {_unused2 = 55 '7', nIteratorsCount = 49 '1', _unused = 52
'4', flags = 56 '8'}, flags = 925971512}, nTableMask = 942567528, arData =
0x70283329,
nNumUsed = 975196264, nNumOfElements = 1634878561, nTableSize = 1952525630, nInternalPointer =
1684366191, nNextFreeElement = 1836085861, pDestructor = 0x73732827},
mounted_dirs = {gc = {refcount = 1952805748, u = {type_info = 657000995}}, u = {v = {_unused2 = 49
'1', nIteratorsCount = 32 ' ', _unused = 123 '{', flags = 109
'm'},
flags = 824212333}, nTableMask = 1634299517, arData = 0x47218, nNumUsed = 0, nNumOfElements =
0, nTableSize = 8, nInternalPointer = 0, nNextFreeElement = 0,
pDestructor = 0x0}, flags = 0, min_timestamp = 0, max_timestamp = 0, fp = 0xfe676300, ufp = 0x0,
refcount = 0, sig_flags = 0, sig_len = 0, signature = 0x0, metadata = {
value = {lval = 0, dval = 0, counted = 0x0, str = 0x0, arr = 0x0, obj = 0x0, res = 0x0, ref =
0x0, ast = 0x0, zv = 0x0, ptr = 0x0, ce = 0x0, func = 0x0, ww = {w1 = 0,
w2 = 0}}, u1 = {v = {u = {extra = 0}, type_flags = 0 '\000', type = 0
'\000'}, type_info = 0}, u2 = {next = 0, cache_slot = 0, opline_num = 0, lineno = 0,
num_args = 0, fe_pos = 0, fe_iter_idx = 0, access_flags = 0, property_guard = 0,
constant_flags = 0, extra = 0}}, metadata_len = 0, phar_pos = 0, is_temporary_alias = 1,
is_modified = 0, is_writeable = 0, is_brandnew = 0, donotflush = 0, is_zip = 0, is_tar = 1,
is_data = 1, is_persistent = 0}
(gdb) print zv
$22 = (zval *) 0xfe667558
(gdb) print *zv
$23 = {value = {lval = -26839552, dval = -7.5209700351807801e+300, counted = 0xfe667600, str =
0xfe667600, arr = 0xfe667600, obj = 0xfe667600, res = 0xfe667600,
ref = 0xfe667600, ast = 0xfe667600, zv = 0xfe667600, ptr = 0xfe667600, ce = 0xfe667600, func =
0xfe667600, ww = {w1 = 4268127744, w2 = 4270256508}}, u1 = {v = {u = {
extra = 0}, type_flags = 0 '\000', type = 14 '\016'}, type_info = 14},
u2 = {next = 4294967295, cache_slot = 4294967295, opline_num = 4294967295, lineno = 4294967295,
num_args = 4294967295, fe_pos = 4294967295, fe_iter_idx = 4294967295, access_flags = 4294967295,
property_guard = 4294967295, constant_flags = 4294967295,
extra = 4294967295}}
It is not a regression in 7.4, teh same happens at least as far back as 7.2, probably even older.
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=78343&edit=1