Bug #78335 [Ver]: Segfault in zend_mm_find_leaks_small

From: Date: Mon, 29 Jul 2019 12:58:16 +0000
Subject: Bug #78335 [Ver]: Segfault in zend_mm_find_leaks_small
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-221991@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=78335&edit=1

 ID:                 78335
 Updated by:         nikic@php.net
 Reported by:        kelunik@php.net
 Summary:            Segfault in zend_mm_find_leaks_small
 Status:             Verified
 Type:               Bug
 Package:            Reproducible crash
 Operating System:   Ubuntu 19.04
 PHP Version:        7.3.7
 Block user comment: N
 Private report:     N

 New Comment:

The problem here is that we're doing the final GC run prior to class destruction, which means
that the static property still holds the cycle at that point.

We could move the final GC run until after class destruction (this should be safe as we call
free_obj handlers before that, so the class entries will no longer be accessed), but I think that
will break other things. In particular I moved the GC run earlier for 7.4 in https://github.com/php/php-src/commit/178dcd47490f7d7842c6c412e2331ed160e55809
to make sure that leaks aren't hidden by the combination of forced free_obj + a GC run.

Not sure what to do here...


Previous Comments:
------------------------------------------------------------------------
[2019-07-29 12:32:38] nikic@php.net

Repro for leaks turned out to be quite simple:

<?php  
class Test {
    public static $test;
}
$foo = [&$foo];
Test::$test = $foo;

------------------------------------------------------------------------
[2019-07-29 11:18:40] nikic@php.net

Leak messages reproduce on 7.3 and master, segfault only on 7.3.

------------------------------------------------------------------------
[2019-07-25 16:27:23] kelunik@php.net

Description:
------------
PHP segfaults in debug builds inside the memory leak detection code.

Test script:
---------------
<?php

// https://github.com/amphp/hpack/issues/2
// Commit: 0c16dfb577458dd3527167c0cb4807f5ccf76b59

require __DIR__ . '/vendor/autoload.php';

(function () {
    var_dump(count(static::$huffmanLookup));
})->bindTo(new Amp\Http\HPack, Amp\Http\HPack::class)();



Expected result:
----------------
No segfault.

Actual result:
--------------
Program received signal SIGSEGV, Segmentation fault.

#0  0x0000555555dfa121 in zend_mm_find_leaks_small (p=0x7ffff3600000, i=509, j=38,
leak=0x7fffffffbb80) at /home/kelunik/.php-build/release/Zend/zend_alloc.c:2056
#1  0x0000555555dfa285 in zend_mm_find_leaks (heap=0x7ffff4000040, p=0x7ffff3600000, i=509,
leak=0x7fffffffbb80) at /home/kelunik/.php-build/release/Zend/zend_alloc.c:2084
#2  0x0000555555dfa768 in zend_mm_check_leaks (heap=0x7ffff4000040) at
/home/kelunik/.php-build/release/Zend/zend_alloc.c:2188
#3  0x0000555555dfaa49 in zend_mm_shutdown (heap=0x7ffff4000040, full=0, silent=0) at
/home/kelunik/.php-build/release/Zend/zend_alloc.c:2253
#4  0x0000555555dfb852 in shutdown_memory_manager (silent=0, full_shutdown=0) at
/home/kelunik/.php-build/release/Zend/zend_alloc.c:2668
#5  0x0000555555d98468 in php_request_shutdown (dummy=0x0) at
/home/kelunik/.php-build/release/main/main.c:1949
#6  0x0000555555f128c7 in do_cli (argc=2, argv=0x55555697cde0) at
/home/kelunik/.php-build/release/sapi/cli/php_cli.c:1164
#7  0x0000555555f13141 in main (argc=2, argv=0x55555697cde0) at
/home/kelunik/.php-build/release/sapi/cli/php_cli.c:1389


------------------------------------------------------------------------



--
Edit this bug report at https://bugs.php.net/bug.php?id=78335&edit=1


Thread (5 messages)

« previous php.bugs (#221991) next »