Bug #78502 [Ver->Asn]: Segmentation Fault in array_map

From: Date: Fri, 06 Sep 2019 09:00:36 +0000
Subject: Bug #78502 [Ver->Asn]: Segmentation Fault in array_map
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-222598@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=78502&edit=1 ID: 78502 Updated by: nikic@php.net Reported by: phofstetter at sensational dot ch Summary: Segmentation Fault in array_map -Status: Verified +Status: Assigned Type: Bug Package: Reproducible crash Operating System: macos 10.14, Debian 10 PHP Version: 7.4.0RC1 -Assigned To: +Assigned To: nikic Block user comment: N Private report: N New Comment: @phofstetter: That commit is indeed relevant, because it changed the registration of the function to happen when we start to compile the function, rather than once it has been fully compiled. That means that stack size calculations end up being performed on a partially compiled function if it is called recursively. Previous Comments: ------------------------------------------------------------------------ [2019-09-06 08:53:22] nikic@php.net I think the issue is an incorrect calculation of the VM stack size for one of the tree_map calls: L3 (17): INIT_FCALL 3 176 string("tree_map") The size is 11*16, which it should be 14*16. ------------------------------------------------------------------------ [2019-09-06 08:46:33] phofstetter at sensational dot ch I have bisected the issue and found b36dbdd1dd431d1a21fdb6f2508c7c41b682466c to be the culprit. I tried to naïvely just revert that one commit, but of course other changes happened since then and I'm definitely not good enough to deal with the internals at this level in order to fix the ensuing conflicts. ------------------------------------------------------------------------ [2019-09-06 08:05:54] nikic@php.net Looks like an icall retval slot ends up pointing into the execute_data frame and clobbers func. ------------------------------------------------------------------------ [2019-09-06 06:45:39] phofstetter at sensational dot ch one last update: This happens independently of whether opcache is loaded or not. ------------------------------------------------------------------------ [2019-09-06 06:41:05] phofstetter at sensational dot ch On Debian 10, the attached test script also crashes with a debugger attached. Here's the backtrace: (gdb) run segv.php Starting program: /opt/php/7.4/bin/php segv.php [Thread debugging using libthread_db enabled] Using host libthread_db library "/lib/x86_64-linux-gnu/libthread_db.so.1". Program received signal SIGSEGV, Segmentation fault. 0x0000555555a881fb in zend_call_function (fci=fci@entry=0x7fffffffa8a0, fci_cache=fci_cache@entry=0x7fffffffa880) at /home/crazyhat/downloads/php-7.4.0RC1/Zend/zend_execute_API.c:681 681 } else if (EG(current_execute_data)->func && (gdb) bt #0 0x0000555555a881fb in zend_call_function (fci=fci@entry=0x7fffffffa8a0, fci_cache=fci_cache@entry=0x7fffffffa880) at /home/crazyhat/downloads/php-7.4.0RC1/Zend/zend_execute_API.c:681 #1 0x00005555559c6428 in zif_array_map (execute_data=<optimized out>, return_value=0x7ffff4013350) at /home/crazyhat/downloads/php-7.4.0RC1/ext/standard/array.c:6203 #2 0x0000555555b10820 in ZEND_DO_ICALL_SPEC_RETVAL_USED_HANDLER () at /home/crazyhat/downloads/php-7.4.0RC1/Zend/zend_vm_execute.h:1323 #3 execute_ex (ex=0x7fffffffa8a0) at /home/crazyhat/downloads/php-7.4.0RC1/Zend/zend_vm_execute.h:53461 #4 0x0000555555a88826 in zend_call_function (fci=fci@entry=0x7fffffffaaf0, fci_cache=<optimized out>, fci_cache@entry=0x7fffffffaad0) at /home/crazyhat/downloads/php-7.4.0RC1/Zend/zend_execute_API.c:816 #5 0x00005555559c6428 in zif_array_map (execute_data=<optimized out>, return_value=0x7ffff4013170) at /home/crazyhat/downloads/php-7.4.0RC1/ext/standard/array.c:6203 #6 0x0000555555b10820 in ZEND_DO_ICALL_SPEC_RETVAL_USED_HANDLER () at /home/crazyhat/downloads/php-7.4.0RC1/Zend/zend_vm_execute.h:1323 #7 execute_ex (ex=0x7fffffffa8a0) at /home/crazyhat/downloads/php-7.4.0RC1/Zend/zend_vm_execute.h:53461 #8 0x0000555555b16a63 in zend_execute (op_array=0x7ffff407c2a0, return_value=<optimized out>) at /home/crazyhat/downloads/php-7.4.0RC1/Zend/zend_vm_execute.h:57561 #9 0x0000555555a964c4 in zend_execute_scripts (type=type@entry=8, retval=0x7ffff40130b0, retval@entry=0x0, file_count=file_count@entry=3) at /home/crazyhat/downloads/php-7.4.0RC1/Zend/zend.c:1663 #10 0x0000555555a39fa0 in php_execute_script (primary_file=<optimized out>) at /home/crazyhat/downloads/php-7.4.0RC1/main/main.c:2619 #11 0x0000555555b18a66 in do_cli (argc=2, argv=0x55555677a5d0) at /home/crazyhat/downloads/php-7.4.0RC1/sapi/cli/php_cli.c:961 #12 0x0000555555794239 in main (argc=2, argv=0x55555677a5d0) at /home/crazyhat/downloads/php-7.4.0RC1/sapi/cli/php_cli.c:1352 ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=78502 -- Edit this bug report at https://bugs.php.net/bug.php?id=78502&edit=1

« previous php.bugs (#222598) next »