Bug #78502 [Ver->Asn]: Segmentation Fault in array_map
| From: | nikic@php.net | Date: | Fri, 06 Sep 2019 09:00:36 +0000 |
| Subject: | Bug #78502 [Ver->Asn]: Segmentation Fault in array_map | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-222598@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=78502&edit=1
ID: 78502
Updated by: nikic@php.net
Reported by: phofstetter at sensational dot ch
Summary: Segmentation Fault in array_map
-Status: Verified
+Status: Assigned
Type: Bug
Package: Reproducible crash
Operating System: macos 10.14, Debian 10
PHP Version: 7.4.0RC1
-Assigned To:
+Assigned To: nikic
Block user comment: N
Private report: N
New Comment:
@phofstetter: That commit is indeed relevant, because it changed the registration of the function to
happen when we start to compile the function, rather than once it has been fully compiled. That
means that stack size calculations end up being performed on a partially compiled function if it is
called recursively.
Previous Comments:
------------------------------------------------------------------------
[2019-09-06 08:53:22] nikic@php.net
I think the issue is an incorrect calculation of the VM stack size for one of the tree_map calls:
L3 (17): INIT_FCALL 3 176 string("tree_map")
The size is 11*16, which it should be 14*16.
------------------------------------------------------------------------
[2019-09-06 08:46:33] phofstetter at sensational dot ch
I have bisected the issue and found
b36dbdd1dd431d1a21fdb6f2508c7c41b682466c
to be the culprit. I tried to naïvely just revert that one commit, but of course other changes
happened since then and I'm definitely not good enough to deal with the internals at this level
in order to fix the ensuing conflicts.
------------------------------------------------------------------------
[2019-09-06 08:05:54] nikic@php.net
Looks like an icall retval slot ends up pointing into the execute_data frame and clobbers func.
------------------------------------------------------------------------
[2019-09-06 06:45:39] phofstetter at sensational dot ch
one last update: This happens independently of whether opcache is loaded or not.
------------------------------------------------------------------------
[2019-09-06 06:41:05] phofstetter at sensational dot ch
On Debian 10, the attached test script also crashes with a debugger attached. Here's the
backtrace:
(gdb) run segv.php
Starting program: /opt/php/7.4/bin/php segv.php
[Thread debugging using libthread_db enabled]
Using host libthread_db library "/lib/x86_64-linux-gnu/libthread_db.so.1".
Program received signal SIGSEGV, Segmentation fault.
0x0000555555a881fb in zend_call_function (fci=fci@entry=0x7fffffffa8a0,
fci_cache=fci_cache@entry=0x7fffffffa880)
at /home/crazyhat/downloads/php-7.4.0RC1/Zend/zend_execute_API.c:681
681 } else if (EG(current_execute_data)->func &&
(gdb) bt
#0 0x0000555555a881fb in zend_call_function (fci=fci@entry=0x7fffffffa8a0,
fci_cache=fci_cache@entry=0x7fffffffa880)
at /home/crazyhat/downloads/php-7.4.0RC1/Zend/zend_execute_API.c:681
#1 0x00005555559c6428 in zif_array_map (execute_data=<optimized out>,
return_value=0x7ffff4013350)
at /home/crazyhat/downloads/php-7.4.0RC1/ext/standard/array.c:6203
#2 0x0000555555b10820 in ZEND_DO_ICALL_SPEC_RETVAL_USED_HANDLER () at
/home/crazyhat/downloads/php-7.4.0RC1/Zend/zend_vm_execute.h:1323
#3 execute_ex (ex=0x7fffffffa8a0) at
/home/crazyhat/downloads/php-7.4.0RC1/Zend/zend_vm_execute.h:53461
#4 0x0000555555a88826 in zend_call_function (fci=fci@entry=0x7fffffffaaf0, fci_cache=<optimized
out>, fci_cache@entry=0x7fffffffaad0)
at /home/crazyhat/downloads/php-7.4.0RC1/Zend/zend_execute_API.c:816
#5 0x00005555559c6428 in zif_array_map (execute_data=<optimized out>,
return_value=0x7ffff4013170)
at /home/crazyhat/downloads/php-7.4.0RC1/ext/standard/array.c:6203
#6 0x0000555555b10820 in ZEND_DO_ICALL_SPEC_RETVAL_USED_HANDLER () at
/home/crazyhat/downloads/php-7.4.0RC1/Zend/zend_vm_execute.h:1323
#7 execute_ex (ex=0x7fffffffa8a0) at
/home/crazyhat/downloads/php-7.4.0RC1/Zend/zend_vm_execute.h:53461
#8 0x0000555555b16a63 in zend_execute (op_array=0x7ffff407c2a0, return_value=<optimized out>)
at /home/crazyhat/downloads/php-7.4.0RC1/Zend/zend_vm_execute.h:57561
#9 0x0000555555a964c4 in zend_execute_scripts (type=type@entry=8, retval=0x7ffff40130b0,
retval@entry=0x0, file_count=file_count@entry=3)
at /home/crazyhat/downloads/php-7.4.0RC1/Zend/zend.c:1663
#10 0x0000555555a39fa0 in php_execute_script (primary_file=<optimized out>) at
/home/crazyhat/downloads/php-7.4.0RC1/main/main.c:2619
#11 0x0000555555b18a66 in do_cli (argc=2, argv=0x55555677a5d0) at
/home/crazyhat/downloads/php-7.4.0RC1/sapi/cli/php_cli.c:961
#12 0x0000555555794239 in main (argc=2, argv=0x55555677a5d0) at
/home/crazyhat/downloads/php-7.4.0RC1/sapi/cli/php_cli.c:1352
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=78502
--
Edit this bug report at https://bugs.php.net/bug.php?id=78502&edit=1