Bug #78752 [Com]: Segfault in lex_scan
Edit report at https://bugs.php.net/bug.php?id=78752&edit=1
ID: 78752
Comment by: kelunik@php.net
Reported by: kelunik@php.net
Summary: Segfault in lex_scan
Status: Open
Type: Bug
Package: Reproducible crash
Operating System: Linux
PHP Version: 7.2.24
Block user comment: N
Private report: N
New Comment:
If I revert this one line [1], it no longer crashes.
[1]: https://github.com/amphp/http-client/commit/f0facd7100b240407ce7aec9817d56febf97618e#diff-e8ff33b36d2294e336921a814352ddf2R177
Previous Comments:
------------------------------------------------------------------------
[2019-10-25 23:17:07] kelunik@php.net
Description:
------------
Clone https://github.com/amphp/http-client/tree/f0facd7100b240407ce7aec9817d56febf97618e
Run composer install
Run vendor/bin/phpunit
Note: The version paths below indicate 7.3.9, but the same applies to 7.3.11. It's not 100%
reproducible, but most runs result in a segfault.
Expected result:
----------------
No segfault.
Actual result:
--------------
Segfault: https://travis-ci.org/amphp/http-client/builds/603057296
â phpgdb
phpenv v0.0.4-dev
GNU gdb (Ubuntu 8.2.91.20190405-0ubuntu3) 8.2.91.20190405-git
Copyright (C) 2019 Free Software Foundation, Inc.
License GPLv3+: GNU GPL version 3 or later <http://gnu.org/licenses/gpl.html>
This is free software: you are free to change and redistribute it.
There is NO WARRANTY, to the extent permitted by law.
Type "show copying" and "show warranty" for details.
This GDB was configured as "x86_64-linux-gnu".
Type "show configuration" for configuration details.
For bug reporting instructions, please see:
<http://www.gnu.org/software/gdb/bugs/>.
Find the GDB manual and other documentation resources online at:
<http://www.gnu.org/software/gdb/documentation/>.
For help, type "help".
Type "apropos word" to search for commands related to "word"...
Reading symbols from /home/kelunik/.phpenv/versions/7.3.9/bin/php...
(gdb) r Quit
(gdb) r vendor/bin/phpunit
Starting program: /home/kelunik/.phpenv/versions/7.3.9/bin/php vendor/bin/phpunit
[Thread debugging using libthread_db enabled]
Using host libthread_db library "/lib/x86_64-linux-gnu/libthread_db.so.1".
[Detaching after vfork from child process 1591]
PHPUnit 8.4.1 by Sebastian Bergmann and contributors.
.........................[Detaching after fork from child process 1594]
.[Detaching after fork from child process 1625]
[Detaching after fork from child process 1627]
.........E........................... 63 / 128 ( 49%)
.......[Detaching after fork from child process 1663]
...
Program received signal SIGSEGV, Segmentation fault.
zend_mm_alloc_small (bin_num=17, size=336, heap=0x7ffff4000040)
at /home/kelunik/.php-build/release/Zend/zend_alloc.c:1289
1289 /home/kelunik/.php-build/release/Zend/zend_alloc.c: Datei oder Verzeichnis nicht gefunden.
(gdb) bt
#0 zend_mm_alloc_small (bin_num=17, size=336, heap=0x7ffff4000040)
at /home/kelunik/.php-build/release/Zend/zend_alloc.c:1289
#1 zend_mm_alloc_heap (size=336, heap=0x7ffff4000040)
at /home/kelunik/.php-build/release/Zend/zend_alloc.c:1360
#2 _emalloc (size=size@entry=336) at /home/kelunik/.php-build/release/Zend/zend_alloc.c:2500
#3 0x0000555555b0116b in zend_string_alloc (persistent=0, len=308)
at /home/kelunik/.php-build/release/Zend/zend_string.h:155
#4 zend_string_init (persistent=0, len=308,
str=0x7ffff7fb001b "/**\n * This Logger can be used to avoid conditional log calls.\n *\n *
Logging should always be optional, and if no logger is provided to your\n * library creating a
NullLogger instance to have something"...) at
/home/kelunik/.php-build/release/Zend/zend_string.h:155
#5 lex_scan (zendlval=zendlval@entry=0x7fffffff8e70, elem=0x7fffffff8ef8)
at Zend/zend_language_scanner.l:2108
#6 0x0000555555b14bda in zendlex (elem=elem@entry=0x7fffffff8ef8)
at /home/kelunik/.php-build/release/Zend/zend_compile.c:1702
#7 0x0000555555afa45e in zendparse ()
at /home/kelunik/.php-build/release/Zend/zend_language_parser.c:4215
#8 0x0000555555afc95a in zend_compile (type=type@entry=2) at Zend/zend_language_scanner.l:586
#9 0x0000555555afe13a in compile_file (file_handle=0x7fffffff9be0, type=2)
at Zend/zend_language_scanner.l:636
#10 0x00005555559bc692 in phar_compile_file (file_handle=0x7fffffff9be0, type=2)
at /home/kelunik/.php-build/release/ext/phar/phar.c:3347
#11 0x0000555555afe1e2 in compile_filename (type=type@entry=2,
filename=filename@entry=0x7ffff40230d0) at Zend/zend_language_scanner.l:661
#12 0x0000555555b77315 in zend_include_or_eval (inc_filename=0x7ffff40230d0, type=2)
at /home/kelunik/.php-build/release/Zend/zend_execute.c:3192
#13 0x0000555555bad8ba in ZEND_INCLUDE_OR_EVAL_SPEC_CV_HANDLER ()
at /home/kelunik/.php-build/release/Zend/zend_vm_execute.h:37419
#14 0x0000555555bb24ed in execute_ex (ex=0x3e5d0e0)
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=78752&edit=1
Thread (6 messages)