Bug #78811 [NEW]: Crash seen during cyclic garbage collection in Phan's unit tests
| From: | tandre@php.net | Date: | Thu, 14 Nov 2019 02:41:56 +0000 |
| Subject: | Bug #78811 [NEW]: Crash seen during cyclic garbage collection in Phan's unit tests | ||
| Groups: | php.bugs | ||
| Request: | Send a blank email to php-bugs+get-223707@lists.php.net to get a copy of this message | ||
From: tandre
Operating system: Linux Mint 18.3 Sylvia
PHP version: Next Major Version
Package: Reproducible crash
Bug Type: Bug
Bug description:Crash seen during cyclic garbage collection in Phan's unit tests
Description:
------------
This occurs even with a clean build. I failed to create a minimal
example - it might require garbage collection at a specific time with a
specific number of references to an object/closure, for all I know.
- It crashes within array_map, seemingly trying to garbage collect the
object which a method is being called on and crashing.
NTS(Debug/normal) and ZTS(tried Debug) builds are having this issue for
me.
Build script used:
https://github.com/TysonAndre/php-src/blob/travis-debug/travis/compile.sh
revision 15fb532 (
git clean -fdx and different install folders were
used)
PHP ini:
extension=ast.so
zend_extension=opcache.so
opcache.protect_memory=1
opcache.enable_cli=1
short_open_tag=0
display_errors=stderr
error_reporting=E_ALL
Script used:
# after composer.phar install on
https://github.com/phan/phan/commit/1a0d7a67742d1727d12dd8556e849c72c71a4de3
USE_ZEND_ALLOC=0 gdb -args which php vendor/bin/phpunit
--stop-on-error --stop-on-failure tests/Phan/PhanTest5.php
.....
(gdb) run
The program being debugged has been started already.
Start it from the beginning? (y or n) y
Starting program: /home/tyson/php-8.0.0-debug-opcache-install/bin/php
vendor/bin/phpunit tests/Phan/PhanTest5.php
[Thread debugging using libthread_db enabled]
Using host libthread_db library
"/lib/x86_64-linux-gnu/libthread_db.so.1".
PHPUnit 7.5.17 by Sebastian Bergmann and contributors.
WARNING: Phan is around twice as slow when php is compiled with
--enable-debug (That option is only needed when debugging Phan itself).
(The above warning(s) about slow PHP settings can be disabled by setting
'skip_slow_php_options_warning' to true in .phan/config.php)
.................F............................................. 63 /
105 ( 60%)
.....F...................
Program received signal SIGSEGV, Segmentation fault.
0x0000000000aad751 in zend_gc_collect_cycles ()
at /path/to/php-src/Zend/zend_gc.c:1562
1562 current->ref =
GC_MAKE_GARBAGE(((char*)obj) - obj->handlers->offset);
(gdb) bt
#0 0x0000000000aad751 in zend_gc_collect_cycles ()
at /path/to/php-src/Zend/zend_gc.c:1562
#1 0x0000000000aab370 in gc_possible_root_when_full
(ref=0x7fffe8328700)
at /path/to/php-src/Zend/zend_gc.c:592
#2 0x0000000000aab4f3 in gc_possible_root (ref=0x7fffe8328700)
at /path/to/php-src/Zend/zend_gc.c:642
#3 0x0000000000ad516f in zend_object_release (obj=0x7fffe8328700)
at /path/to/php-src/Zend/zend_objects_API.h:77
#4 0x0000000000b426e4 in execute_ex (ex=0x7fffeb6155e0)
at /path/to/php-src/Zend/zend_vm_execute.h:51386
#5 0x0000000000a6133f in zend_call_function (fci=0x7fffffff9d70,
fci_cache=0x7fffffff9d50)
at /path/to/php-src/Zend/zend_execute_API.c:779
#6 0x000000000087fb1d in zif_array_map (execute_data=0x7fffeb615570,
return_value=0x7fffeb615560)
at /path/to/php-src/ext/standard/array.c:6221
#7 0x0000000000ae354e in ZEND_DO_ICALL_SPEC_RETVAL_USED_HANDLER ()
at /path/to/php-src/Zend/zend_vm_execute.h:1278
#8 0x0000000000b42b0c in execute_ex (ex=0x7fffeb614020)
at /path/to/php-src/Zend/zend_vm_execute.h:51498
#9 0x0000000000b46b39 in zend_execute (op_array=0x7fffeb672300,
return_value=0x0)
at /path/to/php-src/Zend/zend_vm_execute.h:55566
#10 0x0000000000a771e3 in zend_execute_scripts (type=8, retval=0x0,
file_count=3)
at /path/to/php-src/Zend/zend.c:1666
#11 0x00000000009e4a1f in php_execute_script
(primary_file=0x7fffffffc570)
at /path/to/php-src/main/main.c:2586
#12 0x0000000000b49495 in do_cli (argc=3, argv=0x186e7d0)
at /path/to/php-src/sapi/cli/php_cli.c:959
#13 0x0000000000b4a4b5 in main (argc=3, argv=0x186e7d0)
at /path/to/php-src/sapi/cli/php_cli.c:1350
------
Possible thoughts on why I saw this:
- ReflectionUnionType->__toString() (unlikely)
- Pre-existing issue in php 8 that got exposed due to different number
of objects getting created
- Changes internally in how zend_closure objects get fetched - this was
in an array_map for an instance closure.
--
Edit bug report at https://bugs.php.net/bug.php?id=78811&edit=1
--
Fix committed: https://bugs.php.net/fix.php?id=78811&r=fixed
Fixed in release: https://bugs.php.net/fix.php?id=78811&r=alreadyfixed
Need backtrace: https://bugs.php.net/fix.php?id=78811&r=needtrace
Need Reproduce Script: https://bugs.php.net/fix.php?id=78811&r=needscript
Try newer version: https://bugs.php.net/fix.php?id=78811&r=oldversion
Not developer issue: https://bugs.php.net/fix.php?id=78811&r=support
Expected behavior: https://bugs.php.net/fix.php?id=78811&r=notwrong
Not enough info: https://bugs.php.net/fix.php?id=78811&r=notenoughinfo
Submitted twice: https://bugs.php.net/fix.php?id=78811&r=submittedtwice
register_globals: https://bugs.php.net/fix.php?id=78811&r=globals
PHP version support discontinued: https://bugs.php.net/fix.php?id=78811&r=phptooold
Daylight Savings: https://bugs.php.net/fix.php?id=78811&r=dst
IIS Stability: https://bugs.php.net/fix.php?id=78811&r=isapi
Install GNU Sed: https://bugs.php.net/fix.php?id=78811&r=gnused
Floating point limitations: https://bugs.php.net/fix.php?id=78811&r=float
No Zend Extensions: https://bugs.php.net/fix.php?id=78811&r=nozend
MySQL Configuration Error: https://bugs.php.net/fix.php?id=78811&r=mysqlcfg