Bug #78811 [Com]: Crash seen during cyclic garbage collection in Phan's unit tests

From: Date: Thu, 14 Nov 2019 02:43:05 +0000
Subject: Bug #78811 [Com]: Crash seen during cyclic garbage collection in Phan's unit tests
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-223708@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=78811&edit=1 ID: 78811 Comment by: tandre@php.net Reported by: tandre@php.net Summary: Crash seen during cyclic garbage collection in Phan's unit tests Status: Open Type: Bug Package: Reproducible crash Operating System: Linux Mint 18.3 Sylvia PHP Version: Next Major Version Block user comment: N Private report: N New Comment: A few more details can be found at https://github.com/phan/phan/issues/3511 Previous Comments: ------------------------------------------------------------------------ [2019-11-14 02:41:56] tandre@php.net Description: ------------ This occurs even with a clean build. I failed to create a minimal example - it might require garbage collection at a specific time with a specific number of references to an object/closure, for all I know. - It crashes within array_map, seemingly trying to garbage collect the object which a method is being called on and crashing. NTS(Debug/normal) and ZTS(tried Debug) builds are having this issue for me. Build script used: https://github.com/TysonAndre/php-src/blob/travis-debug/travis/compile.sh revision 15fb532 (git clean -fdx and different install folders were used) PHP ini: extension=ast.so zend_extension=opcache.so opcache.protect_memory=1 opcache.enable_cli=1 short_open_tag=0 display_errors=stderr error_reporting=E_ALL Script used: # after composer.phar install on https://github.com/phan/phan/commit/1a0d7a67742d1727d12dd8556e849c72c71a4de3 USE_ZEND_ALLOC=0 gdb -args which php vendor/bin/phpunit --stop-on-error --stop-on-failure tests/Phan/PhanTest5.php ..... (gdb) run The program being debugged has been started already. Start it from the beginning? (y or n) y Starting program: /home/tyson/php-8.0.0-debug-opcache-install/bin/php vendor/bin/phpunit tests/Phan/PhanTest5.php [Thread debugging using libthread_db enabled] Using host libthread_db library "/lib/x86_64-linux-gnu/libthread_db.so.1". PHPUnit 7.5.17 by Sebastian Bergmann and contributors. WARNING: Phan is around twice as slow when php is compiled with --enable-debug (That option is only needed when debugging Phan itself). (The above warning(s) about slow PHP settings can be disabled by setting 'skip_slow_php_options_warning' to true in .phan/config.php) .................F............................................. 63 / 105 ( 60%) .....F................... Program received signal SIGSEGV, Segmentation fault. 0x0000000000aad751 in zend_gc_collect_cycles () at /path/to/php-src/Zend/zend_gc.c:1562 1562 current->ref = GC_MAKE_GARBAGE(((char*)obj) - obj->handlers->offset); (gdb) bt #0 0x0000000000aad751 in zend_gc_collect_cycles () at /path/to/php-src/Zend/zend_gc.c:1562 #1 0x0000000000aab370 in gc_possible_root_when_full (ref=0x7fffe8328700) at /path/to/php-src/Zend/zend_gc.c:592 #2 0x0000000000aab4f3 in gc_possible_root (ref=0x7fffe8328700) at /path/to/php-src/Zend/zend_gc.c:642 #3 0x0000000000ad516f in zend_object_release (obj=0x7fffe8328700) at /path/to/php-src/Zend/zend_objects_API.h:77 #4 0x0000000000b426e4 in execute_ex (ex=0x7fffeb6155e0) at /path/to/php-src/Zend/zend_vm_execute.h:51386 #5 0x0000000000a6133f in zend_call_function (fci=0x7fffffff9d70, fci_cache=0x7fffffff9d50) at /path/to/php-src/Zend/zend_execute_API.c:779 #6 0x000000000087fb1d in zif_array_map (execute_data=0x7fffeb615570, return_value=0x7fffeb615560) at /path/to/php-src/ext/standard/array.c:6221 #7 0x0000000000ae354e in ZEND_DO_ICALL_SPEC_RETVAL_USED_HANDLER () at /path/to/php-src/Zend/zend_vm_execute.h:1278 #8 0x0000000000b42b0c in execute_ex (ex=0x7fffeb614020) at /path/to/php-src/Zend/zend_vm_execute.h:51498 #9 0x0000000000b46b39 in zend_execute (op_array=0x7fffeb672300, return_value=0x0) at /path/to/php-src/Zend/zend_vm_execute.h:55566 #10 0x0000000000a771e3 in zend_execute_scripts (type=8, retval=0x0, file_count=3) at /path/to/php-src/Zend/zend.c:1666 #11 0x00000000009e4a1f in php_execute_script (primary_file=0x7fffffffc570) at /path/to/php-src/main/main.c:2586 #12 0x0000000000b49495 in do_cli (argc=3, argv=0x186e7d0) at /path/to/php-src/sapi/cli/php_cli.c:959 #13 0x0000000000b4a4b5 in main (argc=3, argv=0x186e7d0) at /path/to/php-src/sapi/cli/php_cli.c:1350 ------ Possible thoughts on why I saw this: - ReflectionUnionType->__toString() (unlikely) - Pre-existing issue in php 8 that got exposed due to different number of objects getting created - Changes internally in how zend_closure objects get fetched - this was in an array_map for an instance closure. ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=78811&edit=1

« previous php.bugs (#223708) next »