Bug #78811 [Com]: Crash seen during cyclic garbage collection in Phan's unit tests
| From: | tandre@php.net | Date: | Fri, 15 Nov 2019 14:44:48 +0000 |
| Subject: | Bug #78811 [Com]: Crash seen during cyclic garbage collection in Phan's unit tests | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-223736@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=78811&edit=1
ID: 78811
Comment by: tandre@php.net
Reported by: tandre@php.net
Summary: Crash seen during cyclic garbage collection in
Phan's unit tests
Status: Feedback
Type: Bug
Package: Reproducible crash
Operating System: Linux Mint 18.3 Sylvia
PHP Version: Next Major Version
Block user comment: N
Private report: N
New Comment:
The valgrind errors I saw with php ZTS debug after the str_pad fix are below - I see the memory that
was pointed to was realloced?
gcc --version
gcc (Ubuntu 5.4.0-6ubuntu1~16.04.12) 5.4.0 20160609
~/programming/phan ±1a0d7a677⡠» php --version
PHP 8.0.0-dev (cli) (built: Nov 15 2019 08:35:24) ( ZTS DEBUG )
Copyright (c) The PHP Group
Zend Engine v4.0.0-dev, Copyright (c) Zend Technologies
with Zend OPcache v8.0.0-dev, Copyright (c), by Zend Technologies
~/programming/phan ±1a0d7a677⡠» valgrind
which php vendor/bin/phpunit
tests/Phan/PhanTest5.php
==23609== Memcheck, a memory error detector
==23609== Copyright (C) 2002-2015, and GNU GPL'd, by Julian Seward et al.
==23609== Using Valgrind-3.11.0 and LibVEX; rerun with -h for copyright info
==23609== Command: /path/to/php-8.0.0-debug-opcache-zts-install/bin/php vendor/bin/phpunit
tests/Phan/PhanTest5.php
==23609==
PHPUnit 7.5.17 by Sebastian Bergmann and contributors.
WARNING: Phan is around twice as slow when php is compiled with --enable-debug (That option is only
needed when debugging Phan itself).
(The above warning(s) about slow PHP settings can be disabled by setting
'skip_slow_php_options_warning' to true in .phan/config.php)
.................F............................................. 63 / 105 ( 60%)
.....F...................==23609== Invalid write of size 8
==23609== at 0xB24BFA: zend_gc_collect_cycles (zend_gc.c:1562)
==23609== by 0xB223EB: gc_possible_root_when_full (zend_gc.c:592)
==23609== by 0xB22621: gc_possible_root (zend_gc.c:642)
==23609== by 0xB4E55D: zend_object_release (zend_objects_API.h:77)
==23609== by 0xBBFE31: execute_ex (zend_vm_execute.h:51386)
==23609== by 0xAD4409: zend_call_function (zend_execute_API.c:779)
==23609== by 0x8A4B79: zif_array_map (array.c:6221)
==23609== by 0xB5D5FE: ZEND_DO_ICALL_SPEC_RETVAL_USED_HANDLER (zend_vm_execute.h:1278)
==23609== by 0xBC02F1: execute_ex (zend_vm_execute.h:51498)
==23609== by 0xBC4393: zend_execute (zend_vm_execute.h:55566)
==23609== by 0xAEBE76: zend_execute_scripts (zend.c:1666)
==23609== by 0xA44A2B: php_execute_script (main.c:2586)
==23609== Address 0x1a8be750 is 16 bytes inside a block of size 262,144 free'd
==23609== at 0x4C2FD5F: realloc (in /usr/lib/valgrind/vgpreload_memcheck-amd64-linux.so)
==23609== by 0xAB1298: __zend_realloc (zend_alloc.c:2994)
==23609== by 0xB221E3: gc_grow_root_buffer (zend_gc.c:548)
==23609== by 0xB224AA: gc_possible_root_when_full (zend_gc.c:606)
==23609== by 0xB22621: gc_possible_root (zend_gc.c:642)
==23609== by 0xAE6811: gc_check_possible_root (zend_gc.h:83)
==23609== by 0xAE6863: i_zval_ptr_dtor (zend_variables.h:46)
==23609== by 0xAE6A38: zval_ptr_dtor (zend_variables.c:84)
==23609== by 0x867BCA: spl_object_storage_dtor (spl_observer.c:151)
==23609== by 0xB029B7: zend_hash_destroy (zend_hash.c:1544)
==23609== by 0x867A18: spl_SplObjectStorage_free_storage (spl_observer.c:108)
==23609== by 0xB428BA: zend_objects_store_del (zend_objects_API.c:193)
==23609== Block was alloc'd at
==23609== at 0x4C2FD5F: realloc (in /usr/lib/valgrind/vgpreload_memcheck-amd64-linux.so)
==23609== by 0xAB1298: __zend_realloc (zend_alloc.c:2994)
==23609== by 0xB221E3: gc_grow_root_buffer (zend_gc.c:548)
==23609== by 0xB2228B: gc_adjust_threshold (zend_gc.c:567)
==23609== by 0xB223F2: gc_possible_root_when_full (zend_gc.c:592)
==23609== by 0xB22621: gc_possible_root (zend_gc.c:642)
==23609== by 0xB4E55D: zend_object_release (zend_objects_API.h:77)
==23609== by 0xBBFE31: execute_ex (zend_vm_execute.h:51386)
==23609== by 0xBC4393: zend_execute (zend_vm_execute.h:55566)
==23609== by 0xAEBE76: zend_execute_scripts (zend.c:1666)
==23609== by 0xA44A2B: php_execute_script (main.c:2586)
==23609== by 0xBC6CD3: do_cli (php_cli.c:959)
==23609==
==23609== Invalid read of size 8
==23609== at 0xB24A48: zend_gc_collect_cycles (zend_gc.c:1545)
==23609== by 0xB223EB: gc_possible_root_when_full (zend_gc.c:592)
==23609== by 0xB22621: gc_possible_root (zend_gc.c:642)
==23609== by 0xB4E55D: zend_object_release (zend_objects_API.h:77)
==23609== by 0xBBFE31: execute_ex (zend_vm_execute.h:51386)
==23609== by 0xAD4409: zend_call_function (zend_execute_API.c:779)
==23609== by 0x8A4B79: zif_array_map (array.c:6221)
==23609== by 0xB5D5FE: ZEND_DO_ICALL_SPEC_RETVAL_USED_HANDLER (zend_vm_execute.h:1278)
==23609== by 0xBC02F1: execute_ex (zend_vm_execute.h:51498)
==23609== by 0xBC4393: zend_execute (zend_vm_execute.h:55566)
==23609== by 0xAEBE76: zend_execute_scripts (zend.c:1666)
==23609== by 0xA44A2B: php_execute_script (main.c:2586)
==23609== Address 0x1a8be758 is 24 bytes inside a block of size 262,144 free'd
==23609== at 0x4C2FD5F: realloc (in /usr/lib/valgrind/vgpreload_memcheck-amd64-linux.so)
==23609== by 0xAB1298: __zend_realloc (zend_alloc.c:2994)
==23609== by 0xB221E3: gc_grow_root_buffer (zend_gc.c:548)
==23609== by 0xB224AA: gc_possible_root_when_full (zend_gc.c:606)
==23609== by 0xB22621: gc_possible_root (zend_gc.c:642)
==23609== by 0xAE6811: gc_check_possible_root (zend_gc.h:83)
==23609== by 0xAE6863: i_zval_ptr_dtor (zend_variables.h:46)
==23609== by 0xAE6A38: zval_ptr_dtor (zend_variables.c:84)
==23609== by 0x867BCA: spl_object_storage_dtor (spl_observer.c:151)
==23609== by 0xB029B7: zend_hash_destroy (zend_hash.c:1544)
==23609== by 0x867A18: spl_SplObjectStorage_free_storage (spl_observer.c:108)
==23609== by 0xB428BA: zend_objects_store_del (zend_objects_API.c:193)
==23609== Block was alloc'd at
==23609== at 0x4C2FD5F: realloc (in /usr/lib/valgrind/vgpreload_memcheck-amd64-linux.so)
==23609== by 0xAB1298: __zend_realloc (zend_alloc.c:2994)
==23609== by 0xB221E3: gc_grow_root_buffer (zend_gc.c:548)
==23609== by 0xB2228B: gc_adjust_threshold (zend_gc.c:567)
==23609== by 0xB223F2: gc_possible_root_when_full (zend_gc.c:592)
==23609== by 0xB22621: gc_possible_root (zend_gc.c:642)
==23609== by 0xB4E55D: zend_object_release (zend_objects_API.h:77)
==23609== by 0xBBFE31: execute_ex (zend_vm_execute.h:51386)
==23609== by 0xBC4393: zend_execute (zend_vm_execute.h:55566)
==23609== by 0xAEBE76: zend_execute_scripts (zend.c:1666)
==23609== by 0xA44A2B: php_execute_script (main.c:2586)
==23609== by 0xBC6CD3: do_cli (php_cli.c:959)
==23609==
==23609== Invalid read of size 8
==23609== at 0xB24A5F: zend_gc_collect_cycles (zend_gc.c:1546)
==23609== by 0xB223EB: gc_possible_root_when_full (zend_gc.c:592)
==23609== by 0xB22621: gc_possible_root (zend_gc.c:642)
==23609== by 0xB4E55D: zend_object_release (zend_objects_API.h:77)
==23609== by 0xBBFE31: execute_ex (zend_vm_execute.h:51386)
==23609== by 0xAD4409: zend_call_function (zend_execute_API.c:779)
==23609== by 0x8A4B79: zif_array_map (array.c:6221)
==23609== by 0xB5D5FE: ZEND_DO_ICALL_SPEC_RETVAL_USED_HANDLER (zend_vm_execute.h:1278)
==23609== by 0xBC02F1: execute_ex (zend_vm_execute.h:51498)
==23609== by 0xBC4393: zend_execute (zend_vm_execute.h:55566)
==23609== by 0xAEBE76: zend_execute_scripts (zend.c:1666)
==23609== by 0xA44A2B: php_execute_script (main.c:2586)
==23609== Address 0x1a8be758 is 24 bytes inside a block of size 262,144 free'd
==23609== at 0x4C2FD5F: realloc (in /usr/lib/valgrind/vgpreload_memcheck-amd64-linux.so)
==23609== by 0xAB1298: __zend_realloc (zend_alloc.c:2994)
==23609== by 0xB221E3: gc_grow_root_buffer (zend_gc.c:548)
==23609== by 0xB224AA: gc_possible_root_when_full (zend_gc.c:606)
==23609== by 0xB22621: gc_possible_root (zend_gc.c:642)
==23609== by 0xAE6811: gc_check_possible_root (zend_gc.h:83)
==23609== by 0xAE6863: i_zval_ptr_dtor (zend_variables.h:46)
==23609== by 0xAE6A38: zval_ptr_dtor (zend_variables.c:84)
==23609== by 0x867BCA: spl_object_storage_dtor (spl_observer.c:151)
==23609== by 0xB029B7: zend_hash_destroy (zend_hash.c:1544)
==23609== by 0x867A18: spl_SplObjectStorage_free_storage (spl_observer.c:108)
==23609== by 0xB428BA: zend_objects_store_del (zend_objects_API.c:193)
==23609== Block was alloc'd at
==23609== at 0x4C2FD5F: realloc (in /usr/lib/valgrind/vgpreload_memcheck-amd64-linux.so)
==23609== by 0xAB1298: __zend_realloc (zend_alloc.c:2994)
==23609== by 0xB221E3: gc_grow_root_buffer (zend_gc.c:548)
==23609== by 0xB2228B: gc_adjust_threshold (zend_gc.c:567)
==23609== by 0xB223F2: gc_possible_root_when_full (zend_gc.c:592)
==23609== by 0xB22621: gc_possible_root (zend_gc.c:642)
==23609== by 0xB4E55D: zend_object_release (zend_objects_API.h:77)
==23609== by 0xBBFE31: execute_ex (zend_vm_execute.h:51386)
==23609== by 0xBC4393: zend_execute (zend_vm_execute.h:55566)
==23609== by 0xAEBE76: zend_execute_scripts (zend.c:1666)
==23609== by 0xA44A2B: php_execute_script (main.c:2586)
==23609== by 0xBC6CD3: do_cli (php_cli.c:959)
==23609==
==23609== Conditional jump or move depends on uninitialised value(s)
==23609== at 0xB24CB6: zend_gc_collect_cycles (zend_gc.c:1581)
==23609== by 0xB223EB: gc_possible_root_when_full (zend_gc.c:592)
==23609== by 0xB22621: gc_possible_root (zend_gc.c:642)
==23609== by 0xB4E55D: zend_object_release (zend_objects_API.h:77)
==23609== by 0xBBFE31: execute_ex (zend_vm_execute.h:51386)
==23609== by 0xAD4409: zend_call_function (zend_execute_API.c:779)
==23609== by 0x8A4B79: zif_array_map (array.c:6221)
==23609== by 0xB5D5FE: ZEND_DO_ICALL_SPEC_RETVAL_USED_HANDLER (zend_vm_execute.h:1278)
==23609== by 0xBC02F1: execute_ex (zend_vm_execute.h:51498)
==23609== by 0xBC4393: zend_execute (zend_vm_execute.h:55566)
==23609== by 0xAEBE76: zend_execute_scripts (zend.c:1666)
==23609== by 0xA44A2B: php_execute_script (main.c:2586)
==23609==
==23609== Invalid read of size 8
==23609== at 0xB24CAC: zend_gc_collect_cycles (zend_gc.c:1581)
==23609== by 0xB223EB: gc_possible_root_when_full (zend_gc.c:592)
==23609== by 0xB22621: gc_possible_root (zend_gc.c:642)
==23609== by 0xB4E55D: zend_object_release (zend_objects_API.h:77)
==23609== by 0xBBFE31: execute_ex (zend_vm_execute.h:51386)
==23609== by 0xAD4409: zend_call_function (zend_execute_API.c:779)
==23609== by 0x8A4B79: zif_array_map (array.c:6221)
==23609== by 0xB5D5FE: ZEND_DO_ICALL_SPEC_RETVAL_USED_HANDLER (zend_vm_execute.h:1278)
==23609== by 0xBC02F1: execute_ex (zend_vm_execute.h:51498)
==23609== by 0xBC4393: zend_execute (zend_vm_execute.h:55566)
==23609== by 0xAEBE76: zend_execute_scripts (zend.c:1666)
==23609== by 0xA44A2B: php_execute_script (main.c:2586)
==23609== Address 0x1d505a60 is 0 bytes after a block of size 524,288 alloc'd
==23609== at 0x4C2FD5F: realloc (in /usr/lib/valgrind/vgpreload_memcheck-amd64-linux.so)
==23609== by 0xAB1298: __zend_realloc (zend_alloc.c:2994)
==23609== by 0xB221E3: gc_grow_root_buffer (zend_gc.c:548)
==23609== by 0xB224AA: gc_possible_root_when_full (zend_gc.c:606)
==23609== by 0xB22621: gc_possible_root (zend_gc.c:642)
==23609== by 0xAE6811: gc_check_possible_root (zend_gc.h:83)
==23609== by 0xAE6863: i_zval_ptr_dtor (zend_variables.h:46)
==23609== by 0xAE6A38: zval_ptr_dtor (zend_variables.c:84)
==23609== by 0x867BCA: spl_object_storage_dtor (spl_observer.c:151)
==23609== by 0xB029B7: zend_hash_destroy (zend_hash.c:1544)
==23609== by 0x867A18: spl_SplObjectStorage_free_storage (spl_observer.c:108)
==23609== by 0xB428BA: zend_objects_store_del (zend_objects_API.c:193)
==23609==
==23609== Invalid read of size 4
==23609== at 0xAAD619: zend_mm_free_heap (zend_alloc.c:1366)
==23609== by 0xAB01DD: _efree (zend_alloc.c:2549)
==23609== by 0xB24D1B: zend_gc_collect_cycles (zend_gc.c:1585)
==23609== by 0xB223EB: gc_possible_root_when_full (zend_gc.c:592)
==23609== by 0xB22621: gc_possible_root (zend_gc.c:642)
==23609== by 0xB4E55D: zend_object_release (zend_objects_API.h:77)
==23609== by 0xBBFE31: execute_ex (zend_vm_execute.h:51386)
==23609== by 0xAD4409: zend_call_function (zend_execute_API.c:779)
==23609== by 0x8A4B79: zif_array_map (array.c:6221)
==23609== by 0xB5D5FE: ZEND_DO_ICALL_SPEC_RETVAL_USED_HANDLER (zend_vm_execute.h:1278)
==23609== by 0xBC02F1: execute_ex (zend_vm_execute.h:51498)
==23609== by 0xBC4393: zend_execute (zend_vm_execute.h:55566)
==23609== Address 0x1ff00000208 is not stack'd, malloc'd or (recently) free'd
==23609==
==23609==
==23609== Process terminating with default action of signal 11 (SIGSEGV)
==23609== Access not within mapped region at address 0x1FF00000208
==23609== at 0xAAD619: zend_mm_free_heap (zend_alloc.c:1366)
==23609== by 0xAB01DD: _efree (zend_alloc.c:2549)
==23609== by 0xB24D1B: zend_gc_collect_cycles (zend_gc.c:1585)
==23609== by 0xB223EB: gc_possible_root_when_full (zend_gc.c:592)
==23609== by 0xB22621: gc_possible_root (zend_gc.c:642)
==23609== by 0xB4E55D: zend_object_release (zend_objects_API.h:77)
==23609== by 0xBBFE31: execute_ex (zend_vm_execute.h:51386)
==23609== by 0xAD4409: zend_call_function (zend_execute_API.c:779)
==23609== by 0x8A4B79: zif_array_map (array.c:6221)
==23609== by 0xB5D5FE: ZEND_DO_ICALL_SPEC_RETVAL_USED_HANDLER (zend_vm_execute.h:1278)
==23609== by 0xBC02F1: execute_ex (zend_vm_execute.h:51498)
==23609== by 0xBC4393: zend_execute (zend_vm_execute.h:55566)
==23609== If you believe this happened as a result of a stack
==23609== overflow in your program's main thread (unlikely but
==23609== possible), you can try to increase the size of the
==23609== main thread stack using the --main-stacksize= flag.
==23609== The main thread stack size used in this run was 8388608.
==23609==
==23609== HEAP SUMMARY:
==23609== in use at exit: 4,754,169 bytes in 33,998 blocks
==23609== total heap usage: 45,058 allocs, 11,060 frees, 12,676,399 bytes allocated
==23609==
==23609== LEAK SUMMARY:
==23609== definitely lost: 7,200 bytes in 300 blocks
==23609== indirectly lost: 0 bytes in 0 blocks
==23609== possibly lost: 3,270,104 bytes in 26,573 blocks
==23609== still reachable: 1,476,865 bytes in 7,125 blocks
==23609== suppressed: 0 bytes in 0 blocks
==23609== Rerun with --leak-check=full to see details of leaked memory
==23609==
==23609== For counts of detected and suppressed errors, rerun with: -v
==23609== Use --track-origins=yes to see where uninitialised values come from
==23609== ERROR SUMMARY: 217915 errors from 6 contexts (suppressed: 0 from 0)
[1] 23609 segmentation fault valgrind which php vendor/bin/phpunit
tests/Phan/PhanTest5.php
Previous Comments:
------------------------------------------------------------------------
[2019-11-15 14:42:11] nikic@php.net
I can't reproduce this on a debug+nts build with opcache without jit. No warnings under
valgrind either.
------------------------------------------------------------------------
[2019-11-15 14:04:11] tandre@php.net
I continue to see this when running with opcache (but without JIT) after rebasing against php-src
40dcf2bd3df6a59b632220c0038cf0c4cd89eeb1.
Both NTS(non-debug) and ZTS debug are affected.
I don't see any issues when I run the ZTS --enable-debug build with
opcache.jit_buffer_size=500M.
The only difference is that I see Parameter::create on top of the previous stack trace
0 Phan\Language\Element\Parameter::create
/home/tyson/programming/phan/src/Phan/Language/Element/Parameter.php:63
1 Phan\Language\Element\FunctionFactory::Phan\Language\Element\{closure}
/home/tyson/programming/phan/src/Phan/Language/Element/FunctionFactory.php:186
2 array_map <internal>:-1
3 Phan\Language\Element\FunctionFactory::functionListFromFunction
/home/tyson/programming/phan/src/Phan/Language/Element/FunctionFactory.php:168
4 Phan\Language\Element\FunctionFactory::functionListFromSignature
/home/tyson/programming/phan/src/Phan/Language/Element/FunctionFactory.php:74
5 Phan\CodeBase::hasInternalFunctionWithFQSEN
/home/tyson/programming/phan/src/Phan/CodeBase.php:1392
6 Phan\CodeBase::hasFunctionWithFQSEN /home/tyson/programming/phan/src/Phan/CodeBase.php:1158
7 Phan\Analysis::loadMethodPlugins /home/tyson/programming/phan/src/Phan/Analysis.php:341
8 Phan\Phan::finishAnalyzingRemainingStatements /home/tyson/programming/phan/src/Phan/Phan.php:318
9 Phan\Phan::analyzeFileList /home/tyson/programming/phan/src/Phan/Phan.php:122
10 Phan\Tests\AbstractPhanFileTest::testFiles
/home/tyson/programming/phan/tests/Phan/AbstractPhanFileTest.php:146
11 PHPUnit\Framework\TestCase::runTest
/home/tyson/programming/phan/vendor/phpunit/phpunit/src/Framework/TestCase.php:1141
12 PHPUnit\Framework\TestCase::runBare
/home/tyson/programming/phan/vendor/phpunit/phpunit/src/Framework/TestCase.php:811
13 PHPUnit\Framework\TestResult::run
/home/tyson/programming/phan/vendor/phpunit/phpunit/src/Framework/TestResult.php:605
14 PHPUnit\Framework\TestCase::run
/home/tyson/programming/phan/vendor/phpunit/phpunit/src/Framework/TestCase.php:667
15 PHPUnit\Framework\TestSuite::run
/home/tyson/programming/phan/vendor/phpunit/phpunit/src/Framework/TestSuite.php:678
16 PHPUnit\Framework\TestSuite::run
/home/tyson/programming/phan/vendor/phpunit/phpunit/src/Framework/TestSuite.php:678
17 PHPUnit\TextUI\TestRunner::doRun
/home/tyson/programming/phan/vendor/phpunit/phpunit/src/TextUI/TestRunner.php:155
18 PHPUnit\TextUI\Command::run
/home/tyson/programming/phan/vendor/phpunit/phpunit/src/TextUI/Command.php:171
19 PHPUnit\TextUI\Command::main
/home/tyson/programming/phan/vendor/phpunit/phpunit/src/TextUI/Command.php:158
20 <main> /home/tyson/programming/phan/vendor/phpunit/phpunit/phpunit:1
PHPUnit 7.5.17 by Sebastian Bergmann and contributors.
.................F............................................. 63 / 105 ( 60%)
.....F...................
Program received signal SIGSEGV, Segmentation fault.
0x0000000000900a8f in zend_gc_collect_cycles ()
(gdb) bt
#0 0x0000000000900a8f in zend_gc_collect_cycles ()
#1 0x00000000008ff499 in gc_possible_root_when_full ()
#2 0x000000000096c17a in execute_ex ()
#3 0x00000000008c2acc in zend_call_function ()
#4 0x0000000000796626 in zif_array_map ()
#5 0x0000000000966093 in execute_ex ()
#6 0x00000000009702dc in zend_execute ()
#7 0x00000000008d4733 in zend_execute_scripts ()
#8 0x000000000085e378 in php_execute_script ()
#9 0x0000000000972783 in do_cli ()
#10 0x0000000000464ac3 in main ()
------------------------------------------------------------------------
[2019-11-15 11:39:17] nikic@php.net
Can you please check whether you still see an issue after https://github.com/php/php-src/commit/bb41a1b7e70f42351b73c12b16947301c4db9cfc?
This fixes the issue I saw, but it might be distinct from yours.
------------------------------------------------------------------------
[2019-11-15 11:31:10] nikic@php.net
Based on JIT bisection, the miscompile is likely in PHPUnit\TextUI\ResultPrinter::formatWithColor in
.../phan/vendor/phpunit/phpunit/src/TextUI/ResultPrinter.php:530.
------------------------------------------------------------------------
[2019-11-15 11:25:31] nikic@php.net
I'm seeing
php: /home/nikic/php-src/Zend/zend_variables.c:65: zend_string_destroy: Assertion
`zend_gc_refcount(&(str)->gc) == 0' failed.
Program received signal SIGABRT, Aborted.
__GI_raise (sig=sig@entry=6) at ../sysdeps/unix/sysv/linux/raise.c:51
51 ../sysdeps/unix/sysv/linux/raise.c: No such file or directory.
(gdb) bt
#0 __GI_raise (sig=sig@entry=6) at ../sysdeps/unix/sysv/linux/raise.c:51
#1 0x00007ffff2775801 in __GI_abort () at abort.c:79
#2 0x00007ffff276539a in __assert_fail_base (
fmt=0x7ffff28ec7d8 "%s%s%s:%u: %s%sAssertion `%s' failed.\n%n",
assertion=assertion@entry=0x5555566017e0 "zend_gc_refcount(&(str)->gc) == 0",
file=file@entry=0x555556601728 "/home/nikic/php-src/Zend/zend_variables.c",
line=line@entry=65,
function=function@entry=0x555556601940 <__PRETTY_FUNCTION__.12241>
"zend_string_destroy") at assert.c:92
#3 0x00007ffff2765412 in __GI___assert_fail (
assertion=0x5555566017e0 "zend_gc_refcount(&(str)->gc) == 0",
file=0x555556601728 "/home/nikic/php-src/Zend/zend_variables.c", line=65,
function=0x555556601940 <__PRETTY_FUNCTION__.12241> "zend_string_destroy")
at assert.c:101
#4 0x0000555555d4f9f0 in zend_string_destroy (str=0x55555858fe40)
at /home/nikic/php-src/Zend/zend_variables.c:65
#5 0x0000555555d4f948 in rc_dtor_func (p=0x55555858fe40)
at /home/nikic/php-src/Zend/zend_variables.c:57
#6 0x00000000480b323f in ?? ()
#7 0x00007fffffffa2a0 in ?? ()
#8 0x0000555555e21422 in execute_ex (ex=0x555556e566d0)
at /home/nikic/php-src/Zend/zend_vm_execute.h:51386
with JIT only though.
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=78811
--
Edit this bug report at https://bugs.php.net/bug.php?id=78811&edit=1