Bug #79128 [Ver]: SIGABRT double free or corruption with preloading

From: Date: Fri, 24 Jan 2020 15:10:19 +0000
Subject: Bug #79128 [Ver]: SIGABRT double free or corruption with preloading
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-225104@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=79128&edit=1

 ID:                 79128
 Updated by:         nikic@php.net
 Reported by:        dotbox at gmail dot com
 Summary:            SIGABRT double free or corruption with preloading
 Status:             Verified
 Type:               Bug
 Package:            opcache
 Operating System:   Debian Buster
 PHP Version:        7.4.2
 Block user comment: N
 Private report:     N

 New Comment:

Here is the valgrind trace:

==375== Invalid write of size 8
==375==    at 0x126BA2AA: _zend_hash_append_ex (zend_hash.h:1126)
==375==    by 0x126C5EEE: preload_load (ZendAccelerator.c:4217)
==375==    by 0x126C7906: accel_finish_startup (ZendAccelerator.c:4657)
==375==    by 0x126C1FBD: accel_post_startup (ZendAccelerator.c:3032)
==375==    by 0x93BE3F: zend_post_startup (zend.c:1002)
==375==    by 0x89F166: php_module_startup (main.c:2356)
==375==    by 0xA1C48F: php_cli_startup (php_cli.c:407)
==375==    by 0xA1E62A: main (php_cli.c:1319)
==375==  Address 0x115818a0 is 0 bytes after a block of size 10,240 alloc'd
==375==    at 0x4C2FB0F: malloc (in /usr/lib/valgrind/vgpreload_memcheck-amd64-linux.so)
==375==    by 0x903A4E: __zend_malloc (zend_alloc.c:2975)
==375==    by 0x9540EE: zend_hash_do_resize (zend_hash.c:1160)
==375==    by 0x952D91: _zend_hash_add_or_update_i (zend_hash.c:772)
==375==    by 0x953345: zend_hash_update (zend_hash.c:879)
==375==    by 0x93E9C0: zend_hash_update_ptr (zend_hash.h:647)
==375==    by 0x94928F: do_register_internal_class (zend_API.c:2713)
==375==    by 0x94943D: zend_register_internal_class (zend_API.c:2757)
==375==    by 0x6BB2C9: spl_register_std_class (spl_functions.c:44)
==375==    by 0x6DB4C6: zm_startup_spl_observer (spl_observer.c:1338)
==375==    by 0x6BAFDA: zm_startup_spl (php_spl.c:1008)
==375==    by 0x945EFA: zend_startup_module_ex (zend_API.c:1860)


Previous Comments:
------------------------------------------------------------------------
[2020-01-24 14:46:49] nikic@php.net

I was able to reproduce this issue outside Docker using "sudo !! -d
opcache.preload_user=root".

------------------------------------------------------------------------
[2020-01-24 11:12:49] dotbox at gmail dot com

As PHP 7.4.2 was released, although the changes between 7.4.2rc1 and 7.4.2 are minimal, I gave it a
try with the new docker images available and I have the exact same segfault.

------------------------------------------------------------------------
[2020-01-17 14:14:47] w3goodies dot com at gmail dot com

Can vote to this same case. I am using official PHP docker images and tested with PHP 7.4.1 and 7.4
and built 7.4.2 myself using same code as in 7.4.1 by just changing the download urls of PHP source.
The issue persists in all the versions.

------------------------------------------------------------------------
[2020-01-17 13:26:11] dotbox at gmail dot com

I could not find official PHP 7.4.2rc1 docker images, so i build my own by cloning the repo from https://github.com/docker-library/php, then i
changed the 7.4/buster/cli/Dockerfile lines 67 to 69:

-ENV PHP_VERSION 7.4.1
-ENV PHP_URL="https://www.php.net/get/php-7.4.1.tar.xz/from/this/mirror"
PHP_ASC_URL="https://www.php.net/get/php-7.4.1.tar.xz.asc/from/this/mirror"
-ENV PHP_SHA256="561bb866bdd509094be00f4ece7c3543ec971c4d878645ee81437e291cffc762"
PHP_MD5=""
+ENV PHP_VERSION 7.4.2RC1
+ENV PHP_URL="https://downloads.php.net/~derick/php-7.4.2RC1.tar.xz"
PHP_ASC_URL=""
+ENV PHP_SHA256="" PHP_MD5=""

then i build with docker build . --tag php:dbg and then run with docker run -t -i --rm -p 8000:8000
php:dbg /bin/bash, sadly the same problem :-(

------------------------------------------------------------------------
[2020-01-17 13:06:11] nikic@php.net

PHP 7.4.1 has known issues with preloading, so I'm not surprised that they exhibit this issue.
I'm assuming that images for 7.4.2rc1 are not available?

------------------------------------------------------------------------


The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at

    https://bugs.php.net/bug.php?id=79128


--
Edit this bug report at https://bugs.php.net/bug.php?id=79128&edit=1


Thread (11 messages)

« previous php.bugs (#225104) next »