Bug #79535 [Ver]: PHP crashes with specific opcache.optimization_level

From: Date: Mon, 04 May 2020 11:09:32 +0000
Subject: Bug #79535 [Ver]: PHP crashes with specific opcache.optimization_level
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-226900@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=79535&edit=1 ID: 79535 Updated by: nikic@php.net Reported by: roland at nextendweb dot com Summary: PHP crashes with specific opcache.optimization_level Status: Verified Type: Bug Package: opcache Operating System: Windows, Linux PHP Version: 7.3.17 Block user comment: N Private report: N New Comment: Minimal: function create() { $name = stdClass::class; return new $name; } var_dump(create()); with -d opcache.optimization_level=0x000000a0 (only SCCP) ==9022== Conditional jump or move depends on uninitialised value(s) ==9022== at 0xADEAEF: ZEND_FETCH_CLASS_SPEC_UNUSED_CONST_HANDLER (zend_vm_execute.h:31745) ==9022== by 0xB096C8: execute_ex (zend_vm_execute.h:58853) ==9022== by 0xB0B8B1: zend_execute (zend_vm_execute.h:60939) ==9022== by 0xA2FD73: zend_execute_scripts (zend.c:1568) ==9022== by 0x99562D: php_execute_script (main.c:2639) ==9022== by 0xB0E6C3: do_cli (php_cli.c:997) ==9022== by 0xB0F8F5: main (php_cli.c:1393) Has something to do with the FETCH_CLASS cache slot. Previous Comments: ------------------------------------------------------------------------ [2020-05-04 10:29:24] nikic@php.net Can confirm that the test case crashes at opcache.optimization_level=0xfffffaaf (but not at the default level). ------------------------------------------------------------------------ [2020-04-30 13:10:08] roland at nextendweb dot com Good news! I was able to create a reduced test case where this bug happens. Could you verify that the crash happens for you too? https://www.dropbox.com/s/3jp5dzyfzmurxcc/php-bug-79535.zip?dl=1 Run index.php The desired output: html{padding:0;}Hello World If you open LessCompiler.php and replace protected function newFormatter() { $className = Compressed::class; return new $className; } with protected function newFormatter() { return new Compressed(); } It will work fine. Also when you invalidate opcode cache for LessCompiler.php, then it works for the first load and every other try crashes. ------------------------------------------------------------------------ [2020-04-30 10:00:41] nikic@php.net I can't do anything about this without a way to reproduce. The only suggestion I have is to make sure that the optimization level is masked with 0xfffeffff, which disables an unsafe (in the sense of "can crash" rather than "can cause misbehavior") optimization, though I doubt that is the actual cause. ------------------------------------------------------------------------ [2020-04-30 09:06:08] cmb@php.net Thanks for the analysis report using PHP 7.3.17! It contains the following slightly different backtrace (unfortunately, again without line numbers, but these might not be that helpful anyway): php7ts!object_and_properties_init+d php7ts!ZEND_NEW_SPEC_VAR_UNUSED_HANDLER+40 php7ts!execute_ex+5f php7ts!zend_call_function+2d0 php7ts!zif_call_user_func_array+da php7ts!ZEND_DO_FCALL_BY_NAME_SPEC_RETVAL_UNUSED_HANDLER+ac php7ts!execute_ex+5f php7ts!zend_execute+1a8 php7ts!zend_execute_scripts+b9 php7ts!php_execute_script+261 php7apache2_4!php_handler+591 Anyhow, assuming that the OPcache instance isn't shared across different PHP configurations, it looks like some combinations of optimizations are not properly supported, which may result in segfaults (likely trying to read offsets of NULL). @roland, I suggest to stick with one of the working optimization levels or just the default (0x7FFEBFFF). ------------------------------------------------------------------------ [2020-04-30 07:57:41] roland at nextendweb dot com Can you download it from here? Is it contains what you need? https://www.dropbox.com/s/qr612f6mkyb14pc/MultipleDumps_MultipleRules.mht?dl=1 ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=79535 -- Edit this bug report at https://bugs.php.net/bug.php?id=79535&edit=1

« previous php.bugs (#226900) next »