Bug #79582 [NEW]: Crash seen when opcache.jit=1235 and opcache.jit_debug=2

From: Date: Sun, 10 May 2020 19:31:59 +0000
Subject: Bug #79582 [NEW]: Crash seen when opcache.jit=1235 and opcache.jit_debug=2
Groups: php.bugs 
Request: Send a blank email to php-bugs+get-226982@lists.php.net to get a copy of this message
From: tandre Operating system: PHP version: master-Git-2020-05-10 (Git) Package: opcache Bug Type: Bug Bug description:Crash seen when opcache.jit=1235 and opcache.jit_debug=2 Description: ------------ Seen when running the jit on php-src b452d5923de3bfef3268bcea289d59d6bc789437 from 2020-05-10 and Phan https://github.com/phan/phan/commit/a2eb629c09952383ae78315d240ce3770670c1a5 (occurs with NTS debug and non-debug) The original example was `php -d opcache.jit=1235 -d opcache.jit_buffer_size=20M -d opcache.jit_debug=2 ./phan`, but it was simplified to the linked gist. Test script: --------------- https://gist.github.com/TysonAndre/4eee037dd9a8e7aa9144eb6b4886e71a (Removing unused functions seemed to prevent the crash, somehow) Expected result: ---------------- opcache.jit_debug=2 should not crash when opcache.jit=1235 (instead of the default of 1205) If it is impossible to fix (e.g. because the necessary info is no longer available), then refuse to print debug output Actual result: -------------- opcache crashed when jit_debug output was being printed to stderr with phan and the attached test script. For some reason, it's trying to resolve a class name for a variable with broad(corrupt?) type info. opcache.protect_memory doesn't change the result. ``` » USE_ZEND_ALLOC=0 gdb -args which php -d opcache.jit=1235 -d opcache.jit_buffer_size=20M -d opcache.jit_debug=2 example.php .... FullyQualifiedGlobalStructuralElement::make: ... output for make() BB5: ; target lines=[12-15] ; from=(BB2, BB3) ; to=(BB6) ; idom=BB2 ; level=3 ; children=(BB6) #17.CV0($namespace) [rc1, rcn, string] = Phi(#4.CV0($namespace) [rc1, rcn, string], #11.CV0($namespace) [rc1, rcn, string]) 0012 FE_FREE #10.V4 [rc1, rcn, array [long] of [string]] 0013 INIT_STATIC_METHOD_CALL 1 (self) (exception) string("cleanNamespace") 0014 SEND_VAR #17.CV0($namespace) [rc1, rcn, string] -> #18.CV0($namespace) NOVAL [rc1, rcn, string] 1 0015 #19.V4 [rc1, rcn, class Program received signal SIGSEGV, Segmentation fault. 0x00007ffff2b81cc0 in _IO_vfprintf_internal (s=0x7fffffff72f0, format=<optimized out>, ap=0x7fffffff99a8) at vfprintf.c:1632 1632 vfprintf.c: No such file or directory. (gdb) bt #0 0x00007ffff2b81cc0 in _IO_vfprintf_internal (s=0x7fffffff72f0, format=<optimized out>, ap=0x7fffffff99a8) at vfprintf.c:1632 #1 0x00007ffff2b82ef1 in buffered_vfprintf (s=0x7ffff2ef8540 <_IO_2_1_stderr_>, format=<optimized out>, args=<optimized out>) at vfprintf.c:2320 #2 0x00007ffff2b8032d in _IO_vfprintf_internal (s=0x7ffff2ef8540 <_IO_2_1_stderr_>, format=0x7fffeb744c55 " (instanceof %s)", ap=ap@entry=0x7fffffff99a8) at vfprintf.c:1293 #3 0x00007ffff2b887f7 in __fprintf (stream=<optimized out>, format=<optimized out>) at fprintf.c:32 #4 0x00007fffeb68db3f in zend_dump_type_info (info=3952614054, ce=0xb75153 <execute_ex+1532>, is_instanceof=1, dump_flags=11) at /path/to/php-src/ext/opcache/Optimizer/zend_dump.c:198 #5 0x00007fffeb68e6f6 in zend_dump_ssa_var_info (ssa=0x7fffffff9cf0, ssa_var_num=19, dump_flags=11) at /path/to/php-src/ext/opcache/Optimizer/zend_dump.c:327 #6 0x00007fffeb68e869 in zend_dump_ssa_var (op_array=0x408be8a8, ssa=0x7fffffff9cf0, ssa_var_num=19, var_type=4 '\004', var_num=4, dump_flags=11) at /path/to/php-src/ext/opcache/Optimizer/zend_dump.c:352 #7 0x00007fffeb68ed33 in zend_dump_op (op_array=0x408be8a8, b=0x1b0b7c8, opline=0x408bebb8, dump_flags=11, ssa=0x7fffffff9cf0, ssa_op=0x1b0bc3c) at /path/to/php-src/ext/opcache/Optimizer/zend_dump.c:418 #8 0x00007fffeb6902d7 in zend_dump_op_line (op_array=0x408be8a8, b=0x1b0b7c8, opline=0x408bebb8, dump_flags=11, data=0x7fffffff9cf0) at /path/to/php-src/ext/opcache/Optimizer/zend_dump.c:729 #9 0x00007fffeb691438 in zend_dump_op_array (op_array=0x408be8a8, dump_flags=11, msg=0x7fffeb74f3b8 "JIT", data=0x7fffffff9cf0) at /path/to/php-src/ext/opcache/Optimizer/zend_dump.c:1014 #10 0x00007fffeb711375 in zend_real_jit_func (op_array=0x408be8a8, script=0x0, rt_opline=0x408bead8) at /path/to/php-src/ext/opcache/jit/zend_jit.c:3091 #11 0x00007fffeb7118e4 in zend_jit_hot_func (execute_data=0x1b1adb0, opline=0x408bead8) at /path/to/php-src/ext/opcache/jit/zend_jit.c:3195 #12 0x00000000480004ea in ?? () #13 0x00007fffffff9dd0 in ?? () #14 0x0000000001b1ad30 in ?? () #15 0x800000000002b60f in ?? () #16 0x00007ffff2ef7b20 in ?? () from /lib/x86_64-linux-gnu/libc.so.6 #17 0x0000010600000018 in ?? () #18 0x000000000044f760 in ?? () #19 0x00007fffffffd860 in ?? () #20 0x0000000001b1aec0 in ?? () #21 0x0000000000000000 in ?? () (go up in the trace) (gdb) #4 0x00007fffeb68db3f in zend_dump_type_info (info=3952614054, ce=0xb75153 <execute_ex+1532>, is_instanceof=1, dump_flags=11) at /path/to/php-src/ext/opcache/Optimizer/zend_dump.c:198 198 fprintf(stderr, " (instanceof %s)", ce->name->val); (gdb) print ce->name $1 = (zend_string *) 0xfffffa9be9008b48 (gdb) print ce->name->val Cannot access memory at address 0xfffffa9be9008b60 ``` -- Edit bug report at https://bugs.php.net/bug.php?id=79582&edit=1 -- Fix committed: https://bugs.php.net/fix.php?id=79582&r=fixed Fixed in release: https://bugs.php.net/fix.php?id=79582&r=alreadyfixed Need backtrace: https://bugs.php.net/fix.php?id=79582&r=needtrace Need Reproduce Script: https://bugs.php.net/fix.php?id=79582&r=needscript Try newer version: https://bugs.php.net/fix.php?id=79582&r=oldversion Not developer issue: https://bugs.php.net/fix.php?id=79582&r=support Expected behavior: https://bugs.php.net/fix.php?id=79582&r=notwrong Not enough info: https://bugs.php.net/fix.php?id=79582&r=notenoughinfo Submitted twice: https://bugs.php.net/fix.php?id=79582&r=submittedtwice register_globals: https://bugs.php.net/fix.php?id=79582&r=globals PHP version support discontinued: https://bugs.php.net/fix.php?id=79582&r=phptooold Daylight Savings: https://bugs.php.net/fix.php?id=79582&r=dst IIS Stability: https://bugs.php.net/fix.php?id=79582&r=isapi Install GNU Sed: https://bugs.php.net/fix.php?id=79582&r=gnused Floating point limitations: https://bugs.php.net/fix.php?id=79582&r=float No Zend Extensions: https://bugs.php.net/fix.php?id=79582&r=nozend MySQL Configuration Error: https://bugs.php.net/fix.php?id=79582&r=mysqlcfg

« previous php.bugs (#226982) next »