Bug #79646 [Opn]: Segmentation fault in garbage collector

From: Date: Mon, 15 Jun 2020 12:43:33 +0000
Subject: Bug #79646 [Opn]: Segmentation fault in garbage collector
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-227493@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=79646&edit=1

 ID:                 79646
 Updated by:         nikic@php.net
 Reported by:        enumag at gmail dot com
 Summary:            Segmentation fault in garbage collector
 Status:             Open
 Type:               Bug
 Package:            Scripting Engine problem
 Operating System:   Alpine
 PHP Version:        7.4.7
 Block user comment: N
 Private report:     N

 New Comment:

@enumag: Thanks! From the new trace it seems clear that those "Invalid read of size 16"
are false positives. They are probably caused by a vectorized implementation of some string function
intentionally reading past the end of strings in a way that it knows is safe.

Unfortunately that also means that the trace ends before it gets to anything useful. Valgrind
suggests using --error-limit=no to avoid that.


Previous Comments:
------------------------------------------------------------------------
[2020-06-15 12:31:31] enumag at gmail dot com

The command I used this time:
USE_ZEND_ALLOC=0 valgrind --tool=memcheck --num-callers=30 --log-file=valgrind.txt
--suppressions=php.supp php vendor/bin/phpunit

------------------------------------------------------------------------
[2020-06-15 12:30:45] enumag at gmail dot com

@nikic Check this one please.
https://gist.github.com/enumag/329cbe88c5e77c5cc5be74aafa330ba8

------------------------------------------------------------------------
[2020-06-15 09:15:18] enumag at gmail dot com

I can use https://github.com/wodby/base-php docker
image for that. Did it before to get the gdb stacktrace. Let me try...

------------------------------------------------------------------------
[2020-06-15 09:04:52] nikic@php.net

Thanks! The first invalid read is:


==182== Invalid read of size 16
==182==    at 0xBDF97E1: ???
==182==    by 0xA36A9C7: ???
==182==    by 0xA36A9C7: ???
==182==    by 0xA36A9F2: ???
==182==    by 0x4A8312F: ???
==182==    by 0xA36A9C7: ???
==182==  Address 0xa36a9ef is 63 bytes inside a block of size 72 alloc'd
==182==    at 0x489F72A: malloc (vg_replace_malloc.c:309)
==182==    by 0x5D30B8: __zend_malloc (in /usr/local/bin/php)
==182==    by 0x53ACA6: ??? (in /usr/local/bin/php)
==182==    by 0x540AA6: ??? (in /usr/local/bin/php)
==182==    by 0x5411E6: ??? (in /usr/local/bin/php)
==182==    by 0x67BF73: execute_ex (in /usr/local/bin/php)
==182==    by 0x5ED108: zend_call_function (in /usr/local/bin/php)
==182==    by 0x617373: zend_call_method (in /usr/local/bin/php)
==182==    by 0x4E352A: ??? (in /usr/local/bin/php)
==182==    by 0x5ED026: zend_call_function (in /usr/local/bin/php)
==182==    by 0x617373: zend_call_method (in /usr/local/bin/php)
==182==    by 0x6178BA: zend_user_it_rewind (in /usr/local/bin/php)

Unfortunately most debug symbols are missing, so we don't actually see where the invalid read
occurs :(

Is it possible to install some kind of -dbg / -dbgsym package for PHP on your system?

------------------------------------------------------------------------
[2020-06-15 09:00:39] enumag at gmail dot com

Okay, I ran USE_ZEND_ALLOC=0 valgrind --suppressions=php.supp php vendor/bin/phpunit 2>
valgrind.txt with the php.supp file you provided. Here is the result:

https://gist.github.com/enumag/42402fcc05d9a404656f50a51fb98d2b

Please let me know if it helps.

------------------------------------------------------------------------


The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at

    https://bugs.php.net/bug.php?id=79646


--
Edit this bug report at https://bugs.php.net/bug.php?id=79646&edit=1


Thread (21 messages)

« previous php.bugs (#227493) next »