Bug #80243 [Opn]: OPCache JIT segfaults at startup

From: Date: Tue, 20 Oct 2020 14:10:23 +0000
Subject: Bug #80243 [Opn]: OPCache JIT segfaults at startup
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-229799@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=80243&edit=1

 ID:                 80243
 Updated by:         nikic@php.net
 Reported by:        jens-erik dot riedel at kippdata dot de
 Summary:            OPCache JIT segfaults at startup
 Status:             Open
 Type:               Bug
 Package:            JIT
 Operating System:   RHEL 8.0
 PHP Version:        8.0.0rc1
 Block user comment: N
 Private report:     N

 New Comment:

Would it be possible for you to set a break point on dasm_setup, step through it, and check that
D->section is initialized at the end?

In the meantime, I've done a php-8.0.0RC2 build on CentOS 7 (rather than Ubuntu 20.04) and
wasn't able to reproduce the issue there either.


Previous Comments:
------------------------------------------------------------------------
[2020-10-20 13:25:53] brainpower at mailbox dot org

Lots of other members of D are zeroed, not sure if that's ok or not:

Program received signal SIGSEGV, Segmentation fault.
dasm_put (Dst=Dst@entry=0x7fffffffcc00, start=start@entry=5) at
/root/shmbuild/src/php-8.0.0RC2/ext/opcache/jit/dynasm/dasm_x86.h:176
176       int pos = sec->pos, ofs = sec->ofs, mrm = -1;
(gdb) print D->section
$1 = (dasm_Section *) 0x0
(gdb) print D->sections[0]
$2 = {rbuf = 0x0, buf = 0x0, bsize = 0, pos = 0, epos = 0, ofs = 0}
(gdb) print &D->sections[0]
$3 = (dasm_Section *) 0x7ffff3608150
(gdb) print D->maxsection
$4 = 0
(gdb) print D->status
$5 = 0
(gdb) print D->actionlist
$6 = (dasm_ActList) 0x0
(gdb) print D->lglabels
$7 = (int *) 0x0
(gdb) print D->lgsize
$8 = 0
(gdb) print D->pclabels
$9 = (int *) 0x0
(gdb) print D->pcsize
$10 = 0
(gdb) print D->globals
$11 = (void **) 0x0
(gdb) print D->psize
$12 = 0
(gdb) print D->codesize
$13 = 0
(gdb)

Maybe dasm_setup didn't run? Or some errand memset() overwrote the wrong thing(s)?

------------------------------------------------------------------------
[2020-10-20 10:20:47] nikic@php.net

D->section is initialized by dasm_setup(), and that does get called directly before the stub is
compiled. Not clear to me how it ends up being NULL.

------------------------------------------------------------------------
[2020-10-19 15:51:10] ricardo at banak dot com

And same in PHP 8.0.0RC2

------------------------------------------------------------------------
[2020-10-19 15:48:52] ricardo at banak dot com

It also happens in Centos 8 and Centos 7.

------------------------------------------------------------------------
[2020-10-19 15:00:21] brainpower at mailbox dot org

I've got the same crash on Debian 10 buster, with 8.0.0rc1 and 8.0.0rc2,
so it still crashes with rc2.
According to gdb it seems that *sec/D->section is NULL:

(gdb) r
Starting program: /opt/php80/bin/php -dopcache.enable_cli=1 -dopcache.jit=1205
-dopcache.jit_buffer_size=32M Zend/bench.php
[Thread debugging using libthread_db enabled]
Using host libthread_db library "/lib/x86_64-linux-gnu/libthread_db.so.1".

Program received signal SIGSEGV, Segmentation fault.
dasm_put (Dst=Dst@entry=0x7fffffffcbf0, start=start@entry=5) at
/root/shmbuild/src/php-8.0.0RC2/ext/opcache/jit/dynasm/dasm_x86.h:176
176       int pos = sec->pos, ofs = sec->ofs, mrm = -1;
(gdb) bt
#0  dasm_put (Dst=Dst@entry=0x7fffffffcbf0, start=start@entry=5) at
/root/shmbuild/src/php-8.0.0RC2/ext/opcache/jit/dynasm/dasm_x86.h:176
#1  0x00007ffff356a703 in zend_jit_interrupt_handler_stub (Dst=0x7fffffffcbf0) at
/root/shmbuild/src/php-8.0.0RC2/ext/opcache/jit/zend_jit_x86.dasc:1726
#2  0x00007ffff35b8727 in zend_jit_make_stubs () at
/root/shmbuild/src/php-8.0.0RC2/ext/opcache/jit/zend_jit.c:3999
#3  zend_jit_startup (buf=<optimized out>, size=size@entry=33554432,
reattached=reattached@entry=false) at
/root/shmbuild/src/php-8.0.0RC2/ext/opcache/jit/zend_jit.c:4249
#4  0x00007ffff34da66f in accel_post_startup () at
/root/shmbuild/src/php-8.0.0RC2/ext/opcache/ZendAccelerator.c:3039
#5  0x0000555555b48f82 in zend_post_startup () at /root/shmbuild/src/php-8.0.0RC2/Zend/zend.c:1030
#6  0x0000555555ae8853 in php_module_startup (sf=<optimized out>,
additional_modules=<optimized out>, num_additional_modules=<optimized out>)
    at /root/shmbuild/src/php-8.0.0RC2/main/main.c:2240
#7  0x0000555555bd01dd in php_cli_startup (sapi_module=<optimized out>) at
/root/shmbuild/src/php-8.0.0RC2/sapi/cli/php_cli.c:406
#8  0x00005555557a061d in main (argc=5, argv=0x555556bb95e0) at
/root/shmbuild/src/php-8.0.0RC2/sapi/cli/php_cli.c:1303
(gdb) list
171     {
172       va_list ap;
173       dasm_State *D = Dst_REF;
174       dasm_ActList p = D->actionlist + start;
175       dasm_Section *sec = D->section;
176       int pos = sec->pos, ofs = sec->ofs, mrm = -1;
177       int *b;
178
179       if (pos >= sec->epos) {
180         DASM_M_GROW(Dst, int, sec->buf, sec->bsize,
(gdb) print sec
$1 = (dasm_Section *) 0x0
(gdb) print D
$2 = (dasm_State *) 0x7ffff3609100

------------------------------------------------------------------------


The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at

    https://bugs.php.net/bug.php?id=80243


--
Edit this bug report at https://bugs.php.net/bug.php?id=80243&edit=1


Thread (18 messages)

« previous php.bugs (#229799) next »