Bug #80243 [Com]: OPCache JIT segfaults at startup

From: Date: Tue, 20 Oct 2020 19:48:09 +0000
Subject: Bug #80243 [Com]: OPCache JIT segfaults at startup
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-229819@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=80243&edit=1

 ID:                 80243
 Comment by:         brainpower at mailbox dot org
 Reported by:        jens-erik dot riedel at kippdata dot de
 Summary:            OPCache JIT segfaults at startup
 Status:             Assigned
 Type:               Bug
 Package:            JIT
 Operating System:   RHEL 8.0
 PHP Version:        8.0.0rc1
 Assigned To:        nikic
 Block user comment: N
 Private report:     N

 New Comment:

The efree in line 390 is in the correct position, libpath is still used in line 389 after all.

The free of err1 in line 384 is not a double free,
because I believe php_win32_image_compatible allocates it again.
It's just a re-use of a variable name, you could name it err3 inside that PHP_WIN32 block and
nothing would change...


Previous Comments:
------------------------------------------------------------------------
[2020-10-20 19:41:35] jens-erik dot riedel at kippdata dot de

The fact that there is an extra efree(libpath) in main/php_ini.c in line 390 may
correspond to the fact that this extra 'efree(libpath)` is not present in 8.0.0beta3 and
OPCache JIT startup does not crash in 8.0.0beta3.
Perhaps the code around line 384 should be revised. IMHO there is a double free for
err1 if PHP_WIN32 is defined.

------------------------------------------------------------------------
[2020-10-20 19:25:28] brainpower at mailbox dot org

The following patch has been added/updated:

Patch Name: php80_fix_double_free.patch
Revision:   1603221928
URL:        https://bugs.php.net/patch-display.php?bug=80243&patch=php80_fix_double_free.patch&revision=1603221928

------------------------------------------------------------------------
[2020-10-20 19:22:09] brainpower at mailbox dot org

Urg, brain fart.

There's not a return missing, but one efree(libpath) too much!
It's a double free error after all.

Curiously I wasn't able to reproduce the original issue with the crash in dasm_put() anymore
after fixing the double free.
I'll attach a patch of what I did...

------------------------------------------------------------------------
[2020-10-20 18:12:50] brainpower at mailbox dot org

Yeah, same crash in php_ini.c for me...

After a short look into that file, I think there is a return missing after line 377:

 368                 efree(orig_libpath);
369                 efree(err1);
370                 efree(libpath);
371                 efree(err2);
372                 return;
373             }
374
375             efree(orig_libpath);
376             efree(err1);
377             efree(libpath);
                >> RETURN MISSING HERE?? <<
378         }
379
380 #ifdef PHP_WIN32
381         if (!php_win32_image_compatible(handle, &err1)) {
....
387 #endif
388
389         zend_load_extension_handle(handle, libpath);
390         efree(libpath); // theese lines should probably not be reached if(!handle) above is
entered...
391     }

------------------------------------------------------------------------
[2020-10-20 16:49:31] jens-erik dot riedel at kippdata dot de

I have tried with USE_ZEND_ALLOC=0 (using 8.0.0rc1 on RHEL 8). It crashes again; I don't know
if this qualifies as "crashes harder" but at least it crashes differently.

$ USE_ZEND_ALLOC=0 /opt/products/php80/8.0.0rc1-1/bin/php -c /opt/instances/php80-fpm/lib/php.ini -d
opcache.enable_cli=1 -i
free(): double free detected in tcache 2
Aborted (core dumped)

Backtrace is as follows:
Core was generated by `/opt/products/php80/8.0.0rc1-1/bin/php -c
/opt/instances/php80-fpm/lib/php.ini'.
Program terminated with signal SIGABRT, Aborted.
#0  0x00007f88746e893f in raise () from /lib64/libc.so.6

(gdb) bt
#0  0x00007f88746e893f in raise () from /lib64/libc.so.6
#1  0x00007f88746d2c95 in abort () from /lib64/libc.so.6
#2  0x00007f887472bd57 in __libc_message () from /lib64/libc.so.6
#3  0x00007f887473268c in malloc_printerr () from /lib64/libc.so.6
#4  0x00007f8874734155 in _int_free () from /lib64/libc.so.6
#5  0x00007f8875ea9ec1 in php_load_zend_extension_cb (arg=<optimized out>)
    at /bld/php80/main/php_ini.c:391
#6  0x00007f8875ef80ee in zend_llist_apply (l=l@entry=0x7f8876443f60 <extension_lists>, 
    func=func@entry=0x7f8875ea9e30 <php_load_zend_extension_cb>)
    at /bld/php80/Zend/zend_llist.c:182
#7  0x00007f8875eaaa47 in php_ini_register_extensions ()
    at /bld/php80/main/php_ini.c:756
#8  0x00007f8875ea3a46 in php_module_startup (sf=<optimized out>,
additional_modules=additional_modules@entry=0x0, 
    num_additional_modules=num_additional_modules@entry=0)
    at /bld/php80/main/main.c:2235
#9  0x0000000000404b6d in php_cli_startup (sapi_module=<optimized out>)
    at /bld/php80/sapi/cli/php_cli.c:407
#10 0x000000000040453c in main (argc=6, argv=0x1ef3700)
    at /bld/php80/sapi/cli/php_cli.c:1304

------------------------------------------------------------------------


The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at

    https://bugs.php.net/bug.php?id=80243


--
Edit this bug report at https://bugs.php.net/bug.php?id=80243&edit=1


Thread (18 messages)

« previous php.bugs (#229819) next »