Bug #80243 [Asn->Csd]: OPCache JIT segfaults at startup

From: Date: Wed, 21 Oct 2020 10:41:20 +0000
Subject: Bug #80243 [Asn->Csd]: OPCache JIT segfaults at startup
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-229837@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=80243&edit=1

 ID:                 80243
 Updated by:         nikic@php.net
 Reported by:        jens-erik dot riedel at kippdata dot de
 Summary:            OPCache JIT segfaults at startup
-Status:             Assigned
+Status:             Closed
 Type:               Bug
 Package:            JIT
 Operating System:   RHEL 8.0
 PHP Version:        8.0.0rc1
 Assigned To:        nikic
 Block user comment: N
 Private report:     N

 New Comment:

Thanks everyone for the investigation! So this turned out to be completely unrelated to the JIT
after all, it's just where the double-free ended up manifesting.

The double free has been fixed by https://github.com/php/php-src/commit/5998b2a3a65042dc7fc4f70945dd72e4e258500f
and I've added some test coverage for zend_extension loading in https://github.com/php/php-src/commit/3966c0f8a47225486865d7cdef2552f746dd274c.
All of our existing CI jobs were loading opcache either as an absolute path, or using an extension,
so this was not noticed.


Previous Comments:
------------------------------------------------------------------------
[2020-10-21 09:32:38] nikic@php.net

Related To: Bug #80175

------------------------------------------------------------------------
[2020-10-20 19:48:09] brainpower at mailbox dot org

The efree in line 390 is in the correct position, libpath is still used in line 389 after all.

The free of err1 in line 384 is not a double free,
because I believe php_win32_image_compatible allocates it again.
It's just a re-use of a variable name, you could name it err3 inside that PHP_WIN32 block and
nothing would change...

------------------------------------------------------------------------
[2020-10-20 19:41:35] jens-erik dot riedel at kippdata dot de

The fact that there is an extra efree(libpath) in main/php_ini.c in line 390 may
correspond to the fact that this extra 'efree(libpath)` is not present in 8.0.0beta3 and
OPCache JIT startup does not crash in 8.0.0beta3.
Perhaps the code around line 384 should be revised. IMHO there is a double free for
err1 if PHP_WIN32 is defined.

------------------------------------------------------------------------
[2020-10-20 19:25:28] brainpower at mailbox dot org

The following patch has been added/updated:

Patch Name: php80_fix_double_free.patch
Revision:   1603221928
URL:        https://bugs.php.net/patch-display.php?bug=80243&patch=php80_fix_double_free.patch&revision=1603221928

------------------------------------------------------------------------
[2020-10-20 19:22:09] brainpower at mailbox dot org

Urg, brain fart.

There's not a return missing, but one efree(libpath) too much!
It's a double free error after all.

Curiously I wasn't able to reproduce the original issue with the crash in dasm_put() anymore
after fixing the double free.
I'll attach a patch of what I did...

------------------------------------------------------------------------


The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at

    https://bugs.php.net/bug.php?id=80243


--
Edit this bug report at https://bugs.php.net/bug.php?id=80243&edit=1


Thread (18 messages)

« previous php.bugs (#229837) next »