Edit report at https://bugs.php.net/bug.php?id=80243&edit=1
ID: 80243
Updated by: nikic@php.net
Reported by: jens-erik dot riedel at kippdata dot de
Summary: OPCache JIT segfaults at startup
-Status: Assigned
+Status: Closed
Type: Bug
Package: JIT
Operating System: RHEL 8.0
PHP Version: 8.0.0rc1
Assigned To: nikic
Block user comment: N
Private report: N
New Comment:
Thanks everyone for the investigation! So this turned out to be completely unrelated to the JIT
after all, it's just where the double-free ended up manifesting.
The double free has been fixed by https://github.com/php/php-src/commit/5998b2a3a65042dc7fc4f70945dd72e4e258500f
and I've added some test coverage for zend_extension loading in https://github.com/php/php-src/commit/3966c0f8a47225486865d7cdef2552f746dd274c.
All of our existing CI jobs were loading opcache either as an absolute path, or using an extension,
so this was not noticed.
Previous Comments:
------------------------------------------------------------------------
[2020-10-21 09:32:38] nikic@php.net
Related To: Bug #80175
------------------------------------------------------------------------
[2020-10-20 19:48:09] brainpower at mailbox dot org
The efree in line 390 is in the correct position, libpath is still used in line 389 after all.
The free of err1 in line 384 is not a double free,
because I believe php_win32_image_compatible allocates it again.
It's just a re-use of a variable name, you could name it err3 inside that PHP_WIN32 block and
nothing would change...
------------------------------------------------------------------------
[2020-10-20 19:41:35] jens-erik dot riedel at kippdata dot de
The fact that there is an extra efree(libpath) in main/php_ini.c in line 390 may
correspond to the fact that this extra 'efree(libpath)` is not present in 8.0.0beta3 and
OPCache JIT startup does not crash in 8.0.0beta3.
Perhaps the code around line 384 should be revised. IMHO there is a double free for
err1 if PHP_WIN32 is defined.
------------------------------------------------------------------------
[2020-10-20 19:25:28] brainpower at mailbox dot org
The following patch has been added/updated:
Patch Name: php80_fix_double_free.patch
Revision: 1603221928
URL: https://bugs.php.net/patch-display.php?bug=80243&patch=php80_fix_double_free.patch&revision=1603221928
------------------------------------------------------------------------
[2020-10-20 19:22:09] brainpower at mailbox dot org
Urg, brain fart.
There's not a return missing, but one efree(libpath) too much!
It's a double free error after all.
Curiously I wasn't able to reproduce the original issue with the crash in dasm_put() anymore
after fixing the double free.
I'll attach a patch of what I did...
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=80243
--
Edit this bug report at https://bugs.php.net/bug.php?id=80243&edit=1