Bug #79646 [Com]: Segmentation fault in garbage collector

From: Date: Thu, 22 Oct 2020 16:36:28 +0000
Subject: Bug #79646 [Com]: Segmentation fault in garbage collector
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-229859@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=79646&edit=1

 ID:                 79646
 Comment by:         aa dot vasilenko at gmail dot com
 Reported by:        enumag at gmail dot com
 Summary:            Segmentation fault in garbage collector
 Status:             Open
 Type:               Bug
 Package:            Scripting Engine problem
 Operating System:   Alpine
 PHP Version:        7.4.7
 Block user comment: N
 Private report:     N

 New Comment:

I've stumbled upon the same problem. Problem is reproducible only with php 7.4 (alternatively
tried 7.3, it worked), using phpunit 9.1. In our case it's debian though.

Works flawlessly without code coverage, segfaults with code coverage on (100% reproducible). Trying
to collect more information now


Previous Comments:
------------------------------------------------------------------------
[2020-09-15 13:55:42] enumag at gmail dot com

What's needed in order to get this problem fixed?

------------------------------------------------------------------------
[2020-06-23 13:01:18] enumag at gmail dot com

Any news on this one @nikic?

------------------------------------------------------------------------
[2020-06-15 12:57:15] enumag at gmail dot com

@nikic Alright, here is another log with no error limit:
https://gist.github.com/enumag/a5bbfbb0cfe606b77148e8b83dfd4d41

------------------------------------------------------------------------
[2020-06-15 12:43:32] nikic@php.net

@enumag: Thanks! From the new trace it seems clear that those "Invalid read of size 16"
are false positives. They are probably caused by a vectorized implementation of some string function
intentionally reading past the end of strings in a way that it knows is safe.

Unfortunately that also means that the trace ends before it gets to anything useful. Valgrind
suggests using --error-limit=no to avoid that.

------------------------------------------------------------------------
[2020-06-15 12:31:31] enumag at gmail dot com

The command I used this time:
USE_ZEND_ALLOC=0 valgrind --tool=memcheck --num-callers=30 --log-file=valgrind.txt
--suppressions=php.supp php vendor/bin/phpunit

------------------------------------------------------------------------


The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at

    https://bugs.php.net/bug.php?id=79646


--
Edit this bug report at https://bugs.php.net/bug.php?id=79646&edit=1


Thread (21 messages)

« previous php.bugs (#229859) next »