Bug #80307 [Ver]: Segfault in zend_execute when opcache preload enabled

From: Date: Thu, 05 Nov 2020 10:06:49 +0000
Subject: Bug #80307 [Ver]: Segfault in zend_execute when opcache preload enabled
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-230112@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=80307&edit=1

 ID:                 80307
 Updated by:         nikic@php.net
 Reported by:        php at shyim dot de
 Summary:            Segfault in zend_execute when opcache preload
                     enabled
 Status:             Verified
 Type:               Bug
 Package:            opcache
 Operating System:   Ubuntu 20.04
 PHP Version:        8.0.0RC3
 Block user comment: N
 Private report:     N

 New Comment:

It looks like this is related to trait method fixup in some way. We end up overwriting the op_array
for some trait methods with the op_array for a different trait method.


Previous Comments:
------------------------------------------------------------------------
[2020-11-04 15:20:52] nikic@php.net

> Only when using the builtin server though, doesn't happen via cli.

Oh, that's because the preloader explicitly exits in that case ... removing that check, it does
reproduce on cli.

------------------------------------------------------------------------
[2020-11-04 15:18:26] nikic@php.net

I've fixed a few more preloading bugs today, but it looks like this one is still failing. I
get:

php: /home/nikic/php/php-8.0/ext/opcache/zend_persist.c:385: zend_persist_op_array_ex: Assertion
`arg_info != ((void *)0)' failed.

Only when using the builtin server though, doesn't happen via cli.

------------------------------------------------------------------------
[2020-11-03 19:20:20] php at shyim dot de

Tested again against branch PHP-8.0(commit: 54668a449e2e535f638b6b0bc22c8c3956e534a2) after seeing
some preload related stuff committed today.
Now the Webserver even does not start :D

php: /home/shyim/src/php-src/ext/opcache/Optimizer/zend_optimizer.c:1035: zend_revert_pass_two:
Assertion `(op_array->fn_flags & (1 << 25)) != 0' failed

#0  __GI_raise (sig=sig@entry=6) at ../sysdeps/unix/sysv/linux/raise.c:50
#1  0x00007ffff6ba7859 in __GI_abort () at abort.c:79
#2  0x00007ffff6ba7729 in __assert_fail_base (fmt=0x7ffff6d3d588 "%s%s%s:%u: %s%sAssertion
`%s' failed.\n%n", assertion=0x7ffff3fb65b8 "(op_array->fn_flags & (1 <<
25)) != 0", file=0x7ffff3fb5780
"/home/shyim/src/php-src/ext/opcache/Optimizer/zend_optimizer.c", line=1035,
function=<optimized out>) at assert.c:92
#3  0x00007ffff6bb8f36 in __GI___assert_fail (assertion=0x7ffff3fb65b8 "(op_array->fn_flags
& (1 << 25)) != 0", file=0x7ffff3fb5780
"/home/shyim/src/php-src/ext/opcache/Optimizer/zend_optimizer.c", line=1035,
function=0x7ffff3fb6940 <__PRETTY_FUNCTION__.19583> "zend_revert_pass_two") at
assert.c:101
#4  0x00007ffff3e636ad in zend_revert_pass_two (op_array=0x7ffff400e990) at
/home/shyim/src/php-src/ext/opcache/Optimizer/zend_optimizer.c:1035
#5  0x00007ffff3e6469b in zend_optimize_script (script=0x7ffff414b600,
optimization_level=2147401727, debug_level=0) at
/home/shyim/src/php-src/ext/opcache/Optimizer/zend_optimizer.c:1421
#6  0x00007ffff3e33bd3 in preload_optimize (script=0x7ffff414b600) at
/home/shyim/src/php-src/ext/opcache/ZendAccelerator.c:4187
#7  0x00007ffff3e3581c in accel_preload (config=0x555556dda3f8
"/home/shyim/bug-80307/preload.php", in_child=false) at
/home/shyim/src/php-src/ext/opcache/ZendAccelerator.c:4677
#8  0x00007ffff3e36341 in accel_finish_startup () at
/home/shyim/src/php-src/ext/opcache/ZendAccelerator.c:4919
#9  0x00007ffff3e30098 in accel_post_startup () at
/home/shyim/src/php-src/ext/opcache/ZendAccelerator.c:3123
#10 0x0000555555db60c2 in zend_post_startup () at /home/shyim/src/php-src/Zend/zend.c:1030
#11 0x0000555555d18e33 in php_module_startup (sf=0x555556d5ce00 <cli_server_sapi_module>,
additional_modules=0x555556d5cd20 <cli_server_module_entry>, num_additional_modules=1) at
/home/shyim/src/php-src/main/main.c:2240
#12 0x0000555555eac244 in sapi_cli_server_startup (sapi_module=0x555556d5ce00
<cli_server_sapi_module>) at /home/shyim/src/php-src/sapi/cli/php_cli_server.c:503
#13 0x0000555555ea7ada in main (argc=5, argv=0x555556db4270) at
/home/shyim/src/php-src/sapi/cli/php_cli.c:1303

------------------------------------------------------------------------
[2020-11-02 21:56:10] php at shyim dot de

I have debugged with die some time and got a very smaller repository.
Repository: https://github.com/shyim/php-bug-80307/tree/master

When I remove the logger assignment it works as expected here: 
https://github.com/php-fig/log/blob/master/Psr/Log/LoggerAwareTrait.php#L24

------------------------------------------------------------------------
[2020-11-02 20:51:25] danack@php.net

Are you able to find a simple reproduce case?

If not, please could you try adding 'echo "got here"; exit(0);' first at the
top-level, and then moving it deeper into the app until you find the function that is causing the
problem?

kind of looks like a borked opcache optimization, so don't need a full repro case, if you can
identify a function that has the borked optimisation applied to it.

------------------------------------------------------------------------


The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at

    https://bugs.php.net/bug.php?id=80307


--
Edit this bug report at https://bugs.php.net/bug.php?id=80307&edit=1


Thread (13 messages)

« previous php.bugs (#230112) next »