Bug #80307 [Com]: Segfault in zend_execute when opcache preload enabled

From: Date: Thu, 05 Nov 2020 14:04:09 +0000
Subject: Bug #80307 [Com]: Segfault in zend_execute when opcache preload enabled
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-230133@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=80307&edit=1

 ID:                 80307
 Comment by:         michael dot zangerle at gmail dot com
 Reported by:        php at shyim dot de
 Summary:            Segfault in zend_execute when opcache preload
                     enabled
 Status:             Closed
 Type:               Bug
 Package:            opcache
 Operating System:   Ubuntu 20.04
 PHP Version:        8.0.0RC3
 Assigned To:        nikic
 Block user comment: N
 Private report:     N

 New Comment:

To which PHP version as this fix applied? Because in the header and description it says 8.0.0RC ...
> PHP Version:	8.0.0RC3
> Tried my Symfony 5.1 project on PHP 8.0RC3, working in 7.4.

.. but in the example it says 7.4.
> Start web server 
> /opt/php-7.4/bin/php -S 0.0.0.0:7050 -t .
> curl localhost:7050 
> 
> => Segmentation fault...

The reason why I am asking is that I am experiencing the same problem with random trait methods
being called (as described by nikic) with Symfony 5.1, preloading and PHP 7.4.12. I do not
experience this with PHP 7.4.11.


Previous Comments:
------------------------------------------------------------------------
[2020-11-05 13:11:49] phil at phil-taylor dot com

Related To: Bug #80321

------------------------------------------------------------------------
[2020-11-05 12:03:25] cmb@php.net

Related To: Bug #80321

------------------------------------------------------------------------
[2020-11-05 11:12:10] nikic@php.net

Should be fixed by https://github.com/php/php-src/commit/33969c2252b2c33a72c9039072af8862fd347a5f
.

------------------------------------------------------------------------
[2020-11-05 10:33:30] nikic@php.net

Okay, I think I see what is happening now. The problem is that trait fixup can be performed multiple
times on the same op_array if it is trivially inherited. Fixup looks up the opcodes in the xlat
table and determines the primary op_array based on that.

Normally, fixing up the same op_array multiple times will work fine, because the later fixup will
see the new opcodes pointer, which will not be in the xlat table. However, it can happen (and what
happens in this case) is that the new opcodes pointer has the same address as the *original* opcodes
of some other trait method, prior to reallocation, and as such is contained in the xlat table. Then
we'll end up overwriting the trait method with a different, unrelated trait method.

------------------------------------------------------------------------
[2020-11-05 10:06:49] nikic@php.net

It looks like this is related to trait method fixup in some way. We end up overwriting the op_array
for some trait methods with the op_array for a different trait method.

------------------------------------------------------------------------


The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at

    https://bugs.php.net/bug.php?id=80307


--
Edit this bug report at https://bugs.php.net/bug.php?id=80307&edit=1


Thread (13 messages)

« previous php.bugs (#230133) next »