Bug #80426 [Opn]: Crash when using JIT and an extension replacing zend_execute_ex with custom
| From: | nikic@php.net | Date: | Fri, 27 Nov 2020 11:50:39 +0000 |
| Subject: | Bug #80426 [Opn]: Crash when using JIT and an extension replacing zend_execute_ex with custom | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-230682@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=80426&edit=1
ID: 80426
Updated by: nikic@php.net
Reported by: patrickallaert@php.net
Summary: Crash when using JIT and an extension replacing
zend_execute_ex with custom
Status: Open
Type: Bug
Package: JIT
Operating System: Linux
PHP Version: 8.0.0
Block user comment: N
Private report: N
New Comment:
Test: https://github.com/php/php-src/pull/6461
Previous Comments:
------------------------------------------------------------------------
[2020-11-26 20:33:18] patrickallaert@php.net
Description:
------------
Using a minimal extension [1] that replaces zend_execute_ex with a decorator function and running in
cli with JIT enabled a simple PHP script [2] makes it crash.
[1] https://github.com/patrickallaert/extcrash
[2] https://github.com/patrickallaert/extcrash/blob/master/test.php
Test script:
---------------
See https://github.com/patrickallaert/extcrash.
Compile it and run the test.php script with:
php -d zend_extension=opcache -dopcache.enable_cli=1 -dopcache.jit_buffer_size=100M
-dextension=extcrash test.php
Expected result:
----------------
No crash
Actual result:
--------------
Crashes with the following info:
gdb /usr/local/php-8.0-debug/bin/php
(gdb) run -d zend_extension=opcache -dopcache.enable_cli=1 -dopcache.jit_buffer_size=100M
-dextension=extcrash test.php
Starting program: /usr/local/php-8.0-debug/bin/php -d zend_extension=opcache -dopcache.enable_cli=1
-dopcache.jit_buffer_size=100M -dextension=extcrash test.php
[Thread debugging using libthread_db enabled]
Using host libthread_db library "/lib64/libthread_db.so.1".
php: ext/opcache/jit/zend_jit_trace.c:7314: zend_jit_trace_exit: Assertion
`((execute_data)->opline) >= ((execute_data)->func)->op_array.opcodes &&
((execute_data)->opline) < ((execute_data)->func)->op_array.opcodes +
((execute_data)->func)->op_array.last' failed.
Program received signal SIGABRT, Aborted.
0x00007ffff757fa41 in raise () from /lib64/libc.so.6
(gdb) bt
#0 0x00007ffff757fa41 in raise () from /lib64/libc.so.6
#1 0x00007ffff7569536 in abort () from /lib64/libc.so.6
#2 0x00007ffff756941f in __assert_fail_base.cold () from /lib64/libc.so.6
#3 0x00007ffff7578332 in __assert_fail () from /lib64/libc.so.6
#4 0x00007ffff4fa30c6 in zend_jit_trace_exit (exit_num=3, regs=0x7fffffff9990) at
ext/opcache/jit/zend_jit_trace.c:7314
#5 0x000000004800049a in ?? ()
#6 0x00000000408d26a0 in ?? ()
#7 0x0000555556d7a6c8 in executor_globals ()
#8 0x00007ffff50022c8 in ?? ()
#9 0x0000555555c9e769 in _destroy_zend_class_traits_info (ce=0x408d26a0) at
/home/patrick.allaert/Projets/php-src/Zend/zend_opcode.c:256
#10 0xff00ffffffffffff in ?? ()
#11 0xffffffff000000ff in ?? ()
#12 0x0000000000000000 in ?? ()
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=80426&edit=1