Bug #78539 [Opn->Fbk]: Segfault with json_decode

From: Date: Tue, 16 Mar 2021 14:57:13 +0000
Subject: Bug #78539 [Opn->Fbk]: Segfault with json_decode
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-232786@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=78539&edit=1

 ID:                 78539
 Updated by:         cmb@php.net
 Reported by:        ymaheo at hexaglobe dot com
 Summary:            Segfault with json_decode
-Status:             Open
+Status:             Feedback
 Type:               Bug
 Package:            JSON related
 Operating System:   CentOS Linux release 7.4.1708 (C
 PHP Version:        7.3.9
-Assigned To:        
+Assigned To:        cmb
 Block user comment: N
 Private report:     N

 New Comment:

Does this still happen with any of the actively supported PHP
versions[1]?  If so, does it also happen with OPcache disabled?

[1] <https://www.php.net/supported-versions.php>


Previous Comments:
------------------------------------------------------------------------
[2019-09-18 22:31:54] henri dot hila at gmail dot com

Hi,

Please update the status back to open as this is still an issue.

Thanks.

------------------------------------------------------------------------
[2019-09-18 20:50:44] henri dot hila at gmail dot com

@nikic@php.net 

I upgraded from 7.1.x to 7.3.9

------------------------------------------------------------------------
[2019-09-18 20:29:42] nikic@php.net

There isn't much to go on here ... a lot of crashes manifest in zend_alloc, but have different
root causes.

@henri dot hila at gmail dot com: To clarify, you are seeing this issue after upgrading from 7.3.8
to 7.3.9?

------------------------------------------------------------------------
[2019-09-18 20:23:49] henri dot hila at gmail dot com

Hi there,

Is there a fix / patch for this issue? We upgraded to php 7.3.9 over the weekend and we are now
seeing this issue. 

Please let us know if a fix / patch is in place.

Thanks.

------------------------------------------------------------------------
[2019-09-16 19:59:01] ymaheo at hexaglobe dot com

After review, it seems that the segfault is not located in JSON part, but in zend_alloc.

We have some other backtraces where it happens in other parts of code. The issue is PHP memory
allocation and all these segfaults happen in zend_mm_alloc_small.

#0 zend_mm_alloc_small (bin_num=6, size=56, heap=0x7f1717a00040) at
/usr/src/debug/php-7.3.9/Zend/zend_alloc.c:1289
#1 zend_mm_alloc_heap (size=56, heap=0x7f1717a00040) at
/usr/src/debug/php-7.3.9/Zend/zend_alloc.c:1360
#2 _emalloc (size=size@entry=56) at /usr/src/debug/php-7.3.9/Zend/zend_alloc.c:2500
#3 0x00007f171fd7ef46 in zend_string_alloc (persistent=0, len=26) at
/usr/src/debug/php-7.3.9/Zend/zend_string.h:133
#4 concat_function (result=0x7f1717a1bea0, op1=<optimized out>, op1@entry=0x7f1717a1beb0,
op2=0x7ffc96ba2bd0, op2@entry=0x7f1717a1bec0) at /usr/src/debug/php-7.3.9/Zend/zend_operators.c:1852
#5 0x00007f171fdd9365 in ZEND_CONCAT_SPEC_TMPVAR_TMPVAR_HANDLER () at
/usr/src/debug/php-7.3.9/Zend/zend_vm_execute.h:14723
#6 0x00007f171fe0f1a4 in execute_ex (ex=0x2fce00) at
/usr/src/debug/php-7.3.9/Zend/zend_vm_execute.h:57011
#7 0x00007f171fe15e83 in zend_execute (op_array=op_array@entry=0x7f1717a721c0, return_value=0x0,
return_value@entry=0x7f16ec5130b8) at /usr/src/debug/php-7.3.9/Zend/zend_vm_execute.h:60881
#8 0x00007f171fd868c2 in zend_execute_scripts (type=type@entry=8, retval=0x7f16ec5130b8,
retval@entry=0x0, file_count=396475968, file_count@entry=3) at
/usr/src/debug/php-7.3.9/Zend/zend.c:1568
#9 0x00007f171fd264f0 in php_execute_script (primary_file=primary_file@entry=0x7ffc96ba5140) at
/usr/src/debug/php-7.3.9/main/main.c:2639
#10 0x00007f171fe180b2 in php_handler (r=<optimized out>) at
/usr/src/debug/php-7.3.9/sapi/apache2handler/sapi_apache2.c:699
#11 0x0000560bdb7b0990 in ?? ()
#12 0x0000560bdd16cd78 in ?? ()
#13 0x0000560bdcf87800 in ?? ()
#14 0x0000560bdd16b3f0 in ?? ()
#15 0x0000560bdb7b0ed9 in ?? ()
#16 0x0000560bdcf9e990 in ?? ()
#17 0x0000560bdb7a9b5f in ?? ()
#18 0x0000000000000000 in ?? ()

------------------------------------------------------------------------


The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at

    https://bugs.php.net/bug.php?id=78539


--
Edit this bug report at https://bugs.php.net/bug.php?id=78539&edit=1


Thread (10 messages)

« previous php.bugs (#232786) next »