Bug #80968 [Com]: jit segfault on php-fpm

From: Date: Fri, 23 Apr 2021 01:55:12 +0000
Subject: Bug #80968 [Com]: jit segfault on php-fpm
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-233560@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=80968&edit=1

 ID:                 80968
 Comment by:         ryan dot brothers at gmail dot com
 Reported by:        ryan dot brothers at gmail dot com
 Summary:            jit segfault on php-fpm
 Status:             Open
 Type:               Bug
 Package:            JIT
 Operating System:   Linux
 PHP Version:        8.0.3
 Block user comment: N
 Private report:     N

 New Comment:

Thanks, I was able to reproduce the issue in master.  It seems to be related to certain php.ini
files.  What I did was take the default php.ini-development file, but added these 4 lines at the top
of the file:

zend_extension = opcache
opcache.enable = 1
opcache.jit = tracing
opcache.jit_buffer_size = 100M

When I do that, I can reproduce the issue.  The same issue happens if I start with
php.ini-production and add the 4 lines.

Please let me know if this helps to reproduce the issue, or I'll try to narrow it down further.
 Thank you again for your help.


Previous Comments:
------------------------------------------------------------------------
[2021-04-19 10:34:10] nikic@php.net

I'm not able to reproduce this on current master. It's possible that the issue has already
been fixed.

------------------------------------------------------------------------
[2021-04-19 02:09:33] ryan dot brothers at gmail dot com

Description:
------------
I am seeing a few segfaults when running PHP 8.0.3 with JIT enabled under nginx/php-fpm on CentOS 8.
 I'm not sure if all the segfaults I'm getting are related, but I've been able to
reproduce one of them so far.

To reproduce, set-up scripts 1.php and 2.php as listed, and then go to 1.php via nginx/php-fpm.  You
may have to hit the URL a few times to get the segfault.

My php.ini has:
opcache.jit = tracing
opcache.jit_buffer_size = 100M

Please let me know if I can give any more info to help reproduce it.

Thank you for your help.

Test script:
---------------
1.php:

<?php
class c1
{
	public static function __callStatic($method_name, $arguments)
	{
		return require('2.php');
	}
}

$data = array(1, 2);

for ($i = 0; $i < 100; $i++)
{
	c1::test($data);
}

=======

2.php:

<?php
if (is_array($arguments[0]) == true)
{
	foreach ($arguments[0] as $item)
	{
		c1::test($item);
	}
}

return $arguments[0];


Expected result:
----------------
No output.

Actual result:
--------------
nginx returns "An error occurred."

php-fpm.log has:
[18-Apr-2021 21:53:25] WARNING: [pool www] child 193586 exited on signal 11 (SIGSEGV) after
11.391747 seconds from start

/var/log/messages has:
Apr 18 21:53:25 server1 kernel: traps: php-fpm[193586] general protection fault ip:55fa3e1d2dbf
sp:7ffe87e6d8c0 error:0 in php-fpm[55fa3e0e4000+11c000]



------------------------------------------------------------------------



--
Edit this bug report at https://bugs.php.net/bug.php?id=80968&edit=1


Thread (8 messages)

« previous php.bugs (#233560) next »