Bug #80968 [Ver]: JIT segfault with return from required file

From: Date: Wed, 05 May 2021 14:47:39 +0000
Subject: Bug #80968 [Ver]: JIT segfault with return from required file
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-233693@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=80968&edit=1

 ID:                 80968
 Updated by:         nikic@php.net
 Reported by:        ryan dot brothers at gmail dot com
-Summary:            jit segfault on php-fpm
+Summary:            JIT segfault with return from required file
 Status:             Verified
 Type:               Bug
 Package:            JIT
 Operating System:   Linux
 PHP Version:        8.0.3
 Block user comment: N
 Private report:     N

 New Comment:

Slightly reduced variant just to show that this has no relation to __callStatic trampolines:

1.php
<?php
function foo($arguments) { 
    var_dump(require('2.php'));
}
for ($i = 0; $i < 100; $i++) {
    foo([[1, 2]]);
}

2.php
<?php 
if (is_array($arguments[0])) {
    foreach ($arguments[0] as $item) {
        foo([$item]);
    }
}
return $arguments[0];


Previous Comments:
------------------------------------------------------------------------
[2021-05-05 13:34:18] nikic@php.net

Not sure what I did wrong before, but I can reproduce the issue now (using built-in server, just
--repeat mode doesn't seem to be sufficient) and get this assertion failure:

php: ext/opcache/jit/zend_jit_trace.c:340: zend_jit_trace_type_to_info_ex: Assertion `info & (1
<< type)' failed.

type is IS_UNDEF and the opline is the RETURN in __callStatic().

------------------------------------------------------------------------
[2021-05-05 07:52:49] philippreddigau+php at gmail dot com

Added a repository with docker image that reproduces the issue:
https://github.com/ItsReddi/sandbox

Reproduce:
1) clone repo
2) docker-compose up -d
3) Refresh one or multiple times at http://localhost:8080/php/bug_80968.php

------------------------------------------------------------------------
[2021-05-04 13:17:22] philippreddigau+php at gmail dot com

We can also confirm this issue on PHP 8.0.5 alpine based docker image.
Disabling the feature, fixes the problem.

dmesg logs:
1. Crash after refeshing the site:
[27876.626172] php-fpm[65114]: segfault at 0 ip 0000000000000000 sp 00007ffcf2210d50 error 14 in
zero (deleted)[41e5e000+6400000]
[27876.626353] Code: Unable to access opcode bytes at RIP 0xffffffffffffffd6.

2. Crash after try to access again 
[27925.466121] php-fpm[65115]: segfault at 18 ip 0000558b23029c94 sp 00007ffcf2210d38 error 4 in
php-fpm[558b23000000+3ba000]
[27925.466297] Code: eb 19 49 83 c7 20 80 bb 22 02 00 00 00 74 0c 5a 5b 5d 41 5c 41 5d e9 7b c2 30
00 58 5b 5d 41 5c 41 5d c3 55 53 51 49 8b 46 08 <48> 8b 68 18 48 8b 50 30 4d 89 3e 8b 58 2c 49
89 56 08 48 8b 55 48

3. Crash, refreshing again
[27945.021344] php-fpm[65116]: segfault at 0 ip 0000000000000000 sp 00007ffcf22084a8 error 14 in
zero (deleted)[41e5e000+6400000]
[27945.021448] Code: Unable to access opcode bytes at RIP 0xffffffffffffffd6.

------------------------------------------------------------------------
[2021-04-23 01:55:12] ryan dot brothers at gmail dot com

Thanks, I was able to reproduce the issue in master.  It seems to be related to certain php.ini
files.  What I did was take the default php.ini-development file, but added these 4 lines at the top
of the file:

zend_extension = opcache
opcache.enable = 1
opcache.jit = tracing
opcache.jit_buffer_size = 100M

When I do that, I can reproduce the issue.  The same issue happens if I start with
php.ini-production and add the 4 lines.

Please let me know if this helps to reproduce the issue, or I'll try to narrow it down further.
 Thank you again for your help.

------------------------------------------------------------------------
[2021-04-19 10:34:10] nikic@php.net

I'm not able to reproduce this on current master. It's possible that the issue has already
been fixed.

------------------------------------------------------------------------


The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at

    https://bugs.php.net/bug.php?id=80968


--
Edit this bug report at https://bugs.php.net/bug.php?id=80968&edit=1


Thread (8 messages)

« previous php.bugs (#233693) next »