Bug #80968 [Ver->Csd]: JIT segfault with return from required file
Edit report at https://bugs.php.net/bug.php?id=80968&edit=1
ID: 80968
Updated by: git@php.net
Reported by: ryan dot brothers at gmail dot com
Summary: JIT segfault with return from required file
-Status: Verified
+Status: Closed
Type: Bug
Package: JIT
Operating System: Linux
PHP Version: 8.0.3
Assigned To: dmitry
Block user comment: N
Private report: N
New Comment:
Automatic comment on behalf of dstogov
Revision: https://github.com/php/php-src/commit/6e2d47e071f5343b3de169a2dc6ce648d145d1a2
Log: Fixed bug #80968 (JIT segfault with return from required file)
Previous Comments:
------------------------------------------------------------------------
[2021-05-05 14:47:39] nikic@php.net
Slightly reduced variant just to show that this has no relation to __callStatic trampolines:
1.php
<?php
function foo($arguments) {
var_dump(require('2.php'));
}
for ($i = 0; $i < 100; $i++) {
foo([[1, 2]]);
}
2.php
<?php
if (is_array($arguments[0])) {
foreach ($arguments[0] as $item) {
foo([$item]);
}
}
return $arguments[0];
------------------------------------------------------------------------
[2021-05-05 13:34:18] nikic@php.net
Not sure what I did wrong before, but I can reproduce the issue now (using built-in server, just
--repeat mode doesn't seem to be sufficient) and get this assertion failure:
php: ext/opcache/jit/zend_jit_trace.c:340: zend_jit_trace_type_to_info_ex: Assertion `info & (1
<< type)' failed.
type is IS_UNDEF and the opline is the RETURN in __callStatic().
------------------------------------------------------------------------
[2021-05-05 07:52:49] philippreddigau+php at gmail dot com
Added a repository with docker image that reproduces the issue:
https://github.com/ItsReddi/sandbox
Reproduce:
1) clone repo
2) docker-compose up -d
3) Refresh one or multiple times at http://localhost:8080/php/bug_80968.php
------------------------------------------------------------------------
[2021-05-04 13:17:22] philippreddigau+php at gmail dot com
We can also confirm this issue on PHP 8.0.5 alpine based docker image.
Disabling the feature, fixes the problem.
dmesg logs:
1. Crash after refeshing the site:
[27876.626172] php-fpm[65114]: segfault at 0 ip 0000000000000000 sp 00007ffcf2210d50 error 14 in
zero (deleted)[41e5e000+6400000]
[27876.626353] Code: Unable to access opcode bytes at RIP 0xffffffffffffffd6.
2. Crash after try to access again
[27925.466121] php-fpm[65115]: segfault at 18 ip 0000558b23029c94 sp 00007ffcf2210d38 error 4 in
php-fpm[558b23000000+3ba000]
[27925.466297] Code: eb 19 49 83 c7 20 80 bb 22 02 00 00 00 74 0c 5a 5b 5d 41 5c 41 5d e9 7b c2 30
00 58 5b 5d 41 5c 41 5d c3 55 53 51 49 8b 46 08 <48> 8b 68 18 48 8b 50 30 4d 89 3e 8b 58 2c 49
89 56 08 48 8b 55 48
3. Crash, refreshing again
[27945.021344] php-fpm[65116]: segfault at 0 ip 0000000000000000 sp 00007ffcf22084a8 error 14 in
zero (deleted)[41e5e000+6400000]
[27945.021448] Code: Unable to access opcode bytes at RIP 0xffffffffffffffd6.
------------------------------------------------------------------------
[2021-04-23 01:55:12] ryan dot brothers at gmail dot com
Thanks, I was able to reproduce the issue in master. It seems to be related to certain php.ini
files. What I did was take the default php.ini-development file, but added these 4 lines at the top
of the file:
zend_extension = opcache
opcache.enable = 1
opcache.jit = tracing
opcache.jit_buffer_size = 100M
When I do that, I can reproduce the issue. The same issue happens if I start with
php.ini-production and add the 4 lines.
Please let me know if this helps to reproduce the issue, or I'll try to narrow it down further.
Thank you again for your help.
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=80968
--
Edit this bug report at https://bugs.php.net/bug.php?id=80968&edit=1
Thread (8 messages)