Bug #74804 [Opn->Fbk]: Segfault when instantiating object in array

From: Date: Wed, 02 Jun 2021 15:01:41 +0000
Subject: Bug #74804 [Opn->Fbk]: Segfault when instantiating object in array
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-234174@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=74804&edit=1

 ID:                 74804
 Updated by:         cmb@php.net
 Reported by:        steve dot hall+bugs dot php dot net at rg456 dot co
                     dot uk
 Summary:            Segfault when instantiating object in array
-Status:             Open
+Status:             Feedback
 Type:               Bug
 Package:            Reproducible crash
 Operating System:   Alpine 3.4 & Windows 10
 PHP Version:        7.1.6
-Assigned To:        
+Assigned To:        cmb
 Block user comment: N
 Private report:     N

 New Comment:

Is this still an issue with any of the actively supported PHP
versions[1]?

[1] <https://www.php.net/supported-versions.php>


Previous Comments:
------------------------------------------------------------------------
[2017-07-08 15:03:39] steve dot hall+bugs dot php dot net at rg456 dot co dot uk

Hi again nikic, 

I have gone through the code base and made every destructor just return without doing anything if
there is an environment variable set:

public function __destruct()
{
    if (null !== getenv('NODESTRUCT')) return;
    //etc...
}

I've then re-run valgrind and it still comes out with things like this:
==63== Invalid read of size 4
==63==    at 0x7901BF: zval_delref_p (zend_types.h:838)
==63==    by 0x7904AC: i_zval_ptr_dtor (zend_variables.h:47)
==63==    by 0x7906A3: zend_object_std_dtor (zend_objects.c:68)
==63==    by 0x77CBB1: zend_gc_collect_cycles (zend_gc.c:1175)
==63==    by 0x77AAF4: gc_possible_root (zend_gc.c:286)
==63==    by 0x728087: gc_check_possible_root (zend_gc.h:149)
==63==    by 0x728137: i_zval_ptr_dtor (zend_variables.h:50)
==63==    by 0x729D4C: _zval_ptr_dtor (zend_execute_API.c:550)
==63==    by 0x60CC03: var_destroy (var_unserializer.c:234)
==63==    by 0x60C5B1: php_var_unserialize_destroy (var_unserializer.c:53)
==63==    by 0x5FB926: zif_unserialize (var.c:1131)
==63==    by 0x7A918A: ZEND_DO_FCALL_BY_NAME_SPEC_RETVAL_USED_HANDLER (zend_vm_execute.h:876)
==63==    by 0x7A7F69: execute_ex (zend_vm_execute.h:429)
==63==    by 0x72B19D: zend_call_function (zend_execute_API.c:855)
==63==    by 0x59B30D: zif_call_user_func_array (basic_functions.c:4860)
==63==    by 0x7A918A: ZEND_DO_FCALL_BY_NAME_SPEC_RETVAL_USED_HANDLER (zend_vm_execute.h:876)
==63==    by 0x7A7F69: execute_ex (zend_vm_execute.h:429)
==63==    by 0x72B19D: zend_call_function (zend_execute_API.c:855)
==63==    by 0x51B617: reflection_method_invoke (php_reflection.c:3325)
==63==    by 0x51B7E7: zim_reflection_method_invokeArgs (php_reflection.c:3361)
==63==    by 0x7A961A: ZEND_DO_FCALL_SPEC_RETVAL_UNUSED_HANDLER (zend_vm_execute.h:970)
==63==    by 0x7A7F69: execute_ex (zend_vm_execute.h:429)
==63==    by 0x7A807A: zend_execute (zend_vm_execute.h:474)
==63==    by 0x744DCD: zend_execute_scripts (zend.c:1476)
==63==    by 0x6A8673: php_execute_script (main.c:2537)
==63==    by 0x82EF29: do_cli (php_cli.c:993)
==63==    by 0x8300F0: main (php_cli.c:1381)


Have I misunderstood the cause of https://bugs.php.net/bug.php?id=72530 or is it
possible that this fault has a different cause? My logic being that #72530 is caused by behaviour in
the destructor, and I'm reasonably sure there is nothing happening in any of my destructors. 

Thanks

------------------------------------------------------------------------
[2017-07-03 15:44:25] nikic@php.net

Based on what we know so far, this is likely an instance of bug #72530.

------------------------------------------------------------------------
[2017-06-23 14:41:33] steve dot hall+bugs dot php dot net at rg456 dot co dot uk

Thank you for your time on this nikic, it is much appreciated. 

Here is a valgrind from php -n 
https://gist.github.com/sh41/30890b1021cac6bec0530292ffc5fd11

I've included the output of php -n -i so that you can see what extensions are
loaded. I think that openssl is compiled in, and it's also required by the program I'm
running, so don't think I can usefully revert to a version without it. 

Must admit that I'm out of my depth when it comes to php internals, but if it helps, the times
I was able to catch the seg fault in action it seemed to happen at this line: https://github.com/symfony/symfony/blob/v3.3.2/src/Symfony/Component/VarDumper/Cloner/VarCloner.php#L123


Not sure if that helps to point in the right direction or not.

Is there anything else I can do to provide more information on this?

------------------------------------------------------------------------
[2017-06-23 14:31:43] nikic@php.net

The last valgrind output looks pretty good. This seems to be some kind of GC issue involving
destructors and nested GCs. From the valgrind output, what seems to be happening:
 1. During the outer GC, while running a destructor and object is created.
 2. During the inner GC that object is freed.
 3. During the outer GC, there is an attempt to free the object again.

Not sure how we could actually end up in that situation though. It might help to find out which
__destruct() method is involved here. (From the trace, the __destruct() might be calling __invoke()
on a closure, though it's not clear if that's a direct call.)

------------------------------------------------------------------------
[2017-06-23 13:55:50] steve dot hall+bugs dot php dot net at rg456 dot co dot uk

New valgrind here with "export USE_ZEND_ALLOC=0" and ZEND_DONT_UNLOAD_MODULES=1 and a
couple of Invalid reads/writes:
https://gist.github.com/sh41/2dd25967ec598f4f48bbdf049df2e462#file-valgrind-L7126

I will try to eliminate un-needed extensions with -n and provide another one as soon as I can.

------------------------------------------------------------------------


The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at

    https://bugs.php.net/bug.php?id=74804


--
Edit this bug report at https://bugs.php.net/bug.php?id=74804&edit=1


Thread (13 messages)

« previous php.bugs (#234174) next »