Bug #81167 [Fbk->Opn]: Segfault when loading a large file

From: Date: Fri, 18 Jun 2021 09:53:17 +0000
Subject: Bug #81167 [Fbk->Opn]: Segfault when loading a large file
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-234483@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=81167&edit=1 ID: 81167 User updated by: kochnorman at rocketmail dot com Reported by: kochnorman at rocketmail dot com Summary: Segfault when loading a large file -Status: Feedback +Status: Open Type: Bug Package: Scripting Engine problem Operating System: Debian 10 -PHP Version: 7.3Git-2021-06-18 (Git) +PHP Version: 7.3.19-1~deb10u1 Block user comment: N Private report: N New Comment: I've created a core dump which is available under https://optimalbliss.de/core-php.329.zip . Sorry for not upload them here, but I found no way of doing that. My php -m gives me: [PHP Modules] calendar Core ctype date dom exif fileinfo filter ftp gd gettext hash http iconv imagick json libxml memprof mysqli mysqlnd openssl pcntl pcre PDO pdo_mysql Phar posix propro raphf readline Reflection session shmop SimpleXML sockets sodium SPL standard sysvmsg sysvsem sysvshm tokenizer wddx xdebug xml xmlreader xmlwriter xsl Zend OPcache zip zlib [Zend Modules] Xdebug Zend OPcache I hope this helps researching this bug. Previous Comments: ------------------------------------------------------------------------ [2021-06-18 09:31:25] krakjoe@php.net Thank you for this bug report. To properly diagnose the problem, we need a backtrace to see what is happening behind the scenes. To find out how to generate a backtrace, please read http://bugs.php.net/bugs-generating-backtrace.php for *NIX and http://bugs.php.net/bugs-generating-backtrace-win32.php for Win32 Once you have generated a backtrace, please submit it to this bug report and change the status back to "Open". Thank you for helping us make PHP better. I also cannot reproduce. A copy of the trace is necessary most likely, and also a list of extensions. ------------------------------------------------------------------------ [2021-06-18 09:25:03] nikic@php.net I can't reproduce this on any supported PHP version. I also tried this with more functions (50000 instead of 1000) with same result. ------------------------------------------------------------------------ [2021-06-18 09:18:27] kochnorman at rocketmail dot com Description: ------------ Sorry first, I use PHP 7.3.19-1~deb10u1, but I could not choose this version. I encountered problems with a very larges script I have. The minimal (not-)working example I could create can be created and tested with perl -e 'sub rstr { my $len = shift; return join("", map { (a..z,A..Z,0..9)[rand 67] } 0..$len) }; print "<?php\n"; my $subname = "a"; foreach (1 .. 1000) { print qq#function test_$subname () { return "#.rstr(100).qq#"; }\n#; $subname++; }' > test.php; php -l test.php The file compiles, but then crashes with [1] 32247 segmentation fault php -l test.php I believe a 1000-line-file should not cause this error. Trying to reduce the length of the file, I even get another message: perl -e 'sub rstr { my $len = shift; return join("", map { (a..z,A..Z,0..9)[rand 67] } 0..$len) }; print "<?php\n"; my $subname = "a"; foreach (1 .. 1000) { print qq#function test_$subname () { return "#.rstr(100).qq#"; }\n#; $subname++; }' > test.php; php -l test.php No syntax errors detected in test.php zend_mm_heap corrupted I have no idea why this happens. I can work around this problem by splitting a large file into several smaller ones and then including the smaller files. Test script: --------------- Segfault: perl -e 'sub rstr { my $len = shift; return join("", map { (a..z,A..Z,0..9)[rand 67] } 0..$len) }; print "<?php\n"; my $subname = "a"; foreach (1 .. 1000) { print qq#function test_$subname () { return "#.rstr(100).qq#"; }\n#; $subname++; }' > test.php; php -l test.php zend_mm_heap corrupted: perl -e 'sub rstr { my $len = shift; return join("", map { (a..z,A..Z,0..9)[rand 67] } 0..$len) }; print "<?php\n"; my $subname = "a"; foreach (1 .. 1000) { print qq#function test_$subname () { return "#.rstr(100).qq#"; }\n#; $subname++; }' > test.php; php -l test.php ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=81167&edit=1

« previous php.bugs (#234483) next »