Bug #81167 [Opn]: Segfault when loading a large file

From: Date: Fri, 18 Jun 2021 12:39:05 +0000
Subject: Bug #81167 [Opn]: Segfault when loading a large file
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-234485@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=81167&edit=1 ID: 81167 Updated by: nikic@php.net Reported by: kochnorman at rocketmail dot com Summary: Segfault when loading a large file Status: Open Type: Bug Package: Scripting Engine problem Operating System: Debian 10 PHP Version: 7.3.19-1~deb10u1 Block user comment: N Private report: N New Comment: > I've created a core dump which is available under > https://optimalbliss.de/core-php.329.zip . Sorry for not upload them > here, but I found no way of doing that. Would it be possible for you to extract the backtrace from the core dump? Something like "gdb path/to/php path/to/core" and then "bt" should do it. Analyzing a core dump requires the original binary to be available, so it's hard to do this on a different machine. It may be worth trying whether it works without xdebug. That's the only extension that looks problematic. Previous Comments: ------------------------------------------------------------------------ [2021-06-18 12:34:44] cmb@php.net PHP-7.3 is no longer actively supported[1]. Can you please try with latest PHP 7.4 or 8.0? [1] <https://www.php.net/supported-versions.php> ------------------------------------------------------------------------ [2021-06-18 09:53:17] kochnorman at rocketmail dot com I've created a core dump which is available under https://optimalbliss.de/core-php.329.zip . Sorry for not upload them here, but I found no way of doing that. My php -m gives me: [PHP Modules] calendar Core ctype date dom exif fileinfo filter ftp gd gettext hash http iconv imagick json libxml memprof mysqli mysqlnd openssl pcntl pcre PDO pdo_mysql Phar posix propro raphf readline Reflection session shmop SimpleXML sockets sodium SPL standard sysvmsg sysvsem sysvshm tokenizer wddx xdebug xml xmlreader xmlwriter xsl Zend OPcache zip zlib [Zend Modules] Xdebug Zend OPcache I hope this helps researching this bug. ------------------------------------------------------------------------ [2021-06-18 09:31:25] krakjoe@php.net Thank you for this bug report. To properly diagnose the problem, we need a backtrace to see what is happening behind the scenes. To find out how to generate a backtrace, please read http://bugs.php.net/bugs-generating-backtrace.php for *NIX and http://bugs.php.net/bugs-generating-backtrace-win32.php for Win32 Once you have generated a backtrace, please submit it to this bug report and change the status back to "Open". Thank you for helping us make PHP better. I also cannot reproduce. A copy of the trace is necessary most likely, and also a list of extensions. ------------------------------------------------------------------------ [2021-06-18 09:25:03] nikic@php.net I can't reproduce this on any supported PHP version. I also tried this with more functions (50000 instead of 1000) with same result. ------------------------------------------------------------------------ [2021-06-18 09:18:27] kochnorman at rocketmail dot com Description: ------------ Sorry first, I use PHP 7.3.19-1~deb10u1, but I could not choose this version. I encountered problems with a very larges script I have. The minimal (not-)working example I could create can be created and tested with perl -e 'sub rstr { my $len = shift; return join("", map { (a..z,A..Z,0..9)[rand 67] } 0..$len) }; print "<?php\n"; my $subname = "a"; foreach (1 .. 1000) { print qq#function test_$subname () { return "#.rstr(100).qq#"; }\n#; $subname++; }' > test.php; php -l test.php The file compiles, but then crashes with [1] 32247 segmentation fault php -l test.php I believe a 1000-line-file should not cause this error. Trying to reduce the length of the file, I even get another message: perl -e 'sub rstr { my $len = shift; return join("", map { (a..z,A..Z,0..9)[rand 67] } 0..$len) }; print "<?php\n"; my $subname = "a"; foreach (1 .. 1000) { print qq#function test_$subname () { return "#.rstr(100).qq#"; }\n#; $subname++; }' > test.php; php -l test.php No syntax errors detected in test.php zend_mm_heap corrupted I have no idea why this happens. I can work around this problem by splitting a large file into several smaller ones and then including the smaller files. Test script: --------------- Segfault: perl -e 'sub rstr { my $len = shift; return join("", map { (a..z,A..Z,0..9)[rand 67] } 0..$len) }; print "<?php\n"; my $subname = "a"; foreach (1 .. 1000) { print qq#function test_$subname () { return "#.rstr(100).qq#"; }\n#; $subname++; }' > test.php; php -l test.php zend_mm_heap corrupted: perl -e 'sub rstr { my $len = shift; return join("", map { (a..z,A..Z,0..9)[rand 67] } 0..$len) }; print "<?php\n"; my $subname = "a"; foreach (1 .. 1000) { print qq#function test_$subname () { return "#.rstr(100).qq#"; }\n#; $subname++; }' > test.php; php -l test.php ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=81167&edit=1

« previous php.bugs (#234485) next »