Bug #81206 [Ver->Csd]: Multiple PHP processes crash with JIT enabled

From: Date: Mon, 19 Jul 2021 21:58:27 +0000
Subject: Bug #81206 [Ver->Csd]: Multiple PHP processes crash with JIT enabled
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-235194@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=81206&edit=1 ID: 81206 Updated by: git@php.net Reported by: dktapps at pmmp dot io Summary: Multiple PHP processes crash with JIT enabled -Status: Verified +Status: Closed Type: Bug Package: JIT Operating System: Windows PHP Version: 8.0.7 Assigned To: cmb Block user comment: N Private report: N New Comment: Automatic comment on behalf of cmb69 Revision: https://github.com/php/php-src/commit/ef77d3c89f3ca7750b78a7974ebb82d8b116506f Log: Fix #81206: Multiple PHP processes crash with JIT enabled Previous Comments: ------------------------------------------------------------------------ [2021-06-29 21:14:15] cmb@php.net The following pull request has been associated: Patch Name: Fix #81206: Multiple PHP processes crash with JIT enabled On GitHub: https://github.com/php/php-src/pull/7208 Patch: https://github.com/php/php-src/pull/7208.patch ------------------------------------------------------------------------ [2021-06-28 21:30:25] dktapps at pmmp dot io To clarify on my previous comment: It appears that this code: https://github.com/php/php-src/blob/0e932f7ceaab503d136a524bf7f9cefb32be29fa/ext/opcache/jit/zend_jit.c#L4911 is trashing the stubs in the shared dasm_buf (which have already been initialized by the parent process) because it assumes that the child process did not reattach to a preexisting SHM. This causes the parent process to explode. ------------------------------------------------------------------------ [2021-06-28 21:18:49] dktapps at pmmp dot io This problem appears to have been caused by https://github.com/php/php-src/pull/6268. Reverting this commit fixes the problem. ------------------------------------------------------------------------ [2021-06-28 20:05:54] dktapps at pmmp dot io Description: ------------ Using the below script with JIT=1205, I'm able to trigger a segfault on require(). This does not happen if JIT is disabled. This only happens on Windows. Test script: --------------- test.php: <?php declare(strict_types=1); system(PHP_BINARY . " -v"); echo "Including script 'Test.php'\n"; require dirname(__DIR__) . '/helpers/Test.php'; echo "Done!\n"; helpers/Test.php: <?php class Test{ public static function doSomething() : void{ $time = time(); while(time() < $time + 10){} echo "done\n"; } } Expected result: ---------------- PHP 8.0.7 (cli) (built: Jun 2 2021 00:40:57) ( NTS Visual C++ 2019 x64 ) Copyright (c) The PHP Group Zend Engine v4.0.7, Copyright (c) Zend Technologies with Zend OPcache v8.0.7, Copyright (c), by Zend Technologies Including script 'Test.php' Done! Actual result: -------------- As seen in the Windows, JIT=1205 run here: https://github.com/dktapps/php-8-jit-bugs/runs/2935629701?check_suite_focus=true PHP 8.0.7 (cli) (built: Jun 2 2021 00:40:57) ( NTS Visual C++ 2019 x64 ) Copyright (c) The PHP Group Zend Engine v4.0.7, Copyright (c) Zend Technologies with Zend OPcache v8.0.7, Copyright (c), by Zend Technologies Including script 'Test.php' FAILED: require-second-process.php (-1073741819) ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=81206&edit=1

« previous php.bugs (#235194) next »