Bug #81353 [Com]: segfault with preloading and statically bound closure
| From: | mhemmings at nwtel dot ca | Date: | Thu, 28 Oct 2021 20:49:11 +0000 |
| Subject: | Bug #81353 [Com]: segfault with preloading and statically bound closure | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-237423@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=81353&edit=1
ID: 81353
Comment by: mhemmings at nwtel dot ca
Reported by: mike@php.net
Summary: segfault with preloading and statically bound
closure
Status: Closed
Type: Bug
Package: opcache
Operating System: Linux, macOS
PHP Version: 7.4Git
Block user comment: N
Private report: N
New Comment:
Disabling opcache does resolve the issue
Can provide a full core dump if necessary
#0 0x000056097c093c06 in _emalloc_56 ()
#1 0x000056097c0c6059 in _zend_new_array_0 ()
#2 0x000056097c021195 in zif_explode ()
#3 0x000056097c13c708 in execute_ex ()
#4 0x000056097c0abdf6 in zend_call_function ()
#5 0x000056097bfb4a0c in zif_spl_autoload_call ()
#6 0x000056097c0abcd2 in zend_call_function ()
#7 0x000056097c0ac2cd in zend_lookup_class_ex ()
#8 0x000056097c0acb4c in zend_fetch_class_by_name ()
#9 0x000056097c11f0a7 in ZEND_NEW_SPEC_CONST_UNUSED_HANDLER ()
#10 0x000056097c13a45a in execute_ex ()
#11 0x000056097c141a21 in zend_execute ()
#12 0x000056097c0ba793 in zend_execute_scripts ()
#13 0x000056097c058f10 in php_execute_script ()
#14 0x000056097bec3e69 in main ()
Previous Comments:
------------------------------------------------------------------------
[2021-10-18 19:40:58] danderson at acromedia dot com
Segfaults are still happening with PHP (FPM) 8.0.11 from Remi's repo on RedHat Enterprise 7.8
(php-opcache-8.0.11-1.el7.remi.x86_64).
Disabling the opcache module stops the segfaults.
I'm happy to provide full environment info in a DM if needed.
------------------------------------------------------------------------
[2021-08-16 13:06:09] git@php.net
Automatic comment on behalf of nikic
Revision: https://github.com/php/php-src/commit/d1e956ff31f607209e16a1e1ea9aff3702bdfe5b
Log: Fixed bug #81353
------------------------------------------------------------------------
[2021-08-16 12:50:24] nikic@php.net
We should be unsetting user defined error handlers before preloading.
------------------------------------------------------------------------
[2021-08-16 07:51:47] mike@php.net
ASAN report:
2021-08-16 09:47:50.462931+0200 php[45131:2277503] ==45131==ERROR: AddressSanitizer:
heap-use-after-free on address 0x000106452ca0 at pc 0x000100dd7b74 bp 0x00016fdf7650 sp
0x00016fdf7648
2021-08-16 09:47:50.462937+0200 php[45131:2277503] READ of size 4 at 0x000106452ca0 thread T0
2021-08-16 09:47:50.462942+0200 php[45131:2277503] #0 0x100dd7b70 in zend_gc_refcount
zend_types.h:1025
2021-08-16 09:47:50.462946+0200 php[45131:2277503] #1 0x100daa908 in
ZEND_BIND_STATIC_SPEC_CV_UNUSED_HANDLER zend_vm_execute.h:46571
2021-08-16 09:47:50.462950+0200 php[45131:2277503] #2 0x100c16490 in execute_ex
zend_vm_execute.h:53291
2021-08-16 09:47:50.462954+0200 php[45131:2277503] #3 0x100a91504 in zend_call_function
zend_execute_API.c:820
2021-08-16 09:47:50.462958+0200 php[45131:2277503] #4 0x1005b1284 in zif_spl_autoload_call
php_spl.c:452
2021-08-16 09:47:50.462962+0200 php[45131:2277503] #5 0x100a917c0 in zend_call_function
zend_execute_API.c:833
2021-08-16 09:47:50.462966+0200 php[45131:2277503] #6 0x100a937a8 in zend_lookup_class_ex
zend_execute_API.c:1002
2021-08-16 09:47:50.462970+0200 php[45131:2277503] #7 0x100a95fdc in zend_fetch_class_by_name
zend_execute_API.c:1433
2021-08-16 09:47:50.462974+0200 php[45131:2277503] #8 0x100ce0aa0 in
ZEND_NEW_SPEC_CONST_UNUSED_HANDLER zend_vm_execute.h:9255
2021-08-16 09:47:50.462978+0200 php[45131:2277503] #9 0x100c16490 in execute_ex
zend_vm_execute.h:53291
2021-08-16 09:47:50.462982+0200 php[45131:2277503] #10 0x100a91504 in zend_call_function
zend_execute_API.c:820
2021-08-16 09:47:50.462986+0200 php[45131:2277503] #11 0x100a8f2e8 in _call_user_function_ex
zend_execute_API.c:645
2021-08-16 09:47:50.462993+0200 php[45131:2277503] #12 0x100adf550 in zend_error_va_list
zend.c:1380
2021-08-16 09:47:50.462998+0200 php[45131:2277503] #13 0x100add7b8 in zend_error_at zend.c:1483
2021-08-16 09:47:50.463001+0200 php[45131:2277503] #14 0x107c21ce0 in preload_link
ZendAccelerator.c:3809
2021-08-16 09:47:50.463005+0200 php[45131:2277503] #15 0x107c1d9f8 in accel_preload
ZendAccelerator.c:4503
2021-08-16 09:47:50.463009+0200 php[45131:2277503] #16 0x107c18054 in accel_finish_startup
ZendAccelerator.c:4830
2021-08-16 09:47:50.463013+0200 php[45131:2277503] #17 0x107c14ee4 in accel_post_startup
ZendAccelerator.c:3059
2021-08-16 09:47:50.463016+0200 php[45131:2277503] #18 0x100adbae8 in zend_post_startup
zend.c:1009
2021-08-16 09:47:50.463020+0200 php[45131:2277503] #19 0x100909bb0 in php_module_startup
main.c:2397
2021-08-16 09:47:50.463024+0200 php[45131:2277503] #20 0x100e0f084 in php_cli_startup
php_cli.c:410
2021-08-16 09:47:50.463027+0200 php[45131:2277503] #21 0x100e0b788 in main php_cli.c:1327
2021-08-16 09:47:50.463031+0200 php[45131:2277503] #22 0x1a119542c in start+0x0
(libdyld.dylib:arm64e+0x1842c)
2021-08-16 09:47:50.463034+0200 php[45131:2277503]
2021-08-16 09:47:50.463038+0200 php[45131:2277503] 0x000106452ca0 is located 0 bytes inside of
56-byte region [0x000106452ca0,0x000106452cd8)
2021-08-16 09:47:50.463042+0200 php[45131:2277503] freed by thread T0 here:
2021-08-16 09:47:50.463045+0200 php[45131:2277503] #0 0x10213f2b4 in wrap_free+0x98
(libclang_rt.asan_osx_dynamic.dylib:arm64e+0x3f2b4)
2021-08-16 09:47:50.463049+0200 php[45131:2277503] #1 0x100a1f280 in _efree_custom
zend_alloc.c:2426
2021-08-16 09:47:50.463053+0200 php[45131:2277503] #2 0x100a1f138 in _efree zend_alloc.c:2546
2021-08-16 09:47:50.463057+0200 php[45131:2277503] #3 0x100b2e790 in zend_array_destroy
zend_hash.c:1637
2021-08-16 09:47:50.463060+0200 php[45131:2277503] #4 0x100a9fee8 in destroy_op_array
zend_opcode.c:428
2021-08-16 09:47:50.463064+0200 php[45131:2277503] #5 0x100b9d90c in zend_closure_free_storage
zend_closures.c:474
2021-08-16 09:47:50.463075+0200 php[45131:2277503] #6 0x100bebdd0 in
zend_objects_store_free_object_storage zend_objects_API.c:104
2021-08-16 09:47:50.463079+0200 php[45131:2277503] #7 0x107c1ca58 in accel_preload
ZendAccelerator.c:4435
2021-08-16 09:47:50.463083+0200 php[45131:2277503] #8 0x107c18054 in accel_finish_startup
ZendAccelerator.c:4830
2021-08-16 09:47:50.463087+0200 php[45131:2277503] #9 0x107c14ee4 in accel_post_startup
ZendAccelerator.c:3059
2021-08-16 09:47:50.463090+0200 php[45131:2277503] #10 0x100adbae8 in zend_post_startup
zend.c:1009
2021-08-16 09:47:50.463094+0200 php[45131:2277503] #11 0x100909bb0 in php_module_startup
main.c:2397
2021-08-16 09:47:50.463098+0200 php[45131:2277503] #12 0x100e0f084 in php_cli_startup
php_cli.c:410
2021-08-16 09:47:50.463102+0200 php[45131:2277503] #13 0x100e0b788 in main php_cli.c:1327
2021-08-16 09:47:50.463105+0200 php[45131:2277503] #14 0x1a119542c in start+0x0
(libdyld.dylib:arm64e+0x1842c)
2021-08-16 09:47:50.463109+0200 php[45131:2277503]
2021-08-16 09:47:50.463112+0200 php[45131:2277503] previously allocated by thread T0 here:
2021-08-16 09:47:50.463116+0200 php[45131:2277503] #0 0x10213f178 in wrap_malloc+0x94
(libclang_rt.asan_osx_dynamic.dylib:arm64e+0x3f178)
2021-08-16 09:47:50.463120+0200 php[45131:2277503] #1 0x100a1f9a0 in __zend_malloc
zend_alloc.c:2982
2021-08-16 09:47:50.463123+0200 php[45131:2277503] #2 0x100a1f080 in _malloc_custom
zend_alloc.c:2417
2021-08-16 09:47:50.463127+0200 php[45131:2277503] #3 0x100a1ef28 in _emalloc zend_alloc.c:2536
2021-08-16 09:47:50.463131+0200 php[45131:2277503] #4 0x100b22ab4 in zend_array_dup
zend_hash.c:2047
2021-08-16 09:47:50.463134+0200 php[45131:2277503] #5 0x100b996fc in zend_create_closure
zend_closures.c:704
2021-08-16 09:47:50.463138+0200 php[45131:2277503] #6 0x100d725c0 in
ZEND_DECLARE_LAMBDA_FUNCTION_SPEC_CONST_UNUSED_HANDLER zend_vm_execute.h:9548
2021-08-16 09:47:50.463142+0200 php[45131:2277503] #7 0x100c16490 in execute_ex
zend_vm_execute.h:53291
2021-08-16 09:47:50.463146+0200 php[45131:2277503] #8 0x100c16930 in zend_execute
zend_vm_execute.h:57593
2021-08-16 09:47:50.463150+0200 php[45131:2277503] #9 0x107c1c690 in accel_preload
ZendAccelerator.c:4372
2021-08-16 09:47:50.463153+0200 php[45131:2277503] #10 0x107c18054 in accel_finish_startup
ZendAccelerator.c:4830
2021-08-16 09:47:50.463157+0200 php[45131:2277503] #11 0x107c14ee4 in accel_post_startup
ZendAccelerator.c:3059
2021-08-16 09:47:50.463161+0200 php[45131:2277503] #12 0x100adbae8 in zend_post_startup
zend.c:1009
2021-08-16 09:47:50.463164+0200 php[45131:2277503] #13 0x100909bb0 in php_module_startup
main.c:2397
2021-08-16 09:47:50.463168+0200 php[45131:2277503] #14 0x100e0f084 in php_cli_startup
php_cli.c:410
2021-08-16 09:47:50.463171+0200 php[45131:2277503] #15 0x100e0b788 in main php_cli.c:1327
2021-08-16 09:47:50.463175+0200 php[45131:2277503] #16 0x1a119542c in start+0x0
(libdyld.dylib:arm64e+0x1842c)
------------------------------------------------------------------------
[2021-08-16 07:20:55] mike@php.net
Looks like it has to do with the static arrays and calling Closure::bind() with a class scope in
composer's autoload_static.
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=81353
--
Edit this bug report at https://bugs.php.net/bug.php?id=81353&edit=1