Bug #81353 [Com]: segfault with preloading and statically bound closure

From: Date: Thu, 28 Oct 2021 20:50:24 +0000
Subject: Bug #81353 [Com]: segfault with preloading and statically bound closure
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-237424@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=81353&edit=1

 ID:                 81353
 Comment by:         mhemmings at nwtel dot ca
 Reported by:        mike@php.net
 Summary:            segfault with preloading and statically bound
                     closure
 Status:             Closed
 Type:               Bug
 Package:            opcache
 Operating System:   Linux, macOS
 PHP Version:        7.4Git
 Block user comment: N
 Private report:     N

 New Comment:

Sorry, related to my above

opcache 7.4.24-1.el7.remi from Remi's Repo RHEL 7.8


Previous Comments:
------------------------------------------------------------------------
[2021-10-28 20:49:11] mhemmings at nwtel dot ca

Disabling opcache does resolve the issue
Can provide a full core dump if necessary

#0  0x000056097c093c06 in _emalloc_56 ()
#1  0x000056097c0c6059 in _zend_new_array_0 ()
#2  0x000056097c021195 in zif_explode ()
#3  0x000056097c13c708 in execute_ex ()
#4  0x000056097c0abdf6 in zend_call_function ()
#5  0x000056097bfb4a0c in zif_spl_autoload_call ()
#6  0x000056097c0abcd2 in zend_call_function ()
#7  0x000056097c0ac2cd in zend_lookup_class_ex ()
#8  0x000056097c0acb4c in zend_fetch_class_by_name ()
#9  0x000056097c11f0a7 in ZEND_NEW_SPEC_CONST_UNUSED_HANDLER ()
#10 0x000056097c13a45a in execute_ex ()
#11 0x000056097c141a21 in zend_execute ()
#12 0x000056097c0ba793 in zend_execute_scripts ()
#13 0x000056097c058f10 in php_execute_script ()
#14 0x000056097bec3e69 in main ()

------------------------------------------------------------------------
[2021-10-18 19:40:58] danderson at acromedia dot com

Segfaults are still happening with PHP (FPM) 8.0.11 from Remi's repo on RedHat Enterprise 7.8
(php-opcache-8.0.11-1.el7.remi.x86_64). 

Disabling the opcache module stops the segfaults.

I'm happy to provide full environment info in a DM if needed.

------------------------------------------------------------------------
[2021-08-16 13:06:09] git@php.net

Automatic comment on behalf of nikic
Revision: https://github.com/php/php-src/commit/d1e956ff31f607209e16a1e1ea9aff3702bdfe5b
Log: Fixed bug #81353

------------------------------------------------------------------------
[2021-08-16 12:50:24] nikic@php.net

We should be unsetting user defined error handlers before preloading.

------------------------------------------------------------------------
[2021-08-16 07:51:47] mike@php.net

ASAN report:

2021-08-16 09:47:50.462931+0200 php[45131:2277503] ==45131==ERROR: AddressSanitizer:
heap-use-after-free on address 0x000106452ca0 at pc 0x000100dd7b74 bp 0x00016fdf7650 sp
0x00016fdf7648
2021-08-16 09:47:50.462937+0200 php[45131:2277503] READ of size 4 at 0x000106452ca0 thread T0
2021-08-16 09:47:50.462942+0200 php[45131:2277503]     #0 0x100dd7b70 in zend_gc_refcount
zend_types.h:1025
2021-08-16 09:47:50.462946+0200 php[45131:2277503]     #1 0x100daa908 in
ZEND_BIND_STATIC_SPEC_CV_UNUSED_HANDLER zend_vm_execute.h:46571
2021-08-16 09:47:50.462950+0200 php[45131:2277503]     #2 0x100c16490 in execute_ex
zend_vm_execute.h:53291
2021-08-16 09:47:50.462954+0200 php[45131:2277503]     #3 0x100a91504 in zend_call_function
zend_execute_API.c:820
2021-08-16 09:47:50.462958+0200 php[45131:2277503]     #4 0x1005b1284 in zif_spl_autoload_call
php_spl.c:452
2021-08-16 09:47:50.462962+0200 php[45131:2277503]     #5 0x100a917c0 in zend_call_function
zend_execute_API.c:833
2021-08-16 09:47:50.462966+0200 php[45131:2277503]     #6 0x100a937a8 in zend_lookup_class_ex
zend_execute_API.c:1002
2021-08-16 09:47:50.462970+0200 php[45131:2277503]     #7 0x100a95fdc in zend_fetch_class_by_name
zend_execute_API.c:1433
2021-08-16 09:47:50.462974+0200 php[45131:2277503]     #8 0x100ce0aa0 in
ZEND_NEW_SPEC_CONST_UNUSED_HANDLER zend_vm_execute.h:9255
2021-08-16 09:47:50.462978+0200 php[45131:2277503]     #9 0x100c16490 in execute_ex
zend_vm_execute.h:53291
2021-08-16 09:47:50.462982+0200 php[45131:2277503]     #10 0x100a91504 in zend_call_function
zend_execute_API.c:820
2021-08-16 09:47:50.462986+0200 php[45131:2277503]     #11 0x100a8f2e8 in _call_user_function_ex
zend_execute_API.c:645
2021-08-16 09:47:50.462993+0200 php[45131:2277503]     #12 0x100adf550 in zend_error_va_list
zend.c:1380
2021-08-16 09:47:50.462998+0200 php[45131:2277503]     #13 0x100add7b8 in zend_error_at zend.c:1483
2021-08-16 09:47:50.463001+0200 php[45131:2277503]     #14 0x107c21ce0 in preload_link
ZendAccelerator.c:3809
2021-08-16 09:47:50.463005+0200 php[45131:2277503]     #15 0x107c1d9f8 in accel_preload
ZendAccelerator.c:4503
2021-08-16 09:47:50.463009+0200 php[45131:2277503]     #16 0x107c18054 in accel_finish_startup
ZendAccelerator.c:4830
2021-08-16 09:47:50.463013+0200 php[45131:2277503]     #17 0x107c14ee4 in accel_post_startup
ZendAccelerator.c:3059
2021-08-16 09:47:50.463016+0200 php[45131:2277503]     #18 0x100adbae8 in zend_post_startup
zend.c:1009
2021-08-16 09:47:50.463020+0200 php[45131:2277503]     #19 0x100909bb0 in php_module_startup
main.c:2397
2021-08-16 09:47:50.463024+0200 php[45131:2277503]     #20 0x100e0f084 in php_cli_startup
php_cli.c:410
2021-08-16 09:47:50.463027+0200 php[45131:2277503]     #21 0x100e0b788 in main php_cli.c:1327
2021-08-16 09:47:50.463031+0200 php[45131:2277503]     #22 0x1a119542c in start+0x0
(libdyld.dylib:arm64e+0x1842c)
2021-08-16 09:47:50.463034+0200 php[45131:2277503] 
2021-08-16 09:47:50.463038+0200 php[45131:2277503] 0x000106452ca0 is located 0 bytes inside of
56-byte region [0x000106452ca0,0x000106452cd8)
2021-08-16 09:47:50.463042+0200 php[45131:2277503] freed by thread T0 here:
2021-08-16 09:47:50.463045+0200 php[45131:2277503]     #0 0x10213f2b4 in wrap_free+0x98
(libclang_rt.asan_osx_dynamic.dylib:arm64e+0x3f2b4)
2021-08-16 09:47:50.463049+0200 php[45131:2277503]     #1 0x100a1f280 in _efree_custom
zend_alloc.c:2426
2021-08-16 09:47:50.463053+0200 php[45131:2277503]     #2 0x100a1f138 in _efree zend_alloc.c:2546
2021-08-16 09:47:50.463057+0200 php[45131:2277503]     #3 0x100b2e790 in zend_array_destroy
zend_hash.c:1637
2021-08-16 09:47:50.463060+0200 php[45131:2277503]     #4 0x100a9fee8 in destroy_op_array
zend_opcode.c:428
2021-08-16 09:47:50.463064+0200 php[45131:2277503]     #5 0x100b9d90c in zend_closure_free_storage
zend_closures.c:474
2021-08-16 09:47:50.463075+0200 php[45131:2277503]     #6 0x100bebdd0 in
zend_objects_store_free_object_storage zend_objects_API.c:104
2021-08-16 09:47:50.463079+0200 php[45131:2277503]     #7 0x107c1ca58 in accel_preload
ZendAccelerator.c:4435
2021-08-16 09:47:50.463083+0200 php[45131:2277503]     #8 0x107c18054 in accel_finish_startup
ZendAccelerator.c:4830
2021-08-16 09:47:50.463087+0200 php[45131:2277503]     #9 0x107c14ee4 in accel_post_startup
ZendAccelerator.c:3059
2021-08-16 09:47:50.463090+0200 php[45131:2277503]     #10 0x100adbae8 in zend_post_startup
zend.c:1009
2021-08-16 09:47:50.463094+0200 php[45131:2277503]     #11 0x100909bb0 in php_module_startup
main.c:2397
2021-08-16 09:47:50.463098+0200 php[45131:2277503]     #12 0x100e0f084 in php_cli_startup
php_cli.c:410
2021-08-16 09:47:50.463102+0200 php[45131:2277503]     #13 0x100e0b788 in main php_cli.c:1327
2021-08-16 09:47:50.463105+0200 php[45131:2277503]     #14 0x1a119542c in start+0x0
(libdyld.dylib:arm64e+0x1842c)
2021-08-16 09:47:50.463109+0200 php[45131:2277503] 
2021-08-16 09:47:50.463112+0200 php[45131:2277503] previously allocated by thread T0 here:
2021-08-16 09:47:50.463116+0200 php[45131:2277503]     #0 0x10213f178 in wrap_malloc+0x94
(libclang_rt.asan_osx_dynamic.dylib:arm64e+0x3f178)
2021-08-16 09:47:50.463120+0200 php[45131:2277503]     #1 0x100a1f9a0 in __zend_malloc
zend_alloc.c:2982
2021-08-16 09:47:50.463123+0200 php[45131:2277503]     #2 0x100a1f080 in _malloc_custom
zend_alloc.c:2417
2021-08-16 09:47:50.463127+0200 php[45131:2277503]     #3 0x100a1ef28 in _emalloc zend_alloc.c:2536
2021-08-16 09:47:50.463131+0200 php[45131:2277503]     #4 0x100b22ab4 in zend_array_dup
zend_hash.c:2047
2021-08-16 09:47:50.463134+0200 php[45131:2277503]     #5 0x100b996fc in zend_create_closure
zend_closures.c:704
2021-08-16 09:47:50.463138+0200 php[45131:2277503]     #6 0x100d725c0 in
ZEND_DECLARE_LAMBDA_FUNCTION_SPEC_CONST_UNUSED_HANDLER zend_vm_execute.h:9548
2021-08-16 09:47:50.463142+0200 php[45131:2277503]     #7 0x100c16490 in execute_ex
zend_vm_execute.h:53291
2021-08-16 09:47:50.463146+0200 php[45131:2277503]     #8 0x100c16930 in zend_execute
zend_vm_execute.h:57593
2021-08-16 09:47:50.463150+0200 php[45131:2277503]     #9 0x107c1c690 in accel_preload
ZendAccelerator.c:4372
2021-08-16 09:47:50.463153+0200 php[45131:2277503]     #10 0x107c18054 in accel_finish_startup
ZendAccelerator.c:4830
2021-08-16 09:47:50.463157+0200 php[45131:2277503]     #11 0x107c14ee4 in accel_post_startup
ZendAccelerator.c:3059
2021-08-16 09:47:50.463161+0200 php[45131:2277503]     #12 0x100adbae8 in zend_post_startup
zend.c:1009
2021-08-16 09:47:50.463164+0200 php[45131:2277503]     #13 0x100909bb0 in php_module_startup
main.c:2397
2021-08-16 09:47:50.463168+0200 php[45131:2277503]     #14 0x100e0f084 in php_cli_startup
php_cli.c:410
2021-08-16 09:47:50.463171+0200 php[45131:2277503]     #15 0x100e0b788 in main php_cli.c:1327
2021-08-16 09:47:50.463175+0200 php[45131:2277503]     #16 0x1a119542c in start+0x0
(libdyld.dylib:arm64e+0x1842c)

------------------------------------------------------------------------


The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at

    https://bugs.php.net/bug.php?id=81353


--
Edit this bug report at https://bugs.php.net/bug.php?id=81353&edit=1


Thread (10 messages)

« previous php.bugs (#237424) next »