Edit report at https://bugs.php.net/bug.php?id=81607&edit=1
ID: 81607
Updated by: nikic@php.net
Reported by: mails at thomasbley dot de
Summary: Segmentation fault for opcache.enable_cli=1
Status: Verified
Type: Bug
Package: opcache
Operating System: linux
PHP Version: 8.1.0RC5
Block user comment: N
Private report: N
New Comment:
Here's a small reproducer:
<?php
// Create a SHM interned string for FooBar.
var_dump("FooBar");
$pid = pcntl_fork();
if ($pid == 0) {
// Child: Declare class FooBar {} to allocate CE cache slot.
require __DIR__ . '/t480_2.php';
} else if ($pid > 0) {
pcntl_wait($status);
var_dump(new FooBar); // Crash.
} else {
echo "pcntl_fork() failed\n";
}
t480_2.php:
<?php
class FooBar {}
Previous Comments:
------------------------------------------------------------------------
[2021-11-11 15:51:59] nikic@php.net
I believe this is a suspected issue where one process allocates a new map ptr slot on an existing
shm interned string and another tries to use it with a too small map ptr segment.
At least the ce cache slot seems to be one past the end of the map ptr segment.
------------------------------------------------------------------------
[2021-11-11 15:44:23] nikic@php.net
Can at least confirm the segfault. The class entry read from CE cache is corrupted.
------------------------------------------------------------------------
[2021-11-11 13:17:02] mails at thomasbley dot de
seems this code causes the segfault:
./src/Psalm/Internal/Fork/Pool.php:352
$message = unserialize(base64_decode($serialized_message, true));
data is:
O:39:"Psalm\Internal\Fork\ForkTaskDoneMessage":1:{s:4:"data";N;}
interface ForkMessage
{
}
class ForkTaskDoneMessage implements ForkMessage
{
/** @var mixed */
public $data;
/**
* @param mixed $data
*/
public function __construct($data)
{
$this->data = $data;
}
}
------------------------------------------------------------------------
[2021-11-11 12:54:53] mails at thomasbley dot de
yes
core-php.27635
#0 0x0000557656c14b67 in ?? ()
#1 0x0000557656c164fe in php_var_unserialize ()
#2 0x0000557656c0520a in php_unserialize_with_options ()
#3 0x0000557656c05457 in ?? ()
#4 0x0000557656cf4081 in execute_ex ()
#5 0x0000557656cfa24d in zend_execute ()
#6 0x0000557656c8b615 in zend_execute_scripts ()
#7 0x0000557656c288ca in php_execute_script ()
#8 0x0000557656d72e1e in ?? ()
#9 0x0000557656acdea8 in ?? ()
#10 0x00007f61a2a310b3 in __libc_start_main (main=0x557656acdaa0, argc=6, argv=0x7ffd37a1c568,
init=<optimized out>, fini=<optimized out>, rtld_fini=<optimized out>,
stack_end=0x7ffd37a1c558) at ../csu/libc-start.c:308
#11 0x0000557656ace04e in _start ()
core-php.27636
#0 0x0000557656c81cc4 in instanceof_function_slow ()
#1 0x0000557656cadcfa in ?? ()
#2 0x0000557656cf29f6 in execute_ex ()
#3 0x0000557656cfa24d in zend_execute ()
#4 0x0000557656c8b615 in zend_execute_scripts ()
#5 0x0000557656c288ca in php_execute_script ()
#6 0x0000557656d72e1e in ?? ()
#7 0x0000557656acdea8 in ?? ()
#8 0x00007f61a2a310b3 in __libc_start_main (main=0x557656acdaa0, argc=6, argv=0x7ffd37a1c568,
init=<optimized out>, fini=<optimized out>, rtld_fini=<optimized out>,
stack_end=0x7ffd37a1c558) at ../csu/libc-start.c:308
#9 0x0000557656ace04e in _start ()
core-php.27637
#0 0x0000557656c8dc74 in object_init_ex ()
#1 0x0000557656cc8495 in ?? ()
#2 0x0000557656cf147d in execute_ex ()
#3 0x0000557656cfa24d in zend_execute ()
#4 0x0000557656c8b615 in zend_execute_scripts ()
#5 0x0000557656c288ca in php_execute_script ()
#6 0x0000557656d72e1e in ?? ()
#7 0x0000557656acdea8 in ?? ()
#8 0x00007f61a2a310b3 in __libc_start_main (main=0x557656acdaa0, argc=6, argv=0x7ffd37a1c568,
init=<optimized out>, fini=<optimized out>, rtld_fini=<optimized out>,
stack_end=0x7ffd37a1c558) at ../csu/libc-start.c:308
#9 0x0000557656ace04e in _start ()
core-php.27638
#0 0x0000557656c8dc74 in object_init_ex ()
#1 0x0000557656cc8495 in ?? ()
#2 0x0000557656cf147d in execute_ex ()
#3 0x0000557656cfa24d in zend_execute ()
#4 0x0000557656c8b615 in zend_execute_scripts ()
#5 0x0000557656c288ca in php_execute_script ()
#6 0x0000557656d72e1e in ?? ()
#7 0x0000557656acdea8 in ?? ()
#8 0x00007f61a2a310b3 in __libc_start_main (main=0x557656acdaa0, argc=6, argv=0x7ffd37a1c568,
init=<optimized out>, fini=<optimized out>, rtld_fini=<optimized out>,
stack_end=0x7ffd37a1c558) at ../csu/libc-start.c:308
#9 0x0000557656ace04e in _start ()
core-php.27639
#0 0x0000557656c8dc74 in object_init_ex ()
#1 0x0000557656cc8495 in ?? ()
#2 0x0000557656cf147d in execute_ex ()
#3 0x0000557656cfa24d in zend_execute ()
#4 0x0000557656c8b615 in zend_execute_scripts ()
#5 0x0000557656c288ca in php_execute_script ()
#6 0x0000557656d72e1e in ?? ()
#7 0x0000557656acdea8 in ?? ()
#8 0x00007f61a2a310b3 in __libc_start_main (main=0x557656acdaa0, argc=6, argv=0x7ffd37a1c568,
init=<optimized out>, fini=<optimized out>, rtld_fini=<optimized out>,
stack_end=0x7ffd37a1c558) at ../csu/libc-start.c:308
#9 0x0000557656ace04e in _start ()
------------------------------------------------------------------------
[2021-11-11 12:05:44] cmb@php.net
Thank you for the backtraces (although backtraces with debug
symbols might be more helpful). Anyhow, does it also segfault
when pcov is disabled?
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=81607
--
Edit this bug report at https://bugs.php.net/bug.php?id=81607&edit=1