Bug #81607 [Ver]: Segmentation fault for opcache.enable_cli=1

From: Date: Thu, 11 Nov 2021 15:57:35 +0000
Subject: Bug #81607 [Ver]: Segmentation fault for opcache.enable_cli=1
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-237698@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=81607&edit=1

 ID:                 81607
 Updated by:         nikic@php.net
 Reported by:        mails at thomasbley dot de
 Summary:            Segmentation fault for opcache.enable_cli=1
 Status:             Verified
 Type:               Bug
 Package:            opcache
 Operating System:   linux
 PHP Version:        8.1.0RC5
 Block user comment: N
 Private report:     N

 New Comment:

Here's a small reproducer:

<?php

// Create a SHM interned string for FooBar.
var_dump("FooBar");

$pid = pcntl_fork();
if ($pid == 0) {
    // Child: Declare class FooBar {} to allocate CE cache slot.
    require __DIR__ . '/t480_2.php';
} else if ($pid > 0) {
    pcntl_wait($status);
    var_dump(new FooBar); // Crash.
} else {
    echo "pcntl_fork() failed\n";
}

t480_2.php:
<?php
class FooBar {}


Previous Comments:
------------------------------------------------------------------------
[2021-11-11 15:51:59] nikic@php.net

I believe this is a suspected issue where one process allocates a new map ptr slot on an existing
shm interned string and another tries to use it with a too small map ptr segment.

At least the ce cache slot seems to be one past the end of the map ptr segment.

------------------------------------------------------------------------
[2021-11-11 15:44:23] nikic@php.net

Can at least confirm the segfault. The class entry read from CE cache is corrupted.

------------------------------------------------------------------------
[2021-11-11 13:17:02] mails at thomasbley dot de

seems this code causes the segfault:

./src/Psalm/Internal/Fork/Pool.php:352
$message = unserialize(base64_decode($serialized_message, true));

data is:

O:39:"Psalm\Internal\Fork\ForkTaskDoneMessage":1:{s:4:"data";N;}

interface ForkMessage
{
}

class ForkTaskDoneMessage implements ForkMessage
{
    /** @var mixed */
    public $data;

    /**
     * @param mixed $data
     */
    public function __construct($data)
    {
        $this->data = $data;
    }
}

------------------------------------------------------------------------
[2021-11-11 12:54:53] mails at thomasbley dot de

yes

core-php.27635

#0  0x0000557656c14b67 in ?? ()
#1  0x0000557656c164fe in php_var_unserialize ()
#2  0x0000557656c0520a in php_unserialize_with_options ()
#3  0x0000557656c05457 in ?? ()
#4  0x0000557656cf4081 in execute_ex ()
#5  0x0000557656cfa24d in zend_execute ()
#6  0x0000557656c8b615 in zend_execute_scripts ()
#7  0x0000557656c288ca in php_execute_script ()
#8  0x0000557656d72e1e in ?? ()
#9  0x0000557656acdea8 in ?? ()
#10 0x00007f61a2a310b3 in __libc_start_main (main=0x557656acdaa0, argc=6, argv=0x7ffd37a1c568,
init=<optimized out>, fini=<optimized out>, rtld_fini=<optimized out>,
stack_end=0x7ffd37a1c558) at ../csu/libc-start.c:308
#11 0x0000557656ace04e in _start ()

core-php.27636

#0  0x0000557656c81cc4 in instanceof_function_slow ()
#1  0x0000557656cadcfa in ?? ()
#2  0x0000557656cf29f6 in execute_ex ()
#3  0x0000557656cfa24d in zend_execute ()
#4  0x0000557656c8b615 in zend_execute_scripts ()
#5  0x0000557656c288ca in php_execute_script ()
#6  0x0000557656d72e1e in ?? ()
#7  0x0000557656acdea8 in ?? ()
#8  0x00007f61a2a310b3 in __libc_start_main (main=0x557656acdaa0, argc=6, argv=0x7ffd37a1c568,
init=<optimized out>, fini=<optimized out>, rtld_fini=<optimized out>,
stack_end=0x7ffd37a1c558) at ../csu/libc-start.c:308
#9  0x0000557656ace04e in _start ()

core-php.27637

#0  0x0000557656c8dc74 in object_init_ex ()
#1  0x0000557656cc8495 in ?? ()
#2  0x0000557656cf147d in execute_ex ()
#3  0x0000557656cfa24d in zend_execute ()
#4  0x0000557656c8b615 in zend_execute_scripts ()
#5  0x0000557656c288ca in php_execute_script ()
#6  0x0000557656d72e1e in ?? ()
#7  0x0000557656acdea8 in ?? ()
#8  0x00007f61a2a310b3 in __libc_start_main (main=0x557656acdaa0, argc=6, argv=0x7ffd37a1c568,
init=<optimized out>, fini=<optimized out>, rtld_fini=<optimized out>,
stack_end=0x7ffd37a1c558) at ../csu/libc-start.c:308
#9  0x0000557656ace04e in _start ()

core-php.27638

#0  0x0000557656c8dc74 in object_init_ex ()
#1  0x0000557656cc8495 in ?? ()
#2  0x0000557656cf147d in execute_ex ()
#3  0x0000557656cfa24d in zend_execute ()
#4  0x0000557656c8b615 in zend_execute_scripts ()
#5  0x0000557656c288ca in php_execute_script ()
#6  0x0000557656d72e1e in ?? ()
#7  0x0000557656acdea8 in ?? ()
#8  0x00007f61a2a310b3 in __libc_start_main (main=0x557656acdaa0, argc=6, argv=0x7ffd37a1c568,
init=<optimized out>, fini=<optimized out>, rtld_fini=<optimized out>,
stack_end=0x7ffd37a1c558) at ../csu/libc-start.c:308
#9  0x0000557656ace04e in _start ()

core-php.27639

#0  0x0000557656c8dc74 in object_init_ex ()
#1  0x0000557656cc8495 in ?? ()
#2  0x0000557656cf147d in execute_ex ()
#3  0x0000557656cfa24d in zend_execute ()
#4  0x0000557656c8b615 in zend_execute_scripts ()
#5  0x0000557656c288ca in php_execute_script ()
#6  0x0000557656d72e1e in ?? ()
#7  0x0000557656acdea8 in ?? ()
#8  0x00007f61a2a310b3 in __libc_start_main (main=0x557656acdaa0, argc=6, argv=0x7ffd37a1c568,
init=<optimized out>, fini=<optimized out>, rtld_fini=<optimized out>,
stack_end=0x7ffd37a1c558) at ../csu/libc-start.c:308
#9  0x0000557656ace04e in _start ()

------------------------------------------------------------------------
[2021-11-11 12:05:44] cmb@php.net

Thank you for the backtraces (although backtraces with debug
symbols might be more helpful).  Anyhow, does it also segfault
when pcov is disabled?

------------------------------------------------------------------------


The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at

    https://bugs.php.net/bug.php?id=81607


--
Edit this bug report at https://bugs.php.net/bug.php?id=81607&edit=1


Thread (13 messages)

« previous php.bugs (#237698) next »