Bug #81679 [Ver->Csd]: Tracing JIT crashes on reattaching

From: Date: Wed, 15 Dec 2021 14:41:48 +0000
Subject: Bug #81679 [Ver->Csd]: Tracing JIT crashes on reattaching
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-238437@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=81679&edit=1

 ID:                 81679
 Updated by:         git@php.net
 Reported by:        alex at ndros dot com
 Summary:            Tracing JIT crashes on reattaching
-Status:             Verified
+Status:             Closed
 Type:               Bug
 Package:            JIT
 Operating System:   Windows Server 2019
 PHP Version:        8.0.13
 Block user comment: N
 Private report:     N

 New Comment:

Automatic comment on behalf of cmb69
Revision: https://github.com/php/php-src/commit/49380b59d28f6ad7f897bf6189ba2e1ad78d4c8b
Log: Fix #81679: Tracing JIT crashes on reattaching


Previous Comments:
------------------------------------------------------------------------
[2021-12-14 23:47:56] cmb@php.net

The following pull request has been associated:

Patch Name: Fix #81679: Tracing JIT crashes on reattaching
On GitHub:  https://github.com/php/php-src/pull/7776
Patch:      https://github.com/php/php-src/pull/7776.patch

------------------------------------------------------------------------
[2021-12-14 14:30:43] cmb@php.net

Related To: Bug #81664

------------------------------------------------------------------------
[2021-12-08 19:30:27] alex at ndros dot com

HI cmb@php.net!

I understand less than half of what you're saying, but it sounds just about right.

All I know is that PHP crashes instantly with jit, even by using a simple small php script.

------------------------------------------------------------------------
[2021-12-08 19:13:59] cmb@php.net

It seems to me that the current tracing JIT implementation is
broken for any multiprocess Web SAPIs which *re*attach to OPcache
SHM (generally (F)CGI, but on Windows potentially any SAPI which
may run multiple PHP processes in parallel, unless they enforce
separate OPcache instances).  The problem begins in
zend_jit_trace_startup[1] where SHM memory is allocated for
zend_jit_traces and zend_jit_exit_groups, but that would be
reallocated whenever a new process attaches to OPcache SHM.  And
that appears to be the reason for the stack backtrace presented
above: where zend_jit_traces is not properly initialized to what
has been calculated previously, and as such causes a segfault.

That might be fixable without ABI break, but otherwise we should
make sure that tracing JIT is not available for such environments.

[1] <https://github.com/php/php-src/blob/php-8.0.13/ext/opcache/jit/zend_jit_trace.c#L51>

------------------------------------------------------------------------
[2021-12-08 13:57:54] cmb@php.net

Thanks for further input!

> From basic observation this seems to happen as soon as a second
> FastCGI php-cgi instance is started by IIS

Ah, right, something is wrong there.  I need to investigate.

------------------------------------------------------------------------


The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at

    https://bugs.php.net/bug.php?id=81679


--
Edit this bug report at https://bugs.php.net/bug.php?id=81679&edit=1


Thread (9 messages)

« previous php.bugs (#238437) next »