Bug #81679 [Ver->Csd]: Tracing JIT crashes on reattaching
Edit report at https://bugs.php.net/bug.php?id=81679&edit=1
ID: 81679
Updated by: git@php.net
Reported by: alex at ndros dot com
Summary: Tracing JIT crashes on reattaching
-Status: Verified
+Status: Closed
Type: Bug
Package: JIT
Operating System: Windows Server 2019
PHP Version: 8.0.13
Block user comment: N
Private report: N
New Comment:
Automatic comment on behalf of cmb69
Revision: https://github.com/php/php-src/commit/49380b59d28f6ad7f897bf6189ba2e1ad78d4c8b
Log: Fix #81679: Tracing JIT crashes on reattaching
Previous Comments:
------------------------------------------------------------------------
[2021-12-14 23:47:56] cmb@php.net
The following pull request has been associated:
Patch Name: Fix #81679: Tracing JIT crashes on reattaching
On GitHub: https://github.com/php/php-src/pull/7776
Patch: https://github.com/php/php-src/pull/7776.patch
------------------------------------------------------------------------
[2021-12-14 14:30:43] cmb@php.net
Related To: Bug #81664
------------------------------------------------------------------------
[2021-12-08 19:30:27] alex at ndros dot com
HI cmb@php.net!
I understand less than half of what you're saying, but it sounds just about right.
All I know is that PHP crashes instantly with jit, even by using a simple small php script.
------------------------------------------------------------------------
[2021-12-08 19:13:59] cmb@php.net
It seems to me that the current tracing JIT implementation is
broken for any multiprocess Web SAPIs which *re*attach to OPcache
SHM (generally (F)CGI, but on Windows potentially any SAPI which
may run multiple PHP processes in parallel, unless they enforce
separate OPcache instances). The problem begins in
zend_jit_trace_startup[1] where SHM memory is allocated for
zend_jit_traces and zend_jit_exit_groups, but that would be
reallocated whenever a new process attaches to OPcache SHM. And
that appears to be the reason for the stack backtrace presented
above: where zend_jit_traces is not properly initialized to what
has been calculated previously, and as such causes a segfault.
That might be fixable without ABI break, but otherwise we should
make sure that tracing JIT is not available for such environments.
[1] <https://github.com/php/php-src/blob/php-8.0.13/ext/opcache/jit/zend_jit_trace.c#L51>
------------------------------------------------------------------------
[2021-12-08 13:57:54] cmb@php.net
Thanks for further input!
> From basic observation this seems to happen as soon as a second
> FastCGI php-cgi instance is started by IIS
Ah, right, something is wrong there. I need to investigate.
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=81679
--
Edit this bug report at https://bugs.php.net/bug.php?id=81679&edit=1
Thread (9 messages)