[php-src] Issue #10311: Segfault in Zend/zend_objects_API.c:zend_objects_store_free_object_storage

From: Date: Fri, 13 Jan 2023 15:59:29 +0000
Subject: [php-src] Issue #10311: Segfault in Zend/zend_objects_API.c:zend_objects_store_free_object_storage
Groups: php.bugs 
Request: Send a blank email to php-bugs+get-243440@lists.php.net to get a copy of this message
Issue: https://github.com/php/php-src/issues/10311 Author: zerodeux ### Description This is a bug encountered on a production server. Occurence frequency is lower than once a day and this server receives 100,000+ PHP req a day. I could only capture crash info with a core dump, but I am not able to reproduce it. The stacktrace is : ``` (gdb) bt #0 0x000055aa54a65b0f in zend_objects_store_free_object_storage (objects=objects@entry=0x55aa54c202c8 <executor_globals+840>, fast_shutdown=fast_shutdown@entry=1 '\001') at ./Zend/zend_objects_API.c:102 #1 0x000055aa54a20a76 in shutdown_executor () at ./Zend/zend_execute_API.c:342 #2 0x000055aa54a305d9 in zend_deactivate () at ./Zend/zend.c:1198 #3 0x000055aa549cdfea in php_request_shutdown (dummy=dummy@entry=0x0) at ./main/main.c:1970 #4 0x000055aa5489aba2 in main (argc=1, argv=0x7ffd10ed3288) at ./sapi/cgi/cgi_main.c:2605 ``` I checked against the source of the version I'm running (PHP 7.4.33, but see below) and it boils down to obj->handlers being NULL in the fast_shutdown loop of zend_objects_store_free_object_storage : ``` (gdb) p *objects $1 = {object_buckets = 0x7f73c8201000, top = 97561, size = 131072, free_list_head = 112} (gdb) info locals obj_ptr = 0x7f73c82bf8c0 end = 0x7f73c8201008 obj = 0x7f73c79ff4d0 (gdb) p *obj $8 = {gc = {refcount = 1, u = {type_info = 792}}, handle = 97560, ce = 0x55aa553f0740, handlers = 0x0, properties = 0x0, properties_table = {{value = {lval = 0, dval = 0, counted = 0x0, str = 0x0, arr = 0x0, obj = 0x0, res = 0x0, ref = 0x0, ast = 0x0, zv = 0x0, ptr = 0x0, ce = 0x0, func = 0x0, ww = {w1 = 0, w2 = 0}}, u1 = {v = {type = 128 '\200', type_flags = 245 '\365', u = {extra = 51103}}, type_info = 3349149056}, u2 = {next = 32627, cache_slot = 32627, opline_num = 32627, lineno = 32627, num_args = 32627, fe_pos = 32627, fe_iter_idx = 32627, access_flags = 32627, property_guard = 32627, constant_flags = 32627, extra = 32627}}}} ``` Since I noticed that PHP's master branch has the same code (https://github.com/php/php-src/blob/fdc22744a8951b605a546ad6f09a2b907043bc54/Zend/zend_objects_API.c#L107) I guess the bug is still there. ### PHP Version PHP 8.2.1 ### Operating System Debian 11

« previous php.bugs (#243440) next »