php.net |  support |  documentation |  report a bug |  advanced search |  search howto |  statistics |  random bug |  login
Bug #74199 SIGBUS in zend_bitset_in on 64bit Solaris/SPARC
Submitted: 2017-03-02 14:14 UTC Modified: 2017-03-07 13:11 UTC
From: stadtkind2 at gmx dot de Assigned: dmitry (profile)
Status: Closed Package: Reproducible crash
PHP Version: 7.1.2 OS: Solaris 11.3
Private report: No CVE-ID: None
View Developer Edit
Welcome! If you don't have a Git account, you can't do anything here.
If you reported this bug, you can edit this bug over here.
(description)
Block user comment
Status: Assign to:
Package:
Bug Type:
Summary:
From: stadtkind2 at gmx dot de
New email:
PHP Version: OS:

 

 [2017-03-02 14:14 UTC] stadtkind2 at gmx dot de
Description:
------------
Hi,

I'm getting a SIGBUS when using a 64bit (32bit code is fine) php7 on Solaris 11.3/SPARC when opcache is enabled:

$ grep opcache php.ini | grep -v ^\;
[opcache]
zend_extension=opcache.so
opcache.enable=1
opcache.enable_cli=1

$ php -v
PHP 7.1.2 (cli) (built: Mar  2 2017 13:34:05) ( NTS )
Copyright (c) 1997-2017 The PHP Group
Zend Engine v3.1.0, Copyright (c) 1998-2017 Zend Technologies
    with Zend OPcache v7.1.2, Copyright (c) 1999-2017, by Zend Technologies

$ cat hallo.php
<?php

echo "Hallo Welt\n";

$ php hallo.php
Bus error(coredump)

$ dbx .../php core

(dbx) where
current thread: t@1
=>[1] zend_bitset_in(set = 0xfffffdee7912f904, n = 0), line 89 in "zend_bitset.h"
  [2] zend_worklist_push(worklist = 0xfffffdee7912f938, i = 0), line 109 in "zend_worklist.h"
  [3] zend_cfg_identify_loops(op_array = 0xfffff9fb9e473008, cfg = 0xfffff9fb9e494028, flags = 0xfffff9fb9e494024), line 769 in "zend_cfg.c"
  [4] zend_dfa_analyze_op_array(op_array = 0xfffff9fb9e473008, ctx = 0xfffffdee7912fb80, ssa = 0xfffff9fb9e494028, flags = 0xfffff9fb9e494024), line 70 in "dfa_pass.c"
  [5] zend_optimize_script(script = 0xfffff9fb9e473000, optimization_level = 2147467263, debug_level = 0), line 977 in "zend_optimizer.c"
  [6] cache_script_in_shared_memory(new_persistent_script = 0xfffff9fb9e473000, key = 0xc583fc0cb0 "/tmp/hallo.php", key_length = 14U, from_shared_memory = 0xfffffdee7912fe40), line 1273 in "ZendAccelerator.c"
  [7] persistent_compile_file(file_handle = 0xfffffdee79130c28, type = 8), line 1865 in "ZendAccelerator.c"
  [8] zend_execute_scripts(type = 8, retval = (nil), file_count = 3, ... = 0x19e45c668, ...), line 1469 in "zend.c"
  [9] php_execute_script(primary_file = 0xfffffdee79130c28), line 2537 in "main.c"
  [10] do_cli(argc = 4, argv = 0xc583fbd3f0), line 993 in "php_cli.c"
  [11] main(argc = 4, argv = 0xc583fbd3f0), line 1381 in "php_cli.c"


Test script:
---------------
Fetch the C code from https://gist.github.com/skrueger8/8f1adc353e2e700de47f9ec5b6561573

$ uname -a
SunOS solaris 5.11 11.3 sun4v sparc sun4v

$ cc -V
cc: Studio 12.5 Sun C 5.14 SunOS_sparc 2016/05/31

$ cc -m64 -Wall -Werror -g -std=c11 test.c && ./a.out
work->visited = ffffffff7ffff4b4
Bus error(coredump)

$ cc -m32 -Wall -Werror -g -std=c11 test.c && ./a.out
work->visited = ffbff5cc



Patches

zend_bitset_in-SIGBUS-SPARC-patch (last revision 2017-03-05 09:47 UTC by stadtkind2 at gmx dot de)

Pull Requests

History

AllCommentsChangesGit/SVN commitsRelated reports
 [2017-03-03 08:09 UTC] laruence@php.net
I have no such box to test this, maybe you could expand the macros manually, to find out which expr trigger the SIGBUG?

thanks
 [2017-03-03 09:16 UTC] laruence@php.net
-Status: Open +Status: Feedback
 [2017-03-05 09:57 UTC] stadtkind2 at gmx dot de
Suggestion to change "int *buf" to "zend_ulong *buf" came from peter.damron@oracle, which fixes the SIGBUS I'm seeing
 [2017-03-06 14:13 UTC] dmitry@php.net
-Assigned To: +Assigned To: dmitry
 [2017-03-06 14:13 UTC] dmitry@php.net
Most probably, the problem is in improperly aligned pointer.
This patch should fix the problem:

http://git.php.net/?p=php-src.git;a=commitdiff;h=e113b6784aa92c74ec3f4d821ccc6492d4b1a52d

Please verify.
 [2017-03-06 15:37 UTC] stadtkind2 at gmx dot de
Hi Dmitry,

your patch is fine. But I have another SIGBUS now:

# dbx /tmp/php-7.1.2/sapi/cli/php /var/cores/core.php.12273.3941
t@1 (l@1) program terminated by signal BUS (invalid address alignment)
Current function is zend_ssa_compute_use_def_chains
 1069                                                   phi->use_chains[0] = ssa_vars[phi->sources[0]].phi_use_chain;
(dbx) where
current thread: t@1
=>[1] zend_ssa_compute_use_def_chains(arena = 0xffffffff7fffd730, op_array = 0xffffffff7e604288, ssa = 0xffffffff7e6a3100), line 1069 in "zend_ssa.c"
  [2] zend_dfa_analyze_op_array(op_array = 0xffffffff7e604288, ctx = 0xffffffff7fffd730, ssa = 0xffffffff7e6a3100, flags = 0xffffffff7e6a30fc), line 94 in "dfa_pass.c"
  [3] zend_optimize_script(script = 0xffffffff7e674000, optimization_level = 2147467263, debug_level = 0), line 977 in "zend_optimizer.c"
  [4] cache_script_in_shared_memory(new_persistent_script = 0xffffffff7e674000, key = 0x101d30910 "/tmp/php-7.1.2/tests/run-test/test007.php", key_length = 41U, from_shared_memory = 0xffffffff7fffd9f0), line 1273 in "ZendAccelerator.c"
  [5] persistent_compile_file(file_handle = 0xffffffff7fffe7d8, type = 8), line 1865 in "ZendAccelerator.c"
  [6] zend_execute_scripts(type = 8, retval = (nil), file_count = 3, ... = 0x17e65d050, ...), line 1469 in "zend.c"
  [7] php_execute_script(primary_file = 0xffffffff7fffe7d8), line 2537 in "main.c"
  [8] do_cli(argc = 66, argv = 0x101d377d0), line 993 in "php_cli.c"
  [9] main(argc = 66, argv = 0x101d377d0), line 1381 in "php_cli.c"
 [2017-03-07 08:05 UTC] dmitry@php.net
Please check this patch:

http://git.php.net/?p=php-src.git;a=commitdiff;h=d9231b16670cd450544cb0f050c72af9809e47e7

It's already committed into PHP-7.1 and above.
 [2017-03-07 12:25 UTC] stadtkind2 at gmx dot de
@dmitry

Everything is fine with your second set of patches. No SIGBUS'ses anymore (survived a full "make test")

Thanks!
 [2017-03-07 13:11 UTC] dmitry@php.net
-Status: Feedback +Status: Closed
 
PHP Copyright © 2001-2026 The PHP Group
All rights reserved.
Last updated: Tue Oct 06 07:00:02 2026 UTC