php.net |  support |  documentation |  report a bug |  advanced search |  search howto |  statistics |  random bug |  login
Bug #74199 SIGBUS in zend_bitset_in on 64bit Solaris/SPARC
Submitted: 2017-03-02 14:14 UTC Modified: 2017-03-07 13:11 UTC
From: stadtkind2 at gmx dot de Assigned: dmitry (profile)
Status: Closed Package: Reproducible crash
PHP Version: 7.1.2 OS: Solaris 11.3
Private report: No CVE-ID: None
Welcome back! If you're the original bug submitter, here's where you can edit the bug or add additional notes.
If you forgot your password, you can retrieve your password here.
Password:
Status:
Package:
Bug Type:
Summary:
From: stadtkind2 at gmx dot de
New email:
PHP Version: OS:

 

 [2017-03-02 14:14 UTC] stadtkind2 at gmx dot de
Description:
------------
Hi,

I'm getting a SIGBUS when using a 64bit (32bit code is fine) php7 on Solaris 11.3/SPARC when opcache is enabled:

$ grep opcache php.ini | grep -v ^\;
[opcache]
zend_extension=opcache.so
opcache.enable=1
opcache.enable_cli=1

$ php -v
PHP 7.1.2 (cli) (built: Mar  2 2017 13:34:05) ( NTS )
Copyright (c) 1997-2017 The PHP Group
Zend Engine v3.1.0, Copyright (c) 1998-2017 Zend Technologies
    with Zend OPcache v7.1.2, Copyright (c) 1999-2017, by Zend Technologies

$ cat hallo.php
<?php

echo "Hallo Welt\n";

$ php hallo.php
Bus error(coredump)

$ dbx .../php core

(dbx) where
current thread: t@1
=>[1] zend_bitset_in(set = 0xfffffdee7912f904, n = 0), line 89 in "zend_bitset.h"
  [2] zend_worklist_push(worklist = 0xfffffdee7912f938, i = 0), line 109 in "zend_worklist.h"
  [3] zend_cfg_identify_loops(op_array = 0xfffff9fb9e473008, cfg = 0xfffff9fb9e494028, flags = 0xfffff9fb9e494024), line 769 in "zend_cfg.c"
  [4] zend_dfa_analyze_op_array(op_array = 0xfffff9fb9e473008, ctx = 0xfffffdee7912fb80, ssa = 0xfffff9fb9e494028, flags = 0xfffff9fb9e494024), line 70 in "dfa_pass.c"
  [5] zend_optimize_script(script = 0xfffff9fb9e473000, optimization_level = 2147467263, debug_level = 0), line 977 in "zend_optimizer.c"
  [6] cache_script_in_shared_memory(new_persistent_script = 0xfffff9fb9e473000, key = 0xc583fc0cb0 "/tmp/hallo.php", key_length = 14U, from_shared_memory = 0xfffffdee7912fe40), line 1273 in "ZendAccelerator.c"
  [7] persistent_compile_file(file_handle = 0xfffffdee79130c28, type = 8), line 1865 in "ZendAccelerator.c"
  [8] zend_execute_scripts(type = 8, retval = (nil), file_count = 3, ... = 0x19e45c668, ...), line 1469 in "zend.c"
  [9] php_execute_script(primary_file = 0xfffffdee79130c28), line 2537 in "main.c"
  [10] do_cli(argc = 4, argv = 0xc583fbd3f0), line 993 in "php_cli.c"
  [11] main(argc = 4, argv = 0xc583fbd3f0), line 1381 in "php_cli.c"


Test script:
---------------
Fetch the C code from https://gist.github.com/skrueger8/8f1adc353e2e700de47f9ec5b6561573

$ uname -a
SunOS solaris 5.11 11.3 sun4v sparc sun4v

$ cc -V
cc: Studio 12.5 Sun C 5.14 SunOS_sparc 2016/05/31

$ cc -m64 -Wall -Werror -g -std=c11 test.c && ./a.out
work->visited = ffffffff7ffff4b4
Bus error(coredump)

$ cc -m32 -Wall -Werror -g -std=c11 test.c && ./a.out
work->visited = ffbff5cc



Patches

zend_bitset_in-SIGBUS-SPARC-patch (last revision 2017-03-05 09:47 UTC by stadtkind2 at gmx dot de)

Pull Requests

History

AllCommentsChangesGit/SVN commitsRelated reports
 [2017-03-03 08:09 UTC] laruence@php.net
I have no such box to test this, maybe you could expand the macros manually, to find out which expr trigger the SIGBUG?

thanks
 [2017-03-03 09:16 UTC] laruence@php.net
-Status: Open +Status: Feedback
 [2017-03-05 09:57 UTC] stadtkind2 at gmx dot de
Suggestion to change "int *buf" to "zend_ulong *buf" came from peter.damron@oracle, which fixes the SIGBUS I'm seeing
 [2017-03-06 14:13 UTC] dmitry@php.net
-Assigned To: +Assigned To: dmitry
 [2017-03-06 14:13 UTC] dmitry@php.net
Most probably, the problem is in improperly aligned pointer.
This patch should fix the problem:

http://git.php.net/?p=php-src.git;a=commitdiff;h=e113b6784aa92c74ec3f4d821ccc6492d4b1a52d

Please verify.
 [2017-03-06 15:37 UTC] stadtkind2 at gmx dot de
Hi Dmitry,

your patch is fine. But I have another SIGBUS now:

# dbx /tmp/php-7.1.2/sapi/cli/php /var/cores/core.php.12273.3941
t@1 (l@1) program terminated by signal BUS (invalid address alignment)
Current function is zend_ssa_compute_use_def_chains
 1069                                                   phi->use_chains[0] = ssa_vars[phi->sources[0]].phi_use_chain;
(dbx) where
current thread: t@1
=>[1] zend_ssa_compute_use_def_chains(arena = 0xffffffff7fffd730, op_array = 0xffffffff7e604288, ssa = 0xffffffff7e6a3100), line 1069 in "zend_ssa.c"
  [2] zend_dfa_analyze_op_array(op_array = 0xffffffff7e604288, ctx = 0xffffffff7fffd730, ssa = 0xffffffff7e6a3100, flags = 0xffffffff7e6a30fc), line 94 in "dfa_pass.c"
  [3] zend_optimize_script(script = 0xffffffff7e674000, optimization_level = 2147467263, debug_level = 0), line 977 in "zend_optimizer.c"
  [4] cache_script_in_shared_memory(new_persistent_script = 0xffffffff7e674000, key = 0x101d30910 "/tmp/php-7.1.2/tests/run-test/test007.php", key_length = 41U, from_shared_memory = 0xffffffff7fffd9f0), line 1273 in "ZendAccelerator.c"
  [5] persistent_compile_file(file_handle = 0xffffffff7fffe7d8, type = 8), line 1865 in "ZendAccelerator.c"
  [6] zend_execute_scripts(type = 8, retval = (nil), file_count = 3, ... = 0x17e65d050, ...), line 1469 in "zend.c"
  [7] php_execute_script(primary_file = 0xffffffff7fffe7d8), line 2537 in "main.c"
  [8] do_cli(argc = 66, argv = 0x101d377d0), line 993 in "php_cli.c"
  [9] main(argc = 66, argv = 0x101d377d0), line 1381 in "php_cli.c"
 [2017-03-07 08:05 UTC] dmitry@php.net
Please check this patch:

http://git.php.net/?p=php-src.git;a=commitdiff;h=d9231b16670cd450544cb0f050c72af9809e47e7

It's already committed into PHP-7.1 and above.
 [2017-03-07 12:25 UTC] stadtkind2 at gmx dot de
@dmitry

Everything is fine with your second set of patches. No SIGBUS'ses anymore (survived a full "make test")

Thanks!
 [2017-03-07 13:11 UTC] dmitry@php.net
-Status: Feedback +Status: Closed
 
PHP Copyright © 2001-2026 The PHP Group
All rights reserved.
Last updated: Tue Oct 06 07:00:02 2026 UTC