php / php/php-src

Spinning 100% CPU in zend_hash_find_bucket

Open
#22,117 0 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Bug Status: Needs Triage
Dominant language
C
Stars
40.4k
Forks
8.1k
Avg merge
2d 13h
Merged PRs (30d)
96

Description

Description

The following code:

(Installed Nextcloud 33 + Postgres and added an IMAP account to Nextcloud Mail)

php-zts occ mail:account:sync 24

Resulted in this output:
It reliably hangs. Maybe a memory corruption? I would love it to just crash, but the symptom is that it starts to spin forever in zend_hash_find_bucket (the line idx = Z_NEXT(p->val); keeps idx being zero). I know this is hot code, but for safety against hanging, there could maybe be some assertion that ensures that idx changes at least once in a while? 100% CPU spins like this could get expensive at scale.

#0  0x000055b3c8dbda37 in zend_hash_find ()
#1  0x000055b3c871b929 in pcre_get_compiled_regex_cache_ex ()
#2  0x000055b3c871f4cd in ?? ()
#3  0x000055b3c871f2e0 in ?? ()
#4  0x000055b3c871f8e9 in ?? ()
#5  0x000055b3c8d3700d in ?? ()
#6  0x000055b3c8cdfbb9 in execute_ex ()
#7  0x000055b3c8cdff75 in zend_execute ()
#8  0x000055b3c8e25b72 in zend_execute_script ()
#9  0x000055b3c8bf0f28 in php_execute_script_ex ()
#10 0x000055b3c8e2a021 in ?? ()
#11 0x000055b3c8e28056 in ?? ()
#12 0x00007f8487e8a8d0 in libc_start_main_stage2 (main=0x55b3c8e26690, argc=4, argv=0x7ffffc22e278) at src/env/__libc_start_main.c:95
#13 0x000055b3c8518b56 in _start ()

If I force return in GDB (set $rax=0; return - saying there is no matching hash), it dies on a null pointer dereference later on.

But I expected this output instead:

47MB of memory used

(this is normal successful execution)

Sorry for no minimized reproducer yet. Is there something I could do without minimizing the test case? I am trying to get a better backtrace, but I believe building with ASAN would work best.

Known working version (Alpine system PHP):

$ php85 -v
PHP 8.5.6 (cli) (built: May  7 2026 16:54:58) (NTS)
Copyright (c) The PHP Group
Built by Alpine Linux aports
Zend Engine v4.5.6, Copyright (c) Zend Technologies
    with Zend OPcache v8.5.6, Copyright (c), by Zend Technologies

Known broken version: (added https://pkg.henderkes.com/api/packages/85/alpine/main/php-zts to /etc/apk/repositories and installed php-zts)

PHP Version
PHP 8.5.6 (cli) (built: May  8 2026 14:59:54) (ZTS zig 0.16.0 x86_64)
Copyright (c) The PHP Group
Built by Static PHP <https://static-php.dev> #StandWithUkraine
Zend Engine v4.5.6, Copyright (c) Zend Technologies
    with Zend OPcache v8.5.6, Copyright (c), by Zend Technologies
Operating System

Alpine 3.23.4

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Reproduce the hang with php-zts occ mail:account:sync 24 and compare it with the known-working NTS Alpine PHP build. Start from the zend_hash_find/zend_hash_find_bucket and pcre_get_compiled_regex_cache_ex frames, then try an ASAN build to improve the backtrace. Done means identifying a reproducible cause or minimized test case for the infinite loop and documenting the result.

Written by the indexing model from the issue text.

Assessment

Tech stack
c, php
Domain
backend
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Quiet
Clarity
Needs clarification
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.