Spinning 100% CPU in zend_hash_find_bucket
还没有人认领这个 Issue。
- 主要语言
- C
- 星标
- 40.4k
- 派生
- 8.1k
- 平均合并
- 2 天 13 小时
- 30 天内合并 PR
- 96
描述
Description
The following code:
(Installed Nextcloud 33 + Postgres and added an IMAP account to Nextcloud Mail)
php-zts occ mail:account:sync 24
Resulted in this output:
It reliably hangs. Maybe a memory corruption? I would love it to just crash, but the symptom is that it starts to spin forever in zend_hash_find_bucket (the line idx = Z_NEXT(p->val); keeps idx being zero). I know this is hot code, but for safety against hanging, there could maybe be some assertion that ensures that idx changes at least once in a while? 100% CPU spins like this could get expensive at scale.
#0 0x000055b3c8dbda37 in zend_hash_find ()
#1 0x000055b3c871b929 in pcre_get_compiled_regex_cache_ex ()
#2 0x000055b3c871f4cd in ?? ()
#3 0x000055b3c871f2e0 in ?? ()
#4 0x000055b3c871f8e9 in ?? ()
#5 0x000055b3c8d3700d in ?? ()
#6 0x000055b3c8cdfbb9 in execute_ex ()
#7 0x000055b3c8cdff75 in zend_execute ()
#8 0x000055b3c8e25b72 in zend_execute_script ()
#9 0x000055b3c8bf0f28 in php_execute_script_ex ()
#10 0x000055b3c8e2a021 in ?? ()
#11 0x000055b3c8e28056 in ?? ()
#12 0x00007f8487e8a8d0 in libc_start_main_stage2 (main=0x55b3c8e26690, argc=4, argv=0x7ffffc22e278) at src/env/__libc_start_main.c:95
#13 0x000055b3c8518b56 in _start ()
If I force return in GDB (set $rax=0; return - saying there is no matching hash), it dies on a null pointer dereference later on.
But I expected this output instead:
47MB of memory used
(this is normal successful execution)
Sorry for no minimized reproducer yet. Is there something I could do without minimizing the test case? I am trying to get a better backtrace, but I believe building with ASAN would work best.
Known working version (Alpine system PHP):
$ php85 -v
PHP 8.5.6 (cli) (built: May 7 2026 16:54:58) (NTS)
Copyright (c) The PHP Group
Built by Alpine Linux aports
Zend Engine v4.5.6, Copyright (c) Zend Technologies
with Zend OPcache v8.5.6, Copyright (c), by Zend Technologies
Known broken version: (added https://pkg.henderkes.com/api/packages/85/alpine/main/php-zts to /etc/apk/repositories and installed php-zts)
PHP Version
PHP 8.5.6 (cli) (built: May 8 2026 14:59:54) (ZTS zig 0.16.0 x86_64)
Copyright (c) The PHP Group
Built by Static PHP <https://static-php.dev> #StandWithUkraine
Zend Engine v4.5.6, Copyright (c) Zend Technologies
with Zend OPcache v8.5.6, Copyright (c), by Zend Technologies
Operating System
Alpine 3.23.4
贡献指南
从这里开始
- 先读完整个 Issue,再读项目的贡献指南。
- 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
- Fork 仓库,在一个分支上完成修改。
- 提交 Pull Request,并在描述里引用这个 Issue 编号。
调研方向
使用 php-zts occ mail:account:sync 24 重现挂起问题,并将其与已知可正常工作的 NTS Alpine PHP build 进行比较。从 zend_hash_find/zend_hash_find_bucket 和 pcre_get_compiled_regex_cache_ex 这几个 frame 开始,然后尝试使用 ASAN build 来改善 backtrace。完成的标准是确定无限循环的可复现原因或最小化测试用例,并记录结果。
由索引模型根据 Issue 内容生成。
评估
- 技术栈
- c, php
- 领域
- backend
- Issue 类型
- 缺陷
- 难度
- 4/5
- 预计耗时
- 3-5 天
- 活跃度
- 冷清
- 描述清晰度
- 需要澄清
- 新手友好度
- 35/100