php / php/php-src

Spinning 100% CPU in zend_hash_find_bucket

未关闭
#22,117 0 条评论 0 个 reaction 已指派 0 人 在 GitHub 查看

还没有人认领这个 Issue。

Bug Status: Needs Triage
主要语言
C
星标
40.4k
派生
8.1k
平均合并
2 天 13 小时
30 天内合并 PR
96

描述

Description

The following code:

(Installed Nextcloud 33 + Postgres and added an IMAP account to Nextcloud Mail)

php-zts occ mail:account:sync 24

Resulted in this output:
It reliably hangs. Maybe a memory corruption? I would love it to just crash, but the symptom is that it starts to spin forever in zend_hash_find_bucket (the line idx = Z_NEXT(p->val); keeps idx being zero). I know this is hot code, but for safety against hanging, there could maybe be some assertion that ensures that idx changes at least once in a while? 100% CPU spins like this could get expensive at scale.

#0  0x000055b3c8dbda37 in zend_hash_find ()
#1  0x000055b3c871b929 in pcre_get_compiled_regex_cache_ex ()
#2  0x000055b3c871f4cd in ?? ()
#3  0x000055b3c871f2e0 in ?? ()
#4  0x000055b3c871f8e9 in ?? ()
#5  0x000055b3c8d3700d in ?? ()
#6  0x000055b3c8cdfbb9 in execute_ex ()
#7  0x000055b3c8cdff75 in zend_execute ()
#8  0x000055b3c8e25b72 in zend_execute_script ()
#9  0x000055b3c8bf0f28 in php_execute_script_ex ()
#10 0x000055b3c8e2a021 in ?? ()
#11 0x000055b3c8e28056 in ?? ()
#12 0x00007f8487e8a8d0 in libc_start_main_stage2 (main=0x55b3c8e26690, argc=4, argv=0x7ffffc22e278) at src/env/__libc_start_main.c:95
#13 0x000055b3c8518b56 in _start ()

If I force return in GDB (set $rax=0; return - saying there is no matching hash), it dies on a null pointer dereference later on.

But I expected this output instead:

47MB of memory used

(this is normal successful execution)

Sorry for no minimized reproducer yet. Is there something I could do without minimizing the test case? I am trying to get a better backtrace, but I believe building with ASAN would work best.

Known working version (Alpine system PHP):

$ php85 -v
PHP 8.5.6 (cli) (built: May  7 2026 16:54:58) (NTS)
Copyright (c) The PHP Group
Built by Alpine Linux aports
Zend Engine v4.5.6, Copyright (c) Zend Technologies
    with Zend OPcache v8.5.6, Copyright (c), by Zend Technologies

Known broken version: (added https://pkg.henderkes.com/api/packages/85/alpine/main/php-zts to /etc/apk/repositories and installed php-zts)

PHP Version
PHP 8.5.6 (cli) (built: May  8 2026 14:59:54) (ZTS zig 0.16.0 x86_64)
Copyright (c) The PHP Group
Built by Static PHP <https://static-php.dev> #StandWithUkraine
Zend Engine v4.5.6, Copyright (c) Zend Technologies
    with Zend OPcache v8.5.6, Copyright (c), by Zend Technologies
Operating System

Alpine 3.23.4

贡献指南

打开贡献指南

从这里开始

  1. 先读完整个 Issue,再读项目的贡献指南。
  2. 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
  3. Fork 仓库,在一个分支上完成修改。
  4. 提交 Pull Request,并在描述里引用这个 Issue 编号。

调研方向

使用 php-zts occ mail:account:sync 24 重现挂起问题,并将其与已知可正常工作的 NTS Alpine PHP build 进行比较。从 zend_hash_find/zend_hash_find_bucketpcre_get_compiled_regex_cache_ex 这几个 frame 开始,然后尝试使用 ASAN build 来改善 backtrace。完成的标准是确定无限循环的可复现原因或最小化测试用例,并记录结果。

由索引模型根据 Issue 内容生成。

评估

技术栈
c, php
领域
backend
Issue 类型
缺陷
难度
4/5
预计耗时
3-5 天
活跃度
冷清
描述清晰度
需要澄清
新手友好度
35/100

把新 issue 发到你的邮箱

精选适合新手参与的 GitHub issue 摘要。