php / php/php-src

PHP8.5: Opcache can crash in `do_implement_interface` when trait causes implicit `Stringable` interface addition

Aperta
#23,567 0 commenti 0 reazioni 0 assegnatari Vedi su GitHub

Nessuno ha ancora preso questa issue.

Bug Status: Needs Triage
Lingua principale
C
Stelle
40.4k
Fork
8.1k
Merge medio
2g 13h
PR unite (30g)
96

Descrizione

Description

Just expanding on the description a little, in the following conditions:

  • PHP8.5 is used (8.4 at least is not affected)
  • opcache.enable & opcache.enable_cli are enabled (This may not require enable_cli with other SAPIs, but my issue was on the CLI / this is where I have narrowed down the issue)
  • A trait exists which has a __toString method
  • A class uses the above trait without declaring it implements Stringable (the base class)
  • A sub-class in a different file extends the base class (regardless of if implements Stringable or not)

With the above conditions, then if you have:

  1. A process that runs for at least the time for the second/third steps)
  2. A process runs that loads the base class into opcache's shared memory
  3. A process runs that loads the file the sub-class is in is ran

The process in step 3 will crash with an exit code of -1073741819 (0xC0000005 - STATUS_ACCESS_VIOLATION).

The above process will also cause the crash if the long running process loads the base class into opcache's shared memory - the important points are that when step 3 happens there is a process that was running when the base class was loaded - it isn't relevant if it is the process that did the loading or not.

Full code for replicating:
Main file

<?php
$mode = $argv[1] ?? "";
if($mode === "hold"){
	\sleep(30);
	echo "hold ok\n";
	exit(0);
}
trait TestTrait{
	public function __toString() : string{
		return "testString";
	}
}

class TestBaseClass{
	use TestTrait;
}
switch($mode){
	case "base":
		echo "base ok\n";
		exit(0);
	case "sub":
		require __DIR__ . "/subclass.php";
		echo "sub ok\n";
		exit(0);
}

subclass.php:

<?php
class TestSubclass extends TestBaseClass{}

Commands to run (terminal one):

php -n -d opcache.enable=1 -d opcache.enable_cli=1 test.php hold

Commands to run (terminal two):

php -n -d opcache.enable=1 -d opcache.enable_cli=1 test.php base
echo %errorlevel%
php -n -d opcache.enable=1 -d opcache.enable_cli=1 test.php sub
echo %errorlevel%

Resulted in this output (terminal one):

hold ok

Resulted in this output (terminal two):

base ok
0

-1073741819

But I expected this output instead (terminal one):

hold ok

But I expected this output instead (terminal two):

base ok
0
sub ok
0
PHP Version
PHP 8.4.6 (cli) (built: Apr  9 2025 09:45:15) (ZTS Visual C++ 2022 x64)
Copyright (c) The PHP Group
Zend Engine v4.4.6, Copyright (c) Zend Technologies
Operating System

Windows 11 x64

Guida per i contributori

Apri la guida per i contributori

Come iniziare

  1. Leggi tutta la issue e poi la guida ai contributi del progetto.
  2. Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
  3. Fai un fork del repository e lavora su un branch.
  4. Apri una pull request che faccia riferimento al numero della issue.

Direzione di ricerca

Iniziare con il file principale fornito e il riproduttore subclass.php, quindi eseguire le due sequenze di comandi Windows CLI con PHP 8.5 e Opcache abilitato. Verificare che il caricamento della classe base seguito da quello della sottoclasse non termini più con STATUS_ACCESS_VIOLATION e stampi invece “sub ok” con codice di uscita 0; l’issue non indica alcun file di implementazione né alcun test.

Scritto dal modello di indicizzazione a partire dal testo della issue.

Valutazione

Stack tecnologico
php
Ambito
backend, performance
Tipo di issue
Bug
Difficoltà
4/5
Tempo stimato
3-5 giorni
Stato di attività
Attiva
Chiarezza
Abbastanza chiara
Idoneità per principianti
55/100

Ricevi le nuove issue nella tua casella

Un breve riepilogo di issue GitHub adatte ai principianti.