PHP8.5: Opcache can crash in `do_implement_interface` when trait causes implicit `Stringable` interface addition
还没有人认领这个 Issue。
- 主要语言
- C
- 星标
- 40.4k
- 派生
- 8.2k
- 平均合并
- 2 天 13 小时
- 30 天内合并 PR
- 96
描述
Description
Just expanding on the description a little, in the following conditions:
- PHP8.5 is used (8.4 at least is not affected)
opcache.enable&opcache.enable_cliare enabled (This may not requireenable_cliwith other SAPIs, but my issue was on the CLI / this is where I have narrowed down the issue)- A trait exists which has a
__toStringmethod - A class uses the above trait without declaring it implements
Stringable(the base class) - A sub-class in a different file extends the base class (regardless of if implements
Stringableor not)
With the above conditions, then if you have:
- A process that runs for at least the time for the second/third steps)
- A process runs that loads the base class into opcache's shared memory
- A process runs that loads the file the sub-class is in is ran
The process in step 3 will crash with an exit code of -1073741819 (0xC0000005 - STATUS_ACCESS_VIOLATION).
The above process will also cause the crash if the long running process loads the base class into opcache's shared memory - the important points are that when step 3 happens there is a process that was running when the base class was loaded - it isn't relevant if it is the process that did the loading or not.
Full code for replicating:
Main file
<?php
$mode = $argv[1] ?? "";
if($mode === "hold"){
\sleep(30);
echo "hold ok\n";
exit(0);
}
trait TestTrait{
public function __toString() : string{
return "testString";
}
}
class TestBaseClass{
use TestTrait;
}
switch($mode){
case "base":
echo "base ok\n";
exit(0);
case "sub":
require __DIR__ . "/subclass.php";
echo "sub ok\n";
exit(0);
}
subclass.php:
<?php
class TestSubclass extends TestBaseClass{}
Commands to run (terminal one):
php -n -d opcache.enable=1 -d opcache.enable_cli=1 test.php hold
Commands to run (terminal two):
php -n -d opcache.enable=1 -d opcache.enable_cli=1 test.php base
echo %errorlevel%
php -n -d opcache.enable=1 -d opcache.enable_cli=1 test.php sub
echo %errorlevel%
Resulted in this output (terminal one):
hold ok
Resulted in this output (terminal two):
base ok
0
-1073741819
But I expected this output instead (terminal one):
hold ok
But I expected this output instead (terminal two):
base ok
0
sub ok
0
PHP Version
PHP 8.4.6 (cli) (built: Apr 9 2025 09:45:15) (ZTS Visual C++ 2022 x64)
Copyright (c) The PHP Group
Zend Engine v4.4.6, Copyright (c) Zend Technologies
Operating System
Windows 11 x64
贡献指南
从这里开始
- 先读完整个 Issue,再读项目的贡献指南。
- 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
- Fork 仓库,在一个分支上完成修改。
- 提交 Pull Request,并在描述里引用这个 Issue 编号。
调研方向
从提供的主文件和复现文件 subclass.php 开始,然后在启用 Opcache 的 PHP 8.5 下运行两组 Windows CLI 命令序列。确认先加载基类再加载子类时不再以 STATUS_ACCESS_VIOLATION 退出,而是输出“sub ok”,退出代码为 0;该 issue 未指定实现文件或测试。
由索引模型根据 Issue 内容生成。
评估
- 技术栈
- php
- 领域
- backend, performance
- Issue 类型
- 缺陷
- 难度
- 4/5
- 预计耗时
- 3-5 天
- 活跃度
- 活跃
- 描述清晰度
- 基本清楚
- 新手友好度
- 55/100