You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Same binary, same input, same machine — only the run differs.
Why it is worth filing
free(): invalid pointer is heap corruption, not a wrong answer. A case that corrupts the
heap 43% of the time and silently passes the rest is a latent problem in the spread/variadic path,
and the passing runs are not evidence of correctness.
It makes the sweep unreliable as a gate. A default --repeat 3 sweep passes it about 18% of
the time, so it lands in the failing set or not depending on luck. I hit exactly this: comparing a
lowering branch against master, e08_spread showed up as a branch-only "regression" at --repeat 3, and only re-measuring at --repeat 30 on both sides (17/30 vs 17/30) showed it was
noise. That is a day lost to a phantom regression for anyone who does not re-measure.
@differential-repeat: 30 on the case would make a plain sweep exercise it enough to fail
consistently, the way g07a_int_string_resource_collision carries @differential-repeat: 10. That
turns a coin-flip into a stable red line — worse-looking, but honest, and it stops the phantom
regressions.
Note the related k09_spread_variadic_array (#24167) is deterministic, not flaky, and is a different
symptom (array_sum($v) on the pack prints Object). Same feature area, so they may share a root
cause.
Summary
test/differential/cases/e08_spread.phpis not deterministic on AOT. It fails a large fraction ofruns with heap corruption, and passes the rest.
Rate, measured on master
Run alone, uncontended:
Same binary, same input, same machine — only the run differs.
Why it is worth filing
free(): invalid pointeris heap corruption, not a wrong answer. A case that corrupts theheap 43% of the time and silently passes the rest is a latent problem in the spread/variadic path,
and the passing runs are not evidence of correctness.
It makes the sweep unreliable as a gate. A default
--repeat 3sweep passes it about 18% ofthe time, so it lands in the failing set or not depending on luck. I hit exactly this: comparing a
lowering branch against master,
e08_spreadshowed up as a branch-only "regression" at--repeat 3, and only re-measuring at--repeat 30on both sides (17/30 vs 17/30) showed it wasnoise. That is a day lost to a phantom regression for anyone who does not re-measure.
AOT-BASELINE.mddoes not list it as flaky — it is recorded as fixed by AOT: triage of the 8 differential compile failures — 2 compiler crashes, 3 missing runtime methods, 3 lowering gaps #23971. That fix wasreal (the case used to fail outright), but what is left is intermittent rather than gone.
Suggested interim step
@differential-repeat: 30on the case would make a plain sweep exercise it enough to failconsistently, the way
g07a_int_string_resource_collisioncarries@differential-repeat: 10. Thatturns a coin-flip into a stable red line — worse-looking, but honest, and it stops the phantom
regressions.
Note the related
k09_spread_variadic_array(#24167) is deterministic, not flaky, and is a differentsymptom (
array_sum($v)on the pack printsObject). Same feature area, so they may share a rootcause.
Context
Environment:
php-compiler:22.04-dev, PHP 8.2.32, LLVM 9, master949e90f64.