Skip to content

AOT: e08_spread is flaky — fails ~43% of runs with free(): invalid pointer (heap corruption) #24226

Description

@PurHur

Summary

test/differential/cases/e08_spread.php is not deterministic on AOT. It fails a large fraction of
runs with heap corruption, and passes the rest.

<?php function s(...$v){ echo implode(",", $v), "\n"; } $p=[1,2,3]; s(...$p); s(0, ...$p);
zend: 1,2,3
      0,1,2,3
aot : free(): invalid pointer          (then core dump)

Rate, measured on master

Run alone, uncontended:

--repeat 10 :  8/10 matched
--repeat 30 : 17/30 matched      -> fails ~43% of runs

Same binary, same input, same machine — only the run differs.

Why it is worth filing

  1. free(): invalid pointer is heap corruption, not a wrong answer. A case that corrupts the
    heap 43% of the time and silently passes the rest is a latent problem in the spread/variadic path,
    and the passing runs are not evidence of correctness.

  2. It makes the sweep unreliable as a gate. A default --repeat 3 sweep passes it about 18% of
    the time, so it lands in the failing set or not depending on luck. I hit exactly this: comparing a
    lowering branch against master, e08_spread showed up as a branch-only "regression" at
    --repeat 3, and only re-measuring at --repeat 30 on both sides (17/30 vs 17/30) showed it was
    noise. That is a day lost to a phantom regression for anyone who does not re-measure.

  3. AOT-BASELINE.md does not list it as flaky — it is recorded as fixed by AOT: triage of the 8 differential compile failures — 2 compiler crashes, 3 missing runtime methods, 3 lowering gaps #23971. That fix was
    real (the case used to fail outright), but what is left is intermittent rather than gone.

Suggested interim step

@differential-repeat: 30 on the case would make a plain sweep exercise it enough to fail
consistently, the way g07a_int_string_resource_collision carries @differential-repeat: 10. That
turns a coin-flip into a stable red line — worse-looking, but honest, and it stops the phantom
regressions.

Note the related k09_spread_variadic_array (#24167) is deterministic, not flaky, and is a different
symptom (array_sum($v) on the pack prints Object). Same feature area, so they may share a root
cause.

Context

Environment: php-compiler:22.04-dev, PHP 8.2.32, LLVM 9, master 949e90f64.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    area:compilerCompiler / CFG / JITbugSomething isn't workingimplementation-readySpec complete: repro, php-src ref, done-when — safe for workers to claimphase-3:aotPhase 3 – AOT deployment

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions