Bug #17724 Updated: php4/imap functions causing apache cores at random
| From: | si at darkness dot nu | Date: | Thu, 13 Jun 2002 03:54:30 +0000 |
| Subject: | Bug #17724 Updated: php4/imap functions causing apache cores at random | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-10302@lists.php.net to get a copy of this message | ||
ID: 17724
Updated by: si@darkness.nu
Reported By: si@darkness.nu
-Status: Feedback
+Status: Open
Bug Type: Reproducible crash
Operating System: IRIX 6.5.16F / IP25
PHP Version: 4.2.1
New Comment:
I'm actually trying to use two different pre-made (fairly widely used)
webmail PHP systems. I get similar problems working with both TWIG and
BasiliX, which is the only reason I suspect it to be IMAP related. I'm
fairly certain it's not the memory in the system, it's an SGI Challenge
L, using ECC parity PROM controlled memory, which is very sensitive to
errors. I haven't seen any faults on the system which would indicate a
memory problem, and I run a considerable amount of other PHP which
doesn't have any problems.
:#0 _doprnt () at mdbm.c:1164
:#1 0x0fa3b1bc in sprintf () at aio.c:844
:#2 0x100862ac in _convert_to_string ()
That tells us the program bombed out while trying to construct a
formatted string. This could happen if you are passing a zero in as the
parameter corresponding to a format which is expecting a pointer. In
other words, you've likely attempted to pass a null pointer to
something that's expecting a string.
PHP Version 4.2.1
System
IRIX64 challenger 6.5 04101931 IP25
Build Date
Jun 12 2002 05:43:21
Configure Command
'./configure'
'--with-mysql=/usr/local/mysql' '--with-apache=../apache_1.3.24'
'--with-imap=/usr/local'
Server API
Apache
Virtual Directory Support
disabled
Configuration File (php.ini)
Path
/usr/local/lib/php.ini
Debug Build
no
Thread Safety
disabled
Previous Comments:
------------------------------------------------------------------------
[2002-06-12 09:20:30] sniper@php.net
Also, how did you configure PHP?
------------------------------------------------------------------------
[2002-06-12 09:19:56] sniper@php.net
Do you get these crashes with exactly ONE script?
Are you sure your machine's memory isn't faulty here?
------------------------------------------------------------------------
[2002-06-12 09:17:33] si@darkness.nu
Would agree this is a c-client bug from the bt, unfortunately this
problem keeps jumping around, sometimes ending at execute(), sometimes
ending up in internal OS calls (mdbm.c _doprnt()), and sometimes in
zend_make_printable_zval(). This would seem symptomatic of corrupted
memory earlier in the function sequence. Would this be feasible? I'm
getting a lot of cores, they don't seem to be very stable. Here's
another trace
(gdb) bt
#0 _doprnt () at mdbm.c:1164
#1 0x0fa3b1bc in sprintf () at aio.c:844
#2 0x100862ac in _convert_to_string ()
#3 0x10072ca0 in zend_make_printable_zval ()
#4 0x1008a974 in concat_function ()
#5 0x1010abf8 in execute ()
#6 0x1010de64 in execute ()
#7 0x10110188 in execute ()
#8 0x1010de64 in execute ()
#9 0x10110188 in execute ()
#10 0x10110188 in execute ()
#11 0x1007484c in zend_execute_scripts ()
#12 0x100654c0 in php_execute_script ()
#13 0x10107624 in apache_php_module_main ()
Cannot access memory at address 0x7fff2a54
------------------------------------------------------------------------
[2002-06-12 09:07:17] sniper@php.net
Not a bug in PHP but in the c-client. Please report this
to the c-client authors.
------------------------------------------------------------------------
[2002-06-12 06:13:15] si@darkness.nu
Appears to be possibly memory corruption in imap functions under
php4.2.1? Compiled using imap-2001a.
This GDB was configured as "mips-sgi-irix6.5"...
Core was generated by `httpd'.
Program terminated with signal 11, Segmentation fault.
Reading symbols from /usr/lib32/libcrypt.so...done.
Reading symbols from /usr/lib32/libm.so...done.
Reading symbols from /usr/lib32/libdl.so...done.
Reading symbols from /usr/lib32/libsocket.so...done.
Reading symbols from /usr/freeware/lib32/libssl.so...done.
Reading symbols from /usr/freeware/lib32/libcrypto.so...done.
Reading symbols from /usr/lib32/libc.so.1...done.
#0 0x1021be74 in imap_valid (name=0x105e9570 "{localhost:143}")
at imap4r1.c:113
113 {
(gdb) bt
#0 0x1021be74 in imap_valid (name=0x105e9570 "{localhost:143}")
at imap4r1.c:113
#1 0x1021c4c8 in imap_list_work (stream=0x105eaae8, cmd=0x102eedc0
"LSUB",
ref=0x105e9570 "{localhost:143}", pat=0x105614c0 "*",
contents=0x0)
at imap4r1.c:280
#2 0x1021c328 in imap_lsub (stream=0x105eaae8,
ref=0x105e9570 "{localhost:143}", pat=0x105614c0 "*") at
imap4r1.c:248
#3 0x101f5458 in mail_lsub (stream=0x105eaae8,
ref=0x105e9570 "{localhost:143}", pat=0x105614c0 "*") at
mail.c:754
#4 0x10148400 in zif_imap_lsub (ht=3, return_value=0x105e92c8,
this_ptr=0x105e9570, return_value_used=274076864) at
php_imap.c:1706
#5 0x100e2eb8 in execute (op_array=0x105557c8) at zend_execute.c:1598
#6 0x100e3100 in execute (op_array=0x10457c90) at zend_execute.c:1638
#7 0x100e3100 in execute (op_array=0x105952b0) at zend_execute.c:1638
#8 0x100e3100 in execute (op_array=0x105d7d50) at zend_execute.c:1638
#9 0x100e5424 in execute (op_array=0x1052b3e0) at zend_execute.c:2141
#10 0x100e5424 in execute (op_array=0x104d5c80) at zend_execute.c:2141
#11 0x100700a0 in zend_execute_scripts (type=8, retval=0x0,
file_count=3)
at zend.c:810
#12 0x10064e44 in php_execute_script (primary_file=0x7fff2970) at
main.c:1381
#13 0x100dcec4 in apache_php_module_main (r=0x7fff2970,
display_source_mode=2147428744) at sapi_apache.c:90
#14 0x10061370 in php_restore_umask ()
This GDB was configured as "mips-sgi-irix6.5"...
Core was generated by `httpd'.
Program terminated with signal 11, Segmentation fault.
Reading symbols from /usr/lib32/libcrypt.so...done.
Reading symbols from /usr/lib32/libm.so...done.
Reading symbols from /usr/lib32/libdl.so...done.
Reading symbols from /usr/lib32/libsocket.so...done.
Reading symbols from /usr/freeware/lib32/libssl.so...done.
Reading symbols from /usr/freeware/lib32/libcrypto.so...done.
Reading symbols from /usr/lib32/libc.so.1...done.
#0 0x1021c284 in imap_list (stream=0x104f74d8, ref=0x1021c280
"'½ÿàÿ¿",
pat=0x104e2507 "/%") at imap4r1.c:232
232 {
(gdb) bt
#0 0x1021c284 in imap_list (stream=0x104f74d8, ref=0x1021c280
"'½ÿàÿ¿",
pat=0x104e2507 "/%") at imap4r1.c:232
#1 0x101f5228 in mail_list (stream=0x104f74d8,
ref=0x104b5500 "{mail.darkness.nu:143}", pat=0x104e2500
"BasiliX/%")
at mail.c:721
#2 0x10146af4 in zif_imap_list_full (ht=3, return_value=0x104e24b0,
this_ptr=0x104e2500, return_value_used=273556743) at
php_imap.c:1420
#3 0x100e2eb8 in execute (op_array=0x1043b5d0) at zend_execute.c:1598
#4 0x100e3100 in execute (op_array=0x1041c530) at zend_execute.c:1638
#5 0x100e3100 in execute (op_array=0x104aedd0) at zend_execute.c:1638
#6 0x100e3100 in execute (op_array=0x104a02b0) at zend_execute.c:1638
#7 0x100e5424 in execute (op_array=0x10468f78) at zend_execute.c:2141
#8 0x100700a0 in zend_execute_scripts (type=8, retval=0x0,
file_count=3)
at zend.c:810
#9 0x10064e44 in php_execute_script (primary_file=0x7fff2930) at
main.c:1381
#10 0x100dcec4 in apache_php_module_main (r=0x7fff2930,
display_source_mode=2147428680) at sapi_apache.c:90
#11 0x10061370 in php_restore_umask ()
------------------------------------------------------------------------
--
Edit this bug report at http://bugs.php.net/?id=17724&edit=1