Bug #17724 Updated: php4/imap functions causing apache cores at random
| From: | si at darkness dot nu | Date: | Sun, 16 Jun 2002 09:00:34 +0000 |
| Subject: | Bug #17724 Updated: php4/imap functions causing apache cores at random | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-10563@lists.php.net to get a copy of this message | ||
ID: 17724
Updated by: si@darkness.nu
Reported By: si@darkness.nu
-Status: Feedback
+Status: Open
Bug Type: IMAP related
Operating System: IRIX 6.5.16F / IP25
PHP Version: 4.2.1
New Comment:
Ok, finally got a good one I think, there's a 0x0 ptr in zif_imap_lsub,
i'm not sure if that's normal or not, but I wouldn't think a null
pointer ever is. There's definitely a problem somewhere in memory
allocation/reference here, you would know better than I if this is
definitely in imap's c-client or the php imap module.
(gdb) bt
#0 0x10286034 in imap_valid (name=Cannot access memory at address
0x7ffe3d34
) at imap4r1.c:113
#1 0x10286590 in imap_list_work (stream=0x0, cmd=0x0, ref=0x7ffe4f68
"",
pat=0x1030ddd9 "|l", contents=0x0) at imap4r1.c:280
#2 0x102863fc in imap_lsub (stream=0x10494ac0, ref=0x0, pat=0x0)
at imap4r1.c:248
#3 0x10262494 in mail_lsub (stream=0x101b11b4,
ref=0xa <Address 0xa out of bounds>, pat=0x1 <Address 0x1 out of
bounds>)
at mail.c:754
#4 0x101b14d4 in zif_imap_lsub (ht=3, return_value=0x104d4c50,
this_ptr=0x0,
return_value_used=1) at php_imap.c:1706
#5 0x101193a0 in execute (op_array=0x1053c220) at zend_execute.c:1598
#6 0x10119608 in execute (op_array=0x104ca0f8) at zend_execute.c:1638
#7 0x10119608 in execute (op_array=0x106921e8) at zend_execute.c:1638
#8 0x10119608 in execute (op_array=0x104cd3f0) at zend_execute.c:1638
#9 0x1011bc14 in execute (op_array=0x105192d8) at zend_execute.c:2141
#10 0x1011bc14 in execute (op_array=0x105532c8) at zend_execute.c:2141
#11 0x10077368 in zend_execute_scripts (type=8, retval=0x0,
file_count=3)
at zend.c:810
#12 0x10065934 in php_execute_script (primary_file=0x7fff28f8) at
main.c:1381
#13 0x101128ac in apache_php_module_main (r=0x10462cc8,
display_source_mode=0)
at sapi_apache.c:90
Cannot access memory at address 0x7fff2a24
Previous Comments:
------------------------------------------------------------------------
[2002-06-13 20:32:51] sniper@php.net
Thank you for this bug report. To properly diagnose the problem, we
need a backtrace to see what is happening behind the scenes. To
find out how to generate a backtrace, please read
http://bugs.php.net/bugs-generating-backtrace.php
Once you have generated a backtrace, please submit it to this bug
report and change the status back to "Open". Thank you for helping
us make PHP better.
the above should have information where to find more
information..(okay, I'm lazy :)
------------------------------------------------------------------------
[2002-06-13 19:59:25] si@darkness.nu
Do I also need to recompile apache with debugging options, as I'm using
static modules? I'm afraid i'm not familiar with adding the PHP
symbols in this fashion. After compiling PHP in debug I still get no
symbols.
#0 0x1011195c in execute ()
#1 0x10110188 in execute ()
#2 0x10110188 in execute ()
#3 0x10110188 in execute ()
#4 0x1007484c in zend_execute_scripts ()
#5 0x100654c0 in php_execute_script ()
#6 0x10107624 in apache_php_module_main ()
Cannot access memory at address 0x7fff2a24
(no debugging symbols found)...
Core was generated by `httpd'.
Program terminated with signal 11, Segmentation fault.
Reading symbols from /usr/lib32/libcrypt.so...done.
Reading symbols from /usr/lib32/libm.so...done.
Reading symbols from /usr/lib32/libdl.so...done.
Reading symbols from /usr/lib32/libsocket.so...done.
Reading symbols from /usr/freeware/lib32/libssl.so...done.
Reading symbols from /usr/freeware/lib32/libcrypto.so...done.
Reading symbols from /usr/lib32/libc.so.1...done.
#0 0x1011195c in execute ()
------------------------------------------------------------------------
[2002-06-13 19:30:32] si@darkness.nu
I just recompiled with --enable-debug, i'm having a hard time
reproducing it now. I did update to the latest c-client devel snap and
recompiled php/apache to reflect, with no changes. I'm attempting to
isolate script which causes this 100%, but due to the nature i'm having
a hard time. It also doesn't seem to be coring with php in
--enable-debug, does this over-allocate pointers?
------------------------------------------------------------------------
[2002-06-13 08:36:52] sniper@php.net
So it's the imap extension..now, what we need to try and
fix this are the following things:
1. a short but complete example script which causes this
2. Better GDB backtrace. (you need to configure PHP with --enable-debug
)
3. Try the latest NON-stable CVS snapshot from http://snaps.php.net as
well as the latest c-client.
--Jani
------------------------------------------------------------------------
[2002-06-12 23:54:29] si@darkness.nu
I'm actually trying to use two different pre-made (fairly widely used)
webmail PHP systems. I get similar problems working with both TWIG and
BasiliX, which is the only reason I suspect it to be IMAP related. I'm
fairly certain it's not the memory in the system, it's an SGI Challenge
L, using ECC parity PROM controlled memory, which is very sensitive to
errors. I haven't seen any faults on the system which would indicate a
memory problem, and I run a considerable amount of other PHP which
doesn't have any problems.
:#0 _doprnt () at mdbm.c:1164
:#1 0x0fa3b1bc in sprintf () at aio.c:844
:#2 0x100862ac in _convert_to_string ()
That tells us the program bombed out while trying to construct a
formatted string. This could happen if you are passing a zero in as the
parameter corresponding to a format which is expecting a pointer. In
other words, you've likely attempted to pass a null pointer to
something that's expecting a string.
PHP Version 4.2.1
System
IRIX64 challenger 6.5 04101931 IP25
Build Date
Jun 12 2002 05:43:21
Configure Command
'./configure'
'--with-mysql=/usr/local/mysql' '--with-apache=../apache_1.3.24'
'--with-imap=/usr/local'
Server API
Apache
Virtual Directory Support
disabled
Configuration File (php.ini)
Path
/usr/local/lib/php.ini
Debug Build
no
Thread Safety
disabled
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
http://bugs.php.net/17724
--
Edit this bug report at http://bugs.php.net/?id=17724&edit=1