#40291 [NEW]: glibc detected - double free or corruption - on fclose for socket
| From: | razzul69 at yahoo dot com | Date: | Tue, 30 Jan 2007 21:41:36 +0000 |
| Subject: | #40291 [NEW]: glibc detected - double free or corruption - on fclose for socket | ||
| Groups: | php.bugs | ||
| Request: | Send a blank email to php-bugs+get-108263@lists.php.net to get a copy of this message | ||
From: razzul69 at yahoo dot com
Operating system: Fedora Core 6
PHP version: 5.2.0
PHP Bug Type: Scripting Engine problem
Bug description: glibc detected - double free or corruption - on fclose for socket
Description:
------------
glibc detected - double free or corruption - on fclose for socket
code will work fine through the web interface, however, will not work from
the command line
will get double free or corruption when issuing fclose or when php does
the automatic fclose at the end.
It will only be an issue for very few blades, however, when it is an
issue, it is reproducible 100% of the time.
When it does not work, one thought is it might be when the blade on the
other end closes the connection ahead of time.
./configure --prefix=/usr/local/php --with-config-file-path=/etc/php.d
--with-zlib --with-apxs2=/etc/httpd/bin/apxs --enable-magic-quotes
--enable-sockets --with-openssl --enable-magic-quotes
--with-mysql=/usr/local/mysql --enable-debug
Reproduce code:
---------------
#!/usr/src/php-5.2.0/sapi/cli/php
<?php
$ip = '';
$username = '';
$password = '';
$ilo_xml ='<RIBCL VERSION="2.0">
<LOGIN USER_LOGIN="' . $username . '" PASSWORD="' . $password .
'">
<RIB_INFO MODE="read">
<GET_FW_VERSION/>
</RIB_INFO>
</LOGIN>
</RIBCL>';
$ssl_handle = @fsockopen ('ssl://' . $ip, 443, $error_number, $error_text,
10);
$split_ilo_xml = split ("\n", $ilo_xml);
stream_set_timeout ($ssl_handle, 10);
fwrite ($ssl_handle, '<?xml version="1.0"?>' . "\r\n");
$ssl_meta_data = stream_get_meta_data ($ssl_handle);
foreach ($split_ilo_xml as $value) {
fwrite ($ssl_handle, $value . "\r\n");
}
do {
$data = fgets ($ssl_handle, 1024);
$data = trim ($data);
$data = str_ireplace (array ('<', '>'), '', $data);
print "\n" . $data . '<br />';
} while (! feof ($ssl_handle));
fclose ($ssl_handle);
?>
Expected result:
----------------
This code is for logging into the back end ilo on a blade. When it works
correctly, I will see xml report back.
Actual result:
--------------
*** glibc detected *** /usr/src/php-5.2.0/sapi/cli/php: double free or
corruption (out): 0x0027f198 ***
======= Backtrace: =========
/lib/libc.so.6[0x1ab09d]
/lib/libc.so.6(cfree+0x90)[0x1ae6f0]
/lib/libcrypto.so.6(CRYPTO_free+0x3a)[0x6a452a]
/lib/libcrypto.so.6(ASN1_STRING_free+0x2d)[0x71bd8d]
/lib/libcrypto.so.6(ASN1_primitive_free+0x75)[0x712a75]
/lib/libcrypto.so.6(ASN1_primitive_free+0xd2)[0x712ad2]
/lib/libcrypto.so.6[0x712d51]
/lib/libcrypto.so.6(ASN1_template_free+0x8b)[0x712e2b]
/lib/libcrypto.so.6[0x712d31]
/lib/libcrypto.so.6(ASN1_template_free+0x8b)[0x712e2b]
/lib/libcrypto.so.6[0x712d31]
/lib/libcrypto.so.6(ASN1_item_free+0x13)[0x712e73]
/lib/libcrypto.so.6(X509_free+0x27)[0x70d887]
/lib/libcrypto.so.6(sk_pop_free+0x33)[0x6f5e83]
/lib/libssl.so.6(ssl_sess_cert_free+0x78)[0xb08218]
/lib/libssl.so.6(SSL_SESSION_free+0xc5)[0xb08e85]
/lib/libssl.so.6(SSL_free+0x10d)[0xb0688d]
/usr/src/php-5.2.0/sapi/cli/php[0x80b760d]
/usr/src/php-5.2.0/sapi/cli/php(_php_stream_free+0xc4)[0x8283604]
/usr/src/php-5.2.0/sapi/cli/php[0x8283867]
/usr/src/php-5.2.0/sapi/cli/php(list_entry_destructor+0xa3)[0x82bf503]
/usr/src/php-5.2.0/sapi/cli/php(zend_hash_del_key_or_index+0x221)[0x82be991]
/usr/src/php-5.2.0/sapi/cli/php(_zend_list_delete+0x8a)[0x82bf79a]
/usr/src/php-5.2.0/sapi/cli/php(zif_fclose+0xa4)[0x820c654]
/usr/src/php-5.2.0/sapi/cli/php[0x82e10b0]
/usr/src/php-5.2.0/sapi/cli/php(execute+0x15d)[0x82d106d]
/usr/src/php-5.2.0/sapi/cli/php(zend_execute_scripts+0x2c4)[0x82b2424]
/usr/src/php-5.2.0/sapi/cli/php(php_execute_script+0x1f3)[0x826df53]
/usr/src/php-5.2.0/sapi/cli/php(main+0xf1c)[0x8335bec]
/lib/libc.so.6(__libc_start_main+0xdc)[0x15af2c]
/usr/src/php-5.2.0/sapi/cli/php[0x80ac361]
--
Edit bug report at http://bugs.php.net/?id=40291&edit=1
--
Try a CVS snapshot (PHP 4.4): http://bugs.php.net/fix.php?id=40291&r=trysnapshot44
Try a CVS snapshot (PHP 5.2): http://bugs.php.net/fix.php?id=40291&r=trysnapshot52
Try a CVS snapshot (PHP 6.0): http://bugs.php.net/fix.php?id=40291&r=trysnapshot60
Fixed in CVS: http://bugs.php.net/fix.php?id=40291&r=fixedcvs
Fixed in release: http://bugs.php.net/fix.php?id=40291&r=alreadyfixed
Need backtrace: http://bugs.php.net/fix.php?id=40291&r=needtrace
Need Reproduce Script: http://bugs.php.net/fix.php?id=40291&r=needscript
Try newer version: http://bugs.php.net/fix.php?id=40291&r=oldversion
Not developer issue: http://bugs.php.net/fix.php?id=40291&r=support
Expected behavior: http://bugs.php.net/fix.php?id=40291&r=notwrong
Not enough info: http://bugs.php.net/fix.php?id=40291&r=notenoughinfo
Submitted twice: http://bugs.php.net/fix.php?id=40291&r=submittedtwice
register_globals: http://bugs.php.net/fix.php?id=40291&r=globals
PHP 3 support discontinued: http://bugs.php.net/fix.php?id=40291&r=php3
Daylight Savings: http://bugs.php.net/fix.php?id=40291&r=dst
IIS Stability: http://bugs.php.net/fix.php?id=40291&r=isapi
Install GNU Sed: http://bugs.php.net/fix.php?id=40291&r=gnused
Floating point limitations: http://bugs.php.net/fix.php?id=40291&r=float
No Zend Extensions: http://bugs.php.net/fix.php?id=40291&r=nozend
MySQL Configuration Error: http://bugs.php.net/fix.php?id=40291&r=mysqlcfg