Bug #18044: apache child segfaults on page using sessions
| From: | mgriego at utdallas dot edu | Date: | Fri, 28 Jun 2002 14:24:17 +0000 |
| Subject: | Bug #18044: apache child segfaults on page using sessions | ||
| Groups: | php.bugs | ||
| Request: | Send a blank email to php-bugs+get-12412@lists.php.net to get a copy of this message | ||
From: mgriego@utdallas.edu
Operating system: RedHat Linux 7.2
PHP version: 4.2.1
PHP Bug Type: Session related
Bug description: apache child segfaults on page using sessions
Unfortunately, I can't provide a GDB backtrace, because this bug takes a
while to manifest itself. It always seems to start about a day after
apache has been started up. When using the apache PHP module, I get
Segmentation Fault errors in the error_log, but the page is sent to the
browser, so I'm guessing the fault happens when PHP tries to serialize the
data. I'm using MM for my session handler. I was, however, able to get
an strace of an apache child right before it crashed, and here's a snippet
right before the SIGSEGV:
[pid 10975] connect(9, {sin_family=AF_INET, sin_port=htons(389),
sin_addr=inet_addr("129.110.21.10")}}, 16) = -1 EINPROGRESS (Operation now
in progress)
[pid 10975] select(1024, NULL, [9], NULL, NULL) = 1 (out [9])
[pid 10975] getpeername(9, {sin_family=AF_INET, sin_port=htons(389),
sin_addr=inet_addr("129.110.21.10")}}, [16]) = 0
[pid 10975] fcntl64(0x9, 0x3, 0x40688842, 0) = 2050
[pid 10975] fcntl64(0x9, 0x4, 0x2, 0) = 0
[pid 10975] getpeername(9, {sin_family=AF_INET, sin_port=htons(389),
sin_addr=inet_addr("129.110.21.10")}}, [16]) = 0
[pid 10975] socket(PF_UNIX, SOCK_STREAM, 0) = 10
[pid 10975] connect(10, {sin_family=AF_UNIX,
path="/var/run/.nscd_socket"}, 110) = 0
[pid 10975] write(10, "\2\0\0\0\6\0\0\0\4\0\0\0", 12) = 12
[pid 10975] write(10, "\201n\25\n", 4) = 4
[pid 10975] read(10,
"\0\0\0\0\1\0\0\0\22\0\0\0\0\0\0\0\2\0\0\0\4\0\0\0\2\0\0"..., 32) = 32
[pid 10975] readv(10, [{"ldap.utdallas.edu\0", 18}, {"", 0},
{"\201n\25\n\201n\25\1", 8}], 3) = 26
[pid 10975] read(10, NULL, 0) = 0
[pid 10975] close(10) = 0
[pid 10975] uname({sys="Linux", node="hebron", ...}) = 0
[pid 10975] time(NULL) = 1025273360
[pid 10975] write(9, "0B\2\1\1`=\2\1\2\4.jamsid=1000007408,ou"..., 68) =
68
[pid 10975] select(1024, [9], [], NULL, NULL) = 1 (in [9])
[pid 10975] read(9, "0\f\2\1\1a\7\n\1\0\4\0\4\0", 16384) = 14
[pid 10975] time(NULL) = 1025273360
[pid 10975] fcntl64(0x6, 0x7, 0x4008753c, 0) = 0
[pid 10975] fcntl64(0x6, 0x7, 0x4008755c, 0x4282f034) = 0
[pid 10975] time([1025273360]) = 1025273360
[pid 10975] fcntl64(0x6, 0x7, 0x4008754c, 0x1) = 0
[pid 10975] --- SIGSEGV (Segmentation fault) ---
Basicall, what's happening here, is that the page is doing an
authentication off a local LDAP server. That last fcntl64 right before
the process segfaults is done on file descriptor 6, which according to
/proc/10975/fd is /tmp/session_mm_apache0.sem, the MM session handler
semaphore. I'm at a loss here as it, like I said, does not manifest
itself until about a day apache is started (which could be because it
receives a certain number if hits to the session shared memory segment).
--
Edit bug report at http://bugs.php.net/?id=18044&edit=1
--
Fixed in CVS: http://bugs.php.net/fix.php?id=18044&r=fixedcvs
Fixed in release: http://bugs.php.net/fix.php?id=18044&r=alreadyfixed
Need backtrace: http://bugs.php.net/fix.php?id=18044&r=needtrace
Try newer version: http://bugs.php.net/fix.php?id=18044&r=oldversion
Not developer issue: http://bugs.php.net/fix.php?id=18044&r=support
Expected behavior: http://bugs.php.net/fix.php?id=18044&r=notwrong
Not enough info: http://bugs.php.net/fix.php?id=18044&r=notenoughinfo
Submitted twice: http://bugs.php.net/fix.php?id=18044&r=submittedtwice
register_globals: http://bugs.php.net/fix.php?id=18044&r=globals