#48104 [Com]: PHP FD-Leak - FastCGI + auto_prepend
ID: 48104
Comment by: james at jamesreno dot com
Reported By: james at jamesreno dot com
Status: Open
Bug Type: Unknown/Other Function
Operating System: Debian 5.0.1 (lenny); 2.6.26-2-a
PHP Version: 5.2.9
New Comment:
Problem still persists. I have not yet found solution to resolve this
problem.
More Information:
----------------------------
This leak only happens in fastCGI mode (-b).
It seems that the leak only happens in a subset of files on the server,
not every file, but i can not find anything in those files other than
the fact that they are larger than the rest (ie: more code). They do not
use any weird extensions or special crazy syntax.
I tried to compile with --disable-all --enable-fastcgi, and the problem
persists.
I was NOT able to re-produce with the "CGI" binary, stracing shows that
php does indeed close the file. Only with -b and running in fastCGI mode
does the PHP leak the FD's.
PHP-fcgi is started like so:
----------------------------
su -m -c "nohup env PHP_FCGI_CHILDREN=5 PHP_FCGI_MAX_REQUESTS=1000
bin/php-fcgi-spawn -b 127.0.0.1:8081 -d 'error_log=$PHP_ERRLOG' >>
$FCGI_LOG 2>&1 &" apache
Is there anything else you can think of trying? The suggestion i
provided in my previous comment, just causes glibc to segfault php with
"glibc detected !prev".
In what file is the original file FD closed when executing via FCGI. I
notice that the other included files are being closed properly, but just
not the main executed .php.
Previous Comments:
------------------------------------------------------------------------
[2009-04-29 17:00:05] james at jamesreno dot com
[*** NOT TESTED - DO NOT USE ***]
After spending countless hours trying to determine where php is leaking
the file descriptors as mentioned in the post. It looks like
zend_destroy_file_handle in Zend/zend_language_scanner.c is missing a
call to zend_file_handle_dtor on file_handler.
If you add zend_file_handle_dtor(file_handle); it would seem the issue
would be fixed.
Is this proper - or is there some reason that zend_destroy_file_handle
does not call the destructor zend_file_handle_dtor????
------------------------------------------------------------------------
[2009-04-29 08:18:06] james at jamesreno dot com
strace of the pid is also now included -- i forgot to include it in the
previous pastebin url.
http://pastebin.com/mc72a99b
------------------------------------------------------------------------
[2009-04-29 07:59:49] james at jamesreno dot com
Description:
------------
PHP leaks file descriptors by not closing the requested file at the end
of request.
See: http://pastebin.com/m3edccacf
*** REGARDLESS of suhosin being enabled/compiled or disable and NOT
patched, the same problem appears. I have removed suhosin from php and
yet the issue still appears. Please dont just "blame suhosin" and ignore
this fact.
No third-party modules are enabled - apc has been disabled &
uninstalled as well.
This seems like an off-by-one somewhere in relation to the
auto_prepend.
removing the auto_prepend statement from the php.ini fixes the problem.
Reproduce code:
---------------
Request http://127.0.0.1/somescript.php
auto_prepend_file = "/tmp/test.php";
#/tmp/test.php
<? include("/tmp/test2.php"); ?>
#/tmp/test2.php
<? echo "hello"; ?>
#/var/www/html/somescript.php
echo " world";
Expected result:
----------------
Output of "hello World";
and PHP should close all of its files it opened.
Actual result:
--------------
Output is proper.
PHP opens:
1) /tmp/test.php
2) /tmp/test2.php
3) /var/www/html/somescript.php
however, php only closes:
1) /tmp/test.php
2) /tmp/test2.php
it does NOT close 3) /var/www/html/somescript.php
------------------------------------------------------------------------
--
Edit this bug report at http://bugs.php.net/?id=48104&edit=1
Thread (6 messages)