Bug #14365 Updated: require_once() causes segfault

From: Date: Tue, 16 Jul 2002 02:33:37 +0000
Subject: Bug #14365 Updated: require_once() causes segfault
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-14270@lists.php.net to get a copy of this message
ID: 14365 Updated by: sean.redmond@brooklynmuseum.org Reported By: sean.redmond@brooklynmuseum.org Status: Bogus Bug Type: Scripting Engine problem -Operating System: RedHat Linux 7.2 +Operating System: RedHat Linux 7.3 -PHP Version: 4.1.1 +PHP Version: snapshot php4-200207151200 New Comment: I guess I also forgot to mention that the last backtrace was alos using the latest snapshot Previous Comments: ------------------------------------------------------------------------ [2002-07-15 20:52:56] sniper@php.net Thank you for taking the time to report a problem with PHP. Unfortunately you are not using a current version of PHP -- the problem might already be fixed. Please download a new PHP version from http://www.php.net/downloads.php If you are able to reproduce the bug with one of the latest versions of PHP, please change the PHP version on this bug report to the version you tested and change the status back to "Open". Again, thank you for your continued support of PHP. ------------------------------------------------------------------------ [2002-07-15 17:17:39] sean.redmond@brookltnmuseum.org BTW, this is now on RedHat 7.3, with SquirrelMail 1.2.7 ------------------------------------------------------------------------ [2002-07-15 17:16:08] sean.redmond@brooklynmuseum.org Still Happens: #0 0x40182cac in php_sock_stream_read_internal (stream=0x8265e3c, sock=0x844245c, tsrm_ls=0x82fc6d8) at /usr/local/src/php4-200207151200/main/network.c:714 #1 0x40183191 in php_sockop_gets (stream=0x8265e3c, buf=0x835abfc "", maxlen=9096, tsrm_ls=0x82fc6d8) at /usr/local/src/php4-200207151200/main/network.c:966 #2 0x4018075e in _php_stream_gets (stream=0x8265e3c, buf=0x835abfc "", maxlen=9096, tsrm_ls=0x82fc6d8) at /usr/local/src/php4-200207151200/main/streams.c:248 #3 0x40121ae8 in zif_fgets (ht=2, return_value=0x83be35c, this_ptr=0x0, return_value_used=1, tsrm_ls=0x82fc6d8) at /usr/local/src/php4-200207151200/ext/standard/file.c:1142 #4 0x401b3b94 in execute (op_array=0x8329378, tsrm_ls=0x82fc6d8) at /usr/local/src/php4-200207151200/Zend/zend_execute.c:1587 #5 0x401b3d69 in execute (op_array=0x8392360, tsrm_ls=0x82fc6d8) at /usr/local/src/php4-200207151200/Zend/zend_execute.c:1627 #6 0x401b3d69 in execute (op_array=0x83297c0, tsrm_ls=0x82fc6d8) at /usr/local/src/php4-200207151200/Zend/zend_execute.c:1627 #7 0x401b3d69 in execute (op_array=0x8309698, tsrm_ls=0x82fc6d8) at /usr/local/src/php4-200207151200/Zend/zend_execute.c:1627 #8 0x401b3d69 in execute (op_array=0x842b230, tsrm_ls=0x82fc6d8) at /usr/local/src/php4-200207151200/Zend/zend_execute.c:1627 #9 0x401b3d69 in execute (op_array=0x820747c, tsrm_ls=0x82fc6d8) at /usr/local/src/php4-200207151200/Zend/zend_execute.c:1627 #10 0x401a0822 in zend_execute_scripts (type=8, tsrm_ls=0x82fc6d8, retval=0x0, file_count=3) at /usr/local/src/php4-200207151200/Zend/zend.c:810 #11 0x401789ea in php_execute_script (primary_file=0x402d16dc, tsrm_ls=0x82fc6d8) at /usr/local/src/php4-200207151200/main/main.c:1390 #12 0x401bc50b in php_ns_module_main (tsrm_ls=0x82fc6d8) at /usr/local/src/php4-200207151200/sapi/aolserver/aolserver.c:420 #13 0x401bc840 in php_ns_request_handler (context=0x8186988, conn=0x819ebc8) at /usr/local/src/php4-200207151200/sapi/aolserver/aolserver.c:504 #14 0x08077a67 in Ns_ConnRunRequest (conn=0x819ebc8) at op.c:196 #15 0x0807e172 in ConnRun (connPtr=0x819ebc8) at serv.c:882 #16 0x0807dac0 in NsConnThread (arg=0x8343920) at serv.c:671 #17 0x081181eb in NsThreadMain (arg=0x8413538) at thread.c:228 #18 0x40020fef in pthread_start_thread () from /lib/i686/libpthread.so.0 #19 0x400210df in pthread_start_thread_event () from /lib/i686/libpthread.so.0 ------------------------------------------------------------------------ [2002-06-24 03:44:06] sniper@php.net Please try this snapshot: http://snaps.php.net/php4-latest.tar.gz ------------------------------------------------------------------------ [2001-12-31 13:54:06] sean.redmond@brooklynmuseum.org Still segfaults with 4.1.1: #0 0x4024b14c in php_fopen_with_path ( filename=0x833e124 "../src/load_prefs.php", mode=0x402f2d94 "rb", path=0x402f40ba ".:/usr/local/lib/php", opened_path=0x403c37d8, tsrm_ls=0x83877a8) at fopen_wrappers.c:374 pathbuf = 0x0 ptr = 0x833e124 "../src/load_prefs.php" end = 0x0 exec_fname = 0x0 trypath = '\000' <repeats 124 times>, "¾ë\023@´V\031@Dð;@\224\000<@|ë\n@\003\000\000\000ìï;@\034\000<@\000\000\000\000/usr/local/aolserver-3.4.2/servers/webmail/pages/squirrelmail-1.2.0-rc3/plugins/filters/filters.php", '\000' <repeats 745 times>, "¾ë\023@´V\031@´ó;@\004\004<@|ë\n@\003\000\000\000\\ó;@\214\003<@\000\000\000\000/usr/loca"... trydir = '\000' <repeats 4094 times> safe_mode_include_dir = '\000' <repeats 4094 times> sb = {st_dev = 0, __pad1 = 0, st_ino = 0, st_mode = 0, st_nlink = 0, st_uid = 0, st_gid = 0, st_rdev = 0, __pad2 = 0, st_size = 0, st_blksize = 0, st_blocks = 0, st_atime = 0, __unused1 = 0, st_mtime = 0, __unused2 = 0, st_ctime = 0, __unused3 = 0, __unused4 = 0, __unused5 = 0} fp = (FILE *) 0x833e124 path_length = 0 safe_mode_include_dir_length = 0 exec_fname_length = 0 #1 0x4024b6f7 in php_fopen_url_wrapper ( path=0x833e124 "../src/load_prefs.php", mode=0x402f2d94 "rb", options=1, issock=0x403bffd0, socketd=0x403bffd4, opened_path=0x403c37d8, tsrm_ls=0x83877a8) at fopen_wrappers.c:556 path = 0x833e124 "../src/load_prefs.php" fp = (FILE *) 0x9 p = 0x83877a8 "\230\016!\b\025" protocol = 0x0 n = 0 #2 0x40247fce in php_fopen_wrapper_for_zend ( filename=0x833e124 "../src/load_prefs.php", opened_path=0x403c37d8) at main.c:524 issock = 0 socketd = 0 old_chunk_size = 8192 retval = (FILE *) 0x83877a8 tsrm_ls = (void ***) 0x83877a8 #3 0x4022e55d in execute (op_array=0x8519370, tsrm_ls=0x83877a8) at ./zend_execute.c:2082 opened_path = 0x0 dummy = 1 file_handle = {type = 0 '\000', filename = 0x8386f0c "c?&\006\r", opened_path = 0x0, handle = {fd = 1076172697, fp = 0x40251799}, free_filename = 232 'è'} new_op_array = (zend_op_array *) 0x0 original_return_value = (zval **) 0x403c40ec return_value_used = 0 inc_filename = (zval *) 0x850a258 tmp_inc_filename = {value = {lval = 1073933696, dval = 6.308106422594733, str = { val = 0x4002ed80 "U\211åS\203ì\004èäúÿÿ\201ÃLÊ", len = 1075395456}, ht = 0x4002ed80, obj = {ce = 0x4002ed80, properties = 0x40193b80}}, type = 164 '¤', is_ref = 55 '7', refcount = 16444} failure_retval = 0 '\000' opline = (zend_op *) 0x850a240 function_state = {function_symbol_table = 0x8211930, function = 0x8519370, reserved = {0x403c3844, 0x0, 0x403c4094, 0x8265818}} fbc = (zend_function *) 0x0 object = {ptr = 0x0} Ts = (temp_variable (*)[0]) 0x403bfffc original_in_execution = 1 '\001' #4 0x4022be6b in execute (op_array=0x83cb080, tsrm_ls=0x83877a8) at ./zend_execute.c:1630 calling_symbol_table = (HashTable *) 0x828dbc4 original_return_value = (zval **) 0x403c59ec return_value_used = 1 opline = (zend_op *) 0x863ebb0 function_state = {function_symbol_table = 0x828dc34, function = 0x8519370, reserved = {0x38, 0x3, 0x4030e85c, 0x8263000}} fbc = (zend_function *) 0x0 object = {ptr = 0x0} Ts = (temp_variable (*)[0]) 0x403c387c original_in_execution = 1 '\001' #5 0x4022be6b in execute (op_array=0x85d9e80, tsrm_ls=0x83877a8) at ./zend_execute.c:1630 calling_symbol_table = (HashTable *) 0x83b2afc original_return_value = (zval **) 0x403ca2e8 return_value_used = 0 opline = (zend_op *) 0x85cc7f4 function_state = {function_symbol_table = 0x828dbc4, function = 0x83cb080, reserved = {0x403c6be4, 0x3, 0x84842dc, 0x82629b0}} fbc = (zend_function *) 0x83cb080 object = {ptr = 0x0} Ts = (temp_variable (*)[0]) 0x403c4f4c original_in_execution = 1 '\001' #6 0x4022be6b in execute (op_array=0x85c7fa8, tsrm_ls=0x83877a8) at ./zend_execute.c:1630 calling_symbol_table = (HashTable *) 0x839747c original_return_value = (zval **) 0x403cb240 return_value_used = 0 opline = (zend_op *) 0x85c1610 function_state = {function_symbol_table = 0x83b2afc, function = 0x85d9e80, reserved = {0x403ca494, 0x3, 0x4030e85c, 0x8263250}} fbc = (zend_function *) 0x85d9e80 object = {ptr = 0x0} Ts = (temp_variable (*)[0]) 0x403c6bfc original_in_execution = 1 '\001' #7 0x4022be6b in execute (op_array=0x828f354, tsrm_ls=0x83877a8) at ./zend_execute.c:1630 calling_symbol_table = (HashTable *) 0x82119f8 original_return_value = (zval **) 0x403cb594 return_value_used = 0 opline = (zend_op *) 0x838e2ac function_state = {function_symbol_table = 0x839747c, function = 0x85c7fa8, reserved = {0x402de534, 0x40233dae, 0x0, 0x0}} fbc = (zend_function *) 0x85c7fa8 object = {ptr = 0x0} Ts = (temp_variable (*)[0]) 0x403ca4ac original_in_execution = 0 '\000' #8 0x4023bdca in zend_execute_scripts (type=8, tsrm_ls=0x83877a8, retval=0x0, file_count=3) at zend.c:814 tsrm_ls = (void ***) 0x83877a8 files = 0x403cb5c4 i = 1 file_handle = (zend_file_handle *) 0x403cc6dc orig_op_array = (zend_op_array *) 0x0 local_retval = (zval *) 0x0 #9 0x4024a04e in php_execute_script (primary_file=0x403cc6dc, tsrm_ls=0x83877a8) at main.c:1307 orig_bailout = {{__jmpbuf = {0, 0, 1, 0, 1, 131329}, __mask_was_saved = 0, __saved_mask = {__val = {325, 80, 4, 18, 0, 0, 1, 138307612, 1, 131331, 8, 1, 0, 0, 0, 325, 80, 4, 19, 0, 0, 1, 138307684, 8, 131331, 8, 1, 0, 0, 0, 325, 66}}}} orig_bailout_set = 0 '\000' prepend_file_p = (zend_file_handle *) 0x83877a8 append_file_p = (zend_file_handle *) 0x82434b8 prepend_file = {type = 0 '\000', filename = 0x145 <Address 0x145 out of bounds>, opened_path = 0x42 <Address 0x42 out of bounds>, handle = {fd = 1076130744, fp = 0x402473b8}, free_filename = 40 '('} append_file = {type = 1 '\001', filename = 0x83e6864 "ºb\"@Àäÿ¿9", opened_path = 0x8 <Address 0x8 out of bounds>, handle = {fd = 131331, fp = 0x20103}, free_filename = 8 '\b'} old_cwd = 0x403cb5cc "/usr/local/aolserver-3.4.2" #10 0x402470db in php_ns_module_main (tsrm_ls=0x83877a8) at aolserver.c:418 tsrm_ls = (void ***) 0x83877a8 file_handle = {type = 2 '\002', filename = 0x81fc7d8 "/usr/local/aolserver/servers/webmail/pages/squirrelmail-1.2.0-rc3/src/right_main.php", opened_path = 0x83862e4 "filters", handle = { fd = 137913240, fp = 0x8386398}, free_filename = 0 '\000'} #11 0x40247410 in php_ns_request_handler (context=0x8174728, conn=0x81960a8) at aolserver.c:502 conn = (Ns_Conn *) 0x81960a8 status = 135880872 tsrm_ls = (void ***) 0x83877a8 #12 0x08077bb7 in Ns_ConnRunRequest (conn=0x81960a8) at op.c:196 reqPtr = (Req *) 0x817d9e0 status = 0 server = 0x8155628 "webmail" #13 0x0807e2c2 in ConnRun (connPtr=0x81960a8) at serv.c:882 conn = (Ns_Conn *) 0x81960a8 ds = { string = 0x403cc798 "GET /squirrelmail-1.2.0-rc3/src/right_main.php HTTP/1.1", length = 55, spaceAvl = 512, staticSpace = "GET /squirrelmail-1.2.0-rc3/src/right_main.php HTTP/1.1\000\000\005=\bn =\b\234L\020\bX)C\bH¿\023\b\004È<@\027J\020\b>@\022\bt!\b\004\000\000\000X)C\b>@\022\bH¿\023\b\024È<@\að\r\b?@\022\bH¿\023\b$È<@VÒ\016\bt!\bH¿\023\bTÈ<@×È\016\b\030d&\b8Û\023\bºÈ<@¼Ç\016\b\231Y\017\b\000\000\000\000(e&\b\034Ò\016\b`t!\bH¿\023\btÈ<@\203Ñ\016\b\030d&\b"..., addr = 0x0} n = 590 status = 0 #14 0x0807dc10 in NsConnThread (arg=0x81f4118) at serv.c:671 connPtr = (Conn *) 0x81960a8 connPtrPtr = (Conn **) 0x81f4118 wait = {sec = 1009824362, usec = 210887} ewait = {sec = 1077725780, usec = 0} eopen = {sec = 1077726176, usec = 1} eclosed = {sec = 1077725764, usec = 135376647} now = {sec = 135522280, usec = 135511880} timePtr = (Ns_Time *) 0x403cca3c next = 3 id = 2 thrname = "-conn2-\000\024Ê<@äí\002@øç\023\b\004\000\000\000\000\000\000\000\214í\002@" new = 1073985496 status = 0 p = 0x813e800 "" headers = (Ns_Set *) 0x81950b8 outputheaders = (Ns_Set *) 0x81b08e0 joinThread = 0x82b72d8 statsPtr = (Stats *) 0x0 entry = (Ns_Entry *) 0x0 #15 0x0811833b in NsThreadMain (arg=0x835cac0) at thread.c:228 thrPtr = (Thread *) 0x835cac0 name = "-thread6151-", '\000' <repeats 16 times>, "´V\031@" #16 0x4002dc6f in pthread_start_thread (arg=0x403ccbe0) at manager.c:284 self = 0x403ccbe0 request = {req_thread = 0x0, req_kind = REQ_CREATE, req_args = { create = {attr = 0x0, fn = 0, arg = 0x0, mask = {__val = { 0 <repeats 18 times>, 1073985496, 1073958704, 0, 1077726116, 1073945068, 1077726176, 0, 0, 1073945214, 0, 0, 0, 0, 0}}}, free = { thread_id = 0}, exit = {code = 0}, post = 0x0}} outcome = (void *) 0x82434b8 #17 0x4002dd5f in pthread_start_thread_event (arg=0x403ccbe0) at manager.c:308 arg = (void *) 0x403ccbe0 ldt_entry = {entry_number = 7, base_addr = 1077726176, limit = 1056, seg_32bit = 1, contents = 0, read_exec_only = 0, limit_in_pages = 0, seg_not_present = 0, useable = 1, empty = 0} ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at http://bugs.php.net/14365 -- Edit this bug report at http://bugs.php.net/?id=14365&edit=1

« previous php.bugs (#14270) next »