Bug #15020 Updated: Segfault - something to do with arBuckets

From: Date: Thu, 18 Jul 2002 05:00:09 +0000
Subject: Bug #15020 Updated: Segfault - something to do with arBuckets
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-14482@lists.php.net to get a copy of this message
ID: 15020 Updated by: php-bugs@lists.php.net Reported By: charlie@charliedyson.net -Status: Feedback +Status: No Feedback Bug Type: Session related Operating System: Linux (SuSE 7.2) PHP Version: 4.1.1 New Comment: No feedback was provided for this bug for over a month, so it is being suspended automatically. If you are able to provide the information that was originally requested, please do so and change the status of the bug back to "Open". Previous Comments: ------------------------------------------------------------------------ [2002-06-17 19:53:40] sniper@php.net I can not reproduce this..can you please try this snapshot: http://snaps.php.net/php4-latest.tar.gz ------------------------------------------------------------------------ [2002-05-04 16:09:11] charlie@charliedyson.net Not much I can do: I've never hacked PHP, and I'm kinda busy at the moment. Have you tried watching arBuckets (whatever that is) in gdb? Maybe one of those libc-allocation-function-replaceing-libraries will work (electric fence, etc). Good luck, and thanks again. BTW: I've been working on a different project with PHP, and had no problems what-so-ever. This seems to be a pretty obscure thing. What does arBuckets do anyway? Thanks, Charlie Dyson - charlie@charliedyson.net ------------------------------------------------------------------------ [2002-05-04 10:04:04] kimmo.mustonen@hut.fi The same(?) problem occurs for me on Tru64 Unix 4.0f. The problem has appeared between 4.0.6 and 4.1.0. 4.0.6 works fine, 4.1.0, 4.1.1 and 4.2.0 just crash. ---<8---<8--- zend_hash.c:935 if ((p->h == h) && (p->nKeyLength == 0)) { (gdb) print p $1 = (Bucket *) 0x5a5a5a5a5a5a5a5a (gdb) print ht->arBuckets[1] $2 = (Bucket *) 0x5a5a5a5a5a5a5a5a (gdb) print *ht $3 = {nTableSize = 8, nTableMask = 7, nNumOfElements = 3, nNextFreeElement = 4, pInternalPointer = 0x140114880, pListHead = 0x140114880, pListTail = 0x0, arBuckets = 0x1400eea60, pDestructor = 0x120068910 <list_entry_destructor>, persistent = 0 '\000', nApplyCount = 0 '\000', bApplyProtection = 1 '\001', inconsistent = 0} ---8<---8<--- It seems that the arBuckets table is completely freed(?) or uninitialized(?) but is still tried to be used. ------------------------------------------------------------------------ [2002-01-15 16:41:25] charlie@charliedyson.net Here are two sample pages that cause the crash on my machine: == login.php == <? session_start(); session_register("isloggedin"); $HTTP_SESSION_VARS["isloggedin"]=0 ?> <html> <body> You are logged in.<br/> <a href="logout.php">Click here</a> to log-out.<br/> </body> </html> == CUT == == logout.php == <? session_unregister("isloggedin"); session_destroy(); ?> <html> <body> You are now logged - out. <a href="login.php">Click here</a> to log-in again. <br/> <?= session_id() ?><br/> </body> </html> == CUT == I also made some small changes to my php.ini file, starting with php.ini-reccomended. Here is the output of diff php.ini-recommended php.ini: 683c683 < session.save_path = /tmp --- > session.save_path = /tmp/phpsess 690c690 < session.name = PHPSESSID --- > session.name = POSSUMSESSID == CUT == Hope this helps, Charlie Dyson - charlie@charliedyson.net ------------------------------------------------------------------------ [2002-01-13 20:25:01] yohgaki@php.net Looks like this is a session module problem. (session_unregister) Could you make short & complete script causes this segfault? ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at http://bugs.php.net/15020 -- Edit this bug report at http://bugs.php.net/?id=15020&edit=1

« previous php.bugs (#14482) next »