Bug #15020 Updated: Segfault - something to do with arBuckets
| From: | php-bugs at lists dot php dot net | Date: | Thu, 18 Jul 2002 05:00:09 +0000 |
| Subject: | Bug #15020 Updated: Segfault - something to do with arBuckets | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-14482@lists.php.net to get a copy of this message | ||
ID: 15020
Updated by: php-bugs@lists.php.net
Reported By: charlie@charliedyson.net
-Status: Feedback
+Status: No Feedback
Bug Type: Session related
Operating System: Linux (SuSE 7.2)
PHP Version: 4.1.1
New Comment:
No feedback was provided for this bug for over a month, so it is
being suspended automatically. If you are able to provide the
information that was originally requested, please do so and change
the status of the bug back to "Open".
Previous Comments:
------------------------------------------------------------------------
[2002-06-17 19:53:40] sniper@php.net
I can not reproduce this..can you please try this snapshot:
http://snaps.php.net/php4-latest.tar.gz
------------------------------------------------------------------------
[2002-05-04 16:09:11] charlie@charliedyson.net
Not much I can do: I've never hacked PHP, and I'm kinda busy at the
moment. Have you tried watching arBuckets (whatever that is) in gdb?
Maybe one of those libc-allocation-function-replaceing-libraries will
work (electric fence, etc). Good luck, and thanks again.
BTW: I've been working on a different project with PHP, and had no
problems what-so-ever. This seems to be a pretty obscure thing. What
does arBuckets do anyway?
Thanks,
Charlie Dyson - charlie@charliedyson.net
------------------------------------------------------------------------
[2002-05-04 10:04:04] kimmo.mustonen@hut.fi
The same(?) problem occurs for me on Tru64 Unix 4.0f.
The problem has appeared between 4.0.6 and 4.1.0. 4.0.6 works fine,
4.1.0, 4.1.1 and 4.2.0 just crash.
---<8---<8---
zend_hash.c:935 if ((p->h == h) && (p->nKeyLength == 0)) {
(gdb) print p
$1 = (Bucket *) 0x5a5a5a5a5a5a5a5a
(gdb) print ht->arBuckets[1]
$2 = (Bucket *) 0x5a5a5a5a5a5a5a5a
(gdb) print *ht
$3 = {nTableSize = 8, nTableMask = 7, nNumOfElements = 3,
nNextFreeElement = 4, pInternalPointer = 0x140114880,
pListHead = 0x140114880, pListTail = 0x0, arBuckets = 0x1400eea60,
pDestructor = 0x120068910 <list_entry_destructor>, persistent = 0
'\000',
nApplyCount = 0 '\000', bApplyProtection = 1 '\001', inconsistent =
0}
---8<---8<---
It seems that the arBuckets table is completely freed(?) or
uninitialized(?) but is still tried to be used.
------------------------------------------------------------------------
[2002-01-15 16:41:25] charlie@charliedyson.net
Here are two sample pages that cause the crash on my
machine:
== login.php ==
<?
session_start();
session_register("isloggedin");
$HTTP_SESSION_VARS["isloggedin"]=0
?>
<html>
<body>
You are logged in.<br/>
<a href="logout.php">Click here</a> to log-out.<br/>
</body>
</html>
== CUT ==
== logout.php ==
<?
session_unregister("isloggedin");
session_destroy();
?>
<html>
<body>
You are now logged - out.
<a href="login.php">Click here</a> to log-in again. <br/>
<?= session_id() ?><br/>
</body>
</html>
== CUT ==
I also made some small changes to my php.ini file,
starting with php.ini-reccomended. Here is the output of
diff php.ini-recommended php.ini:
683c683
< session.save_path = /tmp
---
> session.save_path = /tmp/phpsess
690c690
< session.name = PHPSESSID
---
> session.name = POSSUMSESSID
== CUT ==
Hope this helps,
Charlie Dyson - charlie@charliedyson.net
------------------------------------------------------------------------
[2002-01-13 20:25:01] yohgaki@php.net
Looks like this is a session module problem. (session_unregister)
Could you make short & complete script causes this segfault?
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
http://bugs.php.net/15020
--
Edit this bug report at http://bugs.php.net/?id=15020&edit=1