#18963 [Opn]: Reproducable crash with simple string functions.
| From: | kalowsky@php.net | Date: | Wed, 21 Aug 2002 02:12:17 +0000 |
| Subject: | #18963 [Opn]: Reproducable crash with simple string functions. | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-17390@lists.php.net to get a copy of this message | ||
ID: 18963
Updated by: kalowsky@php.net
Reported By: si@darkness.nu
Status: Open
Bug Type: Scripting Engine problem
Operating System: IRIX64 6.5.16f IP25
-PHP Version: 4.2.2
+PHP Version: 4.3.0-dev
New Comment:
what sort of problems did you have compiling this?
Also updating version
Previous Comments:
------------------------------------------------------------------------
[2002-08-20 10:21:59] si@darkness.nu
A note from another IRIX admin who looked at this problem:
I note that the problemic address is not null. It resembles a stack
address. In that case, the most frequent cause of the problem is a
miscoded procedure that is called and it returns the address of a
variable with is on the stack and that stack frame is then released.
If the stack shortens by enough, then the address may become invalid as
the kernel releases under some circumstances unneeded stack frames.
Randolph J. Herber, herber@fnal.gov, +1 630 840 2966, CD/CDFTF
PK-149F,Mail Stop 318, Fermilab, Kirk & Pine Rds., PO Box 500, Batavia,
IL 60510-0500,USA. (Speaking for myself and not for US, US DOE, FNAL
nor URA.) (Product,trade, or service marks herein belong to their
respective owners.)
------------------------------------------------------------------------
[2002-08-20 00:12:53] si@darkness.nu
(gdb) bt
#0 0x100f622c in zend_fetch_var_address (opline=0x0, Ts=0x1,
type=2147422752)
at /u02/tardists/apache/php4-200208191500/Zend/zend_execute.c:527
#1 0x10103dfc in execute (op_array=0x10555c10)
at /u02/tardists/apache/php4-200208191500/Zend/zend_execute.c:1232
#2 0x100ff2d8 in execute (op_array=0x10555808)
at /u02/tardists/apache/php4-200208191500/Zend/zend_execute.c:1632
#3 0x10101d50 in execute (op_array=0x1055c0e0)
at /u02/tardists/apache/php4-200208191500/Zend/zend_execute.c:2144
#4 0x10076818 in zend_execute_scripts (type=8, retval=0x0,
file_count=3)
at /u02/tardists/apache/php4-200208191500/Zend/zend.c:812
#5 0x1006a628 in php_execute_script (primary_file=0x7fff2850)
at /u02/tardists/apache/php4-200208191500/main/main.c:1509
#6 0x100f2c64 in apache_php_module_main (r=0x7fff2850,
display_source_mode=2147428456)
at
/u02/tardists/apache/php4-200208191500/sapi/apache/sapi_apache.c:55
#7 0x100667a0 in php_restore_umask ()
#8 0x0fa3a6f4 in fopen64 () at aio.c:317
This is using the latest PHP4 snapshot. I had a few problems compiling
it, but I think I got a clean build.
# ./configure --with-mysql=/usr/local/mysql
--with-apache=../apache_1.3.26 --with-imap=/usr/freeware
--disable-ctype --with-openssl=/usr/freeware/lib/openssl
Server: Apache/1.3.26 (Unix) PHP/4.3.0-dev mod_ssl/2.8.9 OpenSSL/0.9.6e
------------------------------------------------------------------------
[2002-08-19 16:29:32] sniper@php.net
Please try using this CVS snapshot:
http://snaps.php.net/php4-latest.tar.gz
For Windows:
http://snaps.php.net/win32/php4-win32-latest.zip
------------------------------------------------------------------------
[2002-08-19 12:58:51] rasmus@php.net
There are a number of 64-bit fixes in current CVS. Any chance you
could grab the latest unstable snapshot from snaps.php.net and try with
that?
------------------------------------------------------------------------
[2002-08-19 08:55:04] si@darkness.nu
# ./configure --with-mysql=/usr/local/mysql
--with-apache=../apache_1.3.26 --with-imap=/usr/freeware
--disable-ctype --with-openssl=/usr/freeware/lib/openssl
Configure options. PHP 4.2.2, Apache 1.3.26, MySQL 3.23.52, IRIX
6.5.16F
Problem manifests itself intermittently, suggestive of heap corruption,
so doesn't allow for a simple script which causes the problem to
manifest, does occur across multiple machines.
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
http://bugs.php.net/18963
--
Edit this bug report at http://bugs.php.net/?id=18963&edit=1