Bug #66358 [Opn->Csd]: fpm starts segfault

From: Date: Fri, 27 Dec 2013 12:46:21 +0000
Subject: Bug #66358 [Opn->Csd]: fpm starts segfault
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-183472@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=66358&edit=1 ID: 66358 Updated by: laruence@php.net Reported by: laruence@php.net Summary: fpm starts segfault -Status: Open +Status: Closed Type: Bug Package: *General Issues PHP Version: master-Git-2013-12-27 (Git) Block user comment: N Private report: N New Comment: Automatic comment on behalf of laruence Revision: http://git.php.net/?p=php-src.git;a=commit;h=a8cd9b417c1195075657ebaf99d792f4e92b99ac Log: Fixed bug #66358 (fpm starts segfault) Previous Comments: ------------------------------------------------------------------------ [2013-12-27 09:58:32] ab@php.net Yes, it should be efree() at that place, tsrm_realpath returns a string allocated in zend mm pool, http://lxr.php.net/xref/PHP_TRUNK/Zend/zend_virtual_cwd.c#1954 . That has to be something i've overseen as there was several multiple places outside zend to fix. If that change passes for you, it should be ok, so please apply. In the current master i see a free() instead. ------------------------------------------------------------------------ [2013-12-27 04:59:34] laruence@php.net Description: ------------ (PHP-5.6) after commit e30b2aae5ad93405eee19bca6125ea872f409c82 php-fpm starts segfault with backtrace Program received signal SIGABRT, Aborted. 0x00000034dc030285 in raise () from /lib64/libc.so.6 (gdb) bt #0 0x00000034dc030285 in raise () from /lib64/libc.so.6 #1 0x00000034dc031d30 in abort () from /lib64/libc.so.6 #2 0x00000034dc06971b in __libc_message () from /lib64/libc.so.6 #3 0x00000034dc071756 in free () from /lib64/libc.so.6 #4 0x000000000099c37b in init_request_info () at /home/huixinchen/opensource/php-5.6/sapi/fpm/fpm/fpm_main.c:1356 #5 0x000000000099d4d8 in main (argc=3, argv=0x7fff7f242528) at /home/huixinchen/opensource/php-5.6/sapi/fpm/fpm/fpm_main.c:1866 seems because tsrm_real_path return previously a malloced realpath, but after that commit it return a emalloced? diff --git a/sapi/fpm/fpm/fpm_main.c b/sapi/fpm/fpm/fpm_main.c index 91abfea..3da603b 100644 --- a/sapi/fpm/fpm/fpm_main.c +++ b/sapi/fpm/fpm/fpm_main.c @@ -1353,7 +1353,7 @@ static void init_request_info(TSRMLS_D) } else { SG(request_info).request_uri = env_script_name; } - free(real_path); + efree(real_path); } } else { /* pre 4.3 behaviour, shouldn't be used but provides BC */ welting, please look at this. Test script: --------------- none Expected result: ---------------- none Actual result: -------------- none ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=66358&edit=1

« previous php.bugs (#183472) next »