Bug #66675 [Com]: sometimes segfault while processing .js as .php
| From: | phpreq at byom dot de | Date: | Sat, 08 Feb 2014 20:40:38 +0000 |
| Subject: | Bug #66675 [Com]: sometimes segfault while processing .js as .php | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-184216@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=66675&edit=1
ID: 66675
Comment by: phpreq at byom dot de
Reported by: phpreq at byom dot de
Summary: sometimes segfault while processing .js as .php
Status: Feedback
Type: Bug
Package: *General Issues
Operating System: Debian 7.2 x64
PHP Version: 5.5.9
Block user comment: N
Private report: N
New Comment:
I am unable to provide a script as a real php-script is not involved here.
Associate .js-files in Apache with php as seen above and download again and again a stock .js-script
of your choice, e.g. jquery.js or jquery-migrate.min.js, but it needs some thousand requests until
the segfault is hit.
I haven't hit a segfault with a script having a .php-file extension, maybe it is something
trivial like a file-extension check fixed to 3 digits or so summing up after some thousand hits...
Previous Comments:
------------------------------------------------------------------------
[2014-02-08 20:29:57] pajoye@php.net
Thank you for this bug report. To properly diagnose the problem, we
need a short but complete example script to be able to reproduce
this bug ourselves.
A proper reproducing script starts with <?php and ends with ?>,
is max. 10-20 lines long and does not require any external
resources such as databases, etc. If the script requires a
database to demonstrate the issue, please make sure it creates
all necessary tables, stored procedures etc.
Please avoid embedding huge scripts into the report.
------------------------------------------------------------------------
[2014-02-08 20:25:06] phpreq at byom dot de
Description:
------------
Hi,
In my setup (Debian Wheezy 64 Bit, Kernel 3.12, Apache 2.4.7, php 5.5.9, gcc Debian 4.7.2-5)
I let php also parse and execute .js - files as some very few contain php-code to have dynamically
created .js files.
Done with: AddType application/x-httpd-php js
Apache segfaults about 5-6 times a day.
Doing a backtrace shows me that only files that end with .js cause the segfault.
The files are typically stock .js-files from a wordpress 3.8.1 installation. Parsing them by php
shouldn't be a problem, especially as they don't contain any <? ?>. But it seems
there is a problem with the file-buf as seen in gdb's frame 4: error: Cannot access memory at
address 0x100000001.
See the output of gdb:
Program terminated with signal SIGSEGV, Segmentation fault.
#0 0x00007f653a6948ef in i_create_execute_data_from_op_array (nested=0 '\000',
op_array=0x7f6540403148)
at /usr/local/src/php-5.5.9/Zend/zend_execute.c:1631
1631 EX(prev_execute_data) = EG(current_execute_data);
(gdb) bt
#0 0x00007f653a6948ef in i_create_execute_data_from_op_array (nested=0 '\000',
op_array=0x7f6540403148)
at /usr/local/src/php-5.5.9/Zend/zend_execute.c:1631
#1 zend_execute (op_array=0x7f6540403148) at /usr/local/src/php-5.5.9/Zend/zend_vm_execute.h:388
#2 zend_execute (op_array=0x7f6540403148) at /usr/local/src/php-5.5.9/Zend/zend_vm_execute.h:383
#3 0x00007f653a5e7b69 in zend_execute_scripts (type=type@entry=2, retval=0x0,
retval@entry=0x2201a60,
file_count=file_count@entry=1) at /usr/local/src/php-5.5.9/Zend/zend.c:1316
#4 0x00007f653a698105 in php_handler (r=0x21f1770)
at /usr/local/src/php-5.5.9/sapi/apache2handler/sapi_apache2.c:669
#5 0x000000000044ee50 in ap_run_handler (r=0x21f1770) at config.c:170
#6 0x000000000044f42b in ap_invoke_handler (r=r@entry=0x21f1770) at config.c:439
#7 0x000000000046354a in ap_process_async_request (r=0x21f1770) at http_request.c:317
#8 0x00000000004637ff in ap_process_request (r=r@entry=0x21f1770) at http_request.c:363
#9 0x000000000045fe05 in ap_process_http_sync_connection (c=0x21e18e0) at http_core.c:190
#10 ap_process_http_connection (c=0x21e18e0) at http_core.c:231
#11 0x0000000000458460 in ap_run_process_connection (c=0x21e18e0) at connection.c:41
#12 0x0000000000458860 in ap_process_connection (c=c@entry=0x21e18e0, csd=<optimized out>) at
connection.c:202
#13 0x000000000046986b in child_main (child_num_arg=child_num_arg@entry=2) at prefork.c:704
#14 0x0000000000469a77 in make_child (s=0x1eaf538, slot=2) at prefork.c:800
#15 0x000000000046a842 in perform_idle_server_maintenance (p=<optimized out>) at prefork.c:902
#16 prefork_run (_pconf=<optimized out>, plog=<optimized out>, s=<optimized out>)
at prefork.c:1090
#17 0x0000000000435a0e in ap_run_mpm (pconf=0x1e86138, plog=0x1eb3378, s=0x1eaf538) at
mpm_common.c:98
#18 0x000000000042f12b in main (argc=3, argv=0x7fff5542e328) at main.c:777
(gdb) bt full
#0 0x00007f653a6948ef in i_create_execute_data_from_op_array (nested=0 '\000',
op_array=0x7f6540403148)
at /usr/local/src/php-5.5.9/Zend/zend_execute.c:1631
execute_data = 0x0
CVs_size = 0
Ts_size = <optimized out>
stack_size = <optimized out>
total_size = <optimized out>
call_slots_size = <optimized out>
#1 zend_execute (op_array=0x7f6540403148) at /usr/local/src/php-5.5.9/Zend/zend_vm_execute.h:388
No locals.
#2 zend_execute (op_array=0x7f6540403148) at /usr/local/src/php-5.5.9/Zend/zend_vm_execute.h:383
No locals.
#3 0x00007f653a5e7b69 in zend_execute_scripts (type=type@entry=2, retval=0x0,
retval@entry=0x2201a60,
file_count=file_count@entry=1) at /usr/local/src/php-5.5.9/Zend/zend.c:1316
files = {{gp_offset = 32, fp_offset = 28, overflow_arg_area = 0x7fff5542dba0,
reg_save_area = 0x7fff5542db30}}
i = <optimized out>
file_handle = 0x7fff5542dc00
orig_op_array = 0x0
orig_retval_ptr_ptr = 0x0
orig_interactive = 0
#4 0x00007f653a698105 in php_handler (r=0x21f1770)
at /usr/local/src/php-5.5.9/sapi/apache2handler/sapi_apache2.c:669
zfd = {type = ZEND_HANDLE_FILENAME,
filename = 0x21f2ef0 "/home/www/htdocs/wp-includes/js/jquery/jquery.js",
opened_path = 0x0, handle = {fd = 1067612014, fp = 0x7f653fa2776e
<apr_table_unset+158>, stream = {
handle = 0x7f653fa2776e <apr_table_unset+158>, isatty = 35598064, mmap = {len =
36590244,
pos = 35591928, map = 0x6440073f370,
buf = 0x100000001 <error: Cannot access memory at address 0x100000001>,
old_handle = 0x1,
old_closer = 0x7180567}, reader = 0x902, fsizer = 0x1, closer = 0x21e18e0}},
free_filename = 0 '\000'}
__orig_bailout = 0x0
__bailout = {{__jmpbuf = {32654544, 6444143732774364179, 35592048, 35526880, 32175416, 0,
-6444483869346667501, -6366886698566065133}, __mask_was_saved = 0, __saved_mask =
{__val = {
32257640, 32563064, 35799832, 1, 32563064, 35799840, 0, 35526880, 32175416, 0,
140072810773443, 0,
0, 0, 0, 0}}}}
ctx = 0x21e9c48
conf = 0x1ee6160
brigade = 0x0
bucket = <optimized out>
rv = <optimized out>
parent_req = 0x2201a60
#5 0x000000000044ee50 in ap_run_handler (r=0x21f1770) at config.c:170
pHook = 0x1f244d0
n = 4
rv = 0
#6 0x000000000044f42b in ap_invoke_handler (r=r@entry=0x21f1770) at config.c:439
handler = <optimized out>
p = <optimized out>
result = <optimized out>
old_handler = 0x0
ignore = <optimized out>
#7 0x000000000046354a in ap_process_async_request (r=0x21f1770) at http_request.c:317
c = 0x21e18e0
access_status = 0
#8 0x00000000004637ff in ap_process_request (r=r@entry=0x21f1770) at http_request.c:363
bb = <optimized out>
b = <optimized out>
c = 0x21e18e0
rv = <optimized out>
#9 0x000000000045fe05 in ap_process_http_sync_connection (c=0x21e18e0) at http_core.c:190
r = 0x21f1770
cs = 0x0
csd = 0x21e16f0
mpm_state = 1
#10 ap_process_http_connection (c=0x21e18e0) at http_core.c:231
No locals.
#11 0x0000000000458460 in ap_run_process_connection (c=0x21e18e0) at connection.c:41
pHook = 0x1f2eaa0
n = 1
rv = 0
#12 0x0000000000458860 in ap_process_connection (c=c@entry=0x21e18e0, csd=<optimized out>) at
connection.c:202
rc = <optimized out>
#13 0x000000000046986b in child_main (child_num_arg=child_num_arg@entry=2) at prefork.c:704
current_conn = 0x21e18e0
csd = 0x21e16f0
thd = 0x20aff70
osthd = 140072847148864
ptrans = 0x21e1678
allocator = 0x20afb70
status = <optimized out>
i = <optimized out>
lr = <optimized out>
pollset = 0x20b0050
sbh = 0x20b0048
bucket_alloc = 0x21e5698
last_poll_idx = 1
lockfile = <optimized out>
#14 0x0000000000469a77 in make_child (s=0x1eaf538, slot=2) at prefork.c:800
pid = 0
#15 0x000000000046a842 in perform_idle_server_maintenance (p=<optimized out>) at prefork.c:902
i = <optimized out>
idle_count = <optimized out>
ws = <optimized out>
free_length = <optimized out>
free_slots = {2, 7, 12, 14, 28, 29, 30, 31, 32, 33, 34, 35, 36, 38, 39, 40, 57, 58, 59, 60,
61, 62, 63, 64,
65, 66, 67, 68, 69, 70, 71, 72}
last_non_dead = <optimized out>
total_non_dead = <optimized out>
#16 prefork_run (_pconf=<optimized out>, plog=<optimized out>, s=<optimized out>)
at prefork.c:1090
status = 0
pid = {pid = -1, in = 0x7f653aaf582d, out = 0x7f653efa8e60, err = 0x20}
child_slot = <optimized out>
exitwhy = APR_PROC_EXIT
processed_status = <optimized out>
index = <optimized out>
remaining_children_to_start = 0
rv = <optimized out>
#17 0x0000000000435a0e in ap_run_mpm (pconf=0x1e86138, plog=0x1eb3378, s=0x1eaf538) at
mpm_common.c:98
pHook = 0x1f2ebc8
n = 0
rv = 0
#18 0x000000000042f12b in main (argc=3, argv=0x7fff5542e328) at main.c:777
c = 0 '\000'
showcompile = 0
showdirectives = 0
confname = 0x46c1f0 "/usr/local/apache/conf/httpd.conf"
def_server_root = 0x46b8f8 "/usr/local/apache/2.4.7"
temp_error_log = <optimized out>
error = <optimized out>
process = 0x1e84218
pconf = 0x1e86138
plog = 0x1eb3378
ptemp = 0x1eb1348
pcommands = 0x1ea8248
opt = 0x1ea8338
rv = <optimized out>
mod = 0x689ac0 <ap_prelinked_modules+32>
opt_arg = 0x1e84128 "\b\001\350\001"
signal_server = <optimized out>
(gdb) frame 1
#1 zend_execute (op_array=0x7f6540403148) at /usr/local/src/php-5.5.9/Zend/zend_vm_execute.h:388
388 zend_execute_ex(i_create_execute_data_from_op_array(op_array, 0 TSRMLS_CC)
TSRMLS_CC);
(gdb)
(gdb) frame 4
#4 0x00007f653a698105 in php_handler (r=0x2376c90)
at /usr/local/src/php-5.5.9/sapi/apache2handler/sapi_apache2.c:669
669 zend_execute_scripts(ZEND_INCLUDE TSRMLS_CC, NULL, 1, &zfd);
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=66675&edit=1