Bug #67644 [Com]: Memory corruption & crash during ob_start function callback

From: Date: Sun, 24 Aug 2014 17:14:11 +0000
Subject: Bug #67644 [Com]: Memory corruption & crash during ob_start function callback
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-187262@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=67644&edit=1 ID: 67644 Comment by: jocelyn dot fournier at gmail dot com Reported by: jocelyn dot fournier at gmail dot com Summary: Memory corruption & crash during ob_start function callback Status: Assigned Type: Bug Package: Reproducible crash Operating System: Mac OS X PHP Version: 5.4.30 Assigned To: mike Block user comment: N Private report: N New Comment: Hi, Any progress on this issue ? Using register_shutdown_function() + ob_start() as a workaround doesn't work for all the cases. Indeed, I are have cases where ob_start() is called before register_shutdown_function(), even with the PHP_OUTPUT_HANDLER_REMOVABLE flag in ob_start(). Thanks, Previous Comments: ------------------------------------------------------------------------ [2014-07-19 06:11:46] jocelyn dot fournier at gmail dot com If I slightly modify the script to run the asynchronous_write function inside a register_shutdown_function instead of ob_start, it doesn't crash anymore : <?php use PhpAmqpLib\Connection\AMQPConnection; class queue { private static $instance = null; private $connection = null; private $channel = null; public static function instance() { if (self::$instance == null) { self::$instance = new self(); } return self::$instance; } private function __construct() { require_once __DIR__.'/libs/php-amqplib-2.4.0/vendor/autoload.php'; $this->connection = new AMQPConnection('localhost', '5672', 'guest', 'guest', '/'); } public function asynchronous_write() { if (!$this->connection) return; if ($this->channel == null) { $this->channel = $this->connection->channel(); } } } register_shutdown_function('async'); ob_start('foo'); echo 'bar'; function async() { queue::instance()->asynchronous_write(); } function foo($content, $mode = 5) { return $content; } exit; ------------------------------------------------------------------------ [2014-07-19 06:00:19] jocelyn dot fournier at gmail dot com 5.5.13 crashes as well ------------------------------------------------------------------------ [2014-07-19 00:24:44] yohgaki@php.net This may not be a output control bug.. Could you try 5.5 also? ------------------------------------------------------------------------ [2014-07-17 21:50:18] jocelyn dot fournier at gmail dot com Part of valgrind output from PHP 5.5 : ==2715== Invalid read of size 8 ==2715== at 0x8DC6A8: _efree (zend_alloc.c:2436) ==2715== by 0x91120F: destroy_op_array (zend_opcode.c:361) ==2715== by 0x9104AF: destroy_zend_function (zend_opcode.c:116) ==2715== by 0x9104E6: zend_function_dtor (zend_opcode.c:128) ==2715== by 0x935A80: zend_hash_destroy (zend_hash.c:560) ==2715== by 0x91F04B: compiler_globals_dtor (zend.c:539) ==2715== by 0x858B1C: tsrm_shutdown (TSRM.c:180) ==2715== by 0x9E4B7B: main (php_cli.c:1399) ==2715== Address 0xd1a3060 is 0 bytes inside a block of size 8 free'd ==2715== at 0x4C2BDEC: free (in /usr/lib/valgrind/vgpreload_memcheck-amd64-linux.so) ==2715== by 0x858B3B: tsrm_shutdown (TSRM.c:182) ==2715== by 0x9E4B7B: main (php_cli.c:1399) ==2715== ==2715== Invalid read of size 4 ==2715== at 0x8DC6AB: _efree (zend_alloc.c:2436) ==2715== by 0x91120F: destroy_op_array (zend_opcode.c:361) ==2715== by 0x9104AF: destroy_zend_function (zend_opcode.c:116) ==2715== by 0x9104E6: zend_function_dtor (zend_opcode.c:128) ==2715== by 0x935A80: zend_hash_destroy (zend_hash.c:560) ==2715== by 0x91F04B: compiler_globals_dtor (zend.c:539) ==2715== by 0x858B1C: tsrm_shutdown (TSRM.c:180) ==2715== by 0x9E4B7B: main (php_cli.c:1399) ==2715== Address 0xd1a3100 is 0 bytes inside a block of size 2,224 free'd ==2715== at 0x4C2BDEC: free (in /usr/lib/valgrind/vgpreload_memcheck-amd64-linux.so) ==2715== by 0x8D9DD6: zend_mm_shutdown (zend_alloc.c:1688) ==2715== by 0x8DCF40: shutdown_memory_manager (zend_alloc.c:2718) ==2715== by 0x8DD028: alloc_globals_dtor (zend_alloc.c:2740) ==2715== by 0x858B1C: tsrm_shutdown (TSRM.c:180) ==2715== by 0x9E4B7B: main (php_cli.c:1399) ==2715== ==2715== Invalid read of size 8 ==2715== at 0x8DC708: _efree (zend_alloc.c:2440) ==2715== by 0x91120F: destroy_op_array (zend_opcode.c:361) ==2715== by 0x9104AF: destroy_zend_function (zend_opcode.c:116) ==2715== by 0x9104E6: zend_function_dtor (zend_opcode.c:128) ==2715== by 0x935A80: zend_hash_destroy (zend_hash.c:560) ==2715== by 0x91F04B: compiler_globals_dtor (zend.c:539) ==2715== by 0x858B1C: tsrm_shutdown (TSRM.c:180) ==2715== by 0x9E4B7B: main (php_cli.c:1399) ==2715== Address 0xd1a3060 is 0 bytes inside a block of size 8 free'd ==2715== at 0x4C2BDEC: free (in /usr/lib/valgrind/vgpreload_memcheck-amd64-linux.so) ==2715== by 0x858B3B: tsrm_shutdown (TSRM.c:182) ==2715== by 0x9E4B7B: main (php_cli.c:1399) ==2715== ==2715== Invalid read of size 8 ==2715== at 0x8D91C5: zend_mm_check_ptr (zend_alloc.c:1374) ==2715== by 0x8DB02F: _zend_mm_free_int (zend_alloc.c:2068) ==2715== by 0x8DC72B: _efree (zend_alloc.c:2440) ==2715== by 0x91120F: destroy_op_array (zend_opcode.c:361) ==2715== by 0x9104AF: destroy_zend_function (zend_opcode.c:116) ==2715== by 0x9104E6: zend_function_dtor (zend_opcode.c:128) ==2715== by 0x935A80: zend_hash_destroy (zend_hash.c:560) ==2715== by 0x91F04B: compiler_globals_dtor (zend.c:539) ==2715== by 0x858B1C: tsrm_shutdown (TSRM.c:180) ==2715== by 0x9E4B7B: main (php_cli.c:1399) ==2715== Address 0xd1e27c8 is 257,496 bytes inside a block of size 262,144 free'd ==2715== at 0x4C2BDEC: free (in /usr/lib/valgrind/vgpreload_memcheck-amd64-linux.so) ==2715== by 0x8D79AA: zend_mm_mem_malloc_free (zend_alloc.c:297) ==2715== by 0x8D9D99: zend_mm_shutdown (zend_alloc.c:1683) ==2715== by 0x8DCF40: shutdown_memory_manager (zend_alloc.c:2718) ==2715== by 0x8DD028: alloc_globals_dtor (zend_alloc.c:2740) ==2715== by 0x858B1C: tsrm_shutdown (TSRM.c:180) ==2715== by 0x9E4B7B: main (php_cli.c:1399) [...] ==2715== Invalid read of size 8 ==2715== at 0x861009: php_message_handler_for_zend (main.c:1458) ==2715== by 0x920750: zend_message_dispatcher (zend.c:973) ==2715== by 0x8D90D6: zend_mm_check_ptr (zend_alloc.c:1352) ==2715== by 0x8D92F0: zend_mm_check_ptr (zend_alloc.c:1389) ==2715== by 0x8DB02F: _zend_mm_free_int (zend_alloc.c:2068) ==2715== by 0x8DC72B: _efree (zend_alloc.c:2440) ==2715== by 0x935B72: zend_hash_destroy (zend_hash.c:568) ==2715== by 0x910EE8: destroy_zend_class (zend_opcode.c:298) ==2715== by 0x935A80: zend_hash_destroy (zend_hash.c:560) ==2715== by 0x91F088: compiler_globals_dtor (zend.c:543) ==2715== by 0x858B1C: tsrm_shutdown (TSRM.c:180) ==2715== by 0x9E4B7B: main (php_cli.c:1399) ==2715== Address 0x40 is not stack'd, malloc'd or (recently) free'd ==2715== ==2715== ==2715== Process terminating with default action of signal 11 (SIGSEGV) ==2715== Access not within mapped region at address 0x40 ==2715== at 0x861009: php_message_handler_for_zend (main.c:1458) ==2715== by 0x920750: zend_message_dispatcher (zend.c:973) ==2715== by 0x8D90D6: zend_mm_check_ptr (zend_alloc.c:1352) ==2715== by 0x8D92F0: zend_mm_check_ptr (zend_alloc.c:1389) ==2715== by 0x8DB02F: _zend_mm_free_int (zend_alloc.c:2068) ==2715== by 0x8DC72B: _efree (zend_alloc.c:2440) ==2715== by 0x935B72: zend_hash_destroy (zend_hash.c:568) ==2715== by 0x910EE8: destroy_zend_class (zend_opcode.c:298) ==2715== by 0x935A80: zend_hash_destroy (zend_hash.c:560) ==2715== by 0x91F088: compiler_globals_dtor (zend.c:543) ==2715== by 0x858B1C: tsrm_shutdown (TSRM.c:180) ==2715== by 0x9E4B7B: main (php_cli.c:1399) ==2715== If you believe this happened as a result of a stack ==2715== overflow in your program's main thread (unlikely but ==2715== possible), you can try to increase the size of the ==2715== main thread stack using the --main-stacksize= flag. ==2715== The main thread stack size used in this run was 8388608. ==2715== ==2715== HEAP SUMMARY: ==2715== in use at exit: 636,155 bytes in 5,094 blocks ==2715== total heap usage: 28,246 allocs, 23,152 frees, 6,173,404 bytes allocated ==2715== ==2715== LEAK SUMMARY: ==2715== definitely lost: 0 bytes in 0 blocks ==2715== indirectly lost: 0 bytes in 0 blocks ==2715== possibly lost: 0 bytes in 0 blocks ==2715== still reachable: 636,155 bytes in 5,094 blocks ==2715== suppressed: 0 bytes in 0 blocks ==2715== Rerun with --leak-check=full to see details of leaked memory ==2715== ==2715== For counts of detected and suppressed errors, rerun with: -v ==2715== ERROR SUMMARY: 5974 errors from 288 contexts (suppressed: 0 from 0) ------------------------------------------------------------------------ [2014-07-17 16:44:02] jocelyn dot fournier at gmail dot com better title ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=67644 -- Edit this bug report at https://bugs.php.net/bug.php?id=67644&edit=1

« previous php.bugs (#187262) next »