Bug #67644 [Com]: Memory corruption & crash during ob_start function callback
| From: | jocelyn dot fournier at gmail dot com | Date: | Sun, 24 Aug 2014 17:14:11 +0000 |
| Subject: | Bug #67644 [Com]: Memory corruption & crash during ob_start function callback | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-187262@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=67644&edit=1
ID: 67644
Comment by: jocelyn dot fournier at gmail dot com
Reported by: jocelyn dot fournier at gmail dot com
Summary: Memory corruption & crash during ob_start function
callback
Status: Assigned
Type: Bug
Package: Reproducible crash
Operating System: Mac OS X
PHP Version: 5.4.30
Assigned To: mike
Block user comment: N
Private report: N
New Comment:
Hi,
Any progress on this issue ?
Using register_shutdown_function() + ob_start() as a workaround doesn't work for all the cases.
Indeed, I are have cases where ob_start() is called before register_shutdown_function(), even with
the PHP_OUTPUT_HANDLER_REMOVABLE flag in ob_start().
Thanks,
Previous Comments:
------------------------------------------------------------------------
[2014-07-19 06:11:46] jocelyn dot fournier at gmail dot com
If I slightly modify the script to run the asynchronous_write function inside a
register_shutdown_function instead of ob_start, it doesn't crash anymore :
<?php
use PhpAmqpLib\Connection\AMQPConnection;
class queue {
private static $instance = null;
private $connection = null;
private $channel = null;
public static function instance() {
if (self::$instance == null) {
self::$instance = new self();
}
return self::$instance;
}
private function __construct() {
require_once __DIR__.'/libs/php-amqplib-2.4.0/vendor/autoload.php';
$this->connection = new AMQPConnection('localhost', '5672',
'guest', 'guest', '/');
}
public function asynchronous_write() {
if (!$this->connection) return;
if ($this->channel == null) {
$this->channel = $this->connection->channel();
}
}
}
register_shutdown_function('async');
ob_start('foo');
echo 'bar';
function async() {
queue::instance()->asynchronous_write();
}
function foo($content, $mode = 5) {
return $content;
}
exit;
------------------------------------------------------------------------
[2014-07-19 06:00:19] jocelyn dot fournier at gmail dot com
5.5.13 crashes as well
------------------------------------------------------------------------
[2014-07-19 00:24:44] yohgaki@php.net
This may not be a output control bug..
Could you try 5.5 also?
------------------------------------------------------------------------
[2014-07-17 21:50:18] jocelyn dot fournier at gmail dot com
Part of valgrind output from PHP 5.5 :
==2715== Invalid read of size 8
==2715== at 0x8DC6A8: _efree (zend_alloc.c:2436)
==2715== by 0x91120F: destroy_op_array (zend_opcode.c:361)
==2715== by 0x9104AF: destroy_zend_function (zend_opcode.c:116)
==2715== by 0x9104E6: zend_function_dtor (zend_opcode.c:128)
==2715== by 0x935A80: zend_hash_destroy (zend_hash.c:560)
==2715== by 0x91F04B: compiler_globals_dtor (zend.c:539)
==2715== by 0x858B1C: tsrm_shutdown (TSRM.c:180)
==2715== by 0x9E4B7B: main (php_cli.c:1399)
==2715== Address 0xd1a3060 is 0 bytes inside a block of size 8 free'd
==2715== at 0x4C2BDEC: free (in /usr/lib/valgrind/vgpreload_memcheck-amd64-linux.so)
==2715== by 0x858B3B: tsrm_shutdown (TSRM.c:182)
==2715== by 0x9E4B7B: main (php_cli.c:1399)
==2715==
==2715== Invalid read of size 4
==2715== at 0x8DC6AB: _efree (zend_alloc.c:2436)
==2715== by 0x91120F: destroy_op_array (zend_opcode.c:361)
==2715== by 0x9104AF: destroy_zend_function (zend_opcode.c:116)
==2715== by 0x9104E6: zend_function_dtor (zend_opcode.c:128)
==2715== by 0x935A80: zend_hash_destroy (zend_hash.c:560)
==2715== by 0x91F04B: compiler_globals_dtor (zend.c:539)
==2715== by 0x858B1C: tsrm_shutdown (TSRM.c:180)
==2715== by 0x9E4B7B: main (php_cli.c:1399)
==2715== Address 0xd1a3100 is 0 bytes inside a block of size 2,224 free'd
==2715== at 0x4C2BDEC: free (in /usr/lib/valgrind/vgpreload_memcheck-amd64-linux.so)
==2715== by 0x8D9DD6: zend_mm_shutdown (zend_alloc.c:1688)
==2715== by 0x8DCF40: shutdown_memory_manager (zend_alloc.c:2718)
==2715== by 0x8DD028: alloc_globals_dtor (zend_alloc.c:2740)
==2715== by 0x858B1C: tsrm_shutdown (TSRM.c:180)
==2715== by 0x9E4B7B: main (php_cli.c:1399)
==2715==
==2715== Invalid read of size 8
==2715== at 0x8DC708: _efree (zend_alloc.c:2440)
==2715== by 0x91120F: destroy_op_array (zend_opcode.c:361)
==2715== by 0x9104AF: destroy_zend_function (zend_opcode.c:116)
==2715== by 0x9104E6: zend_function_dtor (zend_opcode.c:128)
==2715== by 0x935A80: zend_hash_destroy (zend_hash.c:560)
==2715== by 0x91F04B: compiler_globals_dtor (zend.c:539)
==2715== by 0x858B1C: tsrm_shutdown (TSRM.c:180)
==2715== by 0x9E4B7B: main (php_cli.c:1399)
==2715== Address 0xd1a3060 is 0 bytes inside a block of size 8 free'd
==2715== at 0x4C2BDEC: free (in /usr/lib/valgrind/vgpreload_memcheck-amd64-linux.so)
==2715== by 0x858B3B: tsrm_shutdown (TSRM.c:182)
==2715== by 0x9E4B7B: main (php_cli.c:1399)
==2715==
==2715== Invalid read of size 8
==2715== at 0x8D91C5: zend_mm_check_ptr (zend_alloc.c:1374)
==2715== by 0x8DB02F: _zend_mm_free_int (zend_alloc.c:2068)
==2715== by 0x8DC72B: _efree (zend_alloc.c:2440)
==2715== by 0x91120F: destroy_op_array (zend_opcode.c:361)
==2715== by 0x9104AF: destroy_zend_function (zend_opcode.c:116)
==2715== by 0x9104E6: zend_function_dtor (zend_opcode.c:128)
==2715== by 0x935A80: zend_hash_destroy (zend_hash.c:560)
==2715== by 0x91F04B: compiler_globals_dtor (zend.c:539)
==2715== by 0x858B1C: tsrm_shutdown (TSRM.c:180)
==2715== by 0x9E4B7B: main (php_cli.c:1399)
==2715== Address 0xd1e27c8 is 257,496 bytes inside a block of size 262,144 free'd
==2715== at 0x4C2BDEC: free (in /usr/lib/valgrind/vgpreload_memcheck-amd64-linux.so)
==2715== by 0x8D79AA: zend_mm_mem_malloc_free (zend_alloc.c:297)
==2715== by 0x8D9D99: zend_mm_shutdown (zend_alloc.c:1683)
==2715== by 0x8DCF40: shutdown_memory_manager (zend_alloc.c:2718)
==2715== by 0x8DD028: alloc_globals_dtor (zend_alloc.c:2740)
==2715== by 0x858B1C: tsrm_shutdown (TSRM.c:180)
==2715== by 0x9E4B7B: main (php_cli.c:1399)
[...]
==2715== Invalid read of size 8
==2715== at 0x861009: php_message_handler_for_zend (main.c:1458)
==2715== by 0x920750: zend_message_dispatcher (zend.c:973)
==2715== by 0x8D90D6: zend_mm_check_ptr (zend_alloc.c:1352)
==2715== by 0x8D92F0: zend_mm_check_ptr (zend_alloc.c:1389)
==2715== by 0x8DB02F: _zend_mm_free_int (zend_alloc.c:2068)
==2715== by 0x8DC72B: _efree (zend_alloc.c:2440)
==2715== by 0x935B72: zend_hash_destroy (zend_hash.c:568)
==2715== by 0x910EE8: destroy_zend_class (zend_opcode.c:298)
==2715== by 0x935A80: zend_hash_destroy (zend_hash.c:560)
==2715== by 0x91F088: compiler_globals_dtor (zend.c:543)
==2715== by 0x858B1C: tsrm_shutdown (TSRM.c:180)
==2715== by 0x9E4B7B: main (php_cli.c:1399)
==2715== Address 0x40 is not stack'd, malloc'd or (recently) free'd
==2715==
==2715==
==2715== Process terminating with default action of signal 11 (SIGSEGV)
==2715== Access not within mapped region at address 0x40
==2715== at 0x861009: php_message_handler_for_zend (main.c:1458)
==2715== by 0x920750: zend_message_dispatcher (zend.c:973)
==2715== by 0x8D90D6: zend_mm_check_ptr (zend_alloc.c:1352)
==2715== by 0x8D92F0: zend_mm_check_ptr (zend_alloc.c:1389)
==2715== by 0x8DB02F: _zend_mm_free_int (zend_alloc.c:2068)
==2715== by 0x8DC72B: _efree (zend_alloc.c:2440)
==2715== by 0x935B72: zend_hash_destroy (zend_hash.c:568)
==2715== by 0x910EE8: destroy_zend_class (zend_opcode.c:298)
==2715== by 0x935A80: zend_hash_destroy (zend_hash.c:560)
==2715== by 0x91F088: compiler_globals_dtor (zend.c:543)
==2715== by 0x858B1C: tsrm_shutdown (TSRM.c:180)
==2715== by 0x9E4B7B: main (php_cli.c:1399)
==2715== If you believe this happened as a result of a stack
==2715== overflow in your program's main thread (unlikely but
==2715== possible), you can try to increase the size of the
==2715== main thread stack using the --main-stacksize= flag.
==2715== The main thread stack size used in this run was 8388608.
==2715==
==2715== HEAP SUMMARY:
==2715== in use at exit: 636,155 bytes in 5,094 blocks
==2715== total heap usage: 28,246 allocs, 23,152 frees, 6,173,404 bytes allocated
==2715==
==2715== LEAK SUMMARY:
==2715== definitely lost: 0 bytes in 0 blocks
==2715== indirectly lost: 0 bytes in 0 blocks
==2715== possibly lost: 0 bytes in 0 blocks
==2715== still reachable: 636,155 bytes in 5,094 blocks
==2715== suppressed: 0 bytes in 0 blocks
==2715== Rerun with --leak-check=full to see details of leaked memory
==2715==
==2715== For counts of detected and suppressed errors, rerun with: -v
==2715== ERROR SUMMARY: 5974 errors from 288 contexts (suppressed: 0 from 0)
------------------------------------------------------------------------
[2014-07-17 16:44:02] jocelyn dot fournier at gmail dot com
better title
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=67644
--
Edit this bug report at https://bugs.php.net/bug.php?id=67644&edit=1