Bug #68252 [Opn]: segfault in Zend/zend_hash.c in function _zend_hash_del_el
| From: | laruence@php.net | Date: | Mon, 20 Oct 2014 15:33:16 +0000 |
| Subject: | Bug #68252 [Opn]: segfault in Zend/zend_hash.c in function _zend_hash_del_el | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-188199@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=68252&edit=1
ID: 68252
Updated by: laruence@php.net
Reported by: bugs at milos dot nz
Summary: segfault in Zend/zend_hash.c in function
_zend_hash_del_el
Status: Open
Type: Bug
Package: Reproducible crash
Operating System: Linux 3.16 (Gentoo)
PHP Version: master-Git-2014-10-17 (Git)
Block user comment: N
Private report: N
New Comment:
could you please run wordpress index.php with valgrind..
like:
USE_ZEND_ALLOC=0 valgrind path-to-php/bin/php wordpress/index.php
and paste the output out?
thanks
Previous Comments:
------------------------------------------------------------------------
[2014-10-17 14:07:50] bugs at milos dot nz
Description:
------------
WordPress sites with certain plugins enabled cause a segmentation fault. Several different sites
with different plugins cause this and the segmentation fault is the same. I have not encountered the
issue with any isolated PHP script so I cannot currently be more specific than this.
Commenting out most of the _zend_hash_del_el() function resolves the issue, however this must either
reduce performance, cause memory leaks or other anomalies, so if anything this is a temporary
workaround:
static zend_always_inline void _zend_hash_del_el(HashTable *ht, uint32_t idx, Bucket *p)
{
Bucket *prev = NULL;
/*if (!(ht->u.flags & HASH_FLAG_PACKED)) {
uint32_t nIndex = p->h & ht->nTableMask;
uint32_t i = ht->arHash[nIndex];
if (i != idx) {
prev = ht->arData + i;
while (Z_NEXT(prev->val) != idx) {
i = Z_NEXT(prev->val);
prev = ht->arData + i;
}
}
}*/
_zend_hash_del_el_ex(ht, idx, p, prev);
}
Test script:
---------------
I am not able to identify exactly what code causes the segmentation fault so cannot provide a test
script at this current point in time, but the segmentation fault is 100% reproducible on my system.
Expected result:
----------------
No segmentation fault.
Actual result:
--------------
Program received signal SIGSEGV, Segmentation fault.
_zend_hash_del_el (p=0x7fffeff117b0, idx=1725, ht=0xf81890) at
/root/tmp/php-src/Zend/zend_hash.c:658
658 while (Z_NEXT(prev->val) != idx) {
(gdb) bt
#0 _zend_hash_del_el (p=0x7fffeff117b0, idx=1725, ht=0xf81890) at
/root/tmp/php-src/Zend/zend_hash.c:658
#1 zend_hash_apply_deleter (ht=ht@entry=0xf81890, idx=idx@entry=1725, p=p@entry=0x7fffeff117b0) at
/root/tmp/php-src/Zend/zend_hash.c:973
#2 0x000000000074b0a9 in zend_hash_reverse_apply (ht=0xf81890, apply_func=apply_func@entry=0x729ee0
<clean_non_persistent_function>) at /root/tmp/php-src/Zend/zend_hash.c:1133
#3 0x000000000072a6b8 in shutdown_executor () at /root/tmp/php-src/Zend/zend_execute_API.c:347
#4 0x000000000073ac17 in zend_deactivate () at /root/tmp/php-src/Zend/zend.c:883
#5 0x00000000006dface in php_request_shutdown (dummy=dummy@entry=0x0) at
/root/tmp/php-src/main/main.c:1859
#6 0x0000000000484214 in main (argc=2, argv=0x7fffffffe078) at
/root/tmp/php-src/sapi/cgi/cgi_main.c:2515
(gdb) print prev
$1 = (Bucket *) 0x801feff03ff0
(gdb) print prev->val
Cannot access memory at address 0x801feff04000
(gdb) print idx
$2 = 1725
The issue is apparently here:
658: while (Z_NEXT(prev->val) != idx) {
However, I am not sure if the fault lies in _zend_hash_del_el() itself or if _zend_hash_del_el() is
being called with incorrect arguments.
An identical segmentation fault occurs when calling this WordPress index.php script through apache2
with PHP as a SAPI module.
The master PHP branch was compiled with the following options:
'./configure' '--prefix=/root/tmp/usr' '--build=x86_64-pc-linux-gnu'
'--host=x86_64-pc-linux-gnu' '--mandir=/usr/share/man'
'--infodir=/usr/share/info' '--datadir=/usr/share' '--sysconfdir=/etc'
'--localstatedir=/var/lib' '--prefix=/usr/lib64/php7.0'
'--mandir=/usr/lib64/php7.0/man' '--infodir=/usr/lib64/php7.0/info'
'--libdir=/usr/lib64/php7.0/lib' '--with-libdir=lib64'
'--without-pear' '--disable-maintainer-zts' '--enable-bcmath'
'--with-bz2=/usr' '--enable-calendar' '--enable-ctype'
'--with-curl=/usr' '--enable-dom' '--without-enchant'
'--disable-exif' '--enable-fileinfo' '--enable-filter'
'--disable-ftp' '--with-gettext=/usr' '--without-gmp'
'--enable-hash' '--with-mhash=/usr' '--with-iconv'
'--enable-intl' '--enable-ipv6' '--enable-json'
'--without-kerberos' '--enable-libxml' '--with-libxml-dir=/usr'
'--enable-mbstring' '--with-mcrypt=/usr' '--without-mssql'
'--with-onig=/usr' '--with-openssl=/usr' '--with-openssl-dir=/usr'
'--disable-pcntl' '--enable-phar' '--enable-pd!
o' '--enable-opcache' '--without-pgsql' '--enable-posix'
'--with-pspell=/usr' '--without-recode' '--enable-simplexml'
'--disable-shmop' '--without-snmp' '--disable-soap'
'--enable-sockets' '--without-sqlite3' '--without-sybase-ct'
'--disable-sysvmsg' '--disable-sysvsem' '--disable-sysvshm'
'--without-fpm-systemd' '--without-tidy' '--enable-tokenizer'
'--disable-wddx' '--enable-xml' '--enable-xmlreader'
'--enable-xmlwriter' '--without-xmlrpc' '--without-xsl'
'--enable-zip' '--with-zlib=/usr' '--disable-debug'
'--enable-dba' '--without-cdb' '--with-db4=/usr'
'--disable-flatfile' '--with-gdbm=/usr' '--disable-inifile'
'--without-qdbm' '--with-freetype-dir=/usr' '--with-t1lib=/usr'
'--disable-gd-jis-conv' '--with-jpeg-dir=/usr' '--with-png-dir=/usr'
'--without-xpm-dir' '--without-vpx-dir' '--with-gd'
'--with-imap=/usr' '--with-imap-ssl=/usr' '--with-mysql=/usr'
'--with-mysqli=/usr/bin/mysql_config'
'--with-mysql-sock=/var/run/mysqld/mysqld.sock' '--without-pdo-dblib'
'--with-pd!
o-mysql=/usr' '--without-pdo-pgsql' '--without-pdo-sqlite' '--!
without-pdo-odbc' '--with-readline=/usr' '--without-libedit'
'--without-mm' '--with-pic' '--with-pcre-regex=/usr'
'--with-pcre-dir=/usr' '--with-config-file-path=/root/tmp/usr/etc'
'--disable-embed' '--enable-cli' '--enable-cgi'
'--enable-fpm' '--with-apxs2=/usr/sbin/apxs2'
'build_alias=x86_64-pc-linux-gnu' 'host_alias=x86_64-pc-linux-gnu'
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=68252&edit=1