Bug #68486 [NEW]: PHP SegFault zend_hash_find
| From: | wattwood at tcstire dot com | Date: | Mon, 24 Nov 2014 06:32:29 +0000 |
| Subject: | Bug #68486 [NEW]: PHP SegFault zend_hash_find | ||
| Groups: | php.bugs | ||
| Request: | Send a blank email to php-bugs+get-188770@lists.php.net to get a copy of this message | ||
From: wattwood at tcstire dot com
Operating system: Ubuntu 14.04.1 LTS
PHP version: 5.5.19
Package: Apache2 related
Bug Type: Bug
Bug description:PHP SegFault zend_hash_find
Description:
------------
PHP will randomly crash on zend_hash_find after
zend_set_compiled_filename. This is on Ubuntu 14.04.1 LTS.
The file is always the same for the crash. As you can see, this happens
before any PHP code is executed. It's not always on zend_hash_find.
At times, it's on zend_stack_push as well. Again, before any code
executes.
Here is the backtrace:
Program terminated with signal SIGSEGV, Segmentation fault.
#0 0x00007f7b1dcd4291 in zend_hash_find (ht=ht@entry=0x7f7b1e48ab50
<compiler_globals+272>, arKey=arKey@entry=0x7f7b23fc4388
"/var/lib/jenkins/workspace/TireCore/app/webroot/index.php",
nKeyLength=nKeyLength@entry=58, pData=pData@entry=0x7fffbede6c70) at
/build/buildd/php5-5.5.9+dfsg/Zend/zend_hash.c:924
924 p = ht->arBuckets[nIndex];
#0 0x00007f7b1dcd4291 in zend_hash_find (ht=ht@entry=0x7f7b1e48ab50
<compiler_globals+272>,
arKey=arKey@entry=0x7f7b23fc4388
"/var/lib/jenkins/workspace/TireCore/app/webroot/index.php",
nKeyLength=nKeyLength@entry=58, pData=pData@entry=0x7fffbede6c70)
at /build/buildd/php5-5.5.9+dfsg/Zend/zend_hash.c:924
#1 0x00007f7b1dca2a3c in zend_set_compiled_filename
(new_compiled_filename=0x7f7b23fc4388
"/var/lib/jenkins/workspace/TireCore/app/webroot/index.php")
at /build/buildd/php5-5.5.9+dfsg/Zend/zend_compile.c:254
#2 0x00007f7b1dc900ba in open_file_for_scanning
(file_handle=file_handle@entry=0x7fffbede70a0) at
Zend/zend_language_scanner.l:537
#3 0x00007f7b1dc902d3 in compile_file
(file_handle=file_handle@entry=0x7fffbede70a0, type=2) at
Zend/zend_language_scanner.l:574
#4 0x00007f7b1dcb5afa in dtrace_compile_file
(file_handle=0x7fffbede70a0, type=<optimized out>) at
/build/buildd/php5-5.5.9+dfsg/Zend/zend_dtrace.c:40
#5 0x00007f7b1db3ecb4 in phar_compile_file (file_handle=<optimized
out>, type=<optimized out>) at
/build/buildd/php5-5.5.9+dfsg/ext/phar/phar.c:3383
#6 0x00007f7b1dcc757f in zend_execute_scripts (type=type@entry=2,
retval=retval@entry=0x0, file_count=file_count@entry=1) at
/build/buildd/php5-5.5.9+dfsg/Zend/zend.c:1308
#7 0x00007f7b1dd774fd in php_handler (r=<optimized out>) at
/build/buildd/php5-5.5.9+dfsg/sapi/apache2handler/sapi_apache2.c:669
#8 0x00007f7b22463680 in ap_run_handler (r=0x7f7b2230f3a8) at
config.c:169
#9 0x00007f7b22463bc9 in ap_invoke_handler (r=r@entry=0x7f7b2230f3a8)
at config.c:439
#10 0x00007f7b22478c2c in ap_internal_redirect (new_uri=<optimized out>,
r=<optimized out>) at http_request.c:644
#11 0x00007f7b1ba4ccfc in handler_redirect (r=0x7f7b222fe0a0) at
mod_rewrite.c:5063
#12 0x00007f7b22463680 in ap_run_handler (r=0x7f7b222fe0a0) at
config.c:169
#13 0x00007f7b22463bc9 in ap_invoke_handler (r=r@entry=0x7f7b222fe0a0)
at config.c:439
#14 0x00007f7b2247916a in ap_process_async_request
(r=r@entry=0x7f7b222fe0a0) at http_request.c:317
#15 0x00007f7b22479444 in ap_process_request (r=r@entry=0x7f7b222fe0a0)
at http_request.c:363
#16 0x00007f7b22475f02 in ap_process_http_sync_connection
(c=0x7f7b2231b290) at http_core.c:190
#17 ap_process_http_connection (c=0x7f7b2231b290) at http_core.c:231
#18 0x00007f7b2246ccc0 in ap_run_process_connection (c=0x7f7b2231b290)
at connection.c:41
#19 0x00007f7b2246d0a8 in ap_process_connection
(c=c@entry=0x7f7b2231b290, csd=<optimized out>) at connection.c:202
#20 0x00007f7b1e697767 in child_main
(child_num_arg=child_num_arg@entry=0) at prefork.c:704
#21 0x00007f7b1e6979a6 in make_child (s=0x7f7b223cade0, slot=0) at
prefork.c:800
#22 0x00007f7b1e69860e in perform_idle_server_maintenance (p=<optimized
out>) at prefork.c:902
#23 prefork_run (_pconf=<optimized out>, plog=<optimized out>,
s=<optimized out>) at prefork.c:1090
#24 0x00007f7b2244a69e in ap_run_mpm (pconf=0x7f7b22400028,
plog=0x7f7b223ce028, s=0x7f7b223cade0) at mpm_common.c:96
#25 0x00007f7b22443e36 in main (argc=3, argv=0x7fffbede7848) at
main.c:777
Program terminated with signal SIGSEGV, Segmentation fault.
#0 0x00007f7b1dcc497d in zend_stack_push
(stack=stack@entry=0x7f7b1e48aca0 <compiler_globals+608>,
element=element@entry=0x7f7b1e48ac78 <compiler_globals+568>,
size=size@entry=40)
at /build/buildd/php5-5.5.9+dfsg/Zend/zend_stack.c:42
42 stack->elements[stack->top] = (void *) emalloc(size);
#0 0x00007f7b1dcc497d in zend_stack_push
(stack=stack@entry=0x7f7b1e48aca0 <compiler_globals+608>,
element=element@entry=0x7f7b1e48ac78 <compiler_globals+568>,
size=size@entry=40)
at /build/buildd/php5-5.5.9+dfsg/Zend/zend_stack.c:42
#1 0x00007f7b1dc9031e in compile_file
(file_handle=file_handle@entry=0x7fffbede70a0, type=2) at
Zend/zend_language_scanner.l:586
#2 0x00007f7b1dcb5afa in dtrace_compile_file
(file_handle=0x7fffbede70a0, type=<optimized out>) at
/build/buildd/php5-5.5.9+dfsg/Zend/zend_dtrace.c:40
#3 0x00007f7b1db3ecb4 in phar_compile_file (file_handle=<optimized
out>, type=<optimized out>) at
/build/buildd/php5-5.5.9+dfsg/ext/phar/phar.c:3383
#4 0x00007f7b1dcc757f in zend_execute_scripts (type=type@entry=2,
retval=retval@entry=0x0, file_count=file_count@entry=1) at
/build/buildd/php5-5.5.9+dfsg/Zend/zend.c:1308
#5 0x00007f7b1dd774fd in php_handler (r=<optimized out>) at
/build/buildd/php5-5.5.9+dfsg/sapi/apache2handler/sapi_apache2.c:669
#6 0x00007f7b22463680 in ap_run_handler (r=0x7f7b223053a8) at
config.c:169
#7 0x00007f7b22463bc9 in ap_invoke_handler (r=r@entry=0x7f7b223053a8)
at config.c:439
#8 0x00007f7b22478c2c in ap_internal_redirect (new_uri=<optimized out>,
r=<optimized out>) at http_request.c:644
#9 0x00007f7b1ba4ccfc in handler_redirect (r=0x7f7b223010a0) at
mod_rewrite.c:5063
#10 0x00007f7b22463680 in ap_run_handler (r=0x7f7b223010a0) at
config.c:169
#11 0x00007f7b22463bc9 in ap_invoke_handler (r=r@entry=0x7f7b223010a0)
at config.c:439
#12 0x00007f7b2247916a in ap_process_async_request
(r=r@entry=0x7f7b223010a0) at http_request.c:317
#13 0x00007f7b22479444 in ap_process_request (r=r@entry=0x7f7b223010a0)
at http_request.c:363
#14 0x00007f7b22475f02 in ap_process_http_sync_connection
(c=0x7f7b2231b290) at http_core.c:190
#15 ap_process_http_connection (c=0x7f7b2231b290) at http_core.c:231
#16 0x00007f7b2246ccc0 in ap_run_process_connection (c=0x7f7b2231b290)
at connection.c:41
#17 0x00007f7b2246d0a8 in ap_process_connection
(c=c@entry=0x7f7b2231b290, csd=<optimized out>) at connection.c:202
#18 0x00007f7b1e697767 in child_main
(child_num_arg=child_num_arg@entry=10) at prefork.c:704
#19 0x00007f7b1e6979a6 in make_child (s=0x7f7b223cade0, slot=10) at
prefork.c:800
#20 0x00007f7b1e69860e in perform_idle_server_maintenance (p=<optimized
out>) at prefork.c:902
#21 prefork_run (_pconf=<optimized out>, plog=<optimized out>,
s=<optimized out>) at prefork.c:1090
#22 0x00007f7b2244a69e in ap_run_mpm (pconf=0x7f7b22400028,
plog=0x7f7b223ce028, s=0x7f7b223cade0) at mpm_common.c:96
#23 0x00007f7b22443e36 in main (argc=3, argv=0x7fffbede7848) at
main.c:777
Test script:
---------------
Unavailable as no code executes prior to the crash.
--
Edit bug report at https://bugs.php.net/bug.php?id=68486&edit=1
--
Try a snapshot (PHP 5.4): https://bugs.php.net/fix.php?id=68486&r=trysnapshot54
Try a snapshot (PHP 5.5): https://bugs.php.net/fix.php?id=68486&r=trysnapshot55
Try a snapshot (trunk): https://bugs.php.net/fix.php?id=68486&r=trysnapshottrunk
Fixed in SVN: https://bugs.php.net/fix.php?id=68486&r=fixed
Fixed in release: https://bugs.php.net/fix.php?id=68486&r=alreadyfixed
Need backtrace: https://bugs.php.net/fix.php?id=68486&r=needtrace
Need Reproduce Script: https://bugs.php.net/fix.php?id=68486&r=needscript
Try newer version: https://bugs.php.net/fix.php?id=68486&r=oldversion
Not developer issue: https://bugs.php.net/fix.php?id=68486&r=support
Expected behavior: https://bugs.php.net/fix.php?id=68486&r=notwrong
Not enough info: https://bugs.php.net/fix.php?id=68486&r=notenoughinfo
Submitted twice: https://bugs.php.net/fix.php?id=68486&r=submittedtwice
register_globals: https://bugs.php.net/fix.php?id=68486&r=globals
PHP 4 support discontinued: https://bugs.php.net/fix.php?id=68486&r=php4
Daylight Savings: https://bugs.php.net/fix.php?id=68486&r=dst
IIS Stability: https://bugs.php.net/fix.php?id=68486&r=isapi
Install GNU Sed: https://bugs.php.net/fix.php?id=68486&r=gnused
Floating point limitations: https://bugs.php.net/fix.php?id=68486&r=float
No Zend Extensions: https://bugs.php.net/fix.php?id=68486&r=nozend
MySQL Configuration Error: https://bugs.php.net/fix.php?id=68486&r=mysqlcfg