Bug #68486 [Com]: PHP SegFault zend_hash_find

From: Date: Fri, 23 Jan 2015 13:42:06 +0000
Subject: Bug #68486 [Com]: PHP SegFault zend_hash_find
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-190161@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=68486&edit=1

 ID:                 68486
 Comment by:         biggi at stefna dot is
 Reported by:        wattwood at tcstire dot com
 Summary:            PHP SegFault zend_hash_find
 Status:             Open
 Type:               Bug
 Package:            Apache2 related
 Operating System:   Ubuntu 14.04.1 LTS
 PHP Version:        5.5.19
 Block user comment: N
 Private report:     N

 New Comment:

I think this is related to HTTP pipelining and Apache version 2.4

To test it, do:
echo -e "GET /test.php HTTP/1.1\nHost: localhost\n\nGET /test.php HTTP/1.1\nHost:
localhost\n\n"|nc localhost 80

It does not matter what is in test.php, it can be empty.
Note that it does not always segfault. But if test.php outputs something, only the first output is
delivered, empty on the second one.

I've tested this on php versions 5.4.36, 5.5.1, 5.5.20 and 5.6.4 with version 2.2.29, 2.4.2 and
2.4.10 of apache.
Tested with clean compile of both apache and php (on ubuntu 14.04).
php configure: './configure' '--prefix=/tmp/testing/php5'
'--with-apxs2=/tmp/testing/apache2/bin/apxs' '--disable-all'

Segfaults for all tested version of php for apache 2.4, but never for 2.2.29. 
Also, 2.2.29 outputs all pipelined requests.


Now, I did some digging and I guess the problem is in php_handler function in sapi_apache2.c:
https://github.com/php/php-src/blob/PHP-5.5.20/sapi/apache2handler/sapi_apache2.c#L536

The server_context is reused (parent_req is found), which ends up with a corrupt zend_file_handle
zfd (in line 669).
Note that php_server_context_cleanup is never called.
I assume the server_context should NOT be used again for these kind of requests.


Hopefully this helps.
I am getting a lot of segfaults these days. Seems that HTTP pipelining is enabled for safari on iOS
devices.
I am also seeing some "PHP Fatal Error Allowed memory size of 268435456 bytes exhausted (tried
to allocate 22455254144 bytes)". This definitely relates to this problem, and probably
something that can happen if there is no segfault.


Previous Comments:
------------------------------------------------------------------------
[2014-12-19 08:08:56] rajan dot nagarajan at innogames dot com

I have the same segfault,
PHP 5.5.19 Os Debian

GNU gdb (GDB) 7.4.1-debian
Copyright (C) 2012 Free Software Foundation, Inc.
License GPLv3+: GNU GPL version 3 or later <http://gnu.org/licenses/gpl.html>
This is free software: you are free to change and redistribute it.
There is NO WARRANTY, to the extent permitted by law.  Type "show copying"
and "show warranty" for details.
This GDB was configured as "x86_64-linux-gnu".
For bug reporting instructions, please see:
<http://www.gnu.org/software/gdb/bugs/>...
Reading symbols from /usr/bin/php...Reading symbols from /usr/lib/debug/usr/bin/php5...done.
done.
[New LWP 26995]

warning: Can't read pathname for load map: Input/output error.
[Thread debugging using libthread_db enabled]
Using host libthread_db library "/lib/x86_64-linux-gnu/libthread_db.so.1".
Core was generated by `php test.php'.
Program terminated with signal 11, Segmentation fault.
#0  0x00000000006dfe18 in zend_hash_quick_find (ht=0x7fe72b0396b0, arKey=arKey@entry=0x7fe734bdeb00
"isdirty", nKeyLength=nKeyLength@entry=8, h=7572512272371981, pData=0x7fff6c1bb7e8) at
/usr/src/php5.5/source/dotdeb-php5/Zend/zend_hash.c:950
950	/usr/src/php5.5/source/dotdeb-php5/Zend/zend_hash.c: No such file or directory.
(gdb) bt
#0  0x00000000006dfe18 in zend_hash_quick_find (ht=0x7fe72b0396b0, arKey=arKey@entry=0x7fe734bdeb00
"isdirty", nKeyLength=nKeyLength@entry=8, h=7572512272371981, pData=0x7fff6c1bb7e8) at
/usr/src/php5.5/source/dotdeb-php5/Zend/zend_hash.c:950
#1  0x00000000006f88f9 in zend_std_get_method (object_ptr=<optimized out>,
method_name=0x7fe734bdeab0 "isDirty", method_len=7, key=0x7fe72afefc70) at
/usr/src/php5.5/source/dotdeb-php5/Zend/zend_object_handlers.c:1027
#2  0x0000000000708511 in ZEND_INIT_METHOD_CALL_SPEC_VAR_CONST_HANDLER (execute_data=0x7fe734c5e530)
at /usr/src/php5.5/source/dotdeb-php5/Zend/zend_vm_execute.h:15346
#3  0x0000000000740308 in execute_ex (execute_data=0x7fe734c5e530) at
/usr/src/php5.5/source/dotdeb-php5/Zend/zend_vm_execute.h:363
#4  0x00000000006c0add in dtrace_execute_ex (execute_data=<optimized out>) at
/usr/src/php5.5/source/dotdeb-php5/Zend/zend_dtrace.c:73
#5  0x0000000000780866 in zend_do_fcall_common_helper_SPEC (execute_data=0x7fe734c5e128) at
/usr/src/php5.5/source/dotdeb-php5/Zend/zend_vm_execute.h:584
#6  0x0000000000740308 in execute_ex (execute_data=0x7fe734c5e128) at
/usr/src/php5.5/source/dotdeb-php5/Zend/zend_vm_execute.h:363
#7  0x00000000006c0add in dtrace_execute_ex (execute_data=<optimized out>) at
/usr/src/php5.5/source/dotdeb-php5/Zend/zend_dtrace.c:73
#8  0x00000000006c2df1 in zend_call_function (fci=fci@entry=0x7fff6c1bbc70, fci_cache=0x0,
fci_cache@entry=0x7fff6c1bbc40) at /usr/src/php5.5/source/dotdeb-php5/Zend/zend_execute_API.c:937
#9  0x00000000006e86c5 in zend_call_method (object_pp=object_pp@entry=0x7fff6c1bbd28,
obj_ce=<optimized out>, fn_proxy=fn_proxy@entry=0x7fff6c1bbd20,
function_name=function_name@entry=0xb35eb0 "__destruct",
function_name_len=function_name_len@entry=10, 
    retval_ptr_ptr=retval_ptr_ptr@entry=0x0, param_count=param_count@entry=0, arg1=arg1@entry=0x0,
arg2=arg2@entry=0x0) at /usr/src/php5.5/source/dotdeb-php5/Zend/zend_interfaces.c:97
#10 0x00000000006f3b12 in zend_objects_destroy_object (object=0x7fe72af714c8, handle=<optimized
out>) at /usr/src/php5.5/source/dotdeb-php5/Zend/zend_objects.c:123
#11 0x00000000006f9b50 in zend_objects_store_del_ref_by_handle_ex (handle=40, handlers=<optimized
out>) at /usr/src/php5.5/source/dotdeb-php5/Zend/zend_objects_API.c:212
#12 0x00000000006f9b93 in zend_objects_store_del_ref (zobject=0x2a2d188) at
/usr/src/php5.5/source/dotdeb-php5/Zend/zend_objects_API.c:178
#13 0x00000000006c0e20 in _zval_dtor (zvalue=0x2a2d188) at
/usr/src/php5.5/source/dotdeb-php5/Zend/zend_variables.h:35
#14 i_zval_ptr_dtor (zval_ptr=0x2a2d188) at
/usr/src/php5.5/source/dotdeb-php5/Zend/zend_execute.h:81
#15 _zval_ptr_dtor (zval_ptr=<optimized out>) at
/usr/src/php5.5/source/dotdeb-php5/Zend/zend_execute_API.c:426
#16 0x00000000006f3c07 in zend_object_std_dtor (object=0x2c76de8) at
/usr/src/php5.5/source/dotdeb-php5/Zend/zend_objects.c:54
#17 0x00000000006f3c39 in zend_objects_free_object_storage (object=0x2c76de8) at
/usr/src/php5.5/source/dotdeb-php5/Zend/zend_objects.c:137
#18 0x00000000006f96c6 in zend_objects_store_free_object_storage (objects=objects@entry=0xea65e0) at
/usr/src/php5.5/source/dotdeb-php5/Zend/zend_objects_API.c:97
#19 0x00000000006c1473 in shutdown_executor () at
/usr/src/php5.5/source/dotdeb-php5/Zend/zend_execute_API.c:293
#20 0x00000000006d0e85 in zend_deactivate () at /usr/src/php5.5/source/dotdeb-php5/Zend/zend.c:949
#21 0x000000000066f13a in php_request_shutdown (dummy=dummy@entry=0x0) at
/usr/src/php5.5/source/dotdeb-php5/main/main.c:1808
#22 0x0000000000782b88 in do_cli (argc=2, argv=0x24af1b0) at
/usr/src/php5.5/source/dotdeb-php5/sapi/cli/php_cli.c:1177
#23 0x000000000043236f in main (argc=2, argv=0x24af1b0) at
/usr/src/php5.5/source/dotdeb-php5/sapi/cli/php_cli.c:1378

------------------------------------------------------------------------
[2014-11-24 06:32:26] wattwood at tcstire dot com

Description:
------------
PHP will randomly crash on zend_hash_find after zend_set_compiled_filename.  This is on Ubuntu
14.04.1 LTS.

The file is always the same for the crash.  As you can see, this happens before any PHP code is
executed.   It's not always on zend_hash_find.  At times, it's on zend_stack_push as well.
 Again, before any code executes.

Here is the backtrace:

Program terminated with signal SIGSEGV, Segmentation fault.
#0  0x00007f7b1dcd4291 in zend_hash_find (ht=ht@entry=0x7f7b1e48ab50 <compiler_globals+272>,
arKey=arKey@entry=0x7f7b23fc4388
"/var/lib/jenkins/workspace/TireCore/app/webroot/index.php", 
    nKeyLength=nKeyLength@entry=58, pData=pData@entry=0x7fffbede6c70) at
/build/buildd/php5-5.5.9+dfsg/Zend/zend_hash.c:924
924		p = ht->arBuckets[nIndex];

#0  0x00007f7b1dcd4291 in zend_hash_find (ht=ht@entry=0x7f7b1e48ab50 <compiler_globals+272>, 
    arKey=arKey@entry=0x7f7b23fc4388
"/var/lib/jenkins/workspace/TireCore/app/webroot/index.php",
nKeyLength=nKeyLength@entry=58, pData=pData@entry=0x7fffbede6c70)
    at /build/buildd/php5-5.5.9+dfsg/Zend/zend_hash.c:924
#1  0x00007f7b1dca2a3c in zend_set_compiled_filename (new_compiled_filename=0x7f7b23fc4388
"/var/lib/jenkins/workspace/TireCore/app/webroot/index.php")
    at /build/buildd/php5-5.5.9+dfsg/Zend/zend_compile.c:254
#2  0x00007f7b1dc900ba in open_file_for_scanning (file_handle=file_handle@entry=0x7fffbede70a0) at
Zend/zend_language_scanner.l:537
#3  0x00007f7b1dc902d3 in compile_file (file_handle=file_handle@entry=0x7fffbede70a0, type=2) at
Zend/zend_language_scanner.l:574
#4  0x00007f7b1dcb5afa in dtrace_compile_file (file_handle=0x7fffbede70a0, type=<optimized
out>) at /build/buildd/php5-5.5.9+dfsg/Zend/zend_dtrace.c:40
#5  0x00007f7b1db3ecb4 in phar_compile_file (file_handle=<optimized out>, type=<optimized
out>) at /build/buildd/php5-5.5.9+dfsg/ext/phar/phar.c:3383
#6  0x00007f7b1dcc757f in zend_execute_scripts (type=type@entry=2, retval=retval@entry=0x0,
file_count=file_count@entry=1) at /build/buildd/php5-5.5.9+dfsg/Zend/zend.c:1308
#7  0x00007f7b1dd774fd in php_handler (r=<optimized out>) at
/build/buildd/php5-5.5.9+dfsg/sapi/apache2handler/sapi_apache2.c:669
#8  0x00007f7b22463680 in ap_run_handler (r=0x7f7b2230f3a8) at config.c:169
#9  0x00007f7b22463bc9 in ap_invoke_handler (r=r@entry=0x7f7b2230f3a8) at config.c:439
#10 0x00007f7b22478c2c in ap_internal_redirect (new_uri=<optimized out>, r=<optimized
out>) at http_request.c:644
#11 0x00007f7b1ba4ccfc in handler_redirect (r=0x7f7b222fe0a0) at mod_rewrite.c:5063
#12 0x00007f7b22463680 in ap_run_handler (r=0x7f7b222fe0a0) at config.c:169
#13 0x00007f7b22463bc9 in ap_invoke_handler (r=r@entry=0x7f7b222fe0a0) at config.c:439
#14 0x00007f7b2247916a in ap_process_async_request (r=r@entry=0x7f7b222fe0a0) at http_request.c:317
#15 0x00007f7b22479444 in ap_process_request (r=r@entry=0x7f7b222fe0a0) at http_request.c:363
#16 0x00007f7b22475f02 in ap_process_http_sync_connection (c=0x7f7b2231b290) at http_core.c:190
#17 ap_process_http_connection (c=0x7f7b2231b290) at http_core.c:231
#18 0x00007f7b2246ccc0 in ap_run_process_connection (c=0x7f7b2231b290) at connection.c:41
#19 0x00007f7b2246d0a8 in ap_process_connection (c=c@entry=0x7f7b2231b290, csd=<optimized
out>) at connection.c:202
#20 0x00007f7b1e697767 in child_main (child_num_arg=child_num_arg@entry=0) at prefork.c:704
#21 0x00007f7b1e6979a6 in make_child (s=0x7f7b223cade0, slot=0) at prefork.c:800
#22 0x00007f7b1e69860e in perform_idle_server_maintenance (p=<optimized out>) at prefork.c:902
#23 prefork_run (_pconf=<optimized out>, plog=<optimized out>, s=<optimized out>)
at prefork.c:1090
#24 0x00007f7b2244a69e in ap_run_mpm (pconf=0x7f7b22400028, plog=0x7f7b223ce028, s=0x7f7b223cade0)
at mpm_common.c:96
#25 0x00007f7b22443e36 in main (argc=3, argv=0x7fffbede7848) at main.c:777




Program terminated with signal SIGSEGV, Segmentation fault.
#0  0x00007f7b1dcc497d in zend_stack_push (stack=stack@entry=0x7f7b1e48aca0
<compiler_globals+608>, element=element@entry=0x7f7b1e48ac78 <compiler_globals+568>,
size=size@entry=40)
    at /build/buildd/php5-5.5.9+dfsg/Zend/zend_stack.c:42
42		stack->elements[stack->top] = (void *) emalloc(size);

#0  0x00007f7b1dcc497d in zend_stack_push (stack=stack@entry=0x7f7b1e48aca0
<compiler_globals+608>, element=element@entry=0x7f7b1e48ac78 <compiler_globals+568>,
size=size@entry=40)
    at /build/buildd/php5-5.5.9+dfsg/Zend/zend_stack.c:42
#1  0x00007f7b1dc9031e in compile_file (file_handle=file_handle@entry=0x7fffbede70a0, type=2) at
Zend/zend_language_scanner.l:586
#2  0x00007f7b1dcb5afa in dtrace_compile_file (file_handle=0x7fffbede70a0, type=<optimized
out>) at /build/buildd/php5-5.5.9+dfsg/Zend/zend_dtrace.c:40
#3  0x00007f7b1db3ecb4 in phar_compile_file (file_handle=<optimized out>, type=<optimized
out>) at /build/buildd/php5-5.5.9+dfsg/ext/phar/phar.c:3383
#4  0x00007f7b1dcc757f in zend_execute_scripts (type=type@entry=2, retval=retval@entry=0x0,
file_count=file_count@entry=1) at /build/buildd/php5-5.5.9+dfsg/Zend/zend.c:1308
#5  0x00007f7b1dd774fd in php_handler (r=<optimized out>) at
/build/buildd/php5-5.5.9+dfsg/sapi/apache2handler/sapi_apache2.c:669
#6  0x00007f7b22463680 in ap_run_handler (r=0x7f7b223053a8) at config.c:169
#7  0x00007f7b22463bc9 in ap_invoke_handler (r=r@entry=0x7f7b223053a8) at config.c:439
#8  0x00007f7b22478c2c in ap_internal_redirect (new_uri=<optimized out>, r=<optimized
out>) at http_request.c:644
#9  0x00007f7b1ba4ccfc in handler_redirect (r=0x7f7b223010a0) at mod_rewrite.c:5063
#10 0x00007f7b22463680 in ap_run_handler (r=0x7f7b223010a0) at config.c:169
#11 0x00007f7b22463bc9 in ap_invoke_handler (r=r@entry=0x7f7b223010a0) at config.c:439
#12 0x00007f7b2247916a in ap_process_async_request (r=r@entry=0x7f7b223010a0) at http_request.c:317
#13 0x00007f7b22479444 in ap_process_request (r=r@entry=0x7f7b223010a0) at http_request.c:363
#14 0x00007f7b22475f02 in ap_process_http_sync_connection (c=0x7f7b2231b290) at http_core.c:190
#15 ap_process_http_connection (c=0x7f7b2231b290) at http_core.c:231
#16 0x00007f7b2246ccc0 in ap_run_process_connection (c=0x7f7b2231b290) at connection.c:41
#17 0x00007f7b2246d0a8 in ap_process_connection (c=c@entry=0x7f7b2231b290, csd=<optimized
out>) at connection.c:202
#18 0x00007f7b1e697767 in child_main (child_num_arg=child_num_arg@entry=10) at prefork.c:704
#19 0x00007f7b1e6979a6 in make_child (s=0x7f7b223cade0, slot=10) at prefork.c:800
#20 0x00007f7b1e69860e in perform_idle_server_maintenance (p=<optimized out>) at prefork.c:902
#21 prefork_run (_pconf=<optimized out>, plog=<optimized out>, s=<optimized out>)
at prefork.c:1090
#22 0x00007f7b2244a69e in ap_run_mpm (pconf=0x7f7b22400028, plog=0x7f7b223ce028, s=0x7f7b223cade0)
at mpm_common.c:96
#23 0x00007f7b22443e36 in main (argc=3, argv=0x7fffbede7848) at main.c:777





Test script:
---------------
Unavailable as no code executes prior to the crash. 



------------------------------------------------------------------------



--
Edit this bug report at https://bugs.php.net/bug.php?id=68486&edit=1


Thread (26 messages)

« previous php.bugs (#190161) next »