Bug #66675 [Com]: sometimes segfault while processing .js as .php

From: Date: Wed, 04 Mar 2015 16:34:59 +0000
Subject: Bug #66675 [Com]: sometimes segfault while processing .js as .php
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-191147@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=66675&edit=1 ID: 66675 Comment by: marting at skillset dot co dot uk Reported by: phpreq at byom dot de Summary: sometimes segfault while processing .js as .php Status: No Feedback Type: Bug Package: *General Issues Operating System: Debian 7.2 x64 PHP Version: 5.5.9 Block user comment: N Private report: N New Comment: We are also seeing the same issue. You have stated that there was "No Feedback", despite other people confirming the issue. What feedback do you require to reopen and address the issue? For reference, it is happening on our Ubuntu 14.04 LTS with PHP 5.5.9, Apache 2.4.7. Previous Comments: ------------------------------------------------------------------------ [2014-12-30 10:42:24] php-bugs at lists dot php dot net No feedback was provided. The bug is being suspended because we assume that you are no longer experiencing the problem. If this is not the case and you are able to provide the information that was requested earlier, please do so and change the status of the bug back to "Re-Opened". Thank you. ------------------------------------------------------------------------ [2014-10-02 23:28:07] michael at alphageek dot com dot au I have also experienced this. Here's my backtrace: #0 0x00007f034cd0996d in zend_stack_push (stack=stack@entry=0x7f034d4cfca0 <compiler_globals+608>, element=element@entry=0x7f034d4cfc78 <compiler_globals+568>, size=size@entry=40) at /build/buildd/php5-5.5.9+dfsg/Zend/zend_stack.c:42 No locals. #1 0x00007f034ccd530e in compile_file (file_handle=file_handle@entry=0x7fff94794c10, type=2) at Zend/zend_language_scanner.l:586 original_lex_state = {yy_leng = 0, yy_start = 0x0, yy_text = 0x0, yy_cursor = 0x0, yy_marker = 0x0, yy_limit = 0x0, yy_state = 0, state_stack = {top = 0, max = 0, elements = 0x0}, heredoc_label_stack = {top = 0, max = 0, elements = 0x0, top_element = 0x0, persistent = 0 '\000'}, in = 0x0, lineno = 0, filename = 0x0, script_org = 0x0, script_org_size = 0, script_filtered = 0x0, script_filtered_size = 0, input_filter = 0x0, output_filter = 0x0, script_encoding = 0x0} op_array = 0x7f0350d40040 original_active_op_array = 0x0 retval = 0x7f0350d40040 compiler_result = <optimized out> compilation_successful = 0 '\000' retval_znode = {op_type = 1, u = {op = {constant = 1, var = 1, num = 1, hash = 1, opline_num = 1, jmp_addr = 0x1, zv = 0x1, literal = 0x1, ptr = 0x1}, constant = {value = {lval = 1, dval = 4.9406564584124654e-324, str = { val = 0x1 <error: Cannot access memory at address 0x1>, len = 1355599370}, ht = 0x1, obj = {handle = 1, handlers = 0x7f0350ccce0a}}, refcount__gc = 1, type = 1 '\001', is_ref__gc = 0 '\000'}, op_array = 0x1}, EA = 1352782496} original_in_compilation = 0 '\000' #2 0x00007f034ccfaaea in dtrace_compile_file (file_handle=0x7fff94794c10, type=<optimized out>) at /build/buildd/php5-5.5.9+dfsg/Zend/zend_dtrace.c:40 res = 0x7f0350d41218 #3 0x00007f034cb83cb4 in phar_compile_file (file_handle=<optimized out>, type=<optimized out>) at /build/buildd/php5-5.5.9+dfsg/ext/phar/phar.c:3383 __orig_bailout = 0x7fff94794c90 __bailout = {{__jmpbuf = {139652217134240, 1560366938000916389, 140735684365136, 140735684365328, 139652158519872, 0, -1560319682279440475, -1467874381389299803}, __mask_was_saved = 0, __saved_mask = {__val = {139652217126952, 0, 0, 139652217132542, 139652217128344, 139652217127072, 9, 139652217128728, 139652209727463, 139652219264008, 206158430232, 140735684365152, 140735684364960, 139652217228296, 140735684365056, 80}}}} res = <optimized out> name = 0x0 failed = 0 phar = 0x7f0350cb4028 #4 0x00007f034cd0c56f in zend_execute_scripts (type=type@entry=2, retval=retval@entry=0x0, file_count=file_count@entry=1) at /build/buildd/php5-5.5.9+dfsg/Zend/zend.c:1308 files = {{gp_offset = 32, fp_offset = 32515, overflow_arg_area = 0x7fff94794be0, reg_save_area = 0x7fff94794b70}} i = 0 file_handle = 0x7fff94794c10 orig_op_array = 0x0 orig_retval_ptr_ptr = 0x0 orig_interactive = 0 #5 0x00007f034cdbc4ed in php_handler (r=<optimized out>) at /build/buildd/php5-5.5.9+dfsg/sapi/apache2handler/sapi_apache2.c:669 zfd = {type = ZEND_HANDLE_MAPPED, filename = 0x7f0350cb5ca0 "/var/www/html/site_details_removed/js/stumble.js.php", opened_path = 0x7f0350d401a8 "/var/www/html/site_details_removed/js/stumble.js.php", handle = {fd = 1356071640, fp = 0x7f0350d402d8, stream = {handle = 0x7f0350d402d8, isatty = 0, mmap = {len = 309, pos = 0, map = 0x0, buf = 0x7f0350cb8000 <error: Cannot access memory at address 0x7f0350cb8000>, old_handle = 0x0, old_closer = 0x0}, reader = 0x7f034ccc24d0 <_php_stream_read>, fsizer = 0x7f034cca8cd0 <php_zend_stream_fsizer>, closer = 0x7f034cca8cb0 <php_zend_stream_mmap_closer>}}, free_filename = 0 '\000'} __orig_bailout = 0x0 __bailout = {{__jmpbuf = {139652217127072, 1560366938000654245, 139652217127072, 139652221501312, 0, 139652217270928, -1560319682222817371, -1467873582333755483}, __mask_was_saved = 0, __saved_mask = {__val = {139652218377176, 139652218107936, 139652217229512, 1, 139652218107936, 139652217229520, 139652217270432, 139652221501312, 0, 139652217270928, 139652164910243, 139652217134314, 2, 139652217229520, 139652217127072, 139652217988304}}}} ctx = 0x7f0350cbced8 conf = <optimized out> brigade = 0x7f0350cb6620 bucket = <optimized out> rv = <optimized out> parent_req = 0x7f0350cb90a0 #6 0x00007f0350e9b680 in ap_run_handler (r=0x7f0350cb40a0) at config.c:169 pHook = 0x7f0350d864f8 n = 2 rv = 1356075544 #7 0x00007f0350e9bbc9 in ap_invoke_handler (r=r@entry=0x7f0350cb40a0) at config.c:439 handler = <optimized out> p = <optimized out> result = <optimized out> old_handler = 0x7f0350d98828 "application/x-httpd-php" ignore = <optimized out> #8 0x00007f0350eb116a in ap_process_async_request (r=0x7f0350cb40a0) at http_request.c:317 access_status = 0 #9 0x00007f0350eb1444 in ap_process_request (r=r@entry=0x7f0350cb40a0) at http_request.c:363 bb = <optimized out> b = <optimized out> c = 0x7f0350cd7290 rv = <optimized out> #10 0x00007f0350eadf02 in ap_process_http_sync_connection (c=0x7f0350cd7290) at http_core.c:190 r = 0x7f0350cb40a0 cs = 0x0 csd = 0x7f0350cd70a0 mpm_state = 1 #11 ap_process_http_connection (c=0x7f0350cd7290) at http_core.c:231 No locals. #12 0x00007f0350ea4cc0 in ap_run_process_connection (c=0x7f0350cd7290) at connection.c:41 pHook = 0x7f0350d86a40 n = 0 rv = 1356075544 #13 0x00007f0350ea50a8 in ap_process_connection (c=c@entry=0x7f0350cd7290, csd=<optimized out>) at connection.c:202 rc = <optimized out> #14 0x00007f034d6dc767 in child_main (child_num_arg=child_num_arg@entry=30) at prefork.c:704 current_conn = 0x7f0350cd7290 csd = 0x7f0350cd70a0 thd = 0x7f0350cd90a0 osthd = 139652218701696 ptrans = 0x7f0350cd7028 allocator = 0x7f035186d4b0 status = <optimized out> i = <optimized out> lr = <optimized out> pollset = 0x7f0350cd9158 sbh = 0x7f0350cd9150 bucket_alloc = 0x7f0350cd3028 last_poll_idx = 0 lockfile = <optimized out> #15 0x00007f034d6dc9a6 in make_child (s=0x7f0350e0ade0, slot=30) at prefork.c:800 pid = 0 #16 0x00007f034d6dd60e in perform_idle_server_maintenance (p=<optimized out>) at prefork.c:902 i = <optimized out> idle_count = <optimized out> ws = <optimized out> free_length = <optimized out> free_slots = {28, 30, 34, 35, 38, 39, 40, 41, 42, 43, 44, 45, 46, 47, 48, 49, 50, 51, 52, 53, 54, 55, 56, 57, 58, 59, 60, 61, 62, 63, 64, 65} last_non_dead = <optimized out> total_non_dead = <optimized out> #17 prefork_run (_pconf=<optimized out>, plog=<optimized out>, s=<optimized out>) at prefork.c:1090 status = 0 pid = {pid = -1, in = 0x7f0350ebc048, out = 0xa, err = 0x7f035059aff6} child_slot = <optimized out> exitwhy = APR_PROC_EXIT processed_status = <optimized out> index = <optimized out> remaining_children_to_start = 0 rv = <optimized out> #18 0x00007f0350e8269e in ap_run_mpm (pconf=0x7f0350e32028, plog=0x7f0350e06028, s=0x7f0350e0ade0) at mpm_common.c:96 pHook = 0x7f0350d86da8 n = 0 rv = 1356075544 #19 0x00007f0350e7be36 in main (argc=3, argv=0x7fff94795318) at main.c:777 c = 0 '\000' showcompile = 0 showdirectives = 0 confname = 0x7f0350ebb607 "apache2.conf" def_server_root = 0x7f0350ebb5fa "/etc/apache2" temp_error_log = 0x0 error = <optimized out> process = 0x7f0350e3a118 pconf = 0x7f0350e32028 plog = 0x7f0350e06028 ptemp = 0x7f0350e08028 pcommands = 0x7f0350e10028 opt = 0x7f0350e10118 rv = <optimized out> mod = 0x7f03510dd160 <ap_prelinked_modules+64> opt_arg = 0x7f0350e3a028 "(\340\343P\003\177" signal_server = <optimized out> Additionally, here's the script that is causing the error: <?php header('Content-type: text/javascript'); ?> function bfb_doStumbleShare(url) { window.open( 'http://www.stumbleupon.com/submit?'+ 'url='+url, 'sharer', 'top=' + (screen.height/2 - 160).toString() + ',left=' + (screen.width/2 - 290).toString() + ',toolbar=0,status=0,width=580,height=325' ); } ------------------------------------------------------------------------ [2014-02-08 20:40:38] phpreq at byom dot de I am unable to provide a script as a real php-script is not involved here. Associate .js-files in Apache with php as seen above and download again and again a stock .js-script of your choice, e.g. jquery.js or jquery-migrate.min.js, but it needs some thousand requests until the segfault is hit. I haven't hit a segfault with a script having a .php-file extension, maybe it is something trivial like a file-extension check fixed to 3 digits or so summing up after some thousand hits... ------------------------------------------------------------------------ [2014-02-08 20:29:57] pajoye@php.net Thank you for this bug report. To properly diagnose the problem, we need a short but complete example script to be able to reproduce this bug ourselves. A proper reproducing script starts with <?php and ends with ?>, is max. 10-20 lines long and does not require any external resources such as databases, etc. If the script requires a database to demonstrate the issue, please make sure it creates all necessary tables, stored procedures etc. Please avoid embedding huge scripts into the report. ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=66675 -- Edit this bug report at https://bugs.php.net/bug.php?id=66675&edit=1

« previous php.bugs (#191147) next »