Bug #69547 [Opn]: php-fpm segfault (reproducible)

From: Date: Wed, 29 Apr 2015 15:44:30 +0000
Subject: Bug #69547 [Opn]: php-fpm segfault (reproducible)
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-192404@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=69547&edit=1

 ID:                 69547
 User updated by:    waldner at katamail dot com
 Reported by:        waldner at katamail dot com
 Summary:            php-fpm segfault (reproducible)
 Status:             Open
 Type:               Bug
 Package:            FPM related
 Operating System:   Debian wheezy
 PHP Version:        5.6.8
 Block user comment: N
 Private report:     N

 New Comment:

/etc/php5/fpm/php-fpm.conf:
[global]
pid = /run/php5-fpm.pid
error_log = /var/log/php5-fpm.log 
include=/etc/php5/fpm/pool.d/*.conf

/etc/php5/fpm/pool.d/www.conf:

[www]
user = www-data
group = www-data
listen = /var/run/php5-fpm.sock
listen.owner = www-data
listen.group = www-data
 
pm = static
pm.max_children = 1
pm.start_servers = 1
pm.min_spare_servers = 1
pm.max_spare_servers = 1

chdir = /


Previous Comments:
------------------------------------------------------------------------
[2015-04-29 15:42:22] waldner at katamail dot com

/etc/php5/fpm/php.ini:

[PHP]
engine = On
zend.ze1_compatibility_mode = Off
zend.enable_gc = On
short_open_tag = On
asp_tags = Off
precision    =  14
y2k_compliance = On
output_buffering = 4096
zlib.output_compression = Off
implicit_flush = Off
unserialize_callback_func=
serialize_precision = 17
allow_call_time_pass_reference = Off
safe_mode = Off
safe_mode_gid = Off
safe_mode_include_dir =
safe_mode_exec_dir =
safe_mode_allowed_env_vars = PHP_
safe_mode_protected_env_vars = LD_LIBRARY_PATH
disable_functions =
disable_classes =
expose_php = Off
max_execution_time = 90
max_input_time = 90
; workaround for HOT extranet monster-input

max_input_vars = 4000

; workaround end
; Another workaround for session encryption

;
memory_limit = 128M
error_reporting = E_ALL
;& ~E_NOTICE
display_errors = On
display_startup_errors = Off
log_errors = On
log_errors_max_len = 1024
ignore_repeated_errors = Off
ignore_repeated_source = Off
report_memleaks = On
track_errors = Off
error_log = "/dev/null"
;error_log = "/tmp/eee"
variables_order = "GPCS"
register_globals = Off
register_argc_argv = Off
auto_globals_jit = On
post_max_size = 10M
magic_quotes_runtime = Off
magic_quotes_sybase = Off
auto_prepend_file = ""
auto_append_file =
default_mimetype = "text/html"
default_charset = "iso-8859-1"
include_path = ".:/usr/share/php"
doc_root =
user_dir =
enable_dl = On
file_uploads = On
upload_max_filesize = 2M
allow_url_fopen = On
allow_url_include = Off
default_socket_timeout = 90
browscap = /etc/browscap.ini



[mail function]
SMTP = localhost
smtp_port = 25

[Date]
date.timezone = "Europe/Madrid"

[Syslog]
define_syslog_variables  = Off

[SQL]
sql.safe_mode = Off

[MySQL]
mysql.allow_persistent = On
mysql.max_persistent = -1
mysql.max_links = -1
mysql.default_port =
mysql.default_socket = 
mysql.default_host =
mysql.default_user =
mysql.default_password =
mysql.connect_timeout = 60
mysql.trace_mode = Off

[MySQLi]
mysqli.max_links = -1
mysqli.default_port = 3306
mysqli.default_socket = 
mysqli.default_host =
mysqli.default_user =
mysqli.default_pw =
mysqli.reconnect = Off

[bcmath]
bcmath.scale = 0

[Session]
session.save_handler = files

session.use_cookies = 1
session.use_only_cookies = 1
session.name = PHPSESSID
session.auto_start = 0
session.cookie_lifetime = 0
session.cookie_path = /
session.cookie_domain =
session.cookie_httponly = 1
session.serialize_handler = php
session.gc_probability = 1
session.gc_divisor     = 10000
session.gc_maxlifetime = 1800
session.bug_compat_42 = 0
session.bug_compat_warn = 1
session.referer_check =
session.entropy_length = 0
session.entropy_file =
session.cache_limiter = nocache
session.cache_expire = 180
session.use_trans_sid = 0
session.hash_function = 0
session.hash_bits_per_character = 4
url_rewriter.tags = "a=href,area=href,frame=src,input=src,form=fakeentry"

[Tidy]
tidy.clean_output = Off

[soap]
soap.wsdl_cache_enabled=1
soap.wsdl_cache_dir="/tmp/"
soap.wsdl_cache_ttl=86400


[opcache]
opcache.enable=1
opcache.enable_cli=0
opcache.memory_consumption=256
opcache.interned_strings_buffer=8
opcache.max_accelerated_files=7963
opcache.max_wasted_percentage=5
opcache.use_cwd=1
opcache.validate_timestamps=0
opcache.revalidate_freq=2
opcache.revalidate_path=0
opcache.save_comments=1
opcache.load_comments=1
opcache.fast_shutdown=1
opcache.enable_file_override=0
opcache.optimization_level=0xffffffff
opcache.inherited_hack=1
opcache.dups_fix=0
opcache.blacklist_filename=

opcache.max_file_size=0
opcache.consistency_checks=0
opcache.force_restart_timeout=180
opcache.error_log=
opcache.log_verbosity_level=1
opcache.preferred_memory_model=
opcache.protect_memory=None
opcache.mmap_base=

------------------------------------------------------------------------
[2015-04-29 15:27:49] waldner at katamail dot com

Description:
------------
The following request crashes a php-fpm process almost 100% reliably for me. This is nginx + fpm via
unix socket from the dotdeb repository.
Crucially a request with less headers works (and after that, requests like the one below start
working too - though not always).



Test script:
---------------
curl -X POST -d '{}' -H 'Connection: close' -H 'X-FORWARDED-FOR:
127.0.0.1' -H 'X-REAL-IP: 127.0.0.1' -H 'X-FORWARDED-HOST: 1.2.3.4' -H
'X-FORWARDED-PROTO: https' -H 'Content-Length: 2' -H 'User-Agent:
Mozilla/5.0 (Macintosh; Intel Mac OS X 10.10; rv:37.0) Gecko/20100101 Firefox/37.0' -H
'Accept: application/json' -H 'Accept-Language: ca,en-US;q=0.7,en;q=0.3' -H
'Accept-Encoding: gzip, deflate' -H 'Content-Type: application/json;
charset=UTF-8' -H 'apikey: YmRhZjQ3MGRlYTczYTllZmFjMTNjNTRhYTgxZDg5YTgyODU0OTVhOQ=='
-H 'Referer: https://xxxxxxxxxx.xxxxx.xxx/documentation/'
-H 'Cookie: PHPSESSID=9be03814eea0ef3e3a7fbc9a1f69c062' -H 'Pragma: no-cache' -H
'Cache-Control: no-cache' http://127.0.0.1/api/clients

Expected result:
----------------
The pool process should process the request without segfaulting.

Actual result:
--------------
Backtrace:

(gdb) bt full
#0  0x00000000006e88ea in zend_hash_find (ht=ht@entry=0x7ff11fa6f9b0, 
    arKey=arKey@entry=0x238a820 "Europe/Madrid", nKeyLength=14,
pData=pData@entry=0x7ffe4538fac0)
    at /usr/src/php5.6/nonzts/source/dotdeb-php5/Zend/zend_hash.c:849
        h = 1394799404352781269
        nIndex = 15313
        p = <optimized out>
#1  0x000000000043aad4 in php_date_parse_tzfile (formal_tzname=0x238a820 "Europe/Madrid",
tzdb=0xea4e00)
    at /usr/src/php5.6/nonzts/source/dotdeb-php5/ext/date/php_date.c:918
        ptzi = <optimized out>
#2  0x000000000043c4ca in get_timezone_info ()
    at /usr/src/php5.6/nonzts/source/dotdeb-php5/ext/date/php_date.c:997
        tz = 0x238a820 "Europe/Madrid"
        tzi = <optimized out>
#3  0x000000000043e6c5 in php_format_date (format=format@entry=0xb88939 "d-M-Y H:i:s e", 
    format_len=format_len@entry=13, ts=1430320522, localtime=localtime@entry=1)
    at /usr/src/php5.6/nonzts/source/dotdeb-php5/ext/date/php_date.c:1250
        t = 0x271b050
        tzi = <optimized out>
        string = <optimized out>
#4  0x0000000000673c92 in php_log_err (
    log_message=0x7ff11faa0170 "PHP Deprecated:  Automatically populating $HTTP_RAW_POST_DATA
is deprecated and will be removed in a future version. To avoid this warning set
'always_populate_raw_post_data' to '-1' in php.ini and us"...) at
/usr/src/php5.6/nonzts/source/dotdeb-php5/main/main.c:713
        tmp = <optimized out>
        len = <optimized out>
        error_time_str = <optimized out>
        fd = <optimized out>
        error_time = 1430320522
#5  0x00000000006740a7 in php_error_cb (type=8192, error_filename=0xb6e9d1 "Unknown",
error_lineno=0, 
    format=<optimized out>, args=<optimized out>)
    at /usr/src/php5.6/nonzts/source/dotdeb-php5/main/main.c:1144
        log_buffer = 0x7ff11faa0170 "PHP Deprecated:  Automatically populating
$HTTP_RAW_POST_DATA is deprecated and will be removed in a future version. To avoid this warning set
'always_populate_raw_post_data' to '-1' in php.ini and us"...
        error_type_str = 0xb6bf0a "Deprecated"
        buffer = 0x7ff11faa0010 "Automatically populating $HTTP_RAW_POST_DATA is deprecated and
will be removed in a future version. To avoid this warning set
'always_populate_raw_post_data' to '-1' in php.ini and use the
php://input"...
        buffer_len = 216
        display = <optimized out>
#6  0x00000000005887c0 in soap_error_handler (error_num=8192, error_filename=0xb6e9d1
"Unknown", 
    error_lineno=0, 
    format=0xb95098 "Automatically populating $HTTP_RAW_POST_DATA is deprecated and will be
removed in a future version. To avoid this warning set 'always_populate_raw_post_data' to
'-1' in php.ini and use the php://input"..., args=0x7ffe453902e0) at
/usr/src/php5.6/nonzts/source/dotdeb-php5/ext/soap/soap.c:2216
        copy = {{gp_offset = 16, fp_offset = 48, overflow_arg_area = 0x7ffe45390400, 
            reg_save_area = 0x7ffe45390310}}
        tmp = 0x553787cb
        use_exceptions = <optimized out>
        _old_in_compilation = 0 '\000'
        _old_in_execution = 0 '\000'
        _old_current_execute_data = 0x0
        _old_http_response_code = 200
        _old_http_status_line = 0x0
#7  0x00000000006da92c in zend_error (type=8192, 
    format=0xb95098 "Automatically populating $HTTP_RAW_POST_DATA is deprecated and will be
removed in a future version. To avoid this warning set 'always_populate_raw_post_data' to
'-1' in php.ini and use the php://input"...) at
/usr/src/php5.6/nonzts/source/dotdeb-php5/Zend/zend.c:1142
        args = {{gp_offset = 16, fp_offset = 48, overflow_arg_area = 0x7ffe45390400, 
            reg_save_area = 0x7ffe45390310}}
        usr_copy = {{gp_offset = 2, fp_offset = 0, overflow_arg_area = 0x2002, 
            reg_save_area = 0x7ff11fa9fa18}}
        params = <optimized out>
        retval = <optimized out>
        z_error_type = <optimized out>
        z_error_message = <optimized out>
        z_error_filename = <optimized out>
        z_error_lineno = <optimized out>
        z_context = <optimized out>
        error_filename = 0xb6e9d1 "Unknown"
        error_lineno = <optimized out>
        orig_user_error_handler = <optimized out>
        in_compilation = <optimized out>
        saved_class_entry = <optimized out>
        bp_stack = <optimized out>
        function_call_stack = <optimized out>
        switch_cond_stack = <optimized out>
        foreach_copy_stack = <optimized out>
        object_stack = <optimized out>
        declare_stack = <optimized out>
        list_stack = <optimized out>
        context_stack = <optimized out>
#8  0x0000000000681c97 in php_default_post_reader ()
    at /usr/src/php5.6/nonzts/source/dotdeb-php5/main/php_content_types.c:75
        length = <optimized out>
        data = 0x7ff11fa9fd40 "{}"
#9  php_default_post_reader () at
/usr/src/php5.6/nonzts/source/dotdeb-php5/main/php_content_types.c:51
No locals.
#10 0x000000000067e4c7 in sapi_read_post_data ()
    at /usr/src/php5.6/nonzts/source/dotdeb-php5/main/SAPI.c:247
        content_type_length = <optimized out>
        content_type = 0x7ff11fa9f9b0 "application/json; charset=UTF-8"
        oldchar = <optimized out>
        post_entry = 0x705846
        p = 0x7ff11fa9f9c1 " charset=UTF-8"
        post_reader_func = <optimized out>
#11 sapi_activate () at /usr/src/php5.6/nonzts/source/dotdeb-php5/main/SAPI.c:482
No locals.
#12 0x00000000006754cc in php_request_startup ()
    at /usr/src/php5.6/nonzts/source/dotdeb-php5/main/main.c:1632
        __orig_bailout = <optimized out>
        __bailout = {{__jmpbuf = {15610304, -798298996382607278, 140673594877200, 0,
140673594879856, 
              15501569, 799201161399785554, -798298749005047726}, __mask_was_saved = 0, __saved_mask
= {
              __val = {140673568943750, 140730059785568, 140673594877488, 0, 7876671, 81739,
15610304, 
                140673594877488, 7912927, 15501628, 2, 81739, 856902, 0, 15610304, 0}}}}
        retval = 0
#13 0x0000000000433e97 in main (argc=<optimized out>, argv=<optimized out>)
    at /usr/src/php5.6/nonzts/source/dotdeb-php5/sapi/fpm/fpm/fpm_main.c:1902
        primary_script = 0x0
        __orig_bailout = 0x0
        __bailout = {{__jmpbuf = {0, -798298996382082990, 70, 4294967295, 140730059802835, 15501628,

              799201161435437138, -798298438956328878}, __mask_was_saved = 0, __saved_mask = {__val
= {
                140673540653051, 0, 140673593026626, 0, 0, 0, 0, 0, 0, 0, 0, 4294967296, 0, 0, 0,
0}}}}
        exit_status = 0
        c = <optimized out>
        use_extended_info = 0
        file_handle = {type = ZEND_HANDLE_FILENAME, filename = 0x0, opened_path = 0x0, handle = {fd
= 0, 
            fp = 0x0, stream = {handle = 0x0, isatty = 0, mmap = {len = 0, pos = 0, map = 0x0, buf =
0x0, 
                old_handle = 0x0, old_closer = 0}, reader = 0, fsizer = 0, closer = 0}}, 
          free_filename = 0 '\000'}
        orig_optind = 1
        orig_optarg = 0x0
        ini_entries_len = 0
        max_requests = 0
        requests = 0
        fcgi_fd = 15610304
        request = {listen_socket = 0, fd = 4, id = 1, keep = 0, closed = 0, in_len = 0, in_pad = 6, 
          out_hdr = 0x0, out_pos = 0x7ffe45390900 "", out_buf = '\000'
<repeats 8191 times>, 
          reserved = '\000' <repeats 15 times>, env = 0x7ff11fa6e310}
        fpm_config = 0x7ffe453948d3 ""
        fpm_prefix = 0x0
        fpm_pid = 0x0
        test_conf = 0
        force_daemon = 1
        force_stderr = 0
        php_information = 0
        php_allow_to_run_as_root = 0
        __func__ = "main"

The offending code line is:

p = ht->arBuckets[nIndex];

ht here is date_globals.tzcache:

date_globals.tzcache->arBuckets = (Bucket **) 0x0

It seems to have a valid value until 

SG(request_info).request_body = php_stream_temp_create_ex(TEMP_STREAM_DEFAULT, SAPI_POST_BLOCK_SIZE,
PG(upload_tmp_dir));

(main/SAPI.c, line 282). When php_stream_temp_create_ex returns, it's 0x0.

It looks like memory of date_globals.tzcache->arBuckets gets overwritten by emalloc() or similar
at some point.


------------------------------------------------------------------------



--
Edit this bug report at https://bugs.php.net/bug.php?id=69547&edit=1


Thread (13 messages)

« previous php.bugs (#192404) next »