Bug #70002 [PATCH]: apache2 / php5ts crashes, sometimes reporting zend_mm_heap corrupted

From: Date: Mon, 27 Jul 2015 16:28:03 +0000
Subject: Bug #70002 [PATCH]: apache2 / php5ts crashes, sometimes reporting zend_mm_heap corrupted
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-194763@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=70002&edit=1

 ID:                 70002
 Patch added by:     ab@php.net
 Reported by:        jeremy dot j dot dunn at gmail dot com
 Summary:            apache2 / php5ts crashes, sometimes reporting
                     zend_mm_heap corrupted
 Status:             Feedback
 Type:               Bug
 Package:            Apache2 related
 Operating System:   Windows 2008 R2
 PHP Version:        5.5.26
 Block user comment: N
 Private report:     N

 New Comment:

The following patch has been added/updated:

Patch Name: temporary_dir_ts
Revision:   1438014482
URL:        https://bugs.php.net/patch-display.php?bug=70002&patch=temporary_dir_ts&revision=1438014482


Previous Comments:
------------------------------------------------------------------------
[2015-07-27 15:05:39] jpauli@php.net

Definitely a race condition.
I forgot about it, yes, my bad ;-)
Fixing it...

------------------------------------------------------------------------
[2015-07-27 14:15:55] ab@php.net

@php_150725 thanks for the follow up. Unfortunately it can't be said for sure whether
you've the same bug because we had no backtrace.

But the code in main/php_open_temporary_file.c is definitely not thread safe. Before the patch
you've linked it was only freeing the tmp dir in MSHUTDOWN, now it frees in RSHUTDOWN. That
means - race conditions.

I've just looked through and seems this is present in 5.6 as well.

As a quick solution for you - if your app doesn't suffer under #66048 (you don't change
the tmp dir), you can just revert this particular part. Also yep, you can downgrade PHP. Or you can
upgrade to 5.6 after there's a fix flowed in there.

Does this crash happen with any script, or there's one you use which easy reproduces the crash?

Thanks

Anatol

------------------------------------------------------------------------
[2015-07-25 07:04:34] php_150725 at ayd dot jp

Additional information.

I've compiled the php-5.5.27 with "--enable-debug" option.
The following messages has been displayed in the apache error log.


[Sat Jul 25 15:51:32 2015]  Script:  '/var/www/xxxx.php'
---------------------------------------
/PHP_SRC_PATH/main/php_open_temporary_file.c(184) : Block 0x2aaaaad0c2d0 status:
Invalid pointer: ((thread_id=0x42478940) != (expected=0x4BA87940))

---------------------------------------
[Sat Jul 25 15:51:37 2015]  Script:  '/var/www/xxxx.php'
/PHP_STC_PATH/main/php_open_temporary_file.c(250) :  Freeing 0x2AAAC04B7EA0 (5 bytes),
script=/var/www/xxxx.php
=== Total 1 memory leaks detected ===

------------------------------------------------------------------------
[2015-07-24 20:27:42] php_150725 at ayd dot jp

I also experienced the same problem.

Description:
------------
OS:CentOS(64bit)
Web:apache 2.4.10
PHP:5.5.27/5.5.26
(PHP 5.5.25 does not problem occurs.)

Test script:
---------------
I can not reproduce the problem in a test script.
However, problems occur when applying a load to my server.

For example)

/usr/local/apache2/bin/ab -n 100 -c 50 http://mysite/xxxx.php

I have investigated this problem.
Following commit seem to be the cause.

https://github.com/php/php-src/commit/c117548ea9365adac00960fe5f43425b2955310d

When I return the "main/php_open_temporary_file.c" file, problem no longer occurs.
(efree -> free , estrndup -> zend_strndup etc...)

and,I think running program this flow.

https://github.com/php/php-src/blob/PHP-5.5.27/Zend/zend_alloc.c#L2105
-> 
https://github.com/php/php-src/blob/PHP-5.5.27/Zend/zend_alloc.c#L838

------------------------------------------------------------------------
[2015-07-09 09:32:44] ab@php.net

Hi,

with pastebin - it's just for huge inputs, so the posts are more readable.

Yeah, you was mentioning WER, so i just hoped some dump files are there as well. so lets keep it
open, maybe you have more info later. But regarding others - without a backtrace or repro code
it'll be hard to identify the issue is same.

Thanks.

------------------------------------------------------------------------


The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at

    https://bugs.php.net/bug.php?id=70002


--
Edit this bug report at https://bugs.php.net/bug.php?id=70002&edit=1


Thread (22 messages)

« previous php.bugs (#194763) next »