Edit report at https://bugs.php.net/bug.php?id=70002&edit=1
ID: 70002
Patch added by: ab@php.net
Reported by: jeremy dot j dot dunn at gmail dot com
Summary: apache2 / php5ts crashes, sometimes reporting
zend_mm_heap corrupted
Status: Feedback
Type: Bug
Package: Apache2 related
Operating System: Windows 2008 R2
PHP Version: 5.5.26
Block user comment: N
Private report: N
New Comment:
The following patch has been added/updated:
Patch Name: temporary_dir_ts
Revision: 1438014482
URL: https://bugs.php.net/patch-display.php?bug=70002&patch=temporary_dir_ts&revision=1438014482
Previous Comments:
------------------------------------------------------------------------
[2015-07-27 15:05:39] jpauli@php.net
Definitely a race condition.
I forgot about it, yes, my bad ;-)
Fixing it...
------------------------------------------------------------------------
[2015-07-27 14:15:55] ab@php.net
@php_150725 thanks for the follow up. Unfortunately it can't be said for sure whether
you've the same bug because we had no backtrace.
But the code in main/php_open_temporary_file.c is definitely not thread safe. Before the patch
you've linked it was only freeing the tmp dir in MSHUTDOWN, now it frees in RSHUTDOWN. That
means - race conditions.
I've just looked through and seems this is present in 5.6 as well.
As a quick solution for you - if your app doesn't suffer under #66048 (you don't change
the tmp dir), you can just revert this particular part. Also yep, you can downgrade PHP. Or you can
upgrade to 5.6 after there's a fix flowed in there.
Does this crash happen with any script, or there's one you use which easy reproduces the crash?
Thanks
Anatol
------------------------------------------------------------------------
[2015-07-25 07:04:34] php_150725 at ayd dot jp
Additional information.
I've compiled the php-5.5.27 with "--enable-debug" option.
The following messages has been displayed in the apache error log.
[Sat Jul 25 15:51:32 2015] Script: '/var/www/xxxx.php'
---------------------------------------
/PHP_SRC_PATH/main/php_open_temporary_file.c(184) : Block 0x2aaaaad0c2d0 status:
Invalid pointer: ((thread_id=0x42478940) != (expected=0x4BA87940))
---------------------------------------
[Sat Jul 25 15:51:37 2015] Script: '/var/www/xxxx.php'
/PHP_STC_PATH/main/php_open_temporary_file.c(250) : Freeing 0x2AAAC04B7EA0 (5 bytes),
script=/var/www/xxxx.php
=== Total 1 memory leaks detected ===
------------------------------------------------------------------------
[2015-07-24 20:27:42] php_150725 at ayd dot jp
I also experienced the same problem.
Description:
------------
OS:CentOS(64bit)
Web:apache 2.4.10
PHP:5.5.27/5.5.26
(PHP 5.5.25 does not problem occurs.)
Test script:
---------------
I can not reproduce the problem in a test script.
However, problems occur when applying a load to my server.
For example)
/usr/local/apache2/bin/ab -n 100 -c 50 http://mysite/xxxx.php
I have investigated this problem.
Following commit seem to be the cause.
https://github.com/php/php-src/commit/c117548ea9365adac00960fe5f43425b2955310d
When I return the "main/php_open_temporary_file.c" file, problem no longer occurs.
(efree -> free , estrndup -> zend_strndup etc...)
and,I think running program this flow.
https://github.com/php/php-src/blob/PHP-5.5.27/Zend/zend_alloc.c#L2105
->
https://github.com/php/php-src/blob/PHP-5.5.27/Zend/zend_alloc.c#L838
------------------------------------------------------------------------
[2015-07-09 09:32:44] ab@php.net
Hi,
with pastebin - it's just for huge inputs, so the posts are more readable.
Yeah, you was mentioning WER, so i just hoped some dump files are there as well. so lets keep it
open, maybe you have more info later. But regarding others - without a backtrace or repro code
it'll be hard to identify the issue is same.
Thanks.
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=70002
--
Edit this bug report at https://bugs.php.net/bug.php?id=70002&edit=1