Bug #70002 [PATCH]: apache2 / php5ts crashes, sometimes reporting zend_mm_heap corrupted

From: Date: Tue, 28 Jul 2015 08:40:04 +0000
Subject: Bug #70002 [PATCH]: apache2 / php5ts crashes, sometimes reporting zend_mm_heap corrupted
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-194771@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=70002&edit=1

 ID:                 70002
 Patch added by:     ab@php.net
 Reported by:        jeremy dot j dot dunn at gmail dot com
 Summary:            apache2 / php5ts crashes, sometimes reporting
                     zend_mm_heap corrupted
 Status:             Feedback
 Type:               Bug
 Package:            Apache2 related
 Operating System:   Windows 2008 R2
 PHP Version:        5.5.26
 Block user comment: N
 Private report:     N

 New Comment:

The following patch has been added/updated:

Patch Name: temp_dir_ts_2
Revision:   1438072803
URL:        https://bugs.php.net/patch-display.php?bug=70002&patch=temp_dir_ts_2&revision=1438072803


Previous Comments:
------------------------------------------------------------------------
[2015-07-27 16:28:46] ab@php.net

@php_150725 please check the attached patch.

Thanks.

------------------------------------------------------------------------
[2015-07-27 16:28:02] ab@php.net

The following patch has been added/updated:

Patch Name: temporary_dir_ts
Revision:   1438014482
URL:        https://bugs.php.net/patch-display.php?bug=70002&patch=temporary_dir_ts&revision=1438014482

------------------------------------------------------------------------
[2015-07-27 15:05:39] jpauli@php.net

Definitely a race condition.
I forgot about it, yes, my bad ;-)
Fixing it...

------------------------------------------------------------------------
[2015-07-27 14:15:55] ab@php.net

@php_150725 thanks for the follow up. Unfortunately it can't be said for sure whether
you've the same bug because we had no backtrace.

But the code in main/php_open_temporary_file.c is definitely not thread safe. Before the patch
you've linked it was only freeing the tmp dir in MSHUTDOWN, now it frees in RSHUTDOWN. That
means - race conditions.

I've just looked through and seems this is present in 5.6 as well.

As a quick solution for you - if your app doesn't suffer under #66048 (you don't change
the tmp dir), you can just revert this particular part. Also yep, you can downgrade PHP. Or you can
upgrade to 5.6 after there's a fix flowed in there.

Does this crash happen with any script, or there's one you use which easy reproduces the crash?

Thanks

Anatol

------------------------------------------------------------------------
[2015-07-25 07:04:34] php_150725 at ayd dot jp

Additional information.

I've compiled the php-5.5.27 with "--enable-debug" option.
The following messages has been displayed in the apache error log.


[Sat Jul 25 15:51:32 2015]  Script:  '/var/www/xxxx.php'
---------------------------------------
/PHP_SRC_PATH/main/php_open_temporary_file.c(184) : Block 0x2aaaaad0c2d0 status:
Invalid pointer: ((thread_id=0x42478940) != (expected=0x4BA87940))

---------------------------------------
[Sat Jul 25 15:51:37 2015]  Script:  '/var/www/xxxx.php'
/PHP_STC_PATH/main/php_open_temporary_file.c(250) :  Freeing 0x2AAAC04B7EA0 (5 bytes),
script=/var/www/xxxx.php
=== Total 1 memory leaks detected ===

------------------------------------------------------------------------


The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at

    https://bugs.php.net/bug.php?id=70002


--
Edit this bug report at https://bugs.php.net/bug.php?id=70002&edit=1


Thread (22 messages)

« previous php.bugs (#194771) next »