Bug #70392 [Com]: SIGSEGV during PHP shutdown

From: Date: Mon, 07 Sep 2015 20:20:21 +0000
Subject: Bug #70392 [Com]: SIGSEGV during PHP shutdown
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-195861@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=70392&edit=1

 ID:                 70392
 Comment by:         pegasus at vaultwiki dot org
 Reported by:        pegasus at vaultwiki dot org
 Summary:            SIGSEGV during PHP shutdown
 Status:             Feedback
 Type:               Bug
 Package:            *General Issues
 Operating System:   Centos 7 64-bit
 PHP Version:        7.0Git-2015-08-30 (Git)
 Assigned To:        dmitry
 Block user comment: N
 Private report:     N

 New Comment:

After a few days, issue persists using the suggested commit (different line numbers):

###
#0  0x000000000094733b in zend_mm_find_leaks_small (p=0x7f7df2200000, i=510,
    j=6, leak=0x7fffbe955cf0)
    at /home/***/php-src-0f74bae/Zend/zend_alloc.c:1966
1966                    if (dbg->size != 0) {
###

p dbg
$1 = (zend_mm_debug_info *) 0x7f7df24002e0

p bin_num
$2 = 24

p dbg->size
Cannot access memory at address 0x7f7df24002e0

p leak->filename
$3 = 0xfe5540 "/home/***/php-src-0f74bae/Zend/zend_vm_execute.h"

p leak->lineno
$4 = 15242

I have not checked exhaustively, but when comparing to other instances of the error, it seems
bin_num = 24 is a pattern here (and dbg->size is always inaccessible).


Previous Comments:
------------------------------------------------------------------------
[2015-09-02 12:16:57] pegasus at vaultwiki dot org

I will try the new commit and watch the logs for a few days to see if the error still occurs. I will
also work on getting you the output of those variables next time I am at the terminal.

------------------------------------------------------------------------
[2015-09-02 10:09:18] dmitry@php.net

Please check the latest git version.
The following commit might fix the problem.

http://git.php.net/?p=php-src.git;a=commitdiff;h=111bd5d8c45a9c44b2e39951e6a1a543a893f8bd

------------------------------------------------------------------------
[2015-09-01 17:27:25] dmitry@php.net

p dbg
p bin_num

------------------------------------------------------------------------
[2015-08-31 18:09:06] pegasus at vaultwiki dot org

How would I output the value?

------------------------------------------------------------------------
[2015-08-31 16:30:35] dmitry@php.net

The crash on line "if (dbg->size != 0)" is possible only when "dbg" is
invalid.
The crash occured on processing 25-th element of 510-th page.
We allocate 512 pages at once. So I assume "dbg" somehow points into page after 512.

I don't see how this may happen yet.

Can you show the values of "dbg" and "bin_num"?

------------------------------------------------------------------------


The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at

    https://bugs.php.net/bug.php?id=70392


--
Edit this bug report at https://bugs.php.net/bug.php?id=70392&edit=1


Thread (13 messages)

« previous php.bugs (#195861) next »