Bug #71135 [NEW]: Random memory corruption with strings

From: Date: Wed, 16 Dec 2015 12:18:17 +0000
Subject: Bug #71135 [NEW]: Random memory corruption with strings
Groups: php.bugs 
Request: Send a blank email to php-bugs+get-197925@lists.php.net to get a copy of this message
From:             iquito at gmx dot net
Operating system: Debian Jessie
PHP version:      7.0.0
Package:          opcache
Bug Type:         Bug
Bug description:Random memory corruption with strings

Description:
------------
I have been using PHP7 in production since Saturday, compiling it myself
according to the instructions on
https://www.howtoforge.com/tutorial/how-to-install-php-7-on-debian/
. I
have about 0.5 million pageviews served per day, and two primary web
servers running PHP-FPM.

First, everything worked fine - but after 12-36 hours, when everything
is cached and running perfectly, at least one string in the cached PHP
files seems to "flip" one character in it. One time, it changed a
character in an SQL query, which generated these errors:

"Unknown column 'blocked_by_usdr' in 'field list':
SELECT 1 AS exists, noted, friend, friend_confirmed, friend_position,
known, known_confirmed, blocked AS blocking, blocked_by_usdr AS blocked
FROM userlist_new WHERE profile_id = 137137 AND friend_profile_id =
65297"

Instead of blocked_by_user, it changed to blocked_by_usdr, which
suddenly generated 500 SQL-errors per minute. As soon as I restarted
PHP7-FPM on the affected server, everything was fine again, and I
actually checked the PHP file - the SQL query was correct, and never
contained that error.

24 hours later, on the other server, this error completely broke all
websites:

Warning:
require(/srv_ssd/domains/website/vendor/smarty/smarty/libs/sysplugins/smarty_template_compiled-php):
failed to open stream: No such file or directory in
/srv_ssd/domains/website/vendor/smarty/smarty/libs/sysplugins/smarty_internal_template.php

As you can see, instead of including
/srv_ssd/domains/website/vendor/smarty/smarty/libs/sysplugins/smarty_template_compiled.php
the string was changed from a dot to a dash. Interestingly enough, this
error appeared in all three projects running on the server, although
each had its own (identical) version of smarty_internal_template.php -
but maybe the PHP opcache caches them only once if they are all the
same, even if they are in different directories.

This happened to me three times already, on two different production
servers, and always at night when my webservers are less busy. As soon
as PHP7 is restarted, everything is fine again. When the last error
occured, an SQL query in another file was also broken, so in two files
one character changed at the same time. Because these error occur always
at night and sometimes "grouped", maybe the opcache does some garbage
collection at that time, or some other internal changes?

Unfortunately, I do not know how to reproduce this bug - it always
occurs within 12-36 hours on my servers, but it never occurs when
starting PHP-FPM, and I do not see a clear pattern on when or why it
happens. It is also possible some string changes happened but were not
noticed by me, because they did not result in an immediate PHP or SQL
error.

My configure line:

configure --prefix=/opt/php7 --with-pdo-pgsql --with-zlib-dir
--with-freetype-dir --enable-mbstring --with-libxml-dir=/usr
--enable-soap --enable-calendar --with-curl --with-mcrypt --with-zlib
--with-gd --with-pgsql --disable-rpath --enable-inline-optimization
--with-bz2 --with-zlib --enable-sockets --enable-sysvsem
--enable-sysvshm --enable-pcntl --enable-mbregex --enable-exif
--enable-bcmath --with-mhash --enable-zip --with-pcre-regex
--with-pdo-mysql --with-mysqli
--with-mysql-sock=/var/run/mysqld/mysqld.sock --with-jpeg-dir=/usr
--with-png-dir=/usr --enable-gd-native-ttf --with-openssl
--with-fpm-user=als --with-fpm-group=als
--with-libdir=/lib/x86_64-linux-gnu --enable-ftp --with-imap
--with-imap-ssl --with-kerberos --with-gettext --with-xmlrpc --with-xsl
--with-iconv-dir --enable-intl --enable-opcache --enable-fpm


-- 
Edit bug report at https://bugs.php.net/bug.php?id=71135&edit=1
-- 
Try a snapshot (PHP 5.4):   https://bugs.php.net/fix.php?id=71135&r=trysnapshot54
Try a snapshot (PHP 5.5):   https://bugs.php.net/fix.php?id=71135&r=trysnapshot55
Try a snapshot (trunk):     https://bugs.php.net/fix.php?id=71135&r=trysnapshottrunk
Fixed in SVN:               https://bugs.php.net/fix.php?id=71135&r=fixed
Fixed in release:           https://bugs.php.net/fix.php?id=71135&r=alreadyfixed
Need backtrace:             https://bugs.php.net/fix.php?id=71135&r=needtrace
Need Reproduce Script:      https://bugs.php.net/fix.php?id=71135&r=needscript
Try newer version:          https://bugs.php.net/fix.php?id=71135&r=oldversion
Not developer issue:        https://bugs.php.net/fix.php?id=71135&r=support
Expected behavior:          https://bugs.php.net/fix.php?id=71135&r=notwrong
Not enough info:            https://bugs.php.net/fix.php?id=71135&r=notenoughinfo
Submitted twice:            https://bugs.php.net/fix.php?id=71135&r=submittedtwice
register_globals:           https://bugs.php.net/fix.php?id=71135&r=globals
PHP 4 support discontinued: https://bugs.php.net/fix.php?id=71135&r=php4
Daylight Savings:           https://bugs.php.net/fix.php?id=71135&r=dst
IIS Stability:              https://bugs.php.net/fix.php?id=71135&r=isapi
Install GNU Sed:            https://bugs.php.net/fix.php?id=71135&r=gnused
Floating point limitations: https://bugs.php.net/fix.php?id=71135&r=float
No Zend Extensions:         https://bugs.php.net/fix.php?id=71135&r=nozend
MySQL Configuration Error:  https://bugs.php.net/fix.php?id=71135&r=mysqlcfg



Thread (52 messages)

« previous php.bugs (#197925) next »