Bug #71482 [Fbk->Asn]: Lost zend_string after "reached pm.max_children setting" with segfault

From: Date: Sat, 30 Jan 2016 05:34:29 +0000
Subject: Bug #71482 [Fbk->Asn]: Lost zend_string after "reached pm.max_children setting" with segfault
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-198968@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=71482&edit=1

 ID:                 71482
 User updated by:    alex dot schneider at sevenval dot com
 Reported by:        alex dot schneider at sevenval dot com
 Summary:            Lost zend_string after "reached pm.max_children
                     setting" with segfault
-Status:             Feedback
+Status:             Assigned
 Type:               Bug
 Package:            PCRE related
 Operating System:   Linux Mint 17.3
 PHP Version:        7.0.2
 Assigned To:        laruence
 Block user comment: N
 Private report:     N

 New Comment:

Yes, we use, but i'a almost sure that the error comes from module "pcre" self.

Is also interesting that there is no longer segfaults, once we disable the "opcache".

Is here a big intern difference between the both functions (original and patched)?


Previous Comments:
------------------------------------------------------------------------
[2016-01-30 04:25:09] laruence@php.net

hmm, do you use any other extensions which is not bundled with php ?

------------------------------------------------------------------------
[2016-01-29 09:12:07] alex dot schneider at sevenval dot com

Description:
------------
The destruction of "HashTable module_registry" sometimes "throws" a segfault in
module "pcre".

I can give you the following infos only:
* The segfault is "thrown" while the destruction of "HashTable module_registry"
by "zend_hash_graceful_reverse_destroy(&module_registry)", but before
"PHP_GSHUTDOWN_FUNCTION(pcre)"
* The trigger is the "ZEND_API void ZEND_FASTCALL zend_hash_destroy(HashTable *ht)"
function in zend_hash.c (line 1272) "if (EXPECTED(p->key)) {" with "Access to
address 0xXXXXXXXXX is not allowed"

In the meantime while my test suite runs, I see in the log:

WARNING: [pool fit] server reached pm.max_children setting (2), consider raising it


I think, the bug is related to #63180.

My patch (attached here) works for me. Perhaps your experts can examine the differences here.

PS: Sorry for my english :)

Test script:
---------------
Unfortunately, i cannot isolate the trigger code from my very complex test suite with a lot of test
methods and requests.

fpmlimits.conf for triggering the segfault:
...
pm = dynamic
pm.max_children = 2
pm.start_servers = 2
pm.min_spare_servers = 2
pm.max_spare_servers = 2
pm.max_requests = 5
...

Expected result:
----------------
No segfaults

Actual result:
--------------
segfaults


------------------------------------------------------------------------



--
Edit this bug report at https://bugs.php.net/bug.php?id=71482&edit=1


Thread (11 messages)

« previous php.bugs (#198968) next »