Bug #71754 [NEW]: Regression in PHP7.0: trivial script segfaults php-cgi

From: Date: Wed, 09 Mar 2016 13:33:12 +0000
Subject: Bug #71754 [NEW]: Regression in PHP7.0: trivial script segfaults php-cgi
Groups: php.bugs 
Request: Send a blank email to php-bugs+get-199698@lists.php.net to get a copy of this message
From:             phpbug at wisl dot de
Operating system: Linux
PHP version:      7.0.4
Package:          Reproducible crash
Bug Type:         Bug
Bug description:Regression in PHP7.0: trivial script segfaults php-cgi

Description:
------------
The included trivial 2-line-script crashed php-cgi with the following
backtrace:

(gdb) run bugtest2.php
Starting program: /usr/bin/php-cgi7.0 bugtest2.php
[Thread debugging using libthread_db enabled]
Using host libthread_db library "/lib64/libthread_db.so.1".

Program received signal SIGSEGV, Segmentation fault.
zend_hash_str_find (ht=0x0, str=str@entry=0xd33ece "REQUEST_URI",
len=len@entry=11)
    at
/var/tmp/portage/dev-lang/php-7.0.4/work/sapis-build/cgi/Zend/zend_hash.c:1959
1959   
/var/tmp/portage/dev-lang/php-7.0.4/work/sapis-build/cgi/Zend/zend_hash.c:
No such file or directory.
(gdb) bt
#0  zend_hash_str_find (ht=0x0, str=str@entry=0xd33ece "REQUEST_URI",
len=len@entry=11)
    at
/var/tmp/portage/dev-lang/php-7.0.4/work/sapis-build/cgi/Zend/zend_hash.c:1959
#1  0x0000000000640aeb in php_session_start ()
    at
/var/tmp/portage/dev-lang/php-7.0.4/work/sapis-build/cgi/ext/session/session.c:1613
#2  0x0000000000641cd5 in zif_session_start (execute_data=<optimized
out>,
    return_value=0x7ffff0612090)
    at
/var/tmp/portage/dev-lang/php-7.0.4/work/sapis-build/cgi/ext/session/session.c:2312
#3  0x000000000083c39e in ZEND_DO_ICALL_SPEC_HANDLER ()
    at
/var/tmp/portage/dev-lang/php-7.0.4/work/sapis-build/cgi/Zend/zend_vm_execute.h:586
#4  0x000000000082c83b in execute_ex (ex=<optimized out>)
    at
/var/tmp/portage/dev-lang/php-7.0.4/work/sapis-build/cgi/Zend/zend_vm_execute.h:414
#5  0x0000000000888689 in zend_execute (op_array=<optimized out>,
    return_value=<optimized out>)
    at
/var/tmp/portage/dev-lang/php-7.0.4/work/sapis-build/cgi/Zend/zend_vm_execute.h:458
#6  0x00000000007e9537 in zend_execute_scripts (type=type@entry=8,
    retval=retval@entry=0x0, file_count=file_count@entry=3)
    at
/var/tmp/portage/dev-lang/php-7.0.4/work/sapis-build/cgi/Zend/zend.c:1427
#7  0x000000000077c0a8 in php_execute_script (
    primary_file=primary_file@entry=0x7fffffffd390)
    at
/var/tmp/portage/dev-lang/php-7.0.4/work/sapis-build/cgi/main/main.c:2484
#8  0x000000000048d5f7 in main (argc=2, argv=0x7fffffffd818)
    at
/var/tmp/portage/dev-lang/php-7.0.4/work/sapis-build/cgi/sapi/cgi/cgi_main.c:2453


Test script:
---------------
<?php
ini_set("session.use_only_cookies","0");
session_start();
?>

Expected result:
----------------
Just an empty page, because while the script does start a session it
does nothing else. Instead I get an 500 internal server error, because
the cgi process was aborted with a segfault.

I'm fileing this seperate bug in addition zu #71599, because nobody
seems to care that the transparend session id feature is broken. I hope
this trivial triggereble segfault gets some attention.

The cause seems to be the following commit:
https://github.com/php/php-src/commit/f248df900300c5b2201d4cf634d58d413399e2eb

Please revert this commit because of the following reasons:
* Its description ("Behavior is unchanged.") is plain wrong: The change
causes PHPSESSID parameters added to all URLs even if the user has
cookies enabled. That is a behavior change.
* Its contains bugs, because on multiple occasions I have seen it adding
multiple PHPSESSID parameters.
* It removes a validation check
(Z_ISUNDEF(PG(http_globals)[TRACK_VARS_SERVER])) and because of that the
option session.use_only_cookie=0 now triggers a segfault when calling
session_start(). (At least when using the cgi variant of php.)


-- 
Edit bug report at https://bugs.php.net/bug.php?id=71754&edit=1
-- 
Try a snapshot (PHP 5.4):   https://bugs.php.net/fix.php?id=71754&r=trysnapshot54
Try a snapshot (PHP 5.5):   https://bugs.php.net/fix.php?id=71754&r=trysnapshot55
Try a snapshot (trunk):     https://bugs.php.net/fix.php?id=71754&r=trysnapshottrunk
Fixed in SVN:               https://bugs.php.net/fix.php?id=71754&r=fixed
Fixed in release:           https://bugs.php.net/fix.php?id=71754&r=alreadyfixed
Need backtrace:             https://bugs.php.net/fix.php?id=71754&r=needtrace
Need Reproduce Script:      https://bugs.php.net/fix.php?id=71754&r=needscript
Try newer version:          https://bugs.php.net/fix.php?id=71754&r=oldversion
Not developer issue:        https://bugs.php.net/fix.php?id=71754&r=support
Expected behavior:          https://bugs.php.net/fix.php?id=71754&r=notwrong
Not enough info:            https://bugs.php.net/fix.php?id=71754&r=notenoughinfo
Submitted twice:            https://bugs.php.net/fix.php?id=71754&r=submittedtwice
register_globals:           https://bugs.php.net/fix.php?id=71754&r=globals
PHP 4 support discontinued: https://bugs.php.net/fix.php?id=71754&r=php4
Daylight Savings:           https://bugs.php.net/fix.php?id=71754&r=dst
IIS Stability:              https://bugs.php.net/fix.php?id=71754&r=isapi
Install GNU Sed:            https://bugs.php.net/fix.php?id=71754&r=gnused
Floating point limitations: https://bugs.php.net/fix.php?id=71754&r=float
No Zend Extensions:         https://bugs.php.net/fix.php?id=71754&r=nozend
MySQL Configuration Error:  https://bugs.php.net/fix.php?id=71754&r=mysqlcfg



Thread (2 messages)

« previous php.bugs (#199698) next »