Bug #69547 [Com]: php-fpm segfault (reproducible)

From: Date: Mon, 09 May 2016 12:20:59 +0000
Subject: Bug #69547 [Com]: php-fpm segfault (reproducible)
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-200953@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=69547&edit=1

 ID:                 69547
 Comment by:         php at syntacs dot com
 Reported by:        waldner at katamail dot com
 Summary:            php-fpm segfault (reproducible)
 Status:             No Feedback
 Type:               Bug
 Package:            FPM related
 Operating System:   Debian wheezy
 PHP Version:        5.6.10
 Block user comment: N
 Private report:     N

 New Comment:

definitely memory corruption here

fully patched 14.04 LTS, nginx & php-fpm via unix socket

always_populate_raw_post_data=-1 didn't change anything

short version of coredump, complete version available (can I post files ?)

#0  0x00000000006ea07a in zend_hash_find (ht=0x4b, arKey=0x7fef3c662dd0 "minify",
nKeyLength=7, pData=0x7ffca4f10d90)
    at /build/php5-SqUzIS/php5-5.6.21+dfsg/Zend/zend_hash.c:849
        h = 229474855223889
        nIndex = <error reading variable nIndex (Cannot access memory at address 0x4f)>
        p = <optimized out>
#1  0x00007fef4bf16c87 in xc_restore_zend_op_array () from /usr/lib/php5/20131226/xcache.so
No symbol table info available.
#2  0x00007fef4bf17623 in xc_restore_HashTable_zend_function () from
/usr/lib/php5/20131226/xcache.so
No symbol table info available.
#3  0x00007fef4bf17f82 in xc_restore_zend_class_entry () from /usr/lib/php5/20131226/xcache.so
No symbol table info available.
#4  0x00007fef4bf1872f in xc_restore_xc_entry_data_php_t () from /usr/lib/php5/20131226/xcache.so
No symbol table info available.
#5  0x00007fef4bf18814 in xc_processor_restore_xc_entry_data_php_t () from
/usr/lib/php5/20131226/xcache.so
No symbol table info available.
#6  0x00007fef4bf1c31d in ?? () from /usr/lib/php5/20131226/xcache.so
No symbol table info available.
#7  0x00007fef4bf1ed0c in ?? () from /usr/lib/php5/20131226/xcache.so
No symbol table info available.
#8  0x00007fef4bf2071f in ?? () from /usr/lib/php5/20131226/xcache.so
No symbol table info available.
#9  0x00007fef4bf2294c in ?? () from /usr/lib/php5/20131226/xcache.so
No symbol table info available.
#10 0x000000000078000d in ZEND_INCLUDE_OR_EVAL_SPEC_TMP_HANDLER (execute_data=0x7fef550d6c80) at
/build/php5-SqUzIS/php5-5.6.21+dfsg/Zend/zend_vm_execute.h:8334
        file_handle = {type = ZEND_HANDLE_FILENAME, filename = 0x34d78b0
"/var/www/www.xxxxx.xxx.edu/plugins/compresseur/lib/minify_html/class.minify_html.php", 
          opened_path = 0x34d7918
"/var/www/www.xxxxx.xxx.edu/plugins/compresseur/lib/minify_html/class.minify_html.php",
handle = {fd = 0, fp = 0x0, stream = {handle = 0x0, 
              isatty = 27, mmap = {len = 54112224, pos = 1, map = 0xe9e880
<executor_globals+576>, buf = 0xe83dfc <php_execute.return_semaphore> "", 
                old_handle = 0x6b600f <_estrndup+79>, old_closer = 0x7fef550d6c20}, reader =
0x7fef3c05b6e0, fsizer = 0xe9e640 <executor_globals>, closer = 0x7fef550d6c80}}, 
          free_filename = 0 '\000'}
        resolved_path = <optimized out>
        opline = 0x7fef3c05b740
        new_op_array = 0x0
        free_op1 = {var = 0x7fef550d6c40}
        inc_filename = 0x7fef550d6c40
        tmp_inc_filename = <optimized out>
        failure_retval = <optimized out>


Previous Comments:
------------------------------------------------------------------------
[2015-08-02 04:22:15] php-bugs at lists dot php dot net

No feedback was provided. The bug is being suspended because
we assume that you are no longer experiencing the problem.
If this is not the case and you are able to provide the
information that was requested earlier, please do so and
change the status of the bug back to "Re-Opened". Thank you.

------------------------------------------------------------------------
[2015-07-22 11:07:59] mike@php.net

Hi, could you try 

always_populate_raw_post_data=-1

in php.ini?

------------------------------------------------------------------------
[2015-06-16 11:45:18] waldner at katamail dot com

And with 5.6.10.

------------------------------------------------------------------------
[2015-05-19 09:59:53] waldner at katamail dot com

This happens with 5.6.9 as well.

------------------------------------------------------------------------
[2015-04-30 09:02:04] waldner at katamail dot com

Making seemingly random changes to php.ini sometimes fixes the problem, for example changing

error_log = "/dev/null"

to

error_log = "/tmp/a.log"

or commenting out the line

browscap = /etc/browscap.ini

makes it work. Still (or even more because of this), looks like memory corruption.

------------------------------------------------------------------------


The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at

    https://bugs.php.net/bug.php?id=69547


--
Edit this bug report at https://bugs.php.net/bug.php?id=69547&edit=1


Thread (13 messages)

« previous php.bugs (#200953) next »