Bug #72801 [Opn]: apcu crashes (SIGSEGV) php/Apache on memory allocation failures
| From: | nikic@php.net | Date: | Wed, 10 Aug 2016 12:03:17 +0000 |
| Subject: | Bug #72801 [Opn]: apcu crashes (SIGSEGV) php/Apache on memory allocation failures | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-203153@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=72801&edit=1
ID: 72801
Updated by: nikic@php.net
Reported by: jaromird at microsoft dot com
Summary: apcu crashes (SIGSEGV) php/Apache on memory
allocation failures
Status: Open
Type: Bug
Package: Reproducible crash
Operating System: Mac OS X
PHP Version: 7.0.9
-Assigned To:
+Assigned To: krakjoe
Block user comment: N
Private report: N
New Comment:
Not seeing apcu in the package list, so assigning this to joe directly.
Previous Comments:
------------------------------------------------------------------------
[2016-08-10 11:29:45] jaromird at microsoft dot com
Tested with apcu 5.1.5
------------------------------------------------------------------------
[2016-08-10 11:28:01] jaromird at microsoft dot com
Description:
------------
Started seeing more frequent Apache crashes after upgrade to PHP 7.0 for one of our applications
which makes heavy use of apc cache. After investigation, found a reproduction script to trigger
segmentation fault eventually.
Late apcu code inspection revealed that code doesn't check for memory allocation failures on
many places. Typical case for example: string duplication fails in apcu_store(), code then inserts
zval with NULL value into cache, then apcu_fetch() crashes when dereferencing the value.
I hope I've covered all necessary places in the patch, but surely would suggest close review.
So far only the case triggered by the below test is really tested.
Test script:
---------------
<?php
/*
Might need tweaking to trigger the memory allocation failure
ini settings:
memory_limit = 4512M
apcu shared memory size default - 128M
*/
$f = str_repeat('c', 800 * 1024 * 1024 );
apcu_store('aaa', $f, 5);
$s = apcu_fetch('aaa');
echo ($s == $f) ? "same" : "different";
Expected result:
----------------
script running to completion, returning "same" if no memory problem, "different"
if memory allocation failure in apc_fetch()
Actual result:
--------------
Segmentation fault: 11
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=72801&edit=1