Bug #72801 [Asn->Csd]: apcu crashes (SIGSEGV) php/Apache on memory allocation failures

From: Date: Thu, 29 Sep 2016 09:49:12 +0000
Subject: Bug #72801 [Asn->Csd]: apcu crashes (SIGSEGV) php/Apache on memory allocation failures
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-204335@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=72801&edit=1 ID: 72801 Updated by: krakjoe@php.net Reported by: jaromird at microsoft dot com Summary: apcu crashes (SIGSEGV) php/Apache on memory allocation failures -Status: Assigned +Status: Closed Type: Bug Package: Reproducible crash Operating System: Mac OS X PHP Version: 7.0.9 Assigned To: krakjoe Block user comment: N Private report: N New Comment: The fix for this bug has been committed. Snapshots of the sources are packaged every three hours; this change will be in the next snapshot. You can grab the snapshot at http://snaps.php.net/. For Windows: http://windows.php.net/snapshots/ Thank you for the report, and for helping us make PHP better. Sorry about the delay, thanks for the patch ;) Previous Comments: ------------------------------------------------------------------------ [2016-08-10 12:03:16] nikic@php.net Not seeing apcu in the package list, so assigning this to joe directly. ------------------------------------------------------------------------ [2016-08-10 11:29:45] jaromird at microsoft dot com Tested with apcu 5.1.5 ------------------------------------------------------------------------ [2016-08-10 11:28:01] jaromird at microsoft dot com Description: ------------ Started seeing more frequent Apache crashes after upgrade to PHP 7.0 for one of our applications which makes heavy use of apc cache. After investigation, found a reproduction script to trigger segmentation fault eventually. Late apcu code inspection revealed that code doesn't check for memory allocation failures on many places. Typical case for example: string duplication fails in apcu_store(), code then inserts zval with NULL value into cache, then apcu_fetch() crashes when dereferencing the value. I hope I've covered all necessary places in the patch, but surely would suggest close review. So far only the case triggered by the below test is really tested. Test script: --------------- <?php /* Might need tweaking to trigger the memory allocation failure ini settings: memory_limit = 4512M apcu shared memory size default - 128M */ $f = str_repeat('c', 800 * 1024 * 1024 ); apcu_store('aaa', $f, 5); $s = apcu_fetch('aaa'); echo ($s == $f) ? "same" : "different"; Expected result: ---------------- script running to completion, returning "same" if no memory problem, "different" if memory allocation failure in apc_fetch() Actual result: -------------- Segmentation fault: 11 ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=72801&edit=1

« previous php.bugs (#204335) next »