Bug #73241 [Fbk->Opn]: php-cgi.exe is crashing while the script execution is being finalized

From: Date: Tue, 04 Oct 2016 23:47:44 +0000
Subject: Bug #73241 [Fbk->Opn]: php-cgi.exe is crashing while the script execution is being finalized
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-204458@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=73241&edit=1 ID: 73241 User updated by: petr dot maly at remotehost dot cz Reported by: petr dot maly at remotehost dot cz Summary: php-cgi.exe is crashing while the script execution is being finalized -Status: Feedback +Status: Open Type: Bug Package: COM related Operating System: Windows 10 PHP Version: 7.0.11 Block user comment: N Private report: N New Comment: Thanks for your response. It is really difficult for me to check the latest snapshot, because the environment I use to reproduce this problem, uses many plugins (windows versions) which are not ported to PHP 7.1 yet. However I can check the latest 7.0 snapshot. I am going to provide you memory dump, so be patient, please. Petr Maly Previous Comments: ------------------------------------------------------------------------ [2016-10-04 15:34:25] ab@php.net Thanks for the report. Could you please check the latest snapshots from windows.php.net? If the issue is still there, please share a reproducer - some solution with a test class and php code. Or at least a process dump (you'll need the debug symbols). Thanks. ------------------------------------------------------------------------ [2016-10-04 13:55:05] petr dot maly at remotehost dot cz Description: ------------ When the script uses COM object several times and all the statements are executed, php-cgi.exe crashes while it is shutting down. This causes that Apache returns error 5xx, the script code is executed correctly. The crashing happens randomly. I was inspecting the code of php_com_dotnet extension and I found that the php crashes while it is trying to call destructor on function object: com_handlers.c(237:246): static void function_dtor(zval *zv) { zend_internal_function *f = (zend_internal_function*)Z_PTR_P(zv); zend_string_release(f->function_name); if (f->arg_info) { efree(f->arg_info); } efree(f); } The destructor crashes because f->function_name is NULL (sometimes), therefore zend_string_release is unable to access member variables. Suggested fix: static void function_dtor(zval *zv) { zend_internal_function *f = (zend_internal_function*)Z_PTR_P(zv); if (f->function_name != NULL) { zend_string_release(f->function_name); } if (f->arg_info) { efree(f->arg_info); } efree(f); } Best Regards, Petr Maly ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=73241&edit=1

« previous php.bugs (#204458) next »