Bug #73933 [Com]: error/segfault with ldap_mod_replace and opcache
Edit report at https://bugs.php.net/bug.php?id=73933&edit=1
ID: 73933
Comment by: ryan dot brothers at gmail dot com
Reported by: ryan dot brothers at gmail dot com
Summary: error/segfault with ldap_mod_replace and opcache
Status: Open
Type: Bug
Package: opcache
Operating System: Linux
PHP Version: 7.1.0
Block user comment: N
Private report: N
New Comment:
Thanks. Yes, if I do opcache.protect_memory=1, then the segfault happens every time when running
over CLI. You should be able to reproduce without a working LDAP server. In my script above,
127.0.0.1:5000 is just a made-up port with nothing listening on it. I'm running this to cause
the segfault:
php -n -d zend_extension=opcache.so -d opcache.enable_cli=1 -d opcache.protect_memory=1 ldap.php
where ldap.php is my test script above.
Previous Comments:
------------------------------------------------------------------------
[2017-01-14 12:39:03] nikic@php.net
Can you do a run with -d opcache.protect_memory=1 and see if there's a consistent bus error?
From a quick look, php_ldap_do_modify() is doing in-place string conversions on array elements,
which may lead to SHM corruption of immutable arrays. If this is indeed the problem, this should be
easy to fix by someone with a working ldap setup by replace convert_to_string_ex with
zval_get_string.
------------------------------------------------------------------------
[2017-01-14 11:37:27] ryan dot brothers at gmail dot com
Description:
------------
I am running into an intermittent issue when using ldap_mod_replace with opcache enabled over
php-fpm. Sometimes the script succeeds and other times, the same script fails or has a segfault.
It's tricky to simulate, but I believe the below script shows the issue. The script returns
the error "Can't contact LDAP server" correctly on the first run, but later runs
sometime return the error "Encoding error" or a segfault. I was expecting the error
message to be the same on each run.
The issue only occurs with opcache enabled. When opcache is disabled, the error message is the same
on each run.
The issue also only happens over php-fpm. When I run the script over CLI, the error message is the
same on each run.
I am running PHP 7.1 on CentOS 7, but the problem appears to have started in PHP 7 as PHP 5.6.29
seems ok.
Test script:
---------------
<?php
define('AAA', 1);
error_reporting(E_ALL);
$ldap = ldap_connect('127.0.0.1', 5000);
ldap_mod_replace($ldap, null, array(
'lockoutTime' => array(0),
));
ldap_close($ldap);
Expected result:
----------------
Warning: ldap_mod_replace(): Modify: Can't contact LDAP server in /var/www/html/ldap.php on
line 9
Actual result:
--------------
Sometimes:
Warning: ldap_mod_replace(): Modify: Can't contact LDAP server in /var/www/html/ldap.php on
line 9
Other times:
Warning: ldap_mod_replace(): Modify: Encoding error in /var/www/html/ldap.php on line 9
or a segfault
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=73933&edit=1
Thread (10 messages)