Edit report at https://bugs.php.net/bug.php?id=71129&edit=1
ID: 71129
Comment by: maroszek at gmx dot net
Reported by: maroszek at gmx dot net
Summary: Segmentation fault on ZTS Embed SAPI
Status: Re-Opened
Type: Bug
Package: Reproducible crash
Operating System: OS X 10.11
PHP Version: 7.0.0
Block user comment: N
Private report: N
New Comment:
@ab: I've somehow missed that you already proposed a patch. After applying it everything looks
fine on my linux box. Any chance to get this merged?
Thank!
Previous Comments:
------------------------------------------------------------------------
[2017-01-20 14:09:44] maroszek at gmx dot net
I forgot to mention that this issue is also available on Linux (Ubuntu 16.04)
------------------------------------------------------------------------
[2017-01-20 14:08:19] maroszek at gmx dot net
I updated the code for PHP 7.1.1. The issue remains.
Gist: https://gist.github.com/paresy/b4babb919a86e9764bc4
Needed fix: https://bugs.php.net/bug.php?id=71041
Build: g++ crash.cpp -Imain -ITSRM -IZend -I. --std=c++11 -Llibs -lphp7 -lxml2 -lresolv -ldl
-pthread -fpermissive
Run: ./a.out
Crash:
(gdb) bt
#0 zend_mm_free_heap (ptr=0xf3c080, heap=0x7fffe9600040)
at /home/user/Downloads/php-7.1.1/Zend/zend_alloc.c:1374
#1 _efree (ptr=0xf3c080)
at /home/user/Downloads/php-7.1.1/Zend/zend_alloc.c:2433
#2 0x0000000000490405 in zend_string_release (s=<optimized out>)
at /home/user/Downloads/php-7.1.1/Zend/zend_string.h:272
#3 _zend_hash_del_el_ex (prev=<optimized out>, p=<optimized out>,
idx=<optimized out>, ht=<optimized out>)
at /home/user/Downloads/php-7.1.1/Zend/zend_hash.c:992
#4 _zend_hash_del_el (p=0x7fffe9656120, idx=1, ht=0x7fffc8025140)
at /home/user/Downloads/php-7.1.1/Zend/zend_hash.c:1021
#5 zend_hash_graceful_reverse_destroy (ht=0x7fffc8025140)
at /home/user/Downloads/php-7.1.1/Zend/zend_hash.c:1477
#6 0x000000000046c1f5 in shutdown_executor ()
at /home/user/Downloads/php-7.1.1/Zend/zend_execute_API.c:279
#7 0x000000000047daab in zend_deactivate ()
at /home/user/Downloads/php-7.1.1/Zend/zend.c:997
#8 0x0000000000417fe9 in php_request_shutdown (dummy=<optimized out>)
at /home/user/Downloads/php-7.1.1/main/main.c:1877
#9 0x0000000000414364 in main::{lambda()#1}::operator()() const ()
#10 0x000000000041548c in void std::_Bind_simple<main::{lambda()#1}
()>::_M_invoke<>(std::_Index_tuple<>) ()
#11 0x00000000004153e2 in std::_Bind_simple<main::{lambda()#1} ()>::operator()() ()
#12 0x0000000000415372 in std::thread::_Impl<std::_Bind_simple<main::{lambda()#1} ()>
>::_M_run() ()
#13 0x00007ffff7331930 in ?? () from /usr/lib/x86_64-linux-gnu/libstdc++.so.6
#14 0x00007ffff6b406ba in start_thread (arg=0x7fffeb7fe700)
at pthread_create.c:333
Thanks for any hints on the issue!
------------------------------------------------------------------------
[2017-01-16 23:01:25] ejrx7753 at gmail dot com
Adding the lines
php_embed_module.ub_write = php_embed_ub_write;
php_embed_module.flush = php_embed_flush;
after
php_embed_init
works so long as nothing is done with the output. Uncommenting "std::cout << str;"
inside of php_embed_ub_write causes a segmentation fault "pointer being freed was not
allocated" reliably inside the shutdown executor.
------------------------------------------------------------------------
[2017-01-16 22:06:11] ejrx7753 at gmail dot com
Looking through the "php_embed_init" function, it is more or less exactly the same as the
code provided, with the clear exception of a few signalling changes.
In particular,
signal(SIGPIPE, SIG_IGN);
and
zend_signal_startup();
A minor difference is the code
(void)ts_resource(0);
ZEND_TSRMLS_CACHE_UPDATE();
and a malloc on ini_entries.
Does this not suggest that the embed module should get its own initializer, ie.
php_embed_init(&php_embed_module) to init the signals, or that embed_init() [no args} should be
created to run before sapi startup to call the private signalling code and whatever other steps will
arise?
------------------------------------------------------------------------
[2017-01-16 16:43:54] ejrx7753 at gmail dot com
Confirmed that using the code
int argc2 = 1;
char* text = "embed4";
char *argv2[2] = { text, NULL };
php_embed_init(argc2, argv2);
to replace sapi_startup and php_embed_module.startup and deleting the "php_embed_module"
struct (duplicate symbol error) allows the code to work.
I have created a sample file which can test both versions (http://pastebin.com/8sHjP9Jy).
When run with
#define TEST1 0
the test fails, but when run with
#define TEST1 1
it passses. In my case, the script was "echo 1" and proceeded to give an infinite loop of
1s to the std out. The question also needs addressing whether or not we can set the embed module
elements and use embed init. I think so, but it is another difference between the code peices.
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=71129
--
Edit this bug report at https://bugs.php.net/bug.php?id=71129&edit=1