Bug #71129 [Com]: Segmentation fault on ZTS Embed SAPI

From: Date: Fri, 20 Jan 2017 14:17:12 +0000
Subject: Bug #71129 [Com]: Segmentation fault on ZTS Embed SAPI
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-206759@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=71129&edit=1

 ID:                 71129
 Comment by:         maroszek at gmx dot net
 Reported by:        maroszek at gmx dot net
 Summary:            Segmentation fault on ZTS Embed SAPI
 Status:             Re-Opened
 Type:               Bug
 Package:            Reproducible crash
 Operating System:   OS X 10.11
 PHP Version:        7.0.0
 Block user comment: N
 Private report:     N

 New Comment:

@ab:  I've somehow missed that you already proposed a patch. After applying it everything looks
fine on my linux box. Any chance to get this merged?

Thank!


Previous Comments:
------------------------------------------------------------------------
[2017-01-20 14:09:44] maroszek at gmx dot net

I forgot to mention that this issue is also available on Linux (Ubuntu 16.04)

------------------------------------------------------------------------
[2017-01-20 14:08:19] maroszek at gmx dot net

I updated the code for PHP 7.1.1. The issue remains.

Gist: https://gist.github.com/paresy/b4babb919a86e9764bc4
Needed fix: https://bugs.php.net/bug.php?id=71041
Build: g++ crash.cpp -Imain -ITSRM -IZend -I. --std=c++11 -Llibs -lphp7 -lxml2 -lresolv -ldl
-pthread -fpermissive
Run: ./a.out

Crash:
(gdb) bt
#0  zend_mm_free_heap (ptr=0xf3c080, heap=0x7fffe9600040)
    at /home/user/Downloads/php-7.1.1/Zend/zend_alloc.c:1374
#1  _efree (ptr=0xf3c080)
    at /home/user/Downloads/php-7.1.1/Zend/zend_alloc.c:2433
#2  0x0000000000490405 in zend_string_release (s=<optimized out>)
    at /home/user/Downloads/php-7.1.1/Zend/zend_string.h:272
#3  _zend_hash_del_el_ex (prev=<optimized out>, p=<optimized out>, 
    idx=<optimized out>, ht=<optimized out>)
    at /home/user/Downloads/php-7.1.1/Zend/zend_hash.c:992
#4  _zend_hash_del_el (p=0x7fffe9656120, idx=1, ht=0x7fffc8025140)
    at /home/user/Downloads/php-7.1.1/Zend/zend_hash.c:1021
#5  zend_hash_graceful_reverse_destroy (ht=0x7fffc8025140)
    at /home/user/Downloads/php-7.1.1/Zend/zend_hash.c:1477
#6  0x000000000046c1f5 in shutdown_executor ()
    at /home/user/Downloads/php-7.1.1/Zend/zend_execute_API.c:279
#7  0x000000000047daab in zend_deactivate ()
    at /home/user/Downloads/php-7.1.1/Zend/zend.c:997
#8  0x0000000000417fe9 in php_request_shutdown (dummy=<optimized out>)
    at /home/user/Downloads/php-7.1.1/main/main.c:1877
#9  0x0000000000414364 in main::{lambda()#1}::operator()() const ()
#10 0x000000000041548c in void std::_Bind_simple<main::{lambda()#1}
()>::_M_invoke<>(std::_Index_tuple<>) ()
#11 0x00000000004153e2 in std::_Bind_simple<main::{lambda()#1} ()>::operator()() ()
#12 0x0000000000415372 in std::thread::_Impl<std::_Bind_simple<main::{lambda()#1} ()>
>::_M_run() ()
#13 0x00007ffff7331930 in ?? () from /usr/lib/x86_64-linux-gnu/libstdc++.so.6
#14 0x00007ffff6b406ba in start_thread (arg=0x7fffeb7fe700)
    at pthread_create.c:333

Thanks for any hints on the issue!

------------------------------------------------------------------------
[2017-01-16 23:01:25] ejrx7753 at gmail dot com

Adding the lines

    php_embed_module.ub_write = php_embed_ub_write;
    php_embed_module.flush = php_embed_flush;

after

php_embed_init

works so long as nothing is done with the output. Uncommenting "std::cout << str;"
inside of php_embed_ub_write causes a segmentation fault "pointer being freed was not
allocated" reliably inside the shutdown executor.

------------------------------------------------------------------------
[2017-01-16 22:06:11] ejrx7753 at gmail dot com

Looking through the "php_embed_init" function, it is more or less exactly the same as the
code provided, with the clear exception of a few signalling changes.

In particular,

signal(SIGPIPE, SIG_IGN);

and

zend_signal_startup();

A minor difference is the code

  (void)ts_resource(0);
  ZEND_TSRMLS_CACHE_UPDATE();

and a malloc on ini_entries.

Does this not suggest that the embed module should get its own initializer, ie.
php_embed_init(&php_embed_module) to init the signals, or that embed_init() [no args} should be
created to run before sapi startup to call the private signalling code and whatever other steps will
arise?

------------------------------------------------------------------------
[2017-01-16 16:43:54] ejrx7753 at gmail dot com

Confirmed that using the code

    int argc2 = 1;
    char* text = "embed4";
    char *argv2[2] = { text, NULL };
    php_embed_init(argc2, argv2);

to replace sapi_startup and php_embed_module.startup and deleting the "php_embed_module"
struct (duplicate symbol error) allows the code to work.

I have created a sample file which can test both versions (http://pastebin.com/8sHjP9Jy).

When run with

#define TEST1 0

the test fails, but when run with

#define TEST1 1

it passses. In my case, the script was "echo 1" and proceeded to give an infinite loop of
1s to the std out. The question also needs addressing whether or not we can set the embed module
elements and use embed init. I think so, but it is another difference between the code peices.

------------------------------------------------------------------------


The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at

    https://bugs.php.net/bug.php?id=71129


--
Edit this bug report at https://bugs.php.net/bug.php?id=71129&edit=1


Thread (32 messages)

« previous php.bugs (#206759) next »