Bug #74770 [NEW]: open_basedir causes segfault (11)

From: Date: Sat, 17 Jun 2017 08:47:07 +0000
Subject: Bug #74770 [NEW]: open_basedir causes segfault (11)
Groups: php.bugs 
Request: Send a blank email to php-bugs+get-209557@lists.php.net to get a copy of this message
From:             jerry at jmweb dot net
Operating system: CentOS Linux release 7.1.1503
PHP version:      7.1.6
Package:          Reproducible crash
Bug Type:         Bug
Bug description:open_basedir causes segfault (11)

Description:
------------
PHP causes Apache to randomly exit with Segmentation fault (11) when
serving a PHP file residing in an open_basedir directory. This issue was
not present in PHP 5.6.30. I also confirmed the bug in PHP 7.0.19 and
7.2.0 Alpha1.

This bug is similar to https://bugs.php.net/bug.php?id=48744 BUT
produces a different backtrace. Hence, why I created a new bug report.


PHP Build Summary
-----------------
Configure:
'./configure --enable-debug --prefix=/WAMP/php
--with-apxs2=/WAMP/apache/bin/apxs'

Server API: Apache 2.0 Handler (mod_php)
Loaded Configuration file: none
Thread Safety: enabled

Apache Summary
--------------
Server Version: Apache/2.4.25 (Unix) PHP/7.1.6 OpenSSL/1.0.2l
Compiled with APR Version: 1.5.2
Compiled with APU Version: 1.5.4
MPM Name: event

httpd.conf (relevant settings)
------------------------------
CoreDumpDirectory /tmp/core-dumps
DocumentRoot "/JunkServer/website"

<VirtualHost *:80>

	<Directory "/JunkServer/website">
		php_admin_value open_basedir "/JunkServer/website"
	</Directory>

</VirtualHost>

Test script:
---------------
1. In the DocumentRoot directory, create an empty test.php file.
2. Since the segfault is not consistent, I used apache bench to
reproduce the crash consistently:
	ab -n 10000 -c 5 http://localhost/test.php
3. Observe Apache error log and core dump

4. In httpd.conf, remove/comment php_admin_value open_basedir
"/JunkServer/website"
5. Restart apache
6. Repeat step #2
7. Observe no segfaults in log and no core dumps.

Actual result:
--------------
Apache error log
----------------
[core:notice] AH00051: child pid 18214 exit signal Segmentation fault
(11), possible coredump in /tmp/core-dumps

Backtrace
---------
#0  0x00007f68c9baf325 in zend_mm_free_heap (heap=0x7f6899200040,
ptr=0x1b0de20, __zend_filename=0x7f68ca141ea8
"/install/php-7.1.6/Zend/zend_string.h", __zend_lineno=272, 
    __zend_orig_filename=0x0, __zend_orig_lineno=0) at
/install/php-7.1.6/Zend/zend_alloc.c:1372
#1  0x00007f68c9bb1dac in _efree (ptr=0x1b0de20,
__zend_filename=0x7f68ca141ea8 "/install/php-7.1.6/Zend/zend_string.h",
__zend_lineno=272, __zend_orig_filename=0x0, 
    __zend_orig_lineno=0) at /install/php-7.1.6/Zend/zend_alloc.c:2433
#2  0x00007f68c9c06ad7 in zend_string_release (s=0x1b0de20) at
/install/php-7.1.6/Zend/zend_string.h:272
#3  0x00007f68c9c0b13a in zend_hash_destroy (ht=0x7f687c004558) at
/install/php-7.1.6/Zend/zend_hash.c:1249
#4  0x00007f68c9ce95d9 in destroy_php_config (data=0x7f687c004558) at
/install/php-7.1.6/sapi/apache2handler/apache_config.c:201
#5  0x00007f68cb2c03fe in run_cleanups (cref=<optimized out>) at
memory/unix/apr_pools.c:2352
#6  apr_pool_destroy (pool=0x7f687c0028f8) at
memory/unix/apr_pools.c:814
#7  0x000000000044a1e6 in remove_empty_buckets
(bb=bb@entry=0x7f68a4039b18) at core_filters.c:720
#8  0x000000000044a526 in send_brigade_nonblocking (s=0x7f68a4039290,
bb=bb@entry=0x7f68a4039b18,
bytes_written=bytes_written@entry=0x7f68a4039ad0,
c=c@entry=0x7f68a4039528)
    at core_filters.c:710
#9  0x000000000044b42a in ap_core_output_filter (f=0x7f68a4039970,
new_bb=0x0) at core_filters.c:468
#10 0x000000000046ce17 in process_socket (my_thread_num=6,
my_child_num=1, cs=0x7f68a4039498, sock=<optimized out>, p=<optimized
out>, thd=<optimized out>) at event.c:1116
#11 worker_thread (thd=<optimized out>, dummy=<optimized out>) at
event.c:2001
#12 0x00007f68cac50df5 in start_thread (arg=0x7f68a3fff700) at
pthread_create.c:308
#13 0x00007f68ca77a1ad in clone () at
../sysdeps/unix/sysv/linux/x86_64/clone.S:113


-- 
Edit bug report at https://bugs.php.net/bug.php?id=74770&edit=1
-- 
Try a snapshot (PHP 5.4):   https://bugs.php.net/fix.php?id=74770&r=trysnapshot54
Try a snapshot (PHP 5.5):   https://bugs.php.net/fix.php?id=74770&r=trysnapshot55
Try a snapshot (trunk):     https://bugs.php.net/fix.php?id=74770&r=trysnapshottrunk
Fixed in SVN:               https://bugs.php.net/fix.php?id=74770&r=fixed
Fixed in release:           https://bugs.php.net/fix.php?id=74770&r=alreadyfixed
Need backtrace:             https://bugs.php.net/fix.php?id=74770&r=needtrace
Need Reproduce Script:      https://bugs.php.net/fix.php?id=74770&r=needscript
Try newer version:          https://bugs.php.net/fix.php?id=74770&r=oldversion
Not developer issue:        https://bugs.php.net/fix.php?id=74770&r=support
Expected behavior:          https://bugs.php.net/fix.php?id=74770&r=notwrong
Not enough info:            https://bugs.php.net/fix.php?id=74770&r=notenoughinfo
Submitted twice:            https://bugs.php.net/fix.php?id=74770&r=submittedtwice
register_globals:           https://bugs.php.net/fix.php?id=74770&r=globals
PHP 4 support discontinued: https://bugs.php.net/fix.php?id=74770&r=php4
Daylight Savings:           https://bugs.php.net/fix.php?id=74770&r=dst
IIS Stability:              https://bugs.php.net/fix.php?id=74770&r=isapi
Install GNU Sed:            https://bugs.php.net/fix.php?id=74770&r=gnused
Floating point limitations: https://bugs.php.net/fix.php?id=74770&r=float
No Zend Extensions:         https://bugs.php.net/fix.php?id=74770&r=nozend
MySQL Configuration Error:  https://bugs.php.net/fix.php?id=74770&r=mysqlcfg



Thread (5 messages)

« previous php.bugs (#209557) next »