Edit report at https://bugs.php.net/bug.php?id=74008&edit=1
ID: 74008
Updated by: kalle@php.net
Reported by: pierre at brin-de-toile dot fr
Summary: Segmentation fault using Drupal 7
-Status: Open
+Status: Feedback
Type: Bug
Package: Reproducible crash
Operating System: Debian Jessie 64 bits
PHP Version: 7.0.15
Block user comment: N
Private report: N
Previous Comments:
------------------------------------------------------------------------
[2017-04-24 17:20:44] tomas dot srnka at gmail dot com
Hi,
@kolsys at github posted a patch for this problem for pecl-memcache that we've ported to PHP7.
Give it a try please, it should be fixed now.
https://github.com/websupport-sk/pecl-memcache
Tomas
------------------------------------------------------------------------
[2017-04-20 13:02:55] dmitry@php.net
It looks like an invalid free in memcache.c:476
Most probably it's caused by a bug in reference counting.
==12487== Invalid read of size 1
==12487== at 0x9048FA7: ZEND_FE_FETCH_R_SPEC_VAR_HANDLER (zend_vm_execute.h:16015)
==12487== by 0x9033E0A: execute_ex (zend_vm_execute.h:414)
==12487== by 0x9087B26: zend_execute (zend_vm_execute.h:458)
==12487== by 0x8FF64B3: zend_execute_scripts (zend.c:1437)
==12487== by 0x8F99C6F: php_execute_script (main.c:2492)
==12487== by 0x9089429: php_handler (sapi_apache2.c:678)
==12487== by 0x16268F: ap_run_handler (in /usr/sbin/apache2)
==12487== by 0x162BD8: ap_invoke_handler (in /usr/sbin/apache2)
==12487== by 0x1783DB: ap_internal_redirect (in /usr/sbin/apache2)
==12487== by 0xA869EA1: ??? (in /usr/lib/apache2/modules/mod_rewrite.so)
==12487== by 0x16268F: ap_run_handler (in /usr/sbin/apache2)
==12487== by 0x162BD8: ap_invoke_handler (in /usr/sbin/apache2)
==12487== by 0x178AB1: ap_process_async_request (in /usr/sbin/apache2)
==12487== by 0x178C4F: ap_process_request (in /usr/sbin/apache2)
==12487== by 0x175551: ??? (in /usr/sbin/apache2)
==12487== by 0x16BF3F: ap_run_process_connection (in /usr/sbin/apache2)
==12487== by 0x89A47B9: ??? (in /usr/lib/apache2/modules/mod_mpm_prefork.so)
==12487== by 0x89A4A00: ??? (in /usr/lib/apache2/modules/mod_mpm_prefork.so)
==12487== by 0x89A5666: ??? (in /usr/lib/apache2/modules/mod_mpm_prefork.so)
==12487== by 0x1467ED: ap_run_mpm (in /usr/sbin/apache2)
==12487== by 0x13F5F2: main (in /usr/sbin/apache2)
==12487== Address 0x35a9d265 is 5 bytes inside a block of size 48 free'd
==12487== at 0x4C29E90: free (vg_replace_malloc.c:473)
==12487== by 0x166F8F9C: zend_string_release (zend_string.h:271)
==12487== by 0x166F8F9C: php_mmc_store (memcache.c:476)
==12487== by 0x9078471: ZEND_DO_FCALL_SPEC_HANDLER (zend_vm_execute.h:842)
==12487== by 0x9033E0A: execute_ex (zend_vm_execute.h:414)
==12487== by 0x9087B26: zend_execute (zend_vm_execute.h:458)
==12487== by 0x8FF64B3: zend_execute_scripts (zend.c:1437)
==12487== by 0x8F99C6F: php_execute_script (main.c:2492)
==12487== by 0x9089429: php_handler (sapi_apache2.c:678)
==12487== by 0x16268F: ap_run_handler (in /usr/sbin/apache2)
==12487== by 0x162BD8: ap_invoke_handler (in /usr/sbin/apache2)
==12487== by 0x1783DB: ap_internal_redirect (in /usr/sbin/apache2)
==12487== by 0xA869EA1: ??? (in /usr/lib/apache2/modules/mod_rewrite.so)
==12487== by 0x16268F: ap_run_handler (in /usr/sbin/apache2)
==12487== by 0x162BD8: ap_invoke_handler (in /usr/sbin/apache2)
==12487== by 0x178AB1: ap_process_async_request (in /usr/sbin/apache2)
==12487== by 0x178C4F: ap_process_request (in /usr/sbin/apache2)
==12487== by 0x175551: ??? (in /usr/sbin/apache2)
==12487== by 0x16BF3F: ap_run_process_connection (in /usr/sbin/apache2)
==12487== by 0x89A47B9: ??? (in /usr/lib/apache2/modules/mod_mpm_prefork.so)
==12487== by 0x89A4A00: ??? (in /usr/lib/apache2/modules/mod_mpm_prefork.so)
==12487== by 0x89A5666: ??? (in /usr/lib/apache2/modules/mod_mpm_prefork.so)
==12487== by 0x1467ED: ap_run_mpm (in /usr/sbin/apache2)
==12487== by 0x13F5F2: main (in /usr/sbin/apache2)
------------------------------------------------------------------------
[2017-04-19 16:32:41] dmitry@php.net
It looks like this problem caused by use-after-free or double-free.
It would be great to catch the original source of the problem using valgrind.
Instead of php-fpm, run single process FastCGI server under valgrind and perform few requests that
caused crash (they are going to be served very slow).
$ USE_ZEND_ALLOC=0 valgrind php-cgi -b <listen-socket>
------------------------------------------------------------------------
[2017-04-18 17:06:07] kol at nextmail dot ru
Same issue. More often on requests to MySQL via PDO.
(gdb) l
1301 } while (0);
1302 #endif
1303
1304 if (EXPECTED(heap->free_slot[bin_num] != NULL)) {
1305 zend_mm_free_slot *p = heap->free_slot[bin_num];
1306 heap->free_slot[bin_num] = p->next_free_slot;
1307 return (void*)p;
1308 } else {
1309 return zend_mm_alloc_small_slow(heap, bin_num ZEND_FILE_LINE_RELAY_CC
ZEND_FILE_LINE_ORIG_RELAY_CC);
1310 }
(gdb) p bin_num
$1 = 7
(gdb) p *heap
$2 = {use_custom_heap = 0, storage = 0x0, size = 8688248, peak = 8874560, free_slot =
{0x7f88dfe62278, 0x7f88dfe698a0, 0x7f88581db900, 0x7f88576c0900, 0x7f88576d4ac8, 0x7f8857682db0,
0x7f885760fb28, 0x1, 0x7f88dffe67d0, 0x7f8857662b40, 0x7f8857629f50, 0x7f88dfe6ef80,
0x7f8858072dc0, 0x7f88dfea5a80, 0x7f8857952b60, 0x7f8857959300, 0x7f88578fd4c0, 0x7f88dfe9b100,
0x7f88dff6f540, 0x7f88dfe9f600, 0x7f8857c0a480, 0x7f88dfed3a00, 0x7f8857992380, 0x7f88dfed4400,
0x7f88576cb400, 0x7f88dfed6000, 0x7f88dfed9000, 0x7f88dfee0000, 0x0,
0x7f8857843c00}, real_size = 4194304, real_peak = 4194304, limit = 134217728, overflow = 0,
huge_list = 0x0, main_chunk = 0x7f88dfe00000, cached_chunks = 0x0, chunks_count = 5,
peak_chunks_count = 5, cached_chunks_count = 0, avg_chunks_count = 4.2484463100770391,
custom_heap = {std = {_malloc = 0x0, _free = 0x0, _realloc = 0x0}, debug = {_malloc = 0x0, _free =
0x0, _realloc = 0x0}}}
(gdb) p p
$3 = (zend_mm_free_slot *) 0x1
(gdb) p *p
Cannot access memory at address 0x1
------------------------------------------------------------------------
[2017-02-21 14:30:42] tim at netlog dot com
FYI the issue still occurs with 7.0.16.
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=74008
--
Edit this bug report at https://bugs.php.net/bug.php?id=74008&edit=1