Bug #74008 [Opn->Fbk]: Segmentation fault using Drupal 7

From: Date: Sun, 23 Jul 2017 02:04:37 +0000
Subject: Bug #74008 [Opn->Fbk]: Segmentation fault using Drupal 7
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-210212@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=74008&edit=1

 ID:                 74008
 Updated by:         kalle@php.net
 Reported by:        pierre at brin-de-toile dot fr
 Summary:            Segmentation fault using Drupal 7
-Status:             Open
+Status:             Feedback
 Type:               Bug
 Package:            Reproducible crash
 Operating System:   Debian Jessie 64 bits
 PHP Version:        7.0.15
 Block user comment: N
 Private report:     N



Previous Comments:
------------------------------------------------------------------------
[2017-04-24 17:20:44] tomas dot srnka at gmail dot com

Hi,

@kolsys at github posted a patch for this problem for pecl-memcache that we've ported to PHP7.
Give it a try please, it should be fixed now.

https://github.com/websupport-sk/pecl-memcache

Tomas

------------------------------------------------------------------------
[2017-04-20 13:02:55] dmitry@php.net

It looks like an invalid free in memcache.c:476
Most probably it's caused by a bug in reference counting.


==12487== Invalid read of size 1
==12487==    at 0x9048FA7: ZEND_FE_FETCH_R_SPEC_VAR_HANDLER (zend_vm_execute.h:16015)
==12487==    by 0x9033E0A: execute_ex (zend_vm_execute.h:414)
==12487==    by 0x9087B26: zend_execute (zend_vm_execute.h:458)
==12487==    by 0x8FF64B3: zend_execute_scripts (zend.c:1437)
==12487==    by 0x8F99C6F: php_execute_script (main.c:2492)
==12487==    by 0x9089429: php_handler (sapi_apache2.c:678)
==12487==    by 0x16268F: ap_run_handler (in /usr/sbin/apache2)
==12487==    by 0x162BD8: ap_invoke_handler (in /usr/sbin/apache2)
==12487==    by 0x1783DB: ap_internal_redirect (in /usr/sbin/apache2)
==12487==    by 0xA869EA1: ??? (in /usr/lib/apache2/modules/mod_rewrite.so)
==12487==    by 0x16268F: ap_run_handler (in /usr/sbin/apache2)
==12487==    by 0x162BD8: ap_invoke_handler (in /usr/sbin/apache2)
==12487==    by 0x178AB1: ap_process_async_request (in /usr/sbin/apache2)
==12487==    by 0x178C4F: ap_process_request (in /usr/sbin/apache2)
==12487==    by 0x175551: ??? (in /usr/sbin/apache2)
==12487==    by 0x16BF3F: ap_run_process_connection (in /usr/sbin/apache2)
==12487==    by 0x89A47B9: ??? (in /usr/lib/apache2/modules/mod_mpm_prefork.so)
==12487==    by 0x89A4A00: ??? (in /usr/lib/apache2/modules/mod_mpm_prefork.so)
==12487==    by 0x89A5666: ??? (in /usr/lib/apache2/modules/mod_mpm_prefork.so)
==12487==    by 0x1467ED: ap_run_mpm (in /usr/sbin/apache2)
==12487==    by 0x13F5F2: main (in /usr/sbin/apache2)
==12487==  Address 0x35a9d265 is 5 bytes inside a block of size 48 free'd
==12487==    at 0x4C29E90: free (vg_replace_malloc.c:473)
==12487==    by 0x166F8F9C: zend_string_release (zend_string.h:271)
==12487==    by 0x166F8F9C: php_mmc_store (memcache.c:476)
==12487==    by 0x9078471: ZEND_DO_FCALL_SPEC_HANDLER (zend_vm_execute.h:842)
==12487==    by 0x9033E0A: execute_ex (zend_vm_execute.h:414)
==12487==    by 0x9087B26: zend_execute (zend_vm_execute.h:458)
==12487==    by 0x8FF64B3: zend_execute_scripts (zend.c:1437)
==12487==    by 0x8F99C6F: php_execute_script (main.c:2492)
==12487==    by 0x9089429: php_handler (sapi_apache2.c:678)
==12487==    by 0x16268F: ap_run_handler (in /usr/sbin/apache2)
==12487==    by 0x162BD8: ap_invoke_handler (in /usr/sbin/apache2)
==12487==    by 0x1783DB: ap_internal_redirect (in /usr/sbin/apache2)
==12487==    by 0xA869EA1: ??? (in /usr/lib/apache2/modules/mod_rewrite.so)
==12487==    by 0x16268F: ap_run_handler (in /usr/sbin/apache2)
==12487==    by 0x162BD8: ap_invoke_handler (in /usr/sbin/apache2)
==12487==    by 0x178AB1: ap_process_async_request (in /usr/sbin/apache2)
==12487==    by 0x178C4F: ap_process_request (in /usr/sbin/apache2)
==12487==    by 0x175551: ??? (in /usr/sbin/apache2)
==12487==    by 0x16BF3F: ap_run_process_connection (in /usr/sbin/apache2)
==12487==    by 0x89A47B9: ??? (in /usr/lib/apache2/modules/mod_mpm_prefork.so)
==12487==    by 0x89A4A00: ??? (in /usr/lib/apache2/modules/mod_mpm_prefork.so)
==12487==    by 0x89A5666: ??? (in /usr/lib/apache2/modules/mod_mpm_prefork.so)
==12487==    by 0x1467ED: ap_run_mpm (in /usr/sbin/apache2)
==12487==    by 0x13F5F2: main (in /usr/sbin/apache2)

------------------------------------------------------------------------
[2017-04-19 16:32:41] dmitry@php.net

It looks like this problem caused by use-after-free or double-free.
It would be great to catch the original source of the problem using valgrind.

Instead of php-fpm, run single process FastCGI server under valgrind and perform few requests that
caused crash (they are going to be served very slow).

$ USE_ZEND_ALLOC=0 valgrind php-cgi -b <listen-socket>

------------------------------------------------------------------------
[2017-04-18 17:06:07] kol at nextmail dot ru

Same issue. More often on requests to MySQL via PDO.

(gdb) l
1301		} while (0);
1302	#endif
1303	
1304		if (EXPECTED(heap->free_slot[bin_num] != NULL)) {
1305			zend_mm_free_slot *p = heap->free_slot[bin_num];
1306			heap->free_slot[bin_num] = p->next_free_slot;
1307			return (void*)p;
1308		} else {
1309			return zend_mm_alloc_small_slow(heap, bin_num ZEND_FILE_LINE_RELAY_CC
ZEND_FILE_LINE_ORIG_RELAY_CC);
1310		}

(gdb) p bin_num
$1 = 7
(gdb) p *heap  
$2 = {use_custom_heap = 0, storage = 0x0, size = 8688248, peak = 8874560, free_slot =
{0x7f88dfe62278, 0x7f88dfe698a0, 0x7f88581db900, 0x7f88576c0900, 0x7f88576d4ac8, 0x7f8857682db0,
0x7f885760fb28, 0x1, 0x7f88dffe67d0, 0x7f8857662b40, 0x7f8857629f50, 0x7f88dfe6ef80, 
    0x7f8858072dc0, 0x7f88dfea5a80, 0x7f8857952b60, 0x7f8857959300, 0x7f88578fd4c0, 0x7f88dfe9b100,
0x7f88dff6f540, 0x7f88dfe9f600, 0x7f8857c0a480, 0x7f88dfed3a00, 0x7f8857992380, 0x7f88dfed4400,
0x7f88576cb400, 0x7f88dfed6000, 0x7f88dfed9000, 0x7f88dfee0000, 0x0, 
    0x7f8857843c00}, real_size = 4194304, real_peak = 4194304, limit = 134217728, overflow = 0,
huge_list = 0x0, main_chunk = 0x7f88dfe00000, cached_chunks = 0x0, chunks_count = 5,
peak_chunks_count = 5, cached_chunks_count = 0, avg_chunks_count = 4.2484463100770391, 
  custom_heap = {std = {_malloc = 0x0, _free = 0x0, _realloc = 0x0}, debug = {_malloc = 0x0, _free =
0x0, _realloc = 0x0}}}


(gdb) p p
$3 = (zend_mm_free_slot *) 0x1

(gdb) p *p   
Cannot access memory at address 0x1

------------------------------------------------------------------------
[2017-02-21 14:30:42] tim at netlog dot com

FYI the issue still occurs with 7.0.16.

------------------------------------------------------------------------


The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at

    https://bugs.php.net/bug.php?id=74008


--
Edit this bug report at https://bugs.php.net/bug.php?id=74008&edit=1


Thread (13 messages)

« previous php.bugs (#210212) next »