Bug #74008 [Com]: Segmentation fault using Drupal 7

From: Date: Wed, 26 Jul 2017 22:02:39 +0000
Subject: Bug #74008 [Com]: Segmentation fault using Drupal 7
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-210361@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=74008&edit=1 ID: 74008 Comment by: mbreden at acromediainc dot com Reported by: pierre at brin-de-toile dot fr Summary: Segmentation fault using Drupal 7 Status: Feedback Type: Bug Package: Reproducible crash Operating System: Debian Jessie 64 bits PHP Version: 7.0.15 Block user comment: N Private report: N New Comment: I also appear to be suffering from this problem, although I do not have memcache enabled at all. Software ========================================== Happens on Ubuntu 16.04 & 14.04 at least Drupal 7.56 Commerce 1.13 Commerce Discount 1.0-alpha8 Commerce Discount Extra 1.0-rc4 PHP - Tested with fpm w/nginx and cli w/ built in server: 7.0.18, 7.0.21, 7.1.7 ========================================== The bug is similar to the first story - multiple discounts being applied to an order, and PHP often segfaults in product pages, the cart, and checkout. The problem appears to be happening with the zend memory manager. With "export USE_ZEND_ALLOC=0" it does not happen. It does also not happen if the garbage collector is disabled. ini_set('zend.enable_gc', 0); Valgrind also can't be run with zend memory manager turned off as per https://bugs.php.net/bugs-getting-valgrind-log.php as the problem seems to be stemming there - with zend mm turned off, there's no issue. A valgrind memcheck gives this log: ==19806== Memcheck, a memory error detector ==19806== Copyright (C) 2002-2017, and GNU GPL'd, by Julian Seward et al. ==19806== Using Valgrind-3.13.0 and LibVEX; rerun with -h for copyright info ==19806== Command: /usr/bin/php7.0 -S localhost:3000 ==19806== Parent PID: 18844 ==19806== ==19806== Invalid read of size 8 ==19806== at 0x3468F4: zend_mm_alloc_small (zend_alloc.c:1306) ==19806== by 0x3468F4: zend_mm_alloc_heap (zend_alloc.c:1377) ==19806== by 0x3468F4: _emalloc (zend_alloc.c:2461) ==19806== by 0x2F9718: zend_string_alloc (zend_string.h:121) ==19806== by 0x2F9718: zend_string_init (zend_string.h:157) ==19806== by 0x2F9718: php_var_unserialize_internal (var_unserializer.c:1047) ==19806== by 0x2F989E: process_nested_data (var_unserializer.c:401) ==19806== by 0x2F989E: php_var_unserialize_internal (var_unserializer.c:940) ==19806== by 0x2F989E: process_nested_data (var_unserializer.c:401) ==19806== by 0x2F989E: php_var_unserialize_internal (var_unserializer.c:940) ==19806== by 0x2F989E: process_nested_data (var_unserializer.c:401) ==19806== by 0x2F989E: php_var_unserialize_internal (var_unserializer.c:940) ==19806== by 0x2EA95F: zif_unserialize (var.c:1076) ==19806== by 0x3BA3AC: ZEND_DO_ICALL_SPEC_HANDLER (zend_vm_execute.h:586) ==19806== by 0x3AB50A: execute_ex (zend_vm_execute.h:414) ==19806== by 0x3FFC86: zend_execute (zend_vm_execute.h:458) ==19806== by 0x36AD42: zend_execute_scripts (zend.c:1443) ==19806== by 0x309E9F: php_execute_script (main.c:2492) ==19806== by 0x4075F9: php_cli_server_dispatch_script (php_cli_server.c:1937) ==19806== by 0x40850A: php_cli_server_dispatch (php_cli_server.c:2111) ==19806== by 0x40850A: php_cli_server_recv_event_read_request (php_cli_server.c:2321) ==19806== by 0x408B2D: php_cli_server_do_event_for_each_fd_callback (php_cli_server.c:2401) ==19806== by 0x4096B8: php_cli_server_poller_iter_on_active (php_cli_server.c:831) ==19806== by 0x4096B8: php_cli_server_do_event_for_each_fd (php_cli_server.c:2424) ==19806== by 0x4096B8: php_cli_server_do_event_loop (php_cli_server.c:2434) ==19806== by 0x4096B8: do_cli_server (php_cli_server.c:2535) ==19806== by 0x1EC975: main (php_cli.c:1350) ==19806== Address 0xc5cf00001f432dff is not stack'd, malloc'd or (recently) free'd ==19806== ==19806== ==19806== Process terminating with default action of signal 11 (SIGSEGV) ==19806== General Protection Fault ==19806== at 0x3468F4: zend_mm_alloc_small (zend_alloc.c:1306) ==19806== by 0x3468F4: zend_mm_alloc_heap (zend_alloc.c:1377) ==19806== by 0x3468F4: _emalloc (zend_alloc.c:2461) ==19806== by 0x2F9718: zend_string_alloc (zend_string.h:121) ==19806== by 0x2F9718: zend_string_init (zend_string.h:157) ==19806== by 0x2F9718: php_var_unserialize_internal (var_unserializer.c:1047) ==19806== by 0x2F989E: process_nested_data (var_unserializer.c:401) ==19806== by 0x2F989E: php_var_unserialize_internal (var_unserializer.c:940) ==19806== by 0x2F989E: process_nested_data (var_unserializer.c:401) ==19806== by 0x2F989E: php_var_unserialize_internal (var_unserializer.c:940) ==19806== by 0x2F989E: process_nested_data (var_unserializer.c:401) ==19806== by 0x2F989E: php_var_unserialize_internal (var_unserializer.c:940) ==19806== by 0x2EA95F: zif_unserialize (var.c:1076) ==19806== by 0x3BA3AC: ZEND_DO_ICALL_SPEC_HANDLER (zend_vm_execute.h:586) ==19806== by 0x3AB50A: execute_ex (zend_vm_execute.h:414) ==19806== by 0x3FFC86: zend_execute (zend_vm_execute.h:458) ==19806== by 0x36AD42: zend_execute_scripts (zend.c:1443) ==19806== by 0x309E9F: php_execute_script (main.c:2492) ==19806== by 0x4075F9: php_cli_server_dispatch_script (php_cli_server.c:1937) ==19806== by 0x40850A: php_cli_server_dispatch (php_cli_server.c:2111) ==19806== by 0x40850A: php_cli_server_recv_event_read_request (php_cli_server.c:2321) ==19806== by 0x408B2D: php_cli_server_do_event_for_each_fd_callback (php_cli_server.c:2401) ==19806== by 0x4096B8: php_cli_server_poller_iter_on_active (php_cli_server.c:831) ==19806== by 0x4096B8: php_cli_server_do_event_for_each_fd (php_cli_server.c:2424) ==19806== by 0x4096B8: php_cli_server_do_event_loop (php_cli_server.c:2434) ==19806== by 0x4096B8: do_cli_server (php_cli_server.c:2535) ==19806== by 0x1EC975: main (php_cli.c:1350) ==19806== ==19806== HEAP SUMMARY: ==19806== in use at exit: 3,601,710 bytes in 28,437 blocks ==19806== total heap usage: 40,253 allocs, 11,816 frees, 15,131,436 bytes allocated ==19806== ==19806== LEAK SUMMARY: ==19806== definitely lost: 0 bytes in 0 blocks ==19806== indirectly lost: 0 bytes in 0 blocks ==19806== possibly lost: 2,344,249 bytes in 17,155 blocks ==19806== still reachable: 1,257,461 bytes in 11,282 blocks ==19806== suppressed: 0 bytes in 0 blocks ==19806== Rerun with --leak-check=full to see details of leaked memory ==19806== ==19806== For counts of detected and suppressed errors, rerun with: -v ==19806== ERROR SUMMARY: 1 errors from 1 contexts (suppressed: 0 from 0) Previous Comments: ------------------------------------------------------------------------ [2017-04-24 17:20:44] tomas dot srnka at gmail dot com Hi, @kolsys at github posted a patch for this problem for pecl-memcache that we've ported to PHP7. Give it a try please, it should be fixed now. https://github.com/websupport-sk/pecl-memcache Tomas ------------------------------------------------------------------------ [2017-04-20 13:02:55] dmitry@php.net It looks like an invalid free in memcache.c:476 Most probably it's caused by a bug in reference counting. ==12487== Invalid read of size 1 ==12487== at 0x9048FA7: ZEND_FE_FETCH_R_SPEC_VAR_HANDLER (zend_vm_execute.h:16015) ==12487== by 0x9033E0A: execute_ex (zend_vm_execute.h:414) ==12487== by 0x9087B26: zend_execute (zend_vm_execute.h:458) ==12487== by 0x8FF64B3: zend_execute_scripts (zend.c:1437) ==12487== by 0x8F99C6F: php_execute_script (main.c:2492) ==12487== by 0x9089429: php_handler (sapi_apache2.c:678) ==12487== by 0x16268F: ap_run_handler (in /usr/sbin/apache2) ==12487== by 0x162BD8: ap_invoke_handler (in /usr/sbin/apache2) ==12487== by 0x1783DB: ap_internal_redirect (in /usr/sbin/apache2) ==12487== by 0xA869EA1: ??? (in /usr/lib/apache2/modules/mod_rewrite.so) ==12487== by 0x16268F: ap_run_handler (in /usr/sbin/apache2) ==12487== by 0x162BD8: ap_invoke_handler (in /usr/sbin/apache2) ==12487== by 0x178AB1: ap_process_async_request (in /usr/sbin/apache2) ==12487== by 0x178C4F: ap_process_request (in /usr/sbin/apache2) ==12487== by 0x175551: ??? (in /usr/sbin/apache2) ==12487== by 0x16BF3F: ap_run_process_connection (in /usr/sbin/apache2) ==12487== by 0x89A47B9: ??? (in /usr/lib/apache2/modules/mod_mpm_prefork.so) ==12487== by 0x89A4A00: ??? (in /usr/lib/apache2/modules/mod_mpm_prefork.so) ==12487== by 0x89A5666: ??? (in /usr/lib/apache2/modules/mod_mpm_prefork.so) ==12487== by 0x1467ED: ap_run_mpm (in /usr/sbin/apache2) ==12487== by 0x13F5F2: main (in /usr/sbin/apache2) ==12487== Address 0x35a9d265 is 5 bytes inside a block of size 48 free'd ==12487== at 0x4C29E90: free (vg_replace_malloc.c:473) ==12487== by 0x166F8F9C: zend_string_release (zend_string.h:271) ==12487== by 0x166F8F9C: php_mmc_store (memcache.c:476) ==12487== by 0x9078471: ZEND_DO_FCALL_SPEC_HANDLER (zend_vm_execute.h:842) ==12487== by 0x9033E0A: execute_ex (zend_vm_execute.h:414) ==12487== by 0x9087B26: zend_execute (zend_vm_execute.h:458) ==12487== by 0x8FF64B3: zend_execute_scripts (zend.c:1437) ==12487== by 0x8F99C6F: php_execute_script (main.c:2492) ==12487== by 0x9089429: php_handler (sapi_apache2.c:678) ==12487== by 0x16268F: ap_run_handler (in /usr/sbin/apache2) ==12487== by 0x162BD8: ap_invoke_handler (in /usr/sbin/apache2) ==12487== by 0x1783DB: ap_internal_redirect (in /usr/sbin/apache2) ==12487== by 0xA869EA1: ??? (in /usr/lib/apache2/modules/mod_rewrite.so) ==12487== by 0x16268F: ap_run_handler (in /usr/sbin/apache2) ==12487== by 0x162BD8: ap_invoke_handler (in /usr/sbin/apache2) ==12487== by 0x178AB1: ap_process_async_request (in /usr/sbin/apache2) ==12487== by 0x178C4F: ap_process_request (in /usr/sbin/apache2) ==12487== by 0x175551: ??? (in /usr/sbin/apache2) ==12487== by 0x16BF3F: ap_run_process_connection (in /usr/sbin/apache2) ==12487== by 0x89A47B9: ??? (in /usr/lib/apache2/modules/mod_mpm_prefork.so) ==12487== by 0x89A4A00: ??? (in /usr/lib/apache2/modules/mod_mpm_prefork.so) ==12487== by 0x89A5666: ??? (in /usr/lib/apache2/modules/mod_mpm_prefork.so) ==12487== by 0x1467ED: ap_run_mpm (in /usr/sbin/apache2) ==12487== by 0x13F5F2: main (in /usr/sbin/apache2) ------------------------------------------------------------------------ [2017-04-19 16:32:41] dmitry@php.net It looks like this problem caused by use-after-free or double-free. It would be great to catch the original source of the problem using valgrind. Instead of php-fpm, run single process FastCGI server under valgrind and perform few requests that caused crash (they are going to be served very slow). $ USE_ZEND_ALLOC=0 valgrind php-cgi -b <listen-socket> ------------------------------------------------------------------------ [2017-04-18 17:06:07] kol at nextmail dot ru Same issue. More often on requests to MySQL via PDO. (gdb) l 1301 } while (0); 1302 #endif 1303 1304 if (EXPECTED(heap->free_slot[bin_num] != NULL)) { 1305 zend_mm_free_slot *p = heap->free_slot[bin_num]; 1306 heap->free_slot[bin_num] = p->next_free_slot; 1307 return (void*)p; 1308 } else { 1309 return zend_mm_alloc_small_slow(heap, bin_num ZEND_FILE_LINE_RELAY_CC ZEND_FILE_LINE_ORIG_RELAY_CC); 1310 } (gdb) p bin_num $1 = 7 (gdb) p *heap $2 = {use_custom_heap = 0, storage = 0x0, size = 8688248, peak = 8874560, free_slot = {0x7f88dfe62278, 0x7f88dfe698a0, 0x7f88581db900, 0x7f88576c0900, 0x7f88576d4ac8, 0x7f8857682db0, 0x7f885760fb28, 0x1, 0x7f88dffe67d0, 0x7f8857662b40, 0x7f8857629f50, 0x7f88dfe6ef80, 0x7f8858072dc0, 0x7f88dfea5a80, 0x7f8857952b60, 0x7f8857959300, 0x7f88578fd4c0, 0x7f88dfe9b100, 0x7f88dff6f540, 0x7f88dfe9f600, 0x7f8857c0a480, 0x7f88dfed3a00, 0x7f8857992380, 0x7f88dfed4400, 0x7f88576cb400, 0x7f88dfed6000, 0x7f88dfed9000, 0x7f88dfee0000, 0x0, 0x7f8857843c00}, real_size = 4194304, real_peak = 4194304, limit = 134217728, overflow = 0, huge_list = 0x0, main_chunk = 0x7f88dfe00000, cached_chunks = 0x0, chunks_count = 5, peak_chunks_count = 5, cached_chunks_count = 0, avg_chunks_count = 4.2484463100770391, custom_heap = {std = {_malloc = 0x0, _free = 0x0, _realloc = 0x0}, debug = {_malloc = 0x0, _free = 0x0, _realloc = 0x0}}} (gdb) p p $3 = (zend_mm_free_slot *) 0x1 (gdb) p *p Cannot access memory at address 0x1 ------------------------------------------------------------------------ [2017-02-21 14:30:42] tim at netlog dot com FYI the issue still occurs with 7.0.16. ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=74008 -- Edit this bug report at https://bugs.php.net/bug.php?id=74008&edit=1

« previous php.bugs (#210361) next »