Bug #74008 [Fbk->NoF]: Segmentation fault using Drupal 7
| From: | php-bugs at lists dot php dot net | Date: | Sun, 30 Jul 2017 04:22:27 +0000 |
| Subject: | Bug #74008 [Fbk->NoF]: Segmentation fault using Drupal 7 | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-210416@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=74008&edit=1
ID: 74008
Updated by: php-bugs@lists.php.net
Reported by: pierre at brin-de-toile dot fr
Summary: Segmentation fault using Drupal 7
-Status: Feedback
+Status: No Feedback
Type: Bug
Package: Reproducible crash
Operating System: Debian Jessie 64 bits
PHP Version: 7.0.15
Private report: N
New Comment:
No feedback was provided. The bug is being suspended because
we assume that you are no longer experiencing the problem.
If this is not the case and you are able to provide the
information that was requested earlier, please do so and
change the status of the bug back to "Re-Opened". Thank you.
Previous Comments:
------------------------------------------------------------------------
[2017-07-26 22:02:33] mbreden at acromediainc dot com
I also appear to be suffering from this problem, although I do not have memcache enabled at all.
Software
==========================================
Happens on Ubuntu 16.04 & 14.04 at least
Drupal 7.56
Commerce 1.13
Commerce Discount 1.0-alpha8
Commerce Discount Extra 1.0-rc4
PHP - Tested with fpm w/nginx and cli w/ built in server: 7.0.18, 7.0.21, 7.1.7
==========================================
The bug is similar to the first story - multiple discounts being applied to an order, and PHP often
segfaults in product pages, the cart, and checkout.
The problem appears to be happening with the zend memory manager.
With "export USE_ZEND_ALLOC=0" it does not happen.
It does also not happen if the garbage collector is disabled.
ini_set('zend.enable_gc', 0);
Valgrind also can't be run with zend memory manager turned off as per https://bugs.php.net/bugs-getting-valgrind-log.php
as the problem seems to be stemming there - with zend mm turned off, there's no issue.
A valgrind memcheck gives this log:
==19806== Memcheck, a memory error detector
==19806== Copyright (C) 2002-2017, and GNU GPL'd, by Julian Seward et al.
==19806== Using Valgrind-3.13.0 and LibVEX; rerun with -h for copyright info
==19806== Command: /usr/bin/php7.0 -S localhost:3000
==19806== Parent PID: 18844
==19806==
==19806== Invalid read of size 8
==19806== at 0x3468F4: zend_mm_alloc_small (zend_alloc.c:1306)
==19806== by 0x3468F4: zend_mm_alloc_heap (zend_alloc.c:1377)
==19806== by 0x3468F4: _emalloc (zend_alloc.c:2461)
==19806== by 0x2F9718: zend_string_alloc (zend_string.h:121)
==19806== by 0x2F9718: zend_string_init (zend_string.h:157)
==19806== by 0x2F9718: php_var_unserialize_internal (var_unserializer.c:1047)
==19806== by 0x2F989E: process_nested_data (var_unserializer.c:401)
==19806== by 0x2F989E: php_var_unserialize_internal (var_unserializer.c:940)
==19806== by 0x2F989E: process_nested_data (var_unserializer.c:401)
==19806== by 0x2F989E: php_var_unserialize_internal (var_unserializer.c:940)
==19806== by 0x2F989E: process_nested_data (var_unserializer.c:401)
==19806== by 0x2F989E: php_var_unserialize_internal (var_unserializer.c:940)
==19806== by 0x2EA95F: zif_unserialize (var.c:1076)
==19806== by 0x3BA3AC: ZEND_DO_ICALL_SPEC_HANDLER (zend_vm_execute.h:586)
==19806== by 0x3AB50A: execute_ex (zend_vm_execute.h:414)
==19806== by 0x3FFC86: zend_execute (zend_vm_execute.h:458)
==19806== by 0x36AD42: zend_execute_scripts (zend.c:1443)
==19806== by 0x309E9F: php_execute_script (main.c:2492)
==19806== by 0x4075F9: php_cli_server_dispatch_script (php_cli_server.c:1937)
==19806== by 0x40850A: php_cli_server_dispatch (php_cli_server.c:2111)
==19806== by 0x40850A: php_cli_server_recv_event_read_request (php_cli_server.c:2321)
==19806== by 0x408B2D: php_cli_server_do_event_for_each_fd_callback (php_cli_server.c:2401)
==19806== by 0x4096B8: php_cli_server_poller_iter_on_active (php_cli_server.c:831)
==19806== by 0x4096B8: php_cli_server_do_event_for_each_fd (php_cli_server.c:2424)
==19806== by 0x4096B8: php_cli_server_do_event_loop (php_cli_server.c:2434)
==19806== by 0x4096B8: do_cli_server (php_cli_server.c:2535)
==19806== by 0x1EC975: main (php_cli.c:1350)
==19806== Address 0xc5cf00001f432dff is not stack'd, malloc'd or (recently) free'd
==19806==
==19806==
==19806== Process terminating with default action of signal 11 (SIGSEGV)
==19806== General Protection Fault
==19806== at 0x3468F4: zend_mm_alloc_small (zend_alloc.c:1306)
==19806== by 0x3468F4: zend_mm_alloc_heap (zend_alloc.c:1377)
==19806== by 0x3468F4: _emalloc (zend_alloc.c:2461)
==19806== by 0x2F9718: zend_string_alloc (zend_string.h:121)
==19806== by 0x2F9718: zend_string_init (zend_string.h:157)
==19806== by 0x2F9718: php_var_unserialize_internal (var_unserializer.c:1047)
==19806== by 0x2F989E: process_nested_data (var_unserializer.c:401)
==19806== by 0x2F989E: php_var_unserialize_internal (var_unserializer.c:940)
==19806== by 0x2F989E: process_nested_data (var_unserializer.c:401)
==19806== by 0x2F989E: php_var_unserialize_internal (var_unserializer.c:940)
==19806== by 0x2F989E: process_nested_data (var_unserializer.c:401)
==19806== by 0x2F989E: php_var_unserialize_internal (var_unserializer.c:940)
==19806== by 0x2EA95F: zif_unserialize (var.c:1076)
==19806== by 0x3BA3AC: ZEND_DO_ICALL_SPEC_HANDLER (zend_vm_execute.h:586)
==19806== by 0x3AB50A: execute_ex (zend_vm_execute.h:414)
==19806== by 0x3FFC86: zend_execute (zend_vm_execute.h:458)
==19806== by 0x36AD42: zend_execute_scripts (zend.c:1443)
==19806== by 0x309E9F: php_execute_script (main.c:2492)
==19806== by 0x4075F9: php_cli_server_dispatch_script (php_cli_server.c:1937)
==19806== by 0x40850A: php_cli_server_dispatch (php_cli_server.c:2111)
==19806== by 0x40850A: php_cli_server_recv_event_read_request (php_cli_server.c:2321)
==19806== by 0x408B2D: php_cli_server_do_event_for_each_fd_callback (php_cli_server.c:2401)
==19806== by 0x4096B8: php_cli_server_poller_iter_on_active (php_cli_server.c:831)
==19806== by 0x4096B8: php_cli_server_do_event_for_each_fd (php_cli_server.c:2424)
==19806== by 0x4096B8: php_cli_server_do_event_loop (php_cli_server.c:2434)
==19806== by 0x4096B8: do_cli_server (php_cli_server.c:2535)
==19806== by 0x1EC975: main (php_cli.c:1350)
==19806==
==19806== HEAP SUMMARY:
==19806== in use at exit: 3,601,710 bytes in 28,437 blocks
==19806== total heap usage: 40,253 allocs, 11,816 frees, 15,131,436 bytes allocated
==19806==
==19806== LEAK SUMMARY:
==19806== definitely lost: 0 bytes in 0 blocks
==19806== indirectly lost: 0 bytes in 0 blocks
==19806== possibly lost: 2,344,249 bytes in 17,155 blocks
==19806== still reachable: 1,257,461 bytes in 11,282 blocks
==19806== suppressed: 0 bytes in 0 blocks
==19806== Rerun with --leak-check=full to see details of leaked memory
==19806==
==19806== For counts of detected and suppressed errors, rerun with: -v
==19806== ERROR SUMMARY: 1 errors from 1 contexts (suppressed: 0 from 0)
------------------------------------------------------------------------
[2017-04-24 17:20:44] tomas dot srnka at gmail dot com
Hi,
@kolsys at github posted a patch for this problem for pecl-memcache that we've ported to PHP7.
Give it a try please, it should be fixed now.
https://github.com/websupport-sk/pecl-memcache
Tomas
------------------------------------------------------------------------
[2017-04-20 13:02:55] dmitry@php.net
It looks like an invalid free in memcache.c:476
Most probably it's caused by a bug in reference counting.
==12487== Invalid read of size 1
==12487== at 0x9048FA7: ZEND_FE_FETCH_R_SPEC_VAR_HANDLER (zend_vm_execute.h:16015)
==12487== by 0x9033E0A: execute_ex (zend_vm_execute.h:414)
==12487== by 0x9087B26: zend_execute (zend_vm_execute.h:458)
==12487== by 0x8FF64B3: zend_execute_scripts (zend.c:1437)
==12487== by 0x8F99C6F: php_execute_script (main.c:2492)
==12487== by 0x9089429: php_handler (sapi_apache2.c:678)
==12487== by 0x16268F: ap_run_handler (in /usr/sbin/apache2)
==12487== by 0x162BD8: ap_invoke_handler (in /usr/sbin/apache2)
==12487== by 0x1783DB: ap_internal_redirect (in /usr/sbin/apache2)
==12487== by 0xA869EA1: ??? (in /usr/lib/apache2/modules/mod_rewrite.so)
==12487== by 0x16268F: ap_run_handler (in /usr/sbin/apache2)
==12487== by 0x162BD8: ap_invoke_handler (in /usr/sbin/apache2)
==12487== by 0x178AB1: ap_process_async_request (in /usr/sbin/apache2)
==12487== by 0x178C4F: ap_process_request (in /usr/sbin/apache2)
==12487== by 0x175551: ??? (in /usr/sbin/apache2)
==12487== by 0x16BF3F: ap_run_process_connection (in /usr/sbin/apache2)
==12487== by 0x89A47B9: ??? (in /usr/lib/apache2/modules/mod_mpm_prefork.so)
==12487== by 0x89A4A00: ??? (in /usr/lib/apache2/modules/mod_mpm_prefork.so)
==12487== by 0x89A5666: ??? (in /usr/lib/apache2/modules/mod_mpm_prefork.so)
==12487== by 0x1467ED: ap_run_mpm (in /usr/sbin/apache2)
==12487== by 0x13F5F2: main (in /usr/sbin/apache2)
==12487== Address 0x35a9d265 is 5 bytes inside a block of size 48 free'd
==12487== at 0x4C29E90: free (vg_replace_malloc.c:473)
==12487== by 0x166F8F9C: zend_string_release (zend_string.h:271)
==12487== by 0x166F8F9C: php_mmc_store (memcache.c:476)
==12487== by 0x9078471: ZEND_DO_FCALL_SPEC_HANDLER (zend_vm_execute.h:842)
==12487== by 0x9033E0A: execute_ex (zend_vm_execute.h:414)
==12487== by 0x9087B26: zend_execute (zend_vm_execute.h:458)
==12487== by 0x8FF64B3: zend_execute_scripts (zend.c:1437)
==12487== by 0x8F99C6F: php_execute_script (main.c:2492)
==12487== by 0x9089429: php_handler (sapi_apache2.c:678)
==12487== by 0x16268F: ap_run_handler (in /usr/sbin/apache2)
==12487== by 0x162BD8: ap_invoke_handler (in /usr/sbin/apache2)
==12487== by 0x1783DB: ap_internal_redirect (in /usr/sbin/apache2)
==12487== by 0xA869EA1: ??? (in /usr/lib/apache2/modules/mod_rewrite.so)
==12487== by 0x16268F: ap_run_handler (in /usr/sbin/apache2)
==12487== by 0x162BD8: ap_invoke_handler (in /usr/sbin/apache2)
==12487== by 0x178AB1: ap_process_async_request (in /usr/sbin/apache2)
==12487== by 0x178C4F: ap_process_request (in /usr/sbin/apache2)
==12487== by 0x175551: ??? (in /usr/sbin/apache2)
==12487== by 0x16BF3F: ap_run_process_connection (in /usr/sbin/apache2)
==12487== by 0x89A47B9: ??? (in /usr/lib/apache2/modules/mod_mpm_prefork.so)
==12487== by 0x89A4A00: ??? (in /usr/lib/apache2/modules/mod_mpm_prefork.so)
==12487== by 0x89A5666: ??? (in /usr/lib/apache2/modules/mod_mpm_prefork.so)
==12487== by 0x1467ED: ap_run_mpm (in /usr/sbin/apache2)
==12487== by 0x13F5F2: main (in /usr/sbin/apache2)
------------------------------------------------------------------------
[2017-04-19 16:32:41] dmitry@php.net
It looks like this problem caused by use-after-free or double-free.
It would be great to catch the original source of the problem using valgrind.
Instead of php-fpm, run single process FastCGI server under valgrind and perform few requests that
caused crash (they are going to be served very slow).
$ USE_ZEND_ALLOC=0 valgrind php-cgi -b <listen-socket>
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=74008
--
Edit this bug report at https://bugs.php.net/bug.php?id=74008&edit=1