Bug #71135 [Com]: Random memory corruption with strings

From: Date: Sun, 10 Sep 2017 09:14:27 +0000
Subject: Bug #71135 [Com]: Random memory corruption with strings
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-211020@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=71135&edit=1

 ID:                 71135
 Comment by:         jjones at smugmug dot com
 Reported by:        iquito at gmx dot net
 Summary:            Random memory corruption with strings
 Status:             Closed
 Type:               Bug
 Package:            opcache
 Operating System:   Debian Jessie
 PHP Version:        7.0.0
 Assigned To:        laruence
 Block user comment: N
 Private report:     N

 New Comment:

I captured another core dump which has different backtrace, but ultimately crashes with a SegFault
due to a string pointer is can't dereference.

#0  0x0000000000bb6763 in ZEND_ECHO_SPEC_CONST_HANDLER ()
    at /home/jjones/ops/ops-tools/deb-build/work/php-7.1.9/Zend/zend_vm_execute.h:2667
#1  0x0000000000ba9a6b in execute_ex (ex=0x7f8f2f415430)
    at /home/jjones/ops/ops-tools/deb-build/work/php-7.1.9/Zend/zend_vm_execute.h:429
#2  0x0000000000c88ec8 in ZEND_INCLUDE_OR_EVAL_SPEC_TMPVAR_HANDLER ()
    at /home/jjones/ops/ops-tools/deb-build/work/php-7.1.9/Zend/zend_vm_execute.h:51699
#3  0x0000000000ba9a6b in execute_ex (ex=0x7f8f2f4153a0)
    at /home/jjones/ops/ops-tools/deb-build/work/php-7.1.9/Zend/zend_vm_execute.h:429
#4  0x0000000000baec11 in ZEND_DO_FCALL_SPEC_RETVAL_USED_HANDLER ()
    at /home/jjones/ops/ops-tools/deb-build/work/php-7.1.9/Zend/zend_vm_execute.h:1076
#5  0x0000000000ba9a6b in execute_ex (ex=0x7f8f2f415300)
    at /home/jjones/ops/ops-tools/deb-build/work/php-7.1.9/Zend/zend_vm_execute.h:429
#6  0x0000000000baec11 in ZEND_DO_FCALL_SPEC_RETVAL_USED_HANDLER ()
    at /home/jjones/ops/ops-tools/deb-build/work/php-7.1.9/Zend/zend_vm_execute.h:1076
#7  0x0000000000ba9a6b in execute_ex (ex=0x7f8f2f415270)
    at /home/jjones/ops/ops-tools/deb-build/work/php-7.1.9/Zend/zend_vm_execute.h:429
#8  0x0000000000baec11 in ZEND_DO_FCALL_SPEC_RETVAL_USED_HANDLER ()
    at /home/jjones/ops/ops-tools/deb-build/work/php-7.1.9/Zend/zend_vm_execute.h:1076
#9  0x0000000000ba9a6b in execute_ex (ex=0x7f8f2f415150)
    at /home/jjones/ops/ops-tools/deb-build/work/php-7.1.9/Zend/zend_vm_execute.h:429
#10 0x0000000000badfa4 in ZEND_DO_FCALL_SPEC_RETVAL_UNUSED_HANDLER ()
    at /home/jjones/ops/ops-tools/deb-build/work/php-7.1.9/Zend/zend_vm_execute.h:949
#11 0x0000000000ba9a6b in execute_ex (ex=0x7f8f2f4150e0)
    at /home/jjones/ops/ops-tools/deb-build/work/php-7.1.9/Zend/zend_vm_execute.h:429
#12 0x0000000000c88ec8 in ZEND_INCLUDE_OR_EVAL_SPEC_TMPVAR_HANDLER ()
    at /home/jjones/ops/ops-tools/deb-build/work/php-7.1.9/Zend/zend_vm_execute.h:51699
#13 0x0000000000ba9a6b in execute_ex (ex=0x7f8f2f415030)
    at /home/jjones/ops/ops-tools/deb-build/work/php-7.1.9/Zend/zend_vm_execute.h:429
#14 0x0000000000baa42b in zend_execute (op_array=0x7f8f2f4731c0, return_value=0x0)
    at /home/jjones/ops/ops-tools/deb-build/work/php-7.1.9/Zend/zend_vm_execute.h:474
#15 0x0000000000b0fcc1 in zend_execute_scripts (type=8, retval=0x0, file_count=3)
    at /home/jjones/ops/ops-tools/deb-build/work/php-7.1.9/Zend/zend.c:1480
#16 0x0000000000a5b290 in php_execute_script (primary_file=0x7ffc59ab28f0)
    at /home/jjones/ops/ops-tools/deb-build/work/php-7.1.9/main/main.c:2552
#17 0x0000000000cb836f in main (argc=2, argv=0x7ffc59ab2be8)
    at /home/jjones/ops/ops-tools/deb-build/work/php-7.1.9/sapi/fpm/fpm/fpm_main.c:1966

some info that might be helpful...

(gdb) list 2667
2662		z = EX_CONSTANT(opline->op1);
2663	
2664		if (Z_TYPE_P(z) == IS_STRING) {
2665			zend_string *str = Z_STR_P(z);
2666	
2667			if (ZSTR_LEN(str) != 0) {
2668				zend_write(ZSTR_VAL(str), ZSTR_LEN(str));
2669			}
2670		} else {
2671			zend_string *str = _zval_get_string_func(z);
(gdb) print *z
$6 = {value = {lval = 140250487923552, dval = 6.9292947895499668e-310, counted = 0x7f8e9c832360, str
= 0x7f8e9c832360, 
    arr = 0x7f8e9c832360, obj = 0x7f8e9c832360, res = 0x7f8e9c832360, ref = 0x7f8e9c832360, ast =
0x7f8e9c832360, zv = 0x7f8e9c832360, 
    ptr = 0x7f8e9c832360, ce = 0x7f8e9c832360, func = 0x7f8e9c832360, ww = {w1 = 2625839968, w2 =
32654}}, u1 = {v = {type = 6 '\006', 
      type_flags = 0 '\000', const_flags = 0 '\000', reserved = 0
'\000'}, type_info = 6}, u2 = {next = 4294967295, 
    cache_slot = 4294967295, lineno = 4294967295, num_args = 4294967295, fe_pos = 4294967295,
fe_iter_idx = 4294967295, 
    access_flags = 4294967295, property_guard = 4294967295, extra = 4294967295}}
(gdb) print z->value->str
$7 = (zend_string *) 0x7f8e9c832360
(gdb) print *z->value->str
Cannot access memory at address 0x7f8e9c832360


Previous Comments:
------------------------------------------------------------------------
[2017-09-10 06:31:44] rasmus@php.net

Is this after a cache full event? As in, when you see this happening, what are the values of these
opcache vars in your phpinfo output?

    OOM restarts
    Hash keys restarts
    Manual restarts

PHP 7.1.x has been running in production on a ton of heavily hit sites with at least some of them
making heavy use of memcached without ever seeing this. The ones I am involved with almost never hit
a cache reset condition, so that might be a difference.

------------------------------------------------------------------------
[2017-09-09 05:37:09] jjones at smugmug dot com

Since posting the previous core dump (and info extracted from it), I found the following in the
source.

ext/opcache/zend_file_cache.c:  op_array~~>refcount = (uint32_t*)(intptr_t)-1;

Zend/zend_execute.c:  #define ZEND_FAKE_OP_ARRAY ((zend_op_array*)(zend_intptr_t)-1)

which explains the 0xffffffff value of the "refcount" field in the failing call.  So
scratch the question I asked about an intended decrement flipping a zero to all 0xff's.

------------------------------------------------------------------------
[2017-09-08 22:37:16] jjones at smugmug dot com

We're running a PHP7.1.9 build on our internal testing servers, preparing for a production
rollout to upgrade from PHP5.6 and are also seeing SegFaults.

Our setup is NGINX/php-fpm and the php-fpm processes sometimes running cleanly for non-trivial
amounts of time, then we'll see or more processes crash before stablizing again.

We have core dumps enabled, have build the binaries with optimization disabled, meaning
"-O0" for the C and C++ compiles.  Ane we are running with
"opcache.protect_memory=1" already, since we were debugging another source of SegFaults
before this use case appeared.

Here's a backtrace from the most recent crash, with a few curious data points that may (or may
not?) be helpful.

This was the last of 5 core dumps in cluster today, so it's possible that it's the victim
of corrupted shared memory rather then the one that caused it in the first place.  The previous core
dump (from a memcache extension issue) was generating core dumps too frequently to save them all. 
So the current setup uses a static name for the core dumps, so the last one is all I have.


Backtrace:

#0  0x0000000000b64983 in zend_inline_hash_func (len=31426464, str=0x7fcf65800001 <error: Cannot
access memory at address 0x7fcf65800001>) at
/home/jjones/ops/ops-tools/deb-build/work/php-7.1.9/Zend/zend_string.h:331
#1  zend_hash_func (str=0x7fcf656e71a0 "", len=32577024) at
/home/jjones/ops/ops-tools/deb-build/work/php-7.1.9/Zend/zend_string.c:34
#2  0x0000000000b3bc9a in zend_string_hash_val (s=0x7fcf656e7188) at
/home/jjones/ops/ops-tools/deb-build/work/php-7.1.9/Zend/zend_string.h:86
#3  zend_hash_find_bucket (key=0x7fcf656e7188, ht=0x1ec34a0) at
/home/jjones/ops/ops-tools/deb-build/work/php-7.1.9/Zend/zend_hash.c:477
#4  zend_hash_find (ht=0x1ec34a0, key=0x7fcf656e7188) at
/home/jjones/ops/ops-tools/deb-build/work/php-7.1.9/Zend/zend_hash.c:1958
#5  0x00007fcf6536cbe5 in zend_accel_class_hash_copy (target=0x1ec34a0, source=0x7fced63878d0,
pCopyConstructor=0x7fcf6536b697 <zend_class_copy_ctor>) at
/home/jjones/ops/ops-tools/deb-build/work/php-7.1.9/ext/opcache/zend_accelerator_util_funcs.c:572
#6  0x00007fcf6536d391 in zend_accel_load_script (persistent_script=0x7fced63877c0,
from_shared_memory=1) at
/home/jjones/ops/ops-tools/deb-build/work/php-7.1.9/ext/opcache/zend_accelerator_util_funcs.c:655
#7  0x00007fcf6534ca87 in persistent_compile_file (file_handle=0x7fff7073a3b0, type=2) at
/home/jjones/ops/ops-tools/deb-build/work/php-7.1.9/ext/opcache/ZendAccelerator.c:1948
#8  0x0000000000a987b6 in compile_filename (type=2, filename=0x7fcf65614790) at
Zend/zend_language_scanner.l:662
#9  0x0000000000ba94c9 in zend_include_or_eval (inc_filename=0x7fcf65614790, type=2) at
/home/jjones/ops/ops-tools/deb-build/work/php-7.1.9/Zend/zend_execute.c:2839
#10 0x0000000000c88862 in ZEND_INCLUDE_OR_EVAL_SPEC_TMPVAR_HANDLER () at
/home/jjones/ops/ops-tools/deb-build/work/php-7.1.9/Zend/zend_vm_execute.h:51660
#11 0x0000000000ba9a6b in execute_ex (ex=0x7fcf656146a0) at
/home/jjones/ops/ops-tools/deb-build/work/php-7.1.9/Zend/zend_vm_execute.h:429
#12 0x00007fcf635e77e0 in hp_execute_ex (execute_data=0x7fcf656146a0) at
/opt/xhprof/build/7.1.6/tideways.c:3603
#13 hp_execute_ex (execute_data=0x7fcf656146a0) at /opt/xhprof/build/7.1.6/tideways.c:3549
#14 0x0000000000aee90e in zend_call_function (fci=0x7fff7073ac50, fci_cache=0x7fff7073ac20) at
/home/jjones/ops/ops-tools/deb-build/work/php-7.1.9/Zend/zend_execute_API.c:855
#15 0x0000000000b4f153 in zend_call_method (object=0x0, obj_ce=0x0, fn_proxy=0x7fcf65663bd0,
function_name=0x7fcf65602a40 "__autoload", function_name_len=10, retval_ptr=0x0,
param_count=1, arg1=0x7fcf65614690, arg2=0x0)
    at /home/jjones/ops/ops-tools/deb-build/work/php-7.1.9/Zend/zend_interfaces.c:99
#16 0x00000000008c3769 in zif_spl_autoload_call (execute_data=0x7fcf65614640,
return_value=0x7fff7073b260) at
/home/jjones/ops/ops-tools/deb-build/work/php-7.1.9/ext/spl/php_spl.c:420
#17 0x0000000000ba612b in execute_internal (execute_data=0x7fcf65614640,
return_value=0x7fff7073b260) at
/home/jjones/ops/ops-tools/deb-build/work/php-7.1.9/Zend/zend_execute.c:2040
#18 0x0000000000aeea21 in zend_call_function (fci=0x7fff7073b2a0, fci_cache=0x7fff7073b270) at
/home/jjones/ops/ops-tools/deb-build/work/php-7.1.9/Zend/zend_execute_API.c:871
#19 0x0000000000aef8d3 in zend_lookup_class_ex (name=0x7fcf65663f90, key=0x0, use_autoload=1) at
/home/jjones/ops/ops-tools/deb-build/work/php-7.1.9/Zend/zend_execute_API.c:1028
#20 0x0000000000af07cf in zend_fetch_class (class_name=0x7fcf65663f90, fetch_type=512) at
/home/jjones/ops/ops-tools/deb-build/work/php-7.1.9/Zend/zend_execute_API.c:1441
#21 0x0000000000bb5cc1 in ZEND_FETCH_CLASS_SPEC_CV_HANDLER () at
/home/jjones/ops/ops-tools/deb-build/work/php-7.1.9/Zend/zend_vm_execute.h:2444
#22 0x0000000000ba9a6b in execute_ex (ex=0x7fcf656145a0) at
/home/jjones/ops/ops-tools/deb-build/work/php-7.1.9/Zend/zend_vm_execute.h:429
#23 0x00007fcf635e77e0 in hp_execute_ex (execute_data=0x7fcf656145a0) at
/opt/xhprof/build/7.1.6/tideways.c:3603
#24 hp_execute_ex (execute_data=0x7fcf656145a0) at /opt/xhprof/build/7.1.6/tideways.c:3549
#25 0x0000000000badfa4 in ZEND_DO_FCALL_SPEC_RETVAL_UNUSED_HANDLER () at
/home/jjones/ops/ops-tools/deb-build/work/php-7.1.9/Zend/zend_vm_execute.h:949
#26 0x0000000000ba9a6b in execute_ex (ex=0x7fcf656140e0) at
/home/jjones/ops/ops-tools/deb-build/work/php-7.1.9/Zend/zend_vm_execute.h:429
#27 0x0000000000c88ec8 in ZEND_INCLUDE_OR_EVAL_SPEC_TMPVAR_HANDLER () at
/home/jjones/ops/ops-tools/deb-build/work/php-7.1.9/Zend/zend_vm_execute.h:51699
#28 0x0000000000ba9a6b in execute_ex (ex=0x7fcf65614030) at
/home/jjones/ops/ops-tools/deb-build/work/php-7.1.9/Zend/zend_vm_execute.h:429
#29 0x0000000000baa42b in zend_execute (op_array=0x7fcf65672000, return_value=0x0) at
/home/jjones/ops/ops-tools/deb-build/work/php-7.1.9/Zend/zend_vm_execute.h:474
#30 0x0000000000b0fcc1 in zend_execute_scripts (type=8, retval=0x0, file_count=3) at
/home/jjones/ops/ops-tools/deb-build/work/php-7.1.9/Zend/zend.c:1480
#31 0x0000000000a5b290 in php_execute_script (primary_file=0x7fff7073dd60) at
/home/jjones/ops/ops-tools/deb-build/work/php-7.1.9/main/main.c:2552
#32 0x0000000000cb836f in main (argc=2, argv=0x7fff7073e058) at
/home/jjones/ops/ops-tools/deb-build/work/php-7.1.9/sapi/fpm/fpm/fpm_main.c:1966

Crash caused by call to compute the hash of a null string with a bogus/corrupt length given.


Data structures/fields in the code mention in the stack that might be clues.

---- Bad "refcount" in string structure

(gdb) list
81	/*---*/
82	
83	static zend_always_inline zend_ulong zend_string_hash_val(zend_string *s)
84	{
85		if (!ZSTR_H(s)) {
86			ZSTR_H(s) = zend_hash_func(ZSTR_VAL(s), ZSTR_LEN(s));
87		}
88		return ZSTR_H(s);
89	}
90	
(gdb) print *s
$11 = {gc = {refcount = 4294967295, u = {v = {type = 0 '\000', flags = 0 '\000',
gc_info = 0}, type_info = 0}}, h = 0, len = 32577024, val = ""}
(gdb) printf "%x\n", s->gc->refcount
ffffffff

Meaning the "refcount" associated with the string is the maximum value that can fit in a
32-bit unsigned int.  Or it's -1 in a signed 32-bit int.  Maybe some refcount tracking code
overflowed the counter, or maybe a '0' value was decremented?



And finally, in case it helps, the functions call chain suggests PHP is crashing trying to fetch
something from cache, not while interpreting PHP code itself.

(gdb) print execute_data->func->common->function_name->val+0
$26 = 0x7fced3fb8248 "__autoload"
(gdb) print execute_data->prev_execute_data->func->common->function_name->val+0
$27 = 0x7fced3fc0be8 "spl_autoload_call"

------------------------------------------------------------------------
[2017-08-30 01:37:42] nick at noodles dot net dot nz

The pecl-memcached patch helped (at least it's not segfaulting every second). But I'm
still seeing random memory corruption. I managed to get some core dumps:

Core was generated by `/usr/sbin/httpd -DFOREGROUND'.
Program terminated with signal 11, Segmentation fault.
#0  sljit_malloc_exec (size=816) at
/usr/src/debug/php-src-php-7.1.8/ext/pcre/pcrelib/sljit/sljitExecAllocator.c:196
196					header->prev_size = chunk_size;
Missing separate debuginfos, use: debuginfo-install apr-1.4.8-3.el7.x86_64
apr-util-1.5.2-6.el7.x86_64 bzip2-libs-1.0.6-13.el7.x86_64 cyrus-sasl-lib-2.1.26-20.el7_2.x86_64
elfutils-libelf-0.166-2.el7.x86_64 elfutils-libs-0.166-2.el7.x86_64 enchant-1.6.0-8.el7.x86_64
expat-2.1.0-10.el7_3.x86_64 fastlz-0.1.0-0.1.20070619svnrev12.el7.x86_64
freetype-2.4.11-12.el7.x86_64 glib2-2.46.2-4.el7.x86_64 glibc-2.17-157.el7_3.5.x86_64
keyutils-libs-1.5.8-3.el7.x86_64 krb5-libs-1.14.1-27.el7_3.x86_64 libX11-1.6.3-3.el7.x86_64
libXau-1.0.8-2.1.el7.x86_64 libXpm-3.5.11-3.el7.x86_64 libattr-2.4.46-12.el7.x86_64
libcap-2.22-8.el7.x86_64 libcom_err-1.42.9-9.el7.x86_64 libcurl-7.29.0-35.el7.centos.x86_64
libdb-5.3.21-19.el7.x86_64 libevent-2.0.21-4.el7.x86_64 libgcc-4.8.5-11.el7.x86_64
libgcrypt-1.5.3-13.el7_3.1.x86_64 libgpg-error-1.12-3.el7.x86_64 libicu-50.1.2-15.el7.x86_64
libidn-1.28-4.el7.x86_64 libjpeg-turbo-1.2.90-5.el7.x86_64 libmcrypt-2.5.8-13.el7.x86_64
libmemcached-libs-1.0.18-1.x86!
 _64 libnghttp2-1.21.1-1.el7.x86_64 libpng-1.5.13-7.el7_2.x86_64 libselinux-2.5-6.el7.x86_64
libssh2-1.4.3-10.el7_2.1.x86_64 libstdc++-4.8.5-11.el7.x86_64 libtool-ltdl-2.4.2-22.el7_3.x86_64
libuuid-2.23.2-33.el7_3.2.x86_64 libwebp-0.3.0-3.el7.x86_64 libxcb-1.11-4.el7.x86_64
libxml2-2.9.1-6.el7_2.3.x86_64 libxslt-1.1.28-5.el7.x86_64 lua-5.1.4-15.el7.x86_64
mod_log_firstbyte-1.01-3.el7.x86_64 nspr-4.13.1-1.0.el7_3.x86_64 nss-3.28.4-1.2.el7_3.x86_64
nss-softokn-freebl-3.16.2.3-14.4.el7.x86_64 nss-util-3.28.4-1.0.el7_3.x86_64
openldap-2.4.40-13.el7.x86_64 openssl-libs-1.0.1e-60.el7_3.1.x86_64 pcre-8.32-15.el7_2.1.x86_64
php-pecl-igbinary-2.0.1-1.el7.x86_64 php-pecl-memcached-3.0.3-2.el7.x86_64
php-pecl-msgpack-2.0.2-1.el7.x86_64 sqlite-3.7.17-8.el7.x86_64 systemd-libs-219-30.el7_3.9.x86_64
xz-libs-5.2.2-1.el7.x86_64 zlib-1.2.7-17.el7.x86_64
(gdb) bt
#0  sljit_malloc_exec (size=816) at
/usr/src/debug/php-src-php-7.1.8/ext/pcre/pcrelib/sljit/sljitExecAllocator.c:196
#1  sljit_generate_code (compiler=compiler@entry=0x7f228e3312f0) at
/usr/src/debug/php-src-php-7.1.8/ext/pcre/pcrelib/sljit/sljitNativeX86_common.c:466
#2  0x00007f227b988a50 in _pcre_jit_compile (re=re@entry=0x7f228e11e870,
extra=extra@entry=0x7f228e2fc0f0, mode=mode@entry=0)
    at /usr/src/debug/php-src-php-7.1.8/ext/pcre/pcrelib/pcre_jit_compile.c:10342
#3  0x00007f227b9639ed in php_pcre_study (external_re=external_re@entry=0x7f228e11e870, options=1,
errorptr=errorptr@entry=0x7ffe7cbea888)
    at /usr/src/debug/php-src-php-7.1.8/ext/pcre/pcrelib/pcre_study.c:1628
#4  0x00007f227b98b99b in pcre_get_compiled_regex_cache (regex=0x7f2266d00728) at
/usr/src/debug/php-src-php-7.1.8/ext/pcre/php_pcre.c:518
#5  0x00007f227b98e1a2 in php_pcre_replace (regex=<optimized out>,
subject_str=subject_str@entry=0x7f227af11000,
    subject=subject@entry=0x7f227af11018 "<html>\n    <head>\n   
\t<title>Gallstones</title>\n    \t<meta name=\"originalfile\"
content=\"AZ_d0198.xml\" />\n    </head>\n    <body>\n    \n", '
' <repeats 12 times>, "\n", ' ' <repeats 15 times>,
"<h1>Gallstones </h1>\n", ' ' <repeats 15 times>, "\n
"..., subject_len=12448, replace_val=replace_val@entry=0x7f227ae11830,
    is_callable_replace=is_callable_replace@entry=0, limit=limit@entry=-1,
replace_count=replace_count@entry=0x7ffe7cbeaa5c) at
/usr/src/debug/php-src-php-7.1.8/ext/pcre/php_pcre.c:1132
#6  0x00007f227b98e2a2 in php_replace_in_subject (regex=regex@entry=0x7f227ae11820,
replace=replace@entry=0x7f227ae11830, subject=subject@entry=0x7f227ae11840, limit=limit@entry=-1,
    is_callable_replace=is_callable_replace@entry=0,
replace_count=replace_count@entry=0x7ffe7cbeaa5c) at
/usr/src/debug/php-src-php-7.1.8/ext/pcre/php_pcre.c:1495
#7  0x00007f227b98e6ae in preg_replace_impl (return_value=return_value@entry=0x7f227ae11770,
regex=regex@entry=0x7f227ae11820, replace=0x7f227ae11830, subject=0x7f227ae11840, limit_val=-1,
    is_callable_replace=is_callable_replace@entry=0, is_filter=is_filter@entry=0) at
/usr/src/debug/php-src-php-7.1.8/ext/pcre/php_pcre.c:1554
#8  0x00007f227b98f20f in zif_preg_replace (execute_data=0x7f227ae117d0,
return_value=0x7f227ae11770) at /usr/src/debug/php-src-php-7.1.8/ext/pcre/php_pcre.c:1593
#9  0x00007f227bb21006 in ZEND_DO_ICALL_SPEC_RETVAL_USED_HANDLER () at
/usr/src/debug/php-src-php-7.1.8/Zend/zend_vm_execute.h:675
#10 0x00007f227bb10fbb in execute_ex (ex=<optimized out>) at
/usr/src/debug/php-src-php-7.1.8/Zend/zend_vm_execute.h:429
#11 0x00007f227bb64c74 in zend_execute (op_array=0x7f227ae7a000, op_array@entry=0x7f22677811f0,
return_value=return_value@entry=0x7f227ae11030)
    at /usr/src/debug/php-src-php-7.1.8/Zend/zend_vm_execute.h:474
#12 0x00007f227bac95b3 in zend_execute_scripts (type=type@entry=8, retval=0x7f227ae11030,
retval@entry=0x0, file_count=file_count@entry=3) at
/usr/src/debug/php-src-php-7.1.8/Zend/zend.c:1476
#13 0x00007f227ba66b18 in php_execute_script (primary_file=primary_file@entry=0x7ffe7cbece90) at
/usr/src/debug/php-src-php-7.1.8/main/main.c:2537
#14 0x00007f227bb66c7d in php_handler (r=<optimized out>) at
/usr/src/debug/php-src-php-7.1.8/sapi/apache2handler/sapi_apache2.c:712
#15 0x00007f228bf4a550 in ap_run_handler (r=r@entry=0x7f228e1f5968) at config.c:170
#16 0x00007f228bf4aa99 in ap_invoke_handler (r=r@entry=0x7f228e1f5968) at config.c:434
#17 0x00007f228bf6094c in ap_internal_redirect (new_uri=<optimized out>, r=<optimized
out>) at http_request.c:765
#18 0x00007f2280e49f1c in handler_redirect (r=0x7f228e1af910) at mod_rewrite.c:5195
#19 0x00007f228bf4a550 in ap_run_handler (r=r@entry=0x7f228e1af910) at config.c:170
#20 0x00007f228bf4aa99 in ap_invoke_handler (r=r@entry=0x7f228e1af910) at config.c:434
#21 0x00007f228bf615ea in ap_process_async_request (r=0x7f228e1af910) at http_request.c:436
#22 0x00007f228bf618c4 in ap_process_request (r=r@entry=0x7f228e1af910) at http_request.c:471
#23 0x00007f228bf5d77d in ap_process_http_sync_connection (c=0x7f228e191310) at http_core.c:210
#24 ap_process_http_connection (c=0x7f228e191310) at http_core.c:251
#25 0x00007f228bf549c0 in ap_run_process_connection (c=c@entry=0x7f228e191310) at connection.c:42
#26 0x00007f228bf54f18 in ap_process_connection (c=c@entry=0x7f228e191310, csd=<optimized
out>) at connection.c:226
#27 0x00007f227e38ba50 in child_main (child_num_arg=child_num_arg@entry=10,
child_bucket=child_bucket@entry=0) at prefork.c:726
#28 0x00007f227e38bcf1 in make_child (s=0x7f228ddbd420, slot=10, bucket=0) at prefork.c:834
#29 0x00007f227e38cc34 in perform_idle_server_maintenance (p=<optimized out>) at prefork.c:942
#30 prefork_run (_pconf=<optimized out>, plog=<optimized out>, s=<optimized out>)
at prefork.c:1138
#31 0x00007f228bf2c45e in ap_run_mpm (pconf=pconf@entry=0x7f228dd96188, plog=0x7f228ddc33a8,
s=0x7f228ddbd420) at mpm_common.c:94
#32 0x00007f228bf24d78 in main (argc=2, argv=0x7ffe7cbed658) at main.c:783

Hopefully this helps

------------------------------------------------------------------------


The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at

    https://bugs.php.net/bug.php?id=71135


--
Edit this bug report at https://bugs.php.net/bug.php?id=71135&edit=1


Thread (52 messages)

« previous php.bugs (#211020) next »