Bug #74008 [Com]: Segmentation fault using Drupal 7

From: Date: Wed, 22 Nov 2017 10:21:45 +0000
Subject: Bug #74008 [Com]: Segmentation fault using Drupal 7
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-212674@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=74008&edit=1

 ID:                 74008
 Comment by:         itsekhmistro at adyax dot com
 Reported by:        pierre at brin-de-toile dot fr
 Summary:            Segmentation fault using Drupal 7
 Status:             No Feedback
 Type:               Bug
 Package:            Reproducible crash
 Operating System:   Debian Jessie 64 bits
 PHP Version:        7.0.15
 Block user comment: N
 Private report:     N

 New Comment:

The issue is still active.
On the website Drupal 	7.56, Commerce, Discounts ( php 7.1.9, php 7.1.11 )

Current fix:  Disabling the Zend garbage collector solves the issue.
ini_set('zend.enable_gc', 0);


Previous Comments:
------------------------------------------------------------------------
[2017-07-30 04:22:26] php-bugs at lists dot php dot net

No feedback was provided. The bug is being suspended because
we assume that you are no longer experiencing the problem.
If this is not the case and you are able to provide the
information that was requested earlier, please do so and
change the status of the bug back to "Re-Opened". Thank you.

------------------------------------------------------------------------
[2017-07-26 22:02:33] mbreden at acromediainc dot com

I also appear to be suffering from this problem, although I do not have memcache enabled at all.

Software
==========================================
Happens on Ubuntu 16.04 & 14.04 at least
Drupal 7.56
Commerce 1.13
Commerce Discount 1.0-alpha8
Commerce Discount Extra 1.0-rc4
PHP - Tested with fpm w/nginx and cli w/ built in server: 7.0.18, 7.0.21, 7.1.7
==========================================

The bug is similar to the first story - multiple discounts being applied to an order, and PHP often
segfaults in product pages, the cart, and checkout.

The problem appears to be happening with the zend memory manager.
With "export USE_ZEND_ALLOC=0" it does not happen.
It does also not happen if the garbage collector is disabled.
ini_set('zend.enable_gc', 0);

Valgrind also can't be run with zend memory manager turned off as per https://bugs.php.net/bugs-getting-valgrind-log.php
as the problem seems to be stemming there - with zend mm turned off, there's no issue.



A valgrind memcheck gives this log:

==19806== Memcheck, a memory error detector
==19806== Copyright (C) 2002-2017, and GNU GPL'd, by Julian Seward et al.
==19806== Using Valgrind-3.13.0 and LibVEX; rerun with -h for copyright info
==19806== Command: /usr/bin/php7.0 -S localhost:3000
==19806== Parent PID: 18844
==19806== 
==19806== Invalid read of size 8
==19806==    at 0x3468F4: zend_mm_alloc_small (zend_alloc.c:1306)
==19806==    by 0x3468F4: zend_mm_alloc_heap (zend_alloc.c:1377)
==19806==    by 0x3468F4: _emalloc (zend_alloc.c:2461)
==19806==    by 0x2F9718: zend_string_alloc (zend_string.h:121)
==19806==    by 0x2F9718: zend_string_init (zend_string.h:157)
==19806==    by 0x2F9718: php_var_unserialize_internal (var_unserializer.c:1047)
==19806==    by 0x2F989E: process_nested_data (var_unserializer.c:401)
==19806==    by 0x2F989E: php_var_unserialize_internal (var_unserializer.c:940)
==19806==    by 0x2F989E: process_nested_data (var_unserializer.c:401)
==19806==    by 0x2F989E: php_var_unserialize_internal (var_unserializer.c:940)
==19806==    by 0x2F989E: process_nested_data (var_unserializer.c:401)
==19806==    by 0x2F989E: php_var_unserialize_internal (var_unserializer.c:940)
==19806==    by 0x2EA95F: zif_unserialize (var.c:1076)
==19806==    by 0x3BA3AC: ZEND_DO_ICALL_SPEC_HANDLER (zend_vm_execute.h:586)
==19806==    by 0x3AB50A: execute_ex (zend_vm_execute.h:414)
==19806==    by 0x3FFC86: zend_execute (zend_vm_execute.h:458)
==19806==    by 0x36AD42: zend_execute_scripts (zend.c:1443)
==19806==    by 0x309E9F: php_execute_script (main.c:2492)
==19806==    by 0x4075F9: php_cli_server_dispatch_script (php_cli_server.c:1937)
==19806==    by 0x40850A: php_cli_server_dispatch (php_cli_server.c:2111)
==19806==    by 0x40850A: php_cli_server_recv_event_read_request (php_cli_server.c:2321)
==19806==    by 0x408B2D: php_cli_server_do_event_for_each_fd_callback (php_cli_server.c:2401)
==19806==    by 0x4096B8: php_cli_server_poller_iter_on_active (php_cli_server.c:831)
==19806==    by 0x4096B8: php_cli_server_do_event_for_each_fd (php_cli_server.c:2424)
==19806==    by 0x4096B8: php_cli_server_do_event_loop (php_cli_server.c:2434)
==19806==    by 0x4096B8: do_cli_server (php_cli_server.c:2535)
==19806==    by 0x1EC975: main (php_cli.c:1350)
==19806==  Address 0xc5cf00001f432dff is not stack'd, malloc'd or (recently) free'd
==19806== 
==19806== 
==19806== Process terminating with default action of signal 11 (SIGSEGV)
==19806==  General Protection Fault
==19806==    at 0x3468F4: zend_mm_alloc_small (zend_alloc.c:1306)
==19806==    by 0x3468F4: zend_mm_alloc_heap (zend_alloc.c:1377)
==19806==    by 0x3468F4: _emalloc (zend_alloc.c:2461)
==19806==    by 0x2F9718: zend_string_alloc (zend_string.h:121)
==19806==    by 0x2F9718: zend_string_init (zend_string.h:157)
==19806==    by 0x2F9718: php_var_unserialize_internal (var_unserializer.c:1047)
==19806==    by 0x2F989E: process_nested_data (var_unserializer.c:401)
==19806==    by 0x2F989E: php_var_unserialize_internal (var_unserializer.c:940)
==19806==    by 0x2F989E: process_nested_data (var_unserializer.c:401)
==19806==    by 0x2F989E: php_var_unserialize_internal (var_unserializer.c:940)
==19806==    by 0x2F989E: process_nested_data (var_unserializer.c:401)
==19806==    by 0x2F989E: php_var_unserialize_internal (var_unserializer.c:940)
==19806==    by 0x2EA95F: zif_unserialize (var.c:1076)
==19806==    by 0x3BA3AC: ZEND_DO_ICALL_SPEC_HANDLER (zend_vm_execute.h:586)
==19806==    by 0x3AB50A: execute_ex (zend_vm_execute.h:414)
==19806==    by 0x3FFC86: zend_execute (zend_vm_execute.h:458)
==19806==    by 0x36AD42: zend_execute_scripts (zend.c:1443)
==19806==    by 0x309E9F: php_execute_script (main.c:2492)
==19806==    by 0x4075F9: php_cli_server_dispatch_script (php_cli_server.c:1937)
==19806==    by 0x40850A: php_cli_server_dispatch (php_cli_server.c:2111)
==19806==    by 0x40850A: php_cli_server_recv_event_read_request (php_cli_server.c:2321)
==19806==    by 0x408B2D: php_cli_server_do_event_for_each_fd_callback (php_cli_server.c:2401)
==19806==    by 0x4096B8: php_cli_server_poller_iter_on_active (php_cli_server.c:831)
==19806==    by 0x4096B8: php_cli_server_do_event_for_each_fd (php_cli_server.c:2424)
==19806==    by 0x4096B8: php_cli_server_do_event_loop (php_cli_server.c:2434)
==19806==    by 0x4096B8: do_cli_server (php_cli_server.c:2535)
==19806==    by 0x1EC975: main (php_cli.c:1350)
==19806== 
==19806== HEAP SUMMARY:
==19806==     in use at exit: 3,601,710 bytes in 28,437 blocks
==19806==   total heap usage: 40,253 allocs, 11,816 frees, 15,131,436 bytes allocated
==19806== 
==19806== LEAK SUMMARY:
==19806==    definitely lost: 0 bytes in 0 blocks
==19806==    indirectly lost: 0 bytes in 0 blocks
==19806==      possibly lost: 2,344,249 bytes in 17,155 blocks
==19806==    still reachable: 1,257,461 bytes in 11,282 blocks
==19806==         suppressed: 0 bytes in 0 blocks
==19806== Rerun with --leak-check=full to see details of leaked memory
==19806== 
==19806== For counts of detected and suppressed errors, rerun with: -v
==19806== ERROR SUMMARY: 1 errors from 1 contexts (suppressed: 0 from 0)

------------------------------------------------------------------------
[2017-04-24 17:20:44] tomas dot srnka at gmail dot com

Hi,

@kolsys at github posted a patch for this problem for pecl-memcache that we've ported to PHP7.
Give it a try please, it should be fixed now.

https://github.com/websupport-sk/pecl-memcache

Tomas

------------------------------------------------------------------------
[2017-04-20 13:02:55] dmitry@php.net

It looks like an invalid free in memcache.c:476
Most probably it's caused by a bug in reference counting.


==12487== Invalid read of size 1
==12487==    at 0x9048FA7: ZEND_FE_FETCH_R_SPEC_VAR_HANDLER (zend_vm_execute.h:16015)
==12487==    by 0x9033E0A: execute_ex (zend_vm_execute.h:414)
==12487==    by 0x9087B26: zend_execute (zend_vm_execute.h:458)
==12487==    by 0x8FF64B3: zend_execute_scripts (zend.c:1437)
==12487==    by 0x8F99C6F: php_execute_script (main.c:2492)
==12487==    by 0x9089429: php_handler (sapi_apache2.c:678)
==12487==    by 0x16268F: ap_run_handler (in /usr/sbin/apache2)
==12487==    by 0x162BD8: ap_invoke_handler (in /usr/sbin/apache2)
==12487==    by 0x1783DB: ap_internal_redirect (in /usr/sbin/apache2)
==12487==    by 0xA869EA1: ??? (in /usr/lib/apache2/modules/mod_rewrite.so)
==12487==    by 0x16268F: ap_run_handler (in /usr/sbin/apache2)
==12487==    by 0x162BD8: ap_invoke_handler (in /usr/sbin/apache2)
==12487==    by 0x178AB1: ap_process_async_request (in /usr/sbin/apache2)
==12487==    by 0x178C4F: ap_process_request (in /usr/sbin/apache2)
==12487==    by 0x175551: ??? (in /usr/sbin/apache2)
==12487==    by 0x16BF3F: ap_run_process_connection (in /usr/sbin/apache2)
==12487==    by 0x89A47B9: ??? (in /usr/lib/apache2/modules/mod_mpm_prefork.so)
==12487==    by 0x89A4A00: ??? (in /usr/lib/apache2/modules/mod_mpm_prefork.so)
==12487==    by 0x89A5666: ??? (in /usr/lib/apache2/modules/mod_mpm_prefork.so)
==12487==    by 0x1467ED: ap_run_mpm (in /usr/sbin/apache2)
==12487==    by 0x13F5F2: main (in /usr/sbin/apache2)
==12487==  Address 0x35a9d265 is 5 bytes inside a block of size 48 free'd
==12487==    at 0x4C29E90: free (vg_replace_malloc.c:473)
==12487==    by 0x166F8F9C: zend_string_release (zend_string.h:271)
==12487==    by 0x166F8F9C: php_mmc_store (memcache.c:476)
==12487==    by 0x9078471: ZEND_DO_FCALL_SPEC_HANDLER (zend_vm_execute.h:842)
==12487==    by 0x9033E0A: execute_ex (zend_vm_execute.h:414)
==12487==    by 0x9087B26: zend_execute (zend_vm_execute.h:458)
==12487==    by 0x8FF64B3: zend_execute_scripts (zend.c:1437)
==12487==    by 0x8F99C6F: php_execute_script (main.c:2492)
==12487==    by 0x9089429: php_handler (sapi_apache2.c:678)
==12487==    by 0x16268F: ap_run_handler (in /usr/sbin/apache2)
==12487==    by 0x162BD8: ap_invoke_handler (in /usr/sbin/apache2)
==12487==    by 0x1783DB: ap_internal_redirect (in /usr/sbin/apache2)
==12487==    by 0xA869EA1: ??? (in /usr/lib/apache2/modules/mod_rewrite.so)
==12487==    by 0x16268F: ap_run_handler (in /usr/sbin/apache2)
==12487==    by 0x162BD8: ap_invoke_handler (in /usr/sbin/apache2)
==12487==    by 0x178AB1: ap_process_async_request (in /usr/sbin/apache2)
==12487==    by 0x178C4F: ap_process_request (in /usr/sbin/apache2)
==12487==    by 0x175551: ??? (in /usr/sbin/apache2)
==12487==    by 0x16BF3F: ap_run_process_connection (in /usr/sbin/apache2)
==12487==    by 0x89A47B9: ??? (in /usr/lib/apache2/modules/mod_mpm_prefork.so)
==12487==    by 0x89A4A00: ??? (in /usr/lib/apache2/modules/mod_mpm_prefork.so)
==12487==    by 0x89A5666: ??? (in /usr/lib/apache2/modules/mod_mpm_prefork.so)
==12487==    by 0x1467ED: ap_run_mpm (in /usr/sbin/apache2)
==12487==    by 0x13F5F2: main (in /usr/sbin/apache2)

------------------------------------------------------------------------


The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at

    https://bugs.php.net/bug.php?id=74008


--
Edit this bug report at https://bugs.php.net/bug.php?id=74008&edit=1


Thread (13 messages)

« previous php.bugs (#212674) next »