Bug #75573 [Com]: Segmentation fault in 7.1.12 and 7.0.26

From: Date: Thu, 30 Nov 2017 15:03:00 +0000
Subject: Bug #75573 [Com]: Segmentation fault in 7.1.12 and 7.0.26
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-212840@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=75573&edit=1 ID: 75573 Comment by: post at minhost dot no Reported by: manuel-php at mausz dot at Summary: Segmentation fault in 7.1.12 and 7.0.26 Status: Closed Type: Bug Package: Reproducible crash Operating System: Linux PHP Version: 7.1.12 Block user comment: N Private report: N New Comment: As I commented before, I applied the patch http://git.php.net/?p=php-src.git;a=commit;h=3b9ba7b6bd9e24bdbeca8e8e3f24cee2fccc51d8 and it seemed to fix the bug. However after testing more today, the bug is still present. I don't know if it is the same bug or not, I have filled a bug report here previous https://bugs.php.net/bug.php?id=75579 - anyway the patch did not work after all. What happens is that after visiting about nine wordpress sites (wich by the way was auto-updating from wordpress 4.9 to 4.9.1), then interned strings used memory became full and sites started to go down with HTTP ERROR 500, and apache error log got lines like this: [Thu Nov 30 15:40:40.273796 2017] [proxy_fcgi:error] [pid 17990:tid 140238684755712] [client 176.74.214.18:42343] AH01071: Got error 'PHP message: PHP Fatal error: Cannot declare interface JsonSerializable, because the name is already in use in /home/USER/domains/DOMAIN.TLD/public_html/wp-includes/compat.php on line 428\n' [Thu Nov 30 15:40:41.697018 2017] [proxy_fcgi:error] [pid 17990:tid 140238693148416] [client 176.74.214.18:52760] AH01071: Got error 'PHP message: PHP Fatal error: Cannot declare interface JsonSerializable, because the name is already in use in /home/USER/domains/DOMAIN.TLD/public_html/wp-includes/compat.php on line 428\n' In PHP info page it looks like this when interned strings used memory become full (and sites stop working!): Interned Strings Used memory 4194288 Interned Strings Free memory 16 This is a completely show stoppper wich makes PHP 7.1.12 not usable. Some developers at PHP really need to take time to look deep into this now. It is a critical bug introduced in PHP 7.1.12 and (possibly 7.0.26) if you use opcache, wich forces you to stay on PHP 7.1.11 wich do not have this bug. Can someone at PHP please understand the seriousness in this? Please study both this bug #75573 and my bug report #75579, they could be the same thing, or separate issues but somehow related. Previous Comments: ------------------------------------------------------------------------ [2017-11-30 15:02:58] post at minhost dot no Related To: Bug #75573 ------------------------------------------------------------------------ [2017-11-30 14:49:03] post at minhost dot no Related To: Bug #75579 ------------------------------------------------------------------------ [2017-11-30 14:02:38] thomas at shadowweb dot org This bug should be re-opened and the fix also applied to the 7.0 branch... Patch for 7.0.26 looks like this: --- Zend/zend_object_handlers.c.org 2017-11-21 12:57:10.000000000 +0100 +++ Zend/zend_object_handlers.c 2017-11-30 14:42:29.154940011 +0100 @@ -602,8 +602,8 @@ zval_ptr_dtor(&tmp_object); goto exit; } else { - zval_ptr_dtor(&tmp_object); if (Z_STRVAL_P(member)[0] == '\0') { + zval_ptr_dtor(&tmp_object); if (Z_STRLEN_P(member) == 0) { zend_throw_error(NULL, "Cannot access empty property"); retval = &EG(uninitialized_zval); Thanks in advance ------------------------------------------------------------------------ [2017-11-29 21:47:05] rob-phpbugs at tigertech dot com I agree that this patch solves the problem on PHP 7.1.12 in my testing. It does seem that a different patch is needed for 7.0.26, though, as the logic appears to be slightly different. ------------------------------------------------------------------------ [2017-11-29 18:53:17] maunel-php at mausz dot at @Xinchen: I'm unable to find the backport for the PHP 7.0 branch. ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=75573 -- Edit this bug report at https://bugs.php.net/bug.php?id=75573&edit=1

« previous php.bugs (#212840) next »