Bug #77430 [Com]: php-fpm crashes with Main process exited, code=dumped, status=11/SEGV

From: Date: Wed, 16 Jan 2019 12:23:58 +0000
Subject: Bug #77430 [Com]: php-fpm crashes with Main process exited, code=dumped, status=11/SEGV
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-218988@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=77430&edit=1 ID: 77430 Comment by: remi@php.net Reported by: claudiu_beta at yahoo dot com Summary: php-fpm crashes with Main process exited, code=dumped, status=11/SEGV Status: Assigned Type: Bug Package: FPM related Operating System: Fedora 28 PHP Version: 7.3.1RC1 Assigned To: bukka Block user comment: N Private report: N New Comment: FYI, build including this patch is available in remi-test repository (F28/F29 only) Previous Comments: ------------------------------------------------------------------------ [2019-01-15 20:20:08] bukka@php.net Actually please try this one if you can: diff --git a/sapi/fpm/fpm/fpm_stdio.c b/sapi/fpm/fpm/fpm_stdio.c index ba8f6d8213..03d15cbf0d 100644 --- a/sapi/fpm/fpm/fpm_stdio.c +++ b/sapi/fpm/fpm/fpm_stdio.c @@ -122,7 +122,7 @@ static void fpm_stdio_child_said(struct fpm_event_s *ev, short which, void *arg) struct fpm_event_s *event; int fifo_in = 1, fifo_out = 1; int in_buf = 0; - int read_fail = 0, finish_log_stream = 0; + int read_fail = 0, finish_log_stream = 0, create_log_stream; int res; struct zlog_stream *log_stream; @@ -138,7 +138,8 @@ static void fpm_stdio_child_said(struct fpm_event_s *ev, short which, void *arg) event = &child->ev_stderr; } - if (!child->log_stream) { + create_log_stream = !child->log_stream; + if (create_log_stream) { log_stream = child->log_stream = malloc(sizeof(struct zlog_stream)); zlog_stream_init_ex(log_stream, ZLOG_WARNING, STDERR_FILENO); zlog_stream_set_decorating(log_stream, child->wp->config->decorate_workers_output); @@ -196,8 +197,10 @@ static void fpm_stdio_child_said(struct fpm_event_s *ev, short which, void *arg) } if (read_fail) { - zlog_stream_set_msg_suffix(log_stream, NULL, ", pipe is closed"); - zlog_stream_finish(log_stream); + if (create_log_stream) { + zlog_stream_set_msg_suffix(log_stream, NULL, ", pipe is closed"); + zlog_stream_finish(log_stream); + } if (read_fail < 0) { zlog(ZLOG_SYSERROR, "unable to read what child say"); } ------------------------------------------------------------------------ [2019-01-15 20:15:14] bukka@php.net I think that I know what the issue is. The event can be received after the child is freed which means that the shared log stream is uninitialized and it can't be used. Are you able to test the following patch: diff --git a/sapi/fpm/fpm/fpm_stdio.c b/sapi/fpm/fpm/fpm_stdio.c index ba8f6d8213..0ff189c9f0 100644 --- a/sapi/fpm/fpm/fpm_stdio.c +++ b/sapi/fpm/fpm/fpm_stdio.c @@ -196,8 +196,10 @@ static void fpm_stdio_child_said(struct fpm_event_s *ev, short which, void *arg) } if (read_fail) { - zlog_stream_set_msg_suffix(log_stream, NULL, ", pipe is closed"); - zlog_stream_finish(log_stream); + if (!child->log_stream) { + zlog_stream_set_msg_suffix(log_stream, NULL, ", pipe is closed"); + zlog_stream_finish(log_stream); + } if (read_fail < 0) { zlog(ZLOG_SYSERROR, "unable to read what child say"); } ------------------------------------------------------------------------ [2019-01-14 12:54:03] sjon at hortensius dot net I reported the exact same issue in 7.3.1 (as released) which NikiC tagged as a duplicate. There aren't necessarily any requests - according to the access-log, the last request was @ 03:43:35 and lasted 50ms (segfault @ 03:43:43). If you need more input let me know - I have a coredump on a debug-build ------------------------------------------------------------------------ [2019-01-14 09:21:24] claudiu_beta at yahoo dot com I have upgraded to Fedora 29 and php 7.3.1. This is a backtrace from a new coredump. #0 0x000055eb8b44fc73 in zlog_stream_set_msg_suffix (stream=stream@entry=0x100, suffix=suffix@entry=0x0, final_suffix=final_suffix@entry=0x55eb8b4aedf6 ", pipe is closed") at /usr/src/debug/php73-php-7.3.1-1.fc29.remi.x86_64/sapi/fpm/fpm/zlog.c:602 #1 0x000055eb8b44d109 in fpm_stdio_child_said (ev=<optimized out>, which=<optimized out>, arg=0x55eb8c536250) at /usr/src/debug/php73-php-7.3.1-1.fc29.remi.x86_64/sapi/fpm/fpm/fpm_stdio.c:199 #2 0x000055eb8b452596 in fpm_event_epoll_wait (queue=<optimized out>, timeout=<optimized out>) at /usr/src/debug/php73-php-7.3.1-1.fc29.remi.x86_64/sapi/fpm/fpm/events/epoll.c:145 #3 0x000055eb8b444e84 in fpm_event_loop (err=err@entry=0) at /usr/src/debug/php73-php-7.3.1-1.fc29.remi.x86_64/sapi/fpm/fpm/fpm_events.c:409 #4 0x000055eb8b43f217 in fpm_run (max_requests=0x7fff9540e34c) at /usr/src/debug/php73-php-7.3.1-1.fc29.remi.x86_64/sapi/fpm/fpm/fpm.c:113 #5 0x000055eb8b21c924 in main (argc=2, argv=0x7fff9540e968) at /usr/src/debug/php73-php-7.3.1-1.fc29.remi.x86_64/sapi/fpm/fpm/fpm_main.c:1864 ------------------------------------------------------------------------ [2019-01-14 09:05:09] nikic@php.net Related To: Bug #77455 ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=77430 -- Edit this bug report at https://bugs.php.net/bug.php?id=77430&edit=1

« previous php.bugs (#218988) next »