Bug #77465 [Com]: Segfault with PHP built-in server

From: Date: Wed, 16 Jan 2019 13:29:53 +0000
Subject: Bug #77465 [Com]: Segfault with PHP built-in server
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-218993@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=77465&edit=1

 ID:                 77465
 Comment by:         girgias@php.net
 Reported by:        girgias@php.net
 Summary:            Segfault with PHP built-in server
 Status:             Open
 Type:               Bug
 Package:            Built-in web server
 Operating System:   WSL with Ubuntu 18.04
 PHP Version:        7.3.1
 Block user comment: N
 Private report:     N

 New Comment:

Just checked again and seems like my test script only works after it segfaults once. (Which I find
confusing but whatever).

Will try to dig up the original issue once again.

However, the original segfault error I got is still:
Program received signal SIGSEGV, Segmentation fault.
0x00000000080eb66f in ?? ()

But not sure that provides any help because the error message is less than ideal.


Previous Comments:
------------------------------------------------------------------------
[2019-01-16 13:07:21] cmb@php.net

I see memory leaks, but no segfault (current master; debug build):

[Wed Jan 16 14:00:14 2019] 127.0.0.1:64505 Accepted
[Wed Jan 16 14:00:14 2019] 127.0.0.1:64506 Accepted
[Wed Jan 16 14:00:14 2019] 127.0.0.1:64505 [200]: /77465.php
[Wed Jan 16 14:00:14 2019]  Script:  '/mnt/c/Users/cmb/php-dev/77465.php'
/mnt/c/Users/cmb/php-dev/php-src/Zend/zend_string.h(132) :  Freeing 0x00007fd2b20640c0 (32 bytes),
script=/mnt/c/Users/cmb/php-dev/77465.php
[Wed Jan 16 14:00:14 2019]  Script:  '/mnt/c/Users/cmb/php-dev/77465.php'
/mnt/c/Users/cmb/php-dev/php-src/ext/date/php_date.c(945) :  Freeing 0x00007fd2b2065240 (56 bytes),
script=/mnt/c/Users/cmb/php-dev/77465.php
[Wed Jan 16 14:00:14 2019]  Script:  '/mnt/c/Users/cmb/php-dev/77465.php'
/mnt/c/Users/cmb/php-dev/php-src/Zend/zend_hash.c(144) :  Freeing 0x00007fd2b2069480 (320 bytes),
script=/mnt/c/Users/cmb/php-dev/77465.php
[Wed Jan 16 14:00:14 2019]  Script:  '/mnt/c/Users/cmb/php-dev/77465.php'
/mnt/c/Users/cmb/php-dev/php-src/ext/date/lib/parse_tz.c(244) :  Freeing 0x00007fd2b206c000 (4
bytes), script=/mnt/c/Users/cmb/php-dev/77465.php
[Wed Jan 16 14:00:14 2019]  Script:  '/mnt/c/Users/cmb/php-dev/77465.php'
/mnt/c/Users/cmb/php-dev/php-src/ext/date/lib/parse_tz.c(488) :  Freeing 0x00007fd2b206c028 (4
bytes), script=/mnt/c/Users/cmb/php-dev/77465.php
[Wed Jan 16 14:00:14 2019]  Script:  '/mnt/c/Users/cmb/php-dev/77465.php'
/mnt/c/Users/cmb/php-dev/php-src/ext/date/lib/parse_tz.c(354) :  Freeing 0x00007fd2b206c050 (1
bytes), script=/mnt/c/Users/cmb/php-dev/77465.php
[Wed Jan 16 14:00:14 2019]  Script:  '/mnt/c/Users/cmb/php-dev/77465.php'
/mnt/c/Users/cmb/php-dev/php-src/ext/date/lib/parse_tz.c(228) :  Freeing 0x00007fd2b206e000 (20
bytes), script=/mnt/c/Users/cmb/php-dev/77465.php
[Wed Jan 16 14:00:14 2019]  Script:  '/mnt/c/Users/cmb/php-dev/77465.php'
/mnt/c/Users/cmb/php-dev/php-src/ext/date/lib/parse_tz.c(487) :  Freeing 0x00007fd2b2074000 (160
bytes), script=/mnt/c/Users/cmb/php-dev/77465.php
/mnt/c/Users/cmb/php-dev/php-src/Zend/zend_alloc.c(2605) : Actual location (location was relayed)
=== Total 8 memory leaks detected ===
[Wed Jan 16 14:00:14 2019] 127.0.0.1:64505 Closing
[Wed Jan 16 14:00:14 2019] 127.0.0.1:64508 Accepted
[Wed Jan 16 14:00:15 2019] 127.0.0.1:64508 Closed without sending a request; it was probably just an
unused speculative preconnection
[Wed Jan 16 14:00:15 2019] 127.0.0.1:64508 Closing
[Wed Jan 16 14:00:15 2019] 127.0.0.1:64506 Closed without sending a request; it was probably just an
unused speculative preconnection
[Wed Jan 16 14:00:15 2019] 127.0.0.1:64506 Closing

------------------------------------------------------------------------
[2019-01-16 11:30:58] girgias@php.net

So this is not related to Guzzle, it segfault during an instantiation of an object.

This example code:
<?php

$object = new stdClass();


Will output the following gdb trace:

gdb --args php -S localhost:8000 -t public/ -d display_errors=1
GNU gdb (Ubuntu 8.1-0ubuntu3) 8.1.0.20180409-git
Copyright (C) 2018 Free Software Foundation, Inc.
License GPLv3+: GNU GPL version 3 or later <http://gnu.org/licenses/gpl.html>
This is free software: you are free to change and redistribute it.
There is NO WARRANTY, to the extent permitted by law.  Type "show copying"
and "show warranty" for details.
This GDB was configured as "x86_64-linux-gnu".
Type "show configuration" for configuration details.
For bug reporting instructions, please see:
<http://www.gnu.org/software/gdb/bugs/>.
Find the GDB manual and other documentation resources online at:
<http://www.gnu.org/software/gdb/documentation/>.
For help, type "help".
Type "apropos word" to search for commands related to "word"...
Reading symbols from php...(no debugging symbols found)...done.
(gdb) r
Starting program: /usr/bin/php -S localhost:8000 -t public/ -d display_errors=1
[Thread debugging using libthread_db enabled]
Using host libthread_db library "/lib/x86_64-linux-gnu/libthread_db.so.1".
PHP 7.3.1-1+ubuntu18.04.1+deb.sury.org+1 Development Server started at Wed Jan 16 12:29:10 2019
Listening on http://localhost:8000
Document root is /mnt/c/Dev/Sites/test-bug/public
Press Ctrl-C to quit.
[Wed Jan 16 12:29:15 2019] 127.0.0.1:57012 [200]: /
[Wed Jan 16 12:29:16 2019] 127.0.0.1:57013 [404]: /favicon.ico - No such file or directory

Program received signal SIGPIPE, Broken pipe.
0x00007ffffd2f2c4d in __libc_send (fd=5, buf=0x8ace8f8, len=55, flags=0) at
../sysdeps/unix/sysv/linux/send.c:28
28      ../sysdeps/unix/sysv/linux/send.c: No such file or directory.
(gdb)

------------------------------------------------------------------------
[2019-01-16 11:23:59] girgias@php.net

Okay, I think I have narrowed down from where the problem comes.

Or it comes from Guzzle ("guzzlehttp/psr7": "^1.5")
Or it comes from first instantiating an object.

gdb backtrace for the following code example:
<?php

require '../vendor/autoload.php';

$response = new GuzzleHttp\Psr7\Response(200, [], 'Hello World');


gdb output:
gdb --args php -S localhost:8000 -t public/ -d display_errors=1
GNU gdb (Ubuntu 8.1-0ubuntu3) 8.1.0.20180409-git
Copyright (C) 2018 Free Software Foundation, Inc.
License GPLv3+: GNU GPL version 3 or later <http://gnu.org/licenses/gpl.html>
This is free software: you are free to change and redistribute it.
There is NO WARRANTY, to the extent permitted by law.  Type "show copying"
and "show warranty" for details.
This GDB was configured as "x86_64-linux-gnu".
Type "show configuration" for configuration details.
For bug reporting instructions, please see:
<http://www.gnu.org/software/gdb/bugs/>.
Find the GDB manual and other documentation resources online at:
<http://www.gnu.org/software/gdb/documentation/>.
For help, type "help".
Type "apropos word" to search for commands related to "word"...
Reading symbols from php...(no debugging symbols found)...done.
(gdb) r
Starting program: /usr/bin/php -S localhost:8000 -t public/ -d display_errors=1
[Thread debugging using libthread_db enabled]
Using host libthread_db library "/lib/x86_64-linux-gnu/libthread_db.so.1".
PHP 7.3.1-1+ubuntu18.04.1+deb.sury.org+1 Development Server started at Wed Jan 16 12:19:29 2019
Listening on http://localhost:8000
Document root is /mnt/c/Dev/Sites/test-bug/public
Press Ctrl-C to quit.
[Wed Jan 16 12:19:30 2019] 127.0.0.1:56899 [200]: /
[Wed Jan 16 12:19:30 2019] 127.0.0.1:56900 [404]: /favicon.ico - No such file or directory

Program received signal SIGPIPE, Broken pipe.
0x00007ffffd2f2c4d in __libc_send (fd=5, buf=0x8a1aaf8, len=55, flags=0) at
../sysdeps/unix/sysv/linux/send.c:28
28      ../sysdeps/unix/sysv/linux/send.c: No such file or directory.



I will try to figure out if it's only related to Guzzle or if it's a general problem.

------------------------------------------------------------------------
[2019-01-16 11:01:40] girgias@php.net

So it does not crash on *any* file, an empty file and a simple echo "Hello World"; work
just fine.

Will dig deeper and see if it's related to the fact that I'm using http-interop
Http\Response\send function with a PSR-7 object instead of a simple echo to display output.

------------------------------------------------------------------------
[2019-01-16 10:25:39] girgias@php.net

I just run the command by running it directly under gdb and got this output:

gdb --args php -S localhost:8000 -t public/ -d display_errors=1
GNU gdb (Ubuntu 8.1-0ubuntu3) 8.1.0.20180409-git
Copyright (C) 2018 Free Software Foundation, Inc.
License GPLv3+: GNU GPL version 3 or later <http://gnu.org/licenses/gpl.html>
This is free software: you are free to change and redistribute it.
There is NO WARRANTY, to the extent permitted by law.  Type "show copying"
and "show warranty" for details.
This GDB was configured as "x86_64-linux-gnu".
Type "show configuration" for configuration details.
For bug reporting instructions, please see:
<http://www.gnu.org/software/gdb/bugs/>.
Find the GDB manual and other documentation resources online at:
<http://www.gnu.org/software/gdb/documentation/>.
For help, type "help".
Type "apropos word" to search for commands related to "word"...
Reading symbols from php...(no debugging symbols found)...done.
(gdb) r
Starting program: /usr/bin/php -S localhost:8000 -t public/ -d display_errors=1
[Thread debugging using libthread_db enabled]
Using host libthread_db library "/lib/x86_64-linux-gnu/libthread_db.so.1".
PHP 7.3.1-1+ubuntu18.04.1+deb.sury.org+1 Development Server started at Wed Jan 16 11:22:50 2019
Listening on http://localhost:8000
Document root is /mnt/c/Dev/Sites/personal/public
Press Ctrl-C to quit.

Program received signal SIGSEGV, Segmentation fault.
0x000000000831c508 in ?? ()



I will try if this applies even to an empty PHP file.

------------------------------------------------------------------------


The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at

    https://bugs.php.net/bug.php?id=77465


--
Edit this bug report at https://bugs.php.net/bug.php?id=77465&edit=1


Thread (16 messages)

« previous php.bugs (#218993) next »