Bug #77430 [Com]: php-fpm crashes with Main process exited, code=dumped, status=11/SEGV

From: Date: Thu, 17 Jan 2019 08:17:38 +0000
Subject: Bug #77430 [Com]: php-fpm crashes with Main process exited, code=dumped, status=11/SEGV
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-219023@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=77430&edit=1 ID: 77430 Comment by: claudiu_beta at yahoo dot com Reported by: claudiu_beta at yahoo dot com Summary: php-fpm crashes with Main process exited, code=dumped, status=11/SEGV Status: Assigned Type: Bug Package: FPM related Operating System: Fedora 28 PHP Version: 7.3.1RC1 Assigned To: bukka Block user comment: N Private report: N New Comment: Thanks to updated, recompiled packages from Remi for Fedora 29, I was able to test the patched version. I can now confirm that the issue is gone. Thank you all! Previous Comments: ------------------------------------------------------------------------ [2019-01-17 04:28:58] mnikulin at plesk dot com With the patch "[2019-01-15 20:20 UTC] bukka@php.net" I faced Bug #77114 "php-fpm master segfaults in fpm_event_epoll_wait/fpm_event_fire" I have adjusted configuration of pools to make child exit events frequent enough and provide moderate load to ~30 pools pm.process_idle_timeout = 2s php_value[error_reporting] = 22519 pm.max_requests = 2 (gdb) bt #0 0x0000004200000000 in ?? () #1 0x000000000085c1e0 in fpm_event_fire (ev=0x1ce15b0) at /usr/src/debug/sapi/fpm/fpm/fpm_events.c:465 #2 0x000000000086f4f8 in fpm_event_epoll_wait (queue=0x1cea5a0, timeout=1000) at /usr/src/debug/sapi/fpm/fpm/events/epoll.c:145 #3 0x000000000085bf24 in fpm_event_loop (err=0) at /usr/src/debug/sapi/fpm/fpm/fpm_events.c:409 #4 0x000000000085420f in fpm_run (max_requests=0x7ffcc6873c9c) at /usr/src/debug/sapi/fpm/fpm/fpm.c:113 #5 0x00000000008618e9 in main (argc=2, argv=0x7ffcc6873ed8) at /usr/src/debug/sapi/fpm/fpm/fpm_main.c:1873 (gdb) frame 1 #1 0x000000000085c1e0 in fpm_event_fire (ev=0x1ce15b0) at /usr/src/debug/sapi/fpm/fpm/fpm_events.c:465 465 in /usr/src/debug/sapi/fpm/fpm/fpm_events.c (gdb) p ev $44 = (struct fpm_event_s *) 0x1ce15b0 (gdb) print epollfds[15] $45 = {events = 1, data = {ptr = 0x1ce15b0, fd = 30283184, u32 = 30283184, u64 = 30283184}} (gdb) print *(struct fpm_event_s *)epollfds[14].data.ptr $41 = {fd = 34, timeout = {tv_sec = 0, tv_usec = 0}, frequency = {tv_sec = 0, tv_usec = 0}, callback = 0x864541 <fpm_pctl_on_socket_accept>, arg = 0x1cd40b0, flags = 10, index = 34, which = 2} (gdb) print *(struct fpm_event_s *)epollfds[15].data.ptr $42 = {fd = 0, timeout = {tv_sec = 8822805, tv_usec = 30283040}, frequency = {tv_sec = 356482285570, tv_usec = 2}, callback = 0x4200000000, arg = 0x53, flags = 0, index = 0, which = 0} (gdb) print *(struct fpm_event_s *)epollfds[16].data.ptr $43 = {fd = 124, timeout = {tv_sec = 0, tv_usec = 0}, frequency = {tv_sec = 0, tv_usec = 0}, callback = 0x86a015 <fpm_stdio_child_said>, arg = 0x1ce0dd0, flags = 2, index = 124, which = 2} Callback in epollfds[15].data.ptr (related to fired ev) looks suspicious. ------------------------------------------------------------------------ [2019-01-16 12:23:58] remi@php.net FYI, build including this patch is available in remi-test repository (F28/F29 only) ------------------------------------------------------------------------ [2019-01-15 20:20:08] bukka@php.net Actually please try this one if you can: diff --git a/sapi/fpm/fpm/fpm_stdio.c b/sapi/fpm/fpm/fpm_stdio.c index ba8f6d8213..03d15cbf0d 100644 --- a/sapi/fpm/fpm/fpm_stdio.c +++ b/sapi/fpm/fpm/fpm_stdio.c @@ -122,7 +122,7 @@ static void fpm_stdio_child_said(struct fpm_event_s *ev, short which, void *arg) struct fpm_event_s *event; int fifo_in = 1, fifo_out = 1; int in_buf = 0; - int read_fail = 0, finish_log_stream = 0; + int read_fail = 0, finish_log_stream = 0, create_log_stream; int res; struct zlog_stream *log_stream; @@ -138,7 +138,8 @@ static void fpm_stdio_child_said(struct fpm_event_s *ev, short which, void *arg) event = &child->ev_stderr; } - if (!child->log_stream) { + create_log_stream = !child->log_stream; + if (create_log_stream) { log_stream = child->log_stream = malloc(sizeof(struct zlog_stream)); zlog_stream_init_ex(log_stream, ZLOG_WARNING, STDERR_FILENO); zlog_stream_set_decorating(log_stream, child->wp->config->decorate_workers_output); @@ -196,8 +197,10 @@ static void fpm_stdio_child_said(struct fpm_event_s *ev, short which, void *arg) } if (read_fail) { - zlog_stream_set_msg_suffix(log_stream, NULL, ", pipe is closed"); - zlog_stream_finish(log_stream); + if (create_log_stream) { + zlog_stream_set_msg_suffix(log_stream, NULL, ", pipe is closed"); + zlog_stream_finish(log_stream); + } if (read_fail < 0) { zlog(ZLOG_SYSERROR, "unable to read what child say"); } ------------------------------------------------------------------------ [2019-01-15 20:15:14] bukka@php.net I think that I know what the issue is. The event can be received after the child is freed which means that the shared log stream is uninitialized and it can't be used. Are you able to test the following patch: diff --git a/sapi/fpm/fpm/fpm_stdio.c b/sapi/fpm/fpm/fpm_stdio.c index ba8f6d8213..0ff189c9f0 100644 --- a/sapi/fpm/fpm/fpm_stdio.c +++ b/sapi/fpm/fpm/fpm_stdio.c @@ -196,8 +196,10 @@ static void fpm_stdio_child_said(struct fpm_event_s *ev, short which, void *arg) } if (read_fail) { - zlog_stream_set_msg_suffix(log_stream, NULL, ", pipe is closed"); - zlog_stream_finish(log_stream); + if (!child->log_stream) { + zlog_stream_set_msg_suffix(log_stream, NULL, ", pipe is closed"); + zlog_stream_finish(log_stream); + } if (read_fail < 0) { zlog(ZLOG_SYSERROR, "unable to read what child say"); } ------------------------------------------------------------------------ [2019-01-14 12:54:03] sjon at hortensius dot net I reported the exact same issue in 7.3.1 (as released) which NikiC tagged as a duplicate. There aren't necessarily any requests - according to the access-log, the last request was @ 03:43:35 and lasted 50ms (segfault @ 03:43:43). If you need more input let me know - I have a coredump on a debug-build ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=77430 -- Edit this bug report at https://bugs.php.net/bug.php?id=77430&edit=1

« previous php.bugs (#219023) next »