Bug #77751 [Opn]: Writing to SplFileObject in ob_start gives segfault

From: Date: Sat, 16 Mar 2019 10:18:48 +0000
Subject: Bug #77751 [Opn]: Writing to SplFileObject in ob_start gives segfault
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-220002@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=77751&edit=1 ID: 77751 User updated by: michael dot mauch at gmx dot de Reported by: michael dot mauch at gmx dot de Summary: Writing to SplFileObject in ob_start gives segfault Status: Open Type: Bug Package: Output Control Operating System: Ubuntu 16.04 PHP Version: 7.3.3 Block user comment: N Private report: N New Comment: With PHP 7.2.0 it crashes, 7.1.27 doesn't. Previous Comments: ------------------------------------------------------------------------ [2019-03-16 10:08:52] michael dot mauch at gmx dot de Hi, no, it's the same with bash: % LC_ALL=C bash --norc -c "ulimit -c unlimited; /usr/local/src/misc/php-7.3.3/sapi/cli/php -n ~/php/crash.php" bash: line 1: 21765 Segmentation fault (core dumped) /usr/local/src/misc/php-7.3.3/sapi/cli/php -n ~/php/crash.php I also tried the crash.php on my Raspberry Pi with PHP 7.2.16 and it also crashes. It's also the same in Docker: % docker run -it --rm -v "$PWD":/tmp -w /tmp php:7.3-cli-alpine /bin/sh -c 'ulimit -c unlimited; php -v; php ./crash.php && echo ok' PHP 7.3.3 (cli) (built: Mar 9 2019 00:59:08) ( NTS ) Copyright (c) 1997-2018 The PHP Group Zend Engine v3.3.3, Copyright (c) 1998-2018 Zend Technologies Segmentation fault (core dumped) ------------------------------------------------------------------------ [2019-03-16 02:41:31] danack@php.net Hi, please could you try running it through a new bash shell like*: bash -c 'sapi/cli/php -n /home/elmicha/php/crash.php' and see if the problem "goes away"? * - (or possibly similar ------------------------------------------------------------------------ [2019-03-15 22:21:06] michael dot mauch at gmx dot de % gdb sapi/cli/php core GNU gdb (Ubuntu 7.11.1-0ubuntu1~16.5) 7.11.1 Copyright (C) 2016 Free Software Foundation, Inc. License GPLv3+: GNU GPL version 3 or later <http://gnu.org/licenses/gpl.html> This is free software: you are free to change and redistribute it. There is NO WARRANTY, to the extent permitted by law. Type "show copying" and "show warranty" for details. This GDB was configured as "x86_64-linux-gnu". Type "show configuration" for configuration details. For bug reporting instructions, please see: <http://www.gnu.org/software/gdb/bugs/>. Find the GDB manual and other documentation resources online at: <http://www.gnu.org/software/gdb/documentation/>. For help, type "help". Type "apropos word" to search for commands related to "word"... Reading symbols from sapi/cli/php...done. [New LWP 16070] [Thread debugging using libthread_db enabled] Using host libthread_db library "/lib/x86_64-linux-gnu/libthread_db.so.1". Core was generated by `sapi/cli/php -n /home/elmicha/php/crash.php'. Program terminated with signal SIGSEGV, Segmentation fault. #0 0x00007f1f5c884460 in ?? () (gdb) bt #0 0x00007f1f5c884460 in ?? () #1 0x000000000070871b in _php_stream_write_buffer (stream=0x7f1f5c884380, buf=0x7f1f5c801a38 "hmm\n", count=4) at /usr/local/src/misc/php-7.3.3/main/streams/streams.c:1083 #2 0x000000000070a1dd in _php_stream_write (stream=0x7f1f5c884380, buf=<optimized out>, count=<optimized out>) at /usr/local/src/misc/php-7.3.3/main/streams/streams.c:1198 #3 0x000000000064f621 in zim_spl_SplFileObject_fwrite (execute_data=0x7f1f5c81e0d0, return_value=0x7ffdf098a380) at /usr/local/src/misc/php-7.3.3/ext/spl/spl_directory.c:2902 #4 0x00000000007e19b8 in ZEND_DO_FCALL_SPEC_RETVAL_UNUSED_HANDLER () at /usr/local/src/misc/php-7.3.3/Zend/zend_vm_execute.h:980 #5 execute_ex (ex=0x7f1f5c884380) at /usr/local/src/misc/php-7.3.3/Zend/zend_vm_execute.h:55485 #6 0x0000000000744598 in zend_call_function (fci=0x7f1f5c81e030, fci_cache=<optimized out>) at /usr/local/src/misc/php-7.3.3/Zend/zend_execute_API.c:756 #7 0x000000000075c1d5 in zend_fcall_info_call (fci=0x7f1f5c87a070, fcc=0x7f1f5c87a0a8, retval_ptr=retval_ptr@entry=0x7ffdf098a540, args=args@entry=0x0) at /usr/local/src/misc/php-7.3.3/Zend/zend_API.c:3663 #8 0x0000000000706a15 in php_output_handler_op (context=0x7ffdf098a570, handler=0x7f1f5c86e140) at /usr/local/src/misc/php-7.3.3/main/output.c:969 #9 php_output_stack_pop (flags=1) at /usr/local/src/misc/php-7.3.3/main/output.c:1230 #10 php_output_end_all () at /usr/local/src/misc/php-7.3.3/main/output.c:339 #11 0x00000000006f0945 in php_request_shutdown (dummy=dummy@entry=0x0) at /usr/local/src/misc/php-7.3.3/main/main.c:1889 #12 0x00000000007e38ac in do_cli (argc=3, argv=0x20ec240) at /usr/local/src/misc/php-7.3.3/sapi/cli/php_cli.c:1164 #13 0x000000000043ba7c in main (argc=3, argv=0x20ec240) at /usr/local/src/misc/php-7.3.3/sapi/cli/php_cli.c:1389 (gdb) ------------------------------------------------------------------------ [2019-03-15 19:45:50] requinix@php.net Thank you for this bug report. To properly diagnose the problem, we need a backtrace to see what is happening behind the scenes. To find out how to generate a backtrace, please read http://bugs.php.net/bugs-generating-backtrace.php for *NIX and http://bugs.php.net/bugs-generating-backtrace-win32.php for Win32 Once you have generated a backtrace, please submit it to this bug report and change the status back to "Open". Thank you for helping us make PHP better. ------------------------------------------------------------------------ [2019-03-15 19:08:23] michael dot mauch at gmx dot de Description: ------------ I'm using a function like below to redirect all output to a log file in PHP CLI scripts. It works until PHP 7.1, but crashes with SIGSEGV in 7.2 and 7.3. If I use old fopen() instead of SplFileObject, it also works with 7.2 and 7.3. Oracle Linux 7.x at work, Ubuntu 16.04 at home, or even in docker with the official images. Test script: --------------- <?php $logfilename = "/tmp/crash.log"; $logfile = new SplFileObject($logfilename, "w"); ob_start(function ($buffer) use ($logfile) { $logfile->fwrite($buffer); $logfile->fflush(); return ""; }); echo "hmm\n"; Expected result: ---------------- # Like with PHP 7.1: % docker run -it --rm -v "$PWD":/tmp -w /tmp php:7.1-cli /bin/bash -c 'ulimit -c unlimited; php -v; php ./crash.php && echo ok' PHP 7.1.27 (cli) (built: Mar 9 2019 02:51:22) ( NTS ) Copyright (c) 1997-2018 The PHP Group Zend Engine v3.1.0, Copyright (c) 1998-2018 Zend Technologies ok Actual result: -------------- # But with PHP 7.3: % docker run -it --rm -v "$PWD":/tmp -w /tmp php:cli /bin/bash -c 'ulimit -c unlimited; php -v; php ./crash.php && echo ok' PHP 7.3.3 (cli) (built: Mar 9 2019 00:27:53) ( NTS ) Copyright (c) 1997-2018 The PHP Group Zend Engine v3.3.3, Copyright (c) 1998-2018 Zend Technologies /bin/bash: line 1: 7 Segmentation fault (core dumped) php ./crash.php ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=77751&edit=1

« previous php.bugs (#220002) next »