Bug #77751 [Opn]: Writing to SplFileObject in ob_start gives segfault
| From: | michael dot mauch at gmx dot de | Date: | Sat, 16 Mar 2019 10:18:48 +0000 |
| Subject: | Bug #77751 [Opn]: Writing to SplFileObject in ob_start gives segfault | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-220002@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=77751&edit=1
ID: 77751
User updated by: michael dot mauch at gmx dot de
Reported by: michael dot mauch at gmx dot de
Summary: Writing to SplFileObject in ob_start gives segfault
Status: Open
Type: Bug
Package: Output Control
Operating System: Ubuntu 16.04
PHP Version: 7.3.3
Block user comment: N
Private report: N
New Comment:
With PHP 7.2.0 it crashes, 7.1.27 doesn't.
Previous Comments:
------------------------------------------------------------------------
[2019-03-16 10:08:52] michael dot mauch at gmx dot de
Hi,
no, it's the same with bash:
% LC_ALL=C bash --norc -c "ulimit -c unlimited; /usr/local/src/misc/php-7.3.3/sapi/cli/php -n
~/php/crash.php"
bash: line 1: 21765 Segmentation fault (core dumped) /usr/local/src/misc/php-7.3.3/sapi/cli/php
-n ~/php/crash.php
I also tried the crash.php on my Raspberry Pi with PHP 7.2.16 and it also crashes.
It's also the same in Docker:
% docker run -it --rm -v "$PWD":/tmp -w /tmp php:7.3-cli-alpine /bin/sh -c 'ulimit -c
unlimited; php -v; php ./crash.php && echo ok'
PHP 7.3.3 (cli) (built: Mar 9 2019 00:59:08) ( NTS )
Copyright (c) 1997-2018 The PHP Group
Zend Engine v3.3.3, Copyright (c) 1998-2018 Zend Technologies
Segmentation fault (core dumped)
------------------------------------------------------------------------
[2019-03-16 02:41:31] danack@php.net
Hi, please could you try running it through a new bash shell like*:
bash -c 'sapi/cli/php -n /home/elmicha/php/crash.php'
and see if the problem "goes away"?
* - (or possibly similar
------------------------------------------------------------------------
[2019-03-15 22:21:06] michael dot mauch at gmx dot de
% gdb sapi/cli/php core
GNU gdb (Ubuntu 7.11.1-0ubuntu1~16.5) 7.11.1
Copyright (C) 2016 Free Software Foundation, Inc.
License GPLv3+: GNU GPL version 3 or later <http://gnu.org/licenses/gpl.html>
This is free software: you are free to change and redistribute it.
There is NO WARRANTY, to the extent permitted by law. Type "show copying"
and "show warranty" for details.
This GDB was configured as "x86_64-linux-gnu".
Type "show configuration" for configuration details.
For bug reporting instructions, please see:
<http://www.gnu.org/software/gdb/bugs/>.
Find the GDB manual and other documentation resources online at:
<http://www.gnu.org/software/gdb/documentation/>.
For help, type "help".
Type "apropos word" to search for commands related to "word"...
Reading symbols from sapi/cli/php...done.
[New LWP 16070]
[Thread debugging using libthread_db enabled]
Using host libthread_db library "/lib/x86_64-linux-gnu/libthread_db.so.1".
Core was generated by `sapi/cli/php -n /home/elmicha/php/crash.php'.
Program terminated with signal SIGSEGV, Segmentation fault.
#0 0x00007f1f5c884460 in ?? ()
(gdb) bt
#0 0x00007f1f5c884460 in ?? ()
#1 0x000000000070871b in _php_stream_write_buffer (stream=0x7f1f5c884380, buf=0x7f1f5c801a38
"hmm\n", count=4)
at /usr/local/src/misc/php-7.3.3/main/streams/streams.c:1083
#2 0x000000000070a1dd in _php_stream_write (stream=0x7f1f5c884380, buf=<optimized out>,
count=<optimized out>)
at /usr/local/src/misc/php-7.3.3/main/streams/streams.c:1198
#3 0x000000000064f621 in zim_spl_SplFileObject_fwrite (execute_data=0x7f1f5c81e0d0,
return_value=0x7ffdf098a380)
at /usr/local/src/misc/php-7.3.3/ext/spl/spl_directory.c:2902
#4 0x00000000007e19b8 in ZEND_DO_FCALL_SPEC_RETVAL_UNUSED_HANDLER () at
/usr/local/src/misc/php-7.3.3/Zend/zend_vm_execute.h:980
#5 execute_ex (ex=0x7f1f5c884380) at /usr/local/src/misc/php-7.3.3/Zend/zend_vm_execute.h:55485
#6 0x0000000000744598 in zend_call_function (fci=0x7f1f5c81e030, fci_cache=<optimized out>)
at /usr/local/src/misc/php-7.3.3/Zend/zend_execute_API.c:756
#7 0x000000000075c1d5 in zend_fcall_info_call (fci=0x7f1f5c87a070, fcc=0x7f1f5c87a0a8,
retval_ptr=retval_ptr@entry=0x7ffdf098a540,
args=args@entry=0x0) at /usr/local/src/misc/php-7.3.3/Zend/zend_API.c:3663
#8 0x0000000000706a15 in php_output_handler_op (context=0x7ffdf098a570, handler=0x7f1f5c86e140)
at /usr/local/src/misc/php-7.3.3/main/output.c:969
#9 php_output_stack_pop (flags=1) at /usr/local/src/misc/php-7.3.3/main/output.c:1230
#10 php_output_end_all () at /usr/local/src/misc/php-7.3.3/main/output.c:339
#11 0x00000000006f0945 in php_request_shutdown (dummy=dummy@entry=0x0) at
/usr/local/src/misc/php-7.3.3/main/main.c:1889
#12 0x00000000007e38ac in do_cli (argc=3, argv=0x20ec240) at
/usr/local/src/misc/php-7.3.3/sapi/cli/php_cli.c:1164
#13 0x000000000043ba7c in main (argc=3, argv=0x20ec240) at
/usr/local/src/misc/php-7.3.3/sapi/cli/php_cli.c:1389
(gdb)
------------------------------------------------------------------------
[2019-03-15 19:45:50] requinix@php.net
Thank you for this bug report. To properly diagnose the problem, we
need a backtrace to see what is happening behind the scenes. To
find out how to generate a backtrace, please read
http://bugs.php.net/bugs-generating-backtrace.php
for *NIX and
http://bugs.php.net/bugs-generating-backtrace-win32.php
for Win32
Once you have generated a backtrace, please submit it to this bug
report and change the status back to "Open". Thank you for helping
us make PHP better.
------------------------------------------------------------------------
[2019-03-15 19:08:23] michael dot mauch at gmx dot de
Description:
------------
I'm using a function like below to redirect all output to a log file in PHP CLI scripts.
It works until PHP 7.1, but crashes with SIGSEGV in 7.2 and 7.3. If I use old fopen() instead of
SplFileObject, it also works with 7.2 and 7.3.
Oracle Linux 7.x at work, Ubuntu 16.04 at home, or even in docker with the official images.
Test script:
---------------
<?php
$logfilename = "/tmp/crash.log";
$logfile = new SplFileObject($logfilename, "w");
ob_start(function ($buffer) use ($logfile) {
$logfile->fwrite($buffer);
$logfile->fflush();
return "";
});
echo "hmm\n";
Expected result:
----------------
# Like with PHP 7.1:
% docker run -it --rm -v "$PWD":/tmp -w /tmp php:7.1-cli /bin/bash -c 'ulimit -c
unlimited; php -v; php ./crash.php && echo ok'
PHP 7.1.27 (cli) (built: Mar 9 2019 02:51:22) ( NTS )
Copyright (c) 1997-2018 The PHP Group
Zend Engine v3.1.0, Copyright (c) 1998-2018 Zend Technologies
ok
Actual result:
--------------
# But with PHP 7.3:
% docker run -it --rm -v "$PWD":/tmp -w /tmp php:cli /bin/bash -c 'ulimit -c
unlimited; php -v; php ./crash.php && echo ok'
PHP 7.3.3 (cli) (built: Mar 9 2019 00:27:53) ( NTS )
Copyright (c) 1997-2018 The PHP Group
Zend Engine v3.3.3, Copyright (c) 1998-2018 Zend Technologies
/bin/bash: line 1: 7 Segmentation fault (core dumped) php ./crash.php
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=77751&edit=1