Bug #77751 [Opn]: Writing to SplFileObject in ob_start gives segfault

From: Date: Mon, 18 Mar 2019 10:10:29 +0000
Subject: Bug #77751 [Opn]: Writing to SplFileObject in ob_start gives segfault
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-220031@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=77751&edit=1 ID: 77751 Updated by: nikic@php.net Reported by: michael dot mauch at gmx dot de Summary: Writing to SplFileObject in ob_start gives segfault Status: Open Type: Bug Package: Output Control Operating System: Ubuntu 16.04 PHP Version: 7.3.3 -Assigned To: +Assigned To: dmitry Block user comment: N Private report: N New Comment: I've committed a partial fix for this in https://github.com/php/php-src/commit/4f034016289f5a52073bfd012899dd3e202742b5. It will prevent the segfault, but not actually write anything into the file for your example. I'm not sure if it should... @dmitry: Can you please take a look at this? I don't remember why it was necessary to move the stream closing into dtor_obj rather than free_obj. Previous Comments: ------------------------------------------------------------------------ [2019-03-16 13:19:13] cmb@php.net Well, the shutdown order is intended[1], likely to cater to echoing destructors. [1] <https://github.com/php/php-src/blob/php-7.3.3/main/main.c#L1871-L1876> ------------------------------------------------------------------------ [2019-03-16 12:42:14] cmb@php.net Looks like $logfile is destroyed before the OB callback is called; if $logfile was “declared” as global instead of being “used”, no segfault occurred. ------------------------------------------------------------------------ [2019-03-16 11:40:22] michael dot mauch at gmx dot de Hah, I found it with git bisect: ./bisect.sh: Zeile 11: 23355 Speicherzugriffsfehler (Speicherabzug geschrieben) sapi/cli/php ~/php/crash.php 09d3b7386c7c7de1ef89ba04d00e93b2287adb00 is the first bad commit commit 09d3b7386c7c7de1ef89ba04d00e93b2287adb00 Author: Dmitry Stogov <dmitry@zend.com> Date: Wed Jul 12 18:53:16 2017 +0300 Resources should be closed during object destructioin, not during freeing. :040000 040000 5cf00a5f2339e62d800c87ee46d9827a00ad27f8 ffceeb3d9160671f1f22b7ca4d0b682e9bfc0dd4 M ext 'bisect run' erfolgreich ausgeführt What I did: git clone https://github.com/php/php-src.git cd php-src git checkout PHP-7.2 git bisect start git bisect bad HEAD # git log --oneline # searched for the first mention of PHP-7.2 from the bottom # and used the commit before that one in the hope that it was still good git checkout 6c32d27 ./buildconf ./configure --disable-all make -j10 sapi/cli/php ~/php/crash.php # worked, therefor: git bisect good # made a script to build and run ./bisect.sh # crashed, therefor: git bisect bad # let it search on its own: git bisect run ./bisect.sh After a while, it found the "bad" commit. For completeness, here's the bisect.sh that I used: #! /bin/bash make distclean ./buildconf ./configure --disable-all make -j10 if sapi/cli/php ~/php/crash.php ; then exit 0 else exit 1 fi ------------------------------------------------------------------------ [2019-03-16 10:25:54] michael dot mauch at gmx dot de Tried to find a tutorial for git bisect, but found https://bugs.php.net/bugs-getting-valgrind-log.php instead. Here's with PHP-7.3.3: % export USE_ZEND_ALLOC=0 % export ZEND_DONT_UNLOAD_MODULES=1 % valgrind --tool=memcheck --num-callers=30 --log-file=php.log sapi/cli/php -n ~/php/crash.php zsh: segmentation fault valgrind --tool=memcheck --num-callers=30 --log-file=php.log sapi/cli/php -n ==23707== Memcheck, a memory error detector ==23707== Copyright (C) 2002-2015, and GNU GPL'd, by Julian Seward et al. ==23707== Using Valgrind-3.11.0 and LibVEX; rerun with -h for copyright info ==23707== Command: sapi/cli/php -n /home/elmicha/php/crash.php ==23707== Parent PID: 17370 ==23707== ==23707== Invalid read of size 8 ==23707== at 0x70A19A: _php_stream_write (streams.c:1191) ==23707== by 0x64F620: zim_spl_SplFileObject_fwrite (spl_directory.c:2902) ==23707== by 0x7E19B7: ZEND_DO_FCALL_SPEC_RETVAL_UNUSED_HANDLER (zend_vm_execute.h:980) ==23707== by 0x7E19B7: execute_ex (zend_vm_execute.h:55485) ==23707== by 0x744597: zend_call_function (zend_execute_API.c:756) ==23707== by 0x75C1D4: zend_fcall_info_call (zend_API.c:3663) ==23707== by 0x706A14: php_output_handler_op (output.c:969) ==23707== by 0x706A14: php_output_stack_pop (output.c:1230) ==23707== by 0x706A14: php_output_end_all (output.c:339) ==23707== by 0x6F0944: php_request_shutdown (main.c:1889) ==23707== by 0x7E38AB: do_cli (php_cli.c:1164) ==23707== by 0x43BA7B: main (php_cli.c:1389) ==23707== Address 0x8bf2360 is 0 bytes inside a block of size 224 free'd ==23707== at 0x4C2EDEB: free (in /usr/lib/valgrind/vgpreload_memcheck-amd64-linux.so) ==23707== by 0x70A0A7: _php_stream_free (streams.c:504) ==23707== by 0x7897E4: zend_objects_store_call_destructors (zend_objects_API.c:56) ==23707== by 0x7430FA: shutdown_destructors (zend_execute_API.c:242) ==23707== by 0x7528F6: zend_call_destructors (zend.c:1089) ==23707== by 0x6F08E4: php_request_shutdown (main.c:1873) ==23707== by 0x7E38AB: do_cli (php_cli.c:1164) ==23707== by 0x43BA7B: main (php_cli.c:1389) ==23707== Block was alloc'd at ==23707== at 0x4C2DB8F: malloc (in /usr/lib/valgrind/vgpreload_memcheck-amd64-linux.so) ==23707== by 0x728C08: __zend_malloc (zend_alloc.c:2903) ==23707== by 0x709264: _php_stream_alloc (streams.c:272) ==23707== by 0x70FF4A: _php_stream_fopen_from_fd (plain_wrapper.c:246) ==23707== by 0x7103AC: _php_stream_fopen (plain_wrapper.c:1054) ==23707== by 0x70BC37: _php_stream_open_wrapper_ex (streams.c:2026) ==23707== by 0x64FE83: spl_filesystem_file_open.isra.3 (spl_directory.c:300) ==23707== by 0x650113: zim_spl_SplFileObject___construct (spl_directory.c:2283) ==23707== by 0x7E19B7: ZEND_DO_FCALL_SPEC_RETVAL_UNUSED_HANDLER (zend_vm_execute.h:980) ==23707== by 0x7E19B7: execute_ex (zend_vm_execute.h:55485) ==23707== by 0x7E2089: zend_execute (zend_vm_execute.h:60881) ==23707== by 0x752CF2: zend_execute_scripts (zend.c:1568) ==23707== by 0x6F1C2F: php_execute_script (main.c:2630) ==23707== by 0x7E4528: do_cli (php_cli.c:997) ==23707== by 0x43BA7B: main (php_cli.c:1389) ==23707== ==23707== Invalid read of size 8 ==23707== at 0x70A1A3: _php_stream_write (streams.c:1195) ==23707== by 0x64F620: zim_spl_SplFileObject_fwrite (spl_directory.c:2902) ==23707== by 0x7E19B7: ZEND_DO_FCALL_SPEC_RETVAL_UNUSED_HANDLER (zend_vm_execute.h:980) ==23707== by 0x7E19B7: execute_ex (zend_vm_execute.h:55485) ==23707== by 0x744597: zend_call_function (zend_execute_API.c:756) ==23707== by 0x75C1D4: zend_fcall_info_call (zend_API.c:3663) ==23707== by 0x706A14: php_output_handler_op (output.c:969) ==23707== by 0x706A14: php_output_stack_pop (output.c:1230) ==23707== by 0x706A14: php_output_end_all (output.c:339) ==23707== by 0x6F0944: php_request_shutdown (main.c:1889) ==23707== by 0x7E38AB: do_cli (php_cli.c:1164) ==23707== by 0x43BA7B: main (php_cli.c:1389) ==23707== Address 0x8bf2388 is 40 bytes inside a block of size 224 free'd ==23707== at 0x4C2EDEB: free (in /usr/lib/valgrind/vgpreload_memcheck-amd64-linux.so) ==23707== by 0x70A0A7: _php_stream_free (streams.c:504) ==23707== by 0x7897E4: zend_objects_store_call_destructors (zend_objects_API.c:56) ==23707== by 0x7430FA: shutdown_destructors (zend_execute_API.c:242) ==23707== by 0x7528F6: zend_call_destructors (zend.c:1089) ==23707== by 0x6F08E4: php_request_shutdown (main.c:1873) ==23707== by 0x7E38AB: do_cli (php_cli.c:1164) ==23707== by 0x43BA7B: main (php_cli.c:1389) ==23707== Block was alloc'd at ==23707== at 0x4C2DB8F: malloc (in /usr/lib/valgrind/vgpreload_memcheck-amd64-linux.so) ==23707== by 0x728C08: __zend_malloc (zend_alloc.c:2903) ==23707== by 0x709264: _php_stream_alloc (streams.c:272) ==23707== by 0x70FF4A: _php_stream_fopen_from_fd (plain_wrapper.c:246) ==23707== by 0x7103AC: _php_stream_fopen (plain_wrapper.c:1054) ==23707== by 0x70BC37: _php_stream_open_wrapper_ex (streams.c:2026) ==23707== by 0x64FE83: spl_filesystem_file_open.isra.3 (spl_directory.c:300) ==23707== by 0x650113: zim_spl_SplFileObject___construct (spl_directory.c:2283) ==23707== by 0x7E19B7: ZEND_DO_FCALL_SPEC_RETVAL_UNUSED_HANDLER (zend_vm_execute.h:980) ==23707== by 0x7E19B7: execute_ex (zend_vm_execute.h:55485) ==23707== by 0x7E2089: zend_execute (zend_vm_execute.h:60881) ==23707== by 0x752CF2: zend_execute_scripts (zend.c:1568) ==23707== by 0x6F1C2F: php_execute_script (main.c:2630) ==23707== by 0x7E4528: do_cli (php_cli.c:997) ==23707== by 0x43BA7B: main (php_cli.c:1389) ==23707== ==23707== Invalid read of size 8 ==23707== at 0x7086B3: _php_stream_write_buffer (streams.c:1071) ==23707== by 0x70A1DC: _php_stream_write (streams.c:1198) ==23707== by 0x64F620: zim_spl_SplFileObject_fwrite (spl_directory.c:2902) ==23707== by 0x7E19B7: ZEND_DO_FCALL_SPEC_RETVAL_UNUSED_HANDLER (zend_vm_execute.h:980) ==23707== by 0x7E19B7: execute_ex (zend_vm_execute.h:55485) ==23707== by 0x744597: zend_call_function (zend_execute_API.c:756) ==23707== by 0x75C1D4: zend_fcall_info_call (zend_API.c:3663) ==23707== by 0x706A14: php_output_handler_op (output.c:969) ==23707== by 0x706A14: php_output_stack_pop (output.c:1230) ==23707== by 0x706A14: php_output_end_all (output.c:339) ==23707== by 0x6F0944: php_request_shutdown (main.c:1889) ==23707== by 0x7E38AB: do_cli (php_cli.c:1164) ==23707== by 0x43BA7B: main (php_cli.c:1389) ==23707== Address 0x8bf2360 is 0 bytes inside a block of size 224 free'd ==23707== at 0x4C2EDEB: free (in /usr/lib/valgrind/vgpreload_memcheck-amd64-linux.so) ==23707== by 0x70A0A7: _php_stream_free (streams.c:504) ==23707== by 0x7897E4: zend_objects_store_call_destructors (zend_objects_API.c:56) ==23707== by 0x7430FA: shutdown_destructors (zend_execute_API.c:242) ==23707== by 0x7528F6: zend_call_destructors (zend.c:1089) ==23707== by 0x6F08E4: php_request_shutdown (main.c:1873) ==23707== by 0x7E38AB: do_cli (php_cli.c:1164) ==23707== by 0x43BA7B: main (php_cli.c:1389) ==23707== Block was alloc'd at ==23707== at 0x4C2DB8F: malloc (in /usr/lib/valgrind/vgpreload_memcheck-amd64-linux.so) ==23707== by 0x728C08: __zend_malloc (zend_alloc.c:2903) ==23707== by 0x709264: _php_stream_alloc (streams.c:272) ==23707== by 0x70FF4A: _php_stream_fopen_from_fd (plain_wrapper.c:246) ==23707== by 0x7103AC: _php_stream_fopen (plain_wrapper.c:1054) ==23707== by 0x70BC37: _php_stream_open_wrapper_ex (streams.c:2026) ==23707== by 0x64FE83: spl_filesystem_file_open.isra.3 (spl_directory.c:300) ==23707== by 0x650113: zim_spl_SplFileObject___construct (spl_directory.c:2283) ==23707== by 0x7E19B7: ZEND_DO_FCALL_SPEC_RETVAL_UNUSED_HANDLER (zend_vm_execute.h:980) ==23707== by 0x7E19B7: execute_ex (zend_vm_execute.h:55485) ==23707== by 0x7E2089: zend_execute (zend_vm_execute.h:60881) ==23707== by 0x752CF2: zend_execute_scripts (zend.c:1568) ==23707== by 0x6F1C2F: php_execute_script (main.c:2630) ==23707== by 0x7E4528: do_cli (php_cli.c:997) ==23707== by 0x43BA7B: main (php_cli.c:1389) ==23707== ==23707== Invalid read of size 1 ==23707== at 0x7086BF: _php_stream_write_buffer (streams.c:1071) ==23707== by 0x70A1DC: _php_stream_write (streams.c:1198) ==23707== by 0x64F620: zim_spl_SplFileObject_fwrite (spl_directory.c:2902) ==23707== by 0x7E19B7: ZEND_DO_FCALL_SPEC_RETVAL_UNUSED_HANDLER (zend_vm_execute.h:980) ==23707== by 0x7E19B7: execute_ex (zend_vm_execute.h:55485) ==23707== by 0x744597: zend_call_function (zend_execute_API.c:756) ==23707== by 0x75C1D4: zend_fcall_info_call (zend_API.c:3663) ==23707== by 0x706A14: php_output_handler_op (output.c:969) ==23707== by 0x706A14: php_output_stack_pop (output.c:1230) ==23707== by 0x706A14: php_output_end_all (output.c:339) ==23707== by 0x6F0944: php_request_shutdown (main.c:1889) ==23707== by 0x7E38AB: do_cli (php_cli.c:1164) ==23707== by 0x43BA7B: main (php_cli.c:1389) ==23707== Address 0x8bf23d4 is 116 bytes inside a block of size 224 free'd ==23707== at 0x4C2EDEB: free (in /usr/lib/valgrind/vgpreload_memcheck-amd64-linux.so) ==23707== by 0x70A0A7: _php_stream_free (streams.c:504) ==23707== by 0x7897E4: zend_objects_store_call_destructors (zend_objects_API.c:56) ==23707== by 0x7430FA: shutdown_destructors (zend_execute_API.c:242) ==23707== by 0x7528F6: zend_call_destructors (zend.c:1089) ==23707== by 0x6F08E4: php_request_shutdown (main.c:1873) ==23707== by 0x7E38AB: do_cli (php_cli.c:1164) ==23707== by 0x43BA7B: main (php_cli.c:1389) ==23707== Block was alloc'd at ==23707== at 0x4C2DB8F: malloc (in /usr/lib/valgrind/vgpreload_memcheck-amd64-linux.so) ==23707== by 0x728C08: __zend_malloc (zend_alloc.c:2903) ==23707== by 0x709264: _php_stream_alloc (streams.c:272) ==23707== by 0x70FF4A: _php_stream_fopen_from_fd (plain_wrapper.c:246) ==23707== by 0x7103AC: _php_stream_fopen (plain_wrapper.c:1054) ==23707== by 0x70BC37: _php_stream_open_wrapper_ex (streams.c:2026) ==23707== by 0x64FE83: spl_filesystem_file_open.isra.3 (spl_directory.c:300) ==23707== by 0x650113: zim_spl_SplFileObject___construct (spl_directory.c:2283) ==23707== by 0x7E19B7: ZEND_DO_FCALL_SPEC_RETVAL_UNUSED_HANDLER (zend_vm_execute.h:980) ==23707== by 0x7E19B7: execute_ex (zend_vm_execute.h:55485) ==23707== by 0x7E2089: zend_execute (zend_vm_execute.h:60881) ==23707== by 0x752CF2: zend_execute_scripts (zend.c:1568) ==23707== by 0x6F1C2F: php_execute_script (main.c:2630) ==23707== by 0x7E4528: do_cli (php_cli.c:997) ==23707== by 0x43BA7B: main (php_cli.c:1389) ==23707== ==23707== Invalid read of size 8 ==23707== at 0x708730: _php_stream_write_buffer (streams.c:1071) ==23707== by 0x70A1DC: _php_stream_write (streams.c:1198) ==23707== by 0x64F620: zim_spl_SplFileObject_fwrite (spl_directory.c:2902) ==23707== by 0x7E19B7: ZEND_DO_FCALL_SPEC_RETVAL_UNUSED_HANDLER (zend_vm_execute.h:980) ==23707== by 0x7E19B7: execute_ex (zend_vm_execute.h:55485) ==23707== by 0x744597: zend_call_function (zend_execute_API.c:756) ==23707== by 0x75C1D4: zend_fcall_info_call (zend_API.c:3663) ==23707== by 0x706A14: php_output_handler_op (output.c:969) ==23707== by 0x706A14: php_output_stack_pop (output.c:1230) ==23707== by 0x706A14: php_output_end_all (output.c:339) ==23707== by 0x6F0944: php_request_shutdown (main.c:1889) ==23707== by 0x7E38AB: do_cli (php_cli.c:1164) ==23707== by 0x43BA7B: main (php_cli.c:1389) ==23707== Address 0x8bf2418 is 184 bytes inside a block of size 224 free'd ==23707== at 0x4C2EDEB: free (in /usr/lib/valgrind/vgpreload_memcheck-amd64-linux.so) ==23707== by 0x70A0A7: _php_stream_free (streams.c:504) ==23707== by 0x7897E4: zend_objects_store_call_destructors (zend_objects_API.c:56) ==23707== by 0x7430FA: shutdown_destructors (zend_execute_API.c:242) ==23707== by 0x7528F6: zend_call_destructors (zend.c:1089) ==23707== by 0x6F08E4: php_request_shutdown (main.c:1873) ==23707== by 0x7E38AB: do_cli (php_cli.c:1164) ==23707== by 0x43BA7B: main (php_cli.c:1389) ==23707== Block was alloc'd at ==23707== at 0x4C2DB8F: malloc (in /usr/lib/valgrind/vgpreload_memcheck-amd64-linux.so) ==23707== by 0x728C08: __zend_malloc (zend_alloc.c:2903) ==23707== by 0x709264: _php_stream_alloc (streams.c:272) ==23707== by 0x70FF4A: _php_stream_fopen_from_fd (plain_wrapper.c:246) ==23707== by 0x7103AC: _php_stream_fopen (plain_wrapper.c:1054) ==23707== by 0x70BC37: _php_stream_open_wrapper_ex (streams.c:2026) ==23707== by 0x64FE83: spl_filesystem_file_open.isra.3 (spl_directory.c:300) ==23707== by 0x650113: zim_spl_SplFileObject___construct (spl_directory.c:2283) ==23707== by 0x7E19B7: ZEND_DO_FCALL_SPEC_RETVAL_UNUSED_HANDLER (zend_vm_execute.h:980) ==23707== by 0x7E19B7: execute_ex (zend_vm_execute.h:55485) ==23707== by 0x7E2089: zend_execute (zend_vm_execute.h:60881) ==23707== by 0x752CF2: zend_execute_scripts (zend.c:1568) ==23707== by 0x6F1C2F: php_execute_script (main.c:2630) ==23707== by 0x7E4528: do_cli (php_cli.c:997) ==23707== by 0x43BA7B: main (php_cli.c:1389) ==23707== ==23707== Invalid read of size 8 ==23707== at 0x708737: _php_stream_write_buffer (streams.c:1071) ==23707== by 0x70A1DC: _php_stream_write (streams.c:1198) ==23707== by 0x64F620: zim_spl_SplFileObject_fwrite (spl_directory.c:2902) ==23707== by 0x7E19B7: ZEND_DO_FCALL_SPEC_RETVAL_UNUSED_HANDLER (zend_vm_execute.h:980) ==23707== by 0x7E19B7: execute_ex (zend_vm_execute.h:55485) ==23707== by 0x744597: zend_call_function (zend_execute_API.c:756) ==23707== by 0x75C1D4: zend_fcall_info_call (zend_API.c:3663) ==23707== by 0x706A14: php_output_handler_op (output.c:969) ==23707== by 0x706A14: php_output_stack_pop (output.c:1230) ==23707== by 0x706A14: php_output_end_all (output.c:339) ==23707== by 0x6F0944: php_request_shutdown (main.c:1889) ==23707== by 0x7E38AB: do_cli (php_cli.c:1164) ==23707== by 0x43BA7B: main (php_cli.c:1389) ==23707== Address 0x8bf2410 is 176 bytes inside a block of size 224 free'd ==23707== at 0x4C2EDEB: free (in /usr/lib/valgrind/vgpreload_memcheck-amd64-linux.so) ==23707== by 0x70A0A7: _php_stream_free (streams.c:504) ==23707== by 0x7897E4: zend_objects_store_call_destructors (zend_objects_API.c:56) ==23707== by 0x7430FA: shutdown_destructors (zend_execute_API.c:242) ==23707== by 0x7528F6: zend_call_destructors (zend.c:1089) ==23707== by 0x6F08E4: php_request_shutdown (main.c:1873) ==23707== by 0x7E38AB: do_cli (php_cli.c:1164) ==23707== by 0x43BA7B: main (php_cli.c:1389) ==23707== Block was alloc'd at ==23707== at 0x4C2DB8F: malloc (in /usr/lib/valgrind/vgpreload_memcheck-amd64-linux.so) ==23707== by 0x728C08: __zend_malloc (zend_alloc.c:2903) ==23707== by 0x709264: _php_stream_alloc (streams.c:272) ==23707== by 0x70FF4A: _php_stream_fopen_from_fd (plain_wrapper.c:246) ==23707== by 0x7103AC: _php_stream_fopen (plain_wrapper.c:1054) ==23707== by 0x70BC37: _php_stream_open_wrapper_ex (streams.c:2026) ==23707== by 0x64FE83: spl_filesystem_file_open.isra.3 (spl_directory.c:300) ==23707== by 0x650113: zim_spl_SplFileObject___construct (spl_directory.c:2283) ==23707== by 0x7E19B7: ZEND_DO_FCALL_SPEC_RETVAL_UNUSED_HANDLER (zend_vm_execute.h:980) ==23707== by 0x7E19B7: execute_ex (zend_vm_execute.h:55485) ==23707== by 0x7E2089: zend_execute (zend_vm_execute.h:60881) ==23707== by 0x752CF2: zend_execute_scripts (zend.c:1568) ==23707== by 0x6F1C2F: php_execute_script (main.c:2630) ==23707== by 0x7E4528: do_cli (php_cli.c:997) ==23707== by 0x43BA7B: main (php_cli.c:1389) ==23707== ==23707== Invalid read of size 8 ==23707== at 0x7086CE: _php_stream_write_buffer (streams.c:1078) ==23707== by 0x70A1DC: _php_stream_write (streams.c:1198) ==23707== by 0x64F620: zim_spl_SplFileObject_fwrite (spl_directory.c:2902) ==23707== by 0x7E19B7: ZEND_DO_FCALL_SPEC_RETVAL_UNUSED_HANDLER (zend_vm_execute.h:980) ==23707== by 0x7E19B7: execute_ex (zend_vm_execute.h:55485) ==23707== by 0x744597: zend_call_function (zend_execute_API.c:756) ==23707== by 0x75C1D4: zend_fcall_info_call (zend_API.c:3663) ==23707== by 0x706A14: php_output_handler_op (output.c:969) ==23707== by 0x706A14: php_output_stack_pop (output.c:1230) ==23707== by 0x706A14: php_output_end_all (output.c:339) ==23707== by 0x6F0944: php_request_shutdown (main.c:1889) ==23707== by 0x7E38AB: do_cli (php_cli.c:1164) ==23707== by 0x43BA7B: main (php_cli.c:1389) ==23707== Address 0x8bf2360 is 0 bytes inside a block of size 224 free'd ==23707== at 0x4C2EDEB: free (in /usr/lib/valgrind/vgpreload_memcheck-amd64-linux.so) ==23707== by 0x70A0A7: _php_stream_free (streams.c:504) ==23707== by 0x7897E4: zend_objects_store_call_destructors (zend_objects_API.c:56) ==23707== by 0x7430FA: shutdown_destructors (zend_execute_API.c:242) ==23707== by 0x7528F6: zend_call_destructors (zend.c:1089) ==23707== by 0x6F08E4: php_request_shutdown (main.c:1873) ==23707== by 0x7E38AB: do_cli (php_cli.c:1164) ==23707== by 0x43BA7B: main (php_cli.c:1389) ==23707== Block was alloc'd at ==23707== at 0x4C2DB8F: malloc (in /usr/lib/valgrind/vgpreload_memcheck-amd64-linux.so) ==23707== by 0x728C08: __zend_malloc (zend_alloc.c:2903) ==23707== by 0x709264: _php_stream_alloc (streams.c:272) ==23707== by 0x70FF4A: _php_stream_fopen_from_fd (plain_wrapper.c:246) ==23707== by 0x7103AC: _php_stream_fopen (plain_wrapper.c:1054) ==23707== by 0x70BC37: _php_stream_open_wrapper_ex (streams.c:2026) ==23707== by 0x64FE83: spl_filesystem_file_open.isra.3 (spl_directory.c:300) ==23707== by 0x650113: zim_spl_SplFileObject___construct (spl_directory.c:2283) ==23707== by 0x7E19B7: ZEND_DO_FCALL_SPEC_RETVAL_UNUSED_HANDLER (zend_vm_execute.h:980) ==23707== by 0x7E19B7: execute_ex (zend_vm_execute.h:55485) ==23707== by 0x7E2089: zend_execute (zend_vm_execute.h:60881) ==23707== by 0x752CF2: zend_execute_scripts (zend.c:1568) ==23707== by 0x6F1C2F: php_execute_script (main.c:2630) ==23707== by 0x7E4528: do_cli (php_cli.c:997) ==23707== by 0x43BA7B: main (php_cli.c:1389) ==23707== ==23707== Invalid read of size 8 ==23707== at 0x708705: _php_stream_write_buffer (streams.c:1080) ==23707== by 0x70A1DC: _php_stream_write (streams.c:1198) ==23707== by 0x64F620: zim_spl_SplFileObject_fwrite (spl_directory.c:2902) ==23707== by 0x7E19B7: ZEND_DO_FCALL_SPEC_RETVAL_UNUSED_HANDLER (zend_vm_execute.h:980) ==23707== by 0x7E19B7: execute_ex (zend_vm_execute.h:55485) ==23707== by 0x744597: zend_call_function (zend_execute_API.c:756) ==23707== by 0x75C1D4: zend_fcall_info_call (zend_API.c:3663) ==23707== by 0x706A14: php_output_handler_op (output.c:969) ==23707== by 0x706A14: php_output_stack_pop (output.c:1230) ==23707== by 0x706A14: php_output_end_all (output.c:339) ==23707== by 0x6F0944: php_request_shutdown (main.c:1889) ==23707== by 0x7E38AB: do_cli (php_cli.c:1164) ==23707== by 0x43BA7B: main (php_cli.c:1389) ==23707== Address 0x8bf2420 is 192 bytes inside a block of size 224 free'd ==23707== at 0x4C2EDEB: free (in /usr/lib/valgrind/vgpreload_memcheck-amd64-linux.so) ==23707== by 0x70A0A7: _php_stream_free (streams.c:504) ==23707== by 0x7897E4: zend_objects_store_call_destructors (zend_objects_API.c:56) ==23707== by 0x7430FA: shutdown_destructors (zend_execute_API.c:242) ==23707== by 0x7528F6: zend_call_destructors (zend.c:1089) ==23707== by 0x6F08E4: php_request_shutdown (main.c:1873) ==23707== by 0x7E38AB: do_cli (php_cli.c:1164) ==23707== by 0x43BA7B: main (php_cli.c:1389) ==23707== Block was alloc'd at ==23707== at 0x4C2DB8F: malloc (in /usr/lib/valgrind/vgpreload_memcheck-amd64-linux.so) ==23707== by 0x728C08: __zend_malloc (zend_alloc.c:2903) ==23707== by 0x709264: _php_stream_alloc (streams.c:272) ==23707== by 0x70FF4A: _php_stream_fopen_from_fd (plain_wrapper.c:246) ==23707== by 0x7103AC: _php_stream_fopen (plain_wrapper.c:1054) ==23707== by 0x70BC37: _php_stream_open_wrapper_ex (streams.c:2026) ==23707== by 0x64FE83: spl_filesystem_file_open.isra.3 (spl_directory.c:300) ==23707== by 0x650113: zim_spl_SplFileObject___construct (spl_directory.c:2283) ==23707== by 0x7E19B7: ZEND_DO_FCALL_SPEC_RETVAL_UNUSED_HANDLER (zend_vm_execute.h:980) ==23707== by 0x7E19B7: execute_ex (zend_vm_execute.h:55485) ==23707== by 0x7E2089: zend_execute (zend_vm_execute.h:60881) ==23707== by 0x752CF2: zend_execute_scripts (zend.c:1568) ==23707== by 0x6F1C2F: php_execute_script (main.c:2630) ==23707== by 0x7E4528: do_cli (php_cli.c:997) ==23707== by 0x43BA7B: main (php_cli.c:1389) ==23707== ==23707== Invalid read of size 8 ==23707== at 0x70F1C0: php_stdiop_write (plain_wrapper.c:339) ==23707== by 0x70871A: _php_stream_write_buffer (streams.c:1083) ==23707== by 0x70A1DC: _php_stream_write (streams.c:1198) ==23707== by 0x64F620: zim_spl_SplFileObject_fwrite (spl_directory.c:2902) ==23707== by 0x7E19B7: ZEND_DO_FCALL_SPEC_RETVAL_UNUSED_HANDLER (zend_vm_execute.h:980) ==23707== by 0x7E19B7: execute_ex (zend_vm_execute.h:55485) ==23707== by 0x744597: zend_call_function (zend_execute_API.c:756) ==23707== by 0x75C1D4: zend_fcall_info_call (zend_API.c:3663) ==23707== by 0x706A14: php_output_handler_op (output.c:969) ==23707== by 0x706A14: php_output_stack_pop (output.c:1230) ==23707== by 0x706A14: php_output_end_all (output.c:339) ==23707== by 0x6F0944: php_request_shutdown (main.c:1889) ==23707== by 0x7E38AB: do_cli (php_cli.c:1164) ==23707== by 0x43BA7B: main (php_cli.c:1389) ==23707== Address 0x8bf2368 is 8 bytes inside a block of size 224 free'd ==23707== at 0x4C2EDEB: free (in /usr/lib/valgrind/vgpreload_memcheck-amd64-linux.so) ==23707== by 0x70A0A7: _php_stream_free (streams.c:504) ==23707== by 0x7897E4: zend_objects_store_call_destructors (zend_objects_API.c:56) ==23707== by 0x7430FA: shutdown_destructors (zend_execute_API.c:242) ==23707== by 0x7528F6: zend_call_destructors (zend.c:1089) ==23707== by 0x6F08E4: php_request_shutdown (main.c:1873) ==23707== by 0x7E38AB: do_cli (php_cli.c:1164) ==23707== by 0x43BA7B: main (php_cli.c:1389) ==23707== Block was alloc'd at ==23707== at 0x4C2DB8F: malloc (in /usr/lib/valgrind/vgpreload_memcheck-amd64-linux.so) ==23707== by 0x728C08: __zend_malloc (zend_alloc.c:2903) ==23707== by 0x709264: _php_stream_alloc (streams.c:272) ==23707== by 0x70FF4A: _php_stream_fopen_from_fd (plain_wrapper.c:246) ==23707== by 0x7103AC: _php_stream_fopen (plain_wrapper.c:1054) ==23707== by 0x70BC37: _php_stream_open_wrapper_ex (streams.c:2026) ==23707== by 0x64FE83: spl_filesystem_file_open.isra.3 (spl_directory.c:300) ==23707== by 0x650113: zim_spl_SplFileObject___construct (spl_directory.c:2283) ==23707== by 0x7E19B7: ZEND_DO_FCALL_SPEC_RETVAL_UNUSED_HANDLER (zend_vm_execute.h:980) ==23707== by 0x7E19B7: execute_ex (zend_vm_execute.h:55485) ==23707== by 0x7E2089: zend_execute (zend_vm_execute.h:60881) ==23707== by 0x752CF2: zend_execute_scripts (zend.c:1568) ==23707== by 0x6F1C2F: php_execute_script (main.c:2630) ==23707== by 0x7E4528: do_cli (php_cli.c:997) ==23707== by 0x43BA7B: main (php_cli.c:1389) ==23707== ==23707== Invalid read of size 4 ==23707== at 0x70F1C7: php_stdiop_write (plain_wrapper.c:343) ==23707== by 0x70871A: _php_stream_write_buffer (streams.c:1083) ==23707== by 0x70A1DC: _php_stream_write (streams.c:1198) ==23707== by 0x64F620: zim_spl_SplFileObject_fwrite (spl_directory.c:2902) ==23707== by 0x7E19B7: ZEND_DO_FCALL_SPEC_RETVAL_UNUSED_HANDLER (zend_vm_execute.h:980) ==23707== by 0x7E19B7: execute_ex (zend_vm_execute.h:55485) ==23707== by 0x744597: zend_call_function (zend_execute_API.c:756) ==23707== by 0x75C1D4: zend_fcall_info_call (zend_API.c:3663) ==23707== by 0x706A14: php_output_handler_op (output.c:969) ==23707== by 0x706A14: php_output_stack_pop (output.c:1230) ==23707== by 0x706A14: php_output_end_all (output.c:339) ==23707== by 0x6F0944: php_request_shutdown (main.c:1889) ==23707== by 0x7E38AB: do_cli (php_cli.c:1164) ==23707== by 0x43BA7B: main (php_cli.c:1389) ==23707== Address 0x8 is not stack'd, malloc'd or (recently) free'd ==23707== ==23707== ==23707== Process terminating with default action of signal 11 (SIGSEGV): dumping core ==23707== Access not within mapped region at address 0x8 ==23707== at 0x70F1C7: php_stdiop_write (plain_wrapper.c:343) ==23707== by 0x70871A: _php_stream_write_buffer (streams.c:1083) ==23707== by 0x70A1DC: _php_stream_write (streams.c:1198) ==23707== by 0x64F620: zim_spl_SplFileObject_fwrite (spl_directory.c:2902) ==23707== by 0x7E19B7: ZEND_DO_FCALL_SPEC_RETVAL_UNUSED_HANDLER (zend_vm_execute.h:980) ==23707== by 0x7E19B7: execute_ex (zend_vm_execute.h:55485) ==23707== by 0x744597: zend_call_function (zend_execute_API.c:756) ==23707== by 0x75C1D4: zend_fcall_info_call (zend_API.c:3663) ==23707== by 0x706A14: php_output_handler_op (output.c:969) ==23707== by 0x706A14: php_output_stack_pop (output.c:1230) ==23707== by 0x706A14: php_output_end_all (output.c:339) ==23707== by 0x6F0944: php_request_shutdown (main.c:1889) ==23707== by 0x7E38AB: do_cli (php_cli.c:1164) ==23707== by 0x43BA7B: main (php_cli.c:1389) ==23707== If you believe this happened as a result of a stack ==23707== overflow in your program's main thread (unlikely but ==23707== possible), you can try to increase the size of the ==23707== main thread stack using the --main-stacksize= flag. ==23707== The main thread stack size used in this run was 8388608. ==23707== ==23707== HEAP SUMMARY: ==23707== in use at exit: 1,820,983 bytes in 10,638 blocks ==23707== total heap usage: 11,496 allocs, 858 frees, 2,160,007 bytes allocated ==23707== ==23707== LEAK SUMMARY: ==23707== definitely lost: 0 bytes in 0 blocks ==23707== indirectly lost: 0 bytes in 0 blocks ==23707== possibly lost: 1,124,583 bytes in 9,365 blocks ==23707== still reachable: 696,400 bytes in 1,273 blocks ==23707== suppressed: 0 bytes in 0 blocks ==23707== Rerun with --leak-check=full to see details of leaked memory ==23707== ==23707== For counts of detected and suppressed errors, rerun with: -v ==23707== ERROR SUMMARY: 10 errors from 10 contexts (suppressed: 0 from 0) ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=77751 -- Edit this bug report at https://bugs.php.net/bug.php?id=77751&edit=1

« previous php.bugs (#220031) next »