Bug #71982 [Opn->Fbk]: Segmentation fault

From: Date: Mon, 18 Mar 2019 16:47:26 +0000
Subject: Bug #71982 [Opn->Fbk]: Segmentation fault
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-220061@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=71982&edit=1

 ID:                 71982
 Updated by:         nikic@php.net
 Reported by:        s dot chernomor at gmail dot com
 Summary:            Segmentation fault
-Status:             Open
+Status:             Feedback
 Type:               Bug
 Package:            PCRE related
 Operating System:   centos7
 PHP Version:        7.0.5
 Block user comment: N
 Private report:     N

 New Comment:

PCRE bug triage: Are you still experiencing this problem? The stack trace doesn't look familiar
to me, but this might have been fixed in the meantime.


Previous Comments:
------------------------------------------------------------------------
[2016-08-22 09:49:44] s dot chernomorets at gmail dot com

I upgrade pcre to last version 8.39 - no changes:



gdb   /usr/sbin/httpd  /tmp/core.18488      
GNU gdb (GDB) Red Hat Enterprise Linux 7.6.1-80.el7
This GDB was configured as "x86_64-redhat-linux-gnu".
Reading symbols from /usr/sbin/httpd...Reading symbols from
/usr/lib/debug/usr/sbin/httpd.debug...done.
done.
[New LWP 18488]
[Thread debugging using libthread_db enabled]
Using host libthread_db library "/lib64/libthread_db.so.1".
Core was generated by `/usr/sbin/httpd -DFOREGROUND'.
Program terminated with signal 11, Segmentation fault.
#0  0x00007fa8f979bc03 in sljit_remove_free_block (free_block=0x7fa8f9a50d38,
free_block=0x7fa8f9a50d38) at sljit/sljitExecAllocator.c:165
165                     free_block->next->prev = free_block->prev;
Missing separate debuginfos, use: ..........
(gdb) 
(gdb) where
#0  0x00007fa8f979bc03 in sljit_remove_free_block (free_block=0x7fa8f9a50d38,
free_block=0x7fa8f9a50d38) at sljit/sljitExecAllocator.c:165
#1  sljit_free_exec (ptr=0x7fa8f9a50538) at sljit/sljitExecAllocator.c:273
#2  0x00007fa8f97c3796 in sljit_free_code (code=<optimized out>) at sljit/sljitLir.c:460
#3  _pcre_jit_free (executable_funcs=0x7fa8fadba040) at pcre_jit_compile.c:11567
#4  0x00007fa8f97c55cc in pcre_free_study (extra=0x7fa8fabd6f90) at pcre_study.c:1681
#5  0x00007fa8f3433fc3 in php_free_pcre_cache (data=<optimized out>) at
/usr/src/debug/php-7.0.10/ext/pcre/php_pcre.c:113
#6  0x00007fa8f37782e1 in zend_hash_destroy (ht=0x7fa8f409c720 <pcre_globals>) at
/usr/src/debug/php-7.0.10/Zend/zend_hash.c:1284
#7  0x00007fa8f3433f49 in zm_globals_dtor_pcre (pcre_globals=<optimized out>) at
/usr/src/debug/php-7.0.10/ext/pcre/php_pcre.c:136
#8  0x00007fa8f376e4a9 in module_destructor (module=module@entry=0x7fa8fab038c0) at
/usr/src/debug/php-7.0.10/Zend/zend_API.c:2516
.............

------------------------------------------------------------------------
[2016-08-22 08:13:26] cmb@php.net

> pcre-8.32-15.el7_2.1.x86_64

Hm, PCRE 8.32 has been released 2012-11-30. I don't know which
fixed have been applied to -15.el7_2.1, but those fixes may not
have been sufficient.

------------------------------------------------------------------------
[2016-08-22 08:10:34] s dot chernomorets at gmail dot com

Max stack size = 10240000

------------------------------------------------------------------------
[2016-08-22 08:03:43] s dot chernomorets at gmail dot com

httpd-2.4.6-40.el7.centos.4.x86_64
pcre-8.32-15.el7_2.1.x86_64

php-7.0.10


# gdb   /usr/sbin/httpd  /tmp/core.31035 
GNU gdb (GDB) Red Hat Enterprise Linux 7.6.1-80.el7
Copyright (C) 2013 Free Software Foundation, Inc.
License GPLv3+: GNU GPL version 3 or later <http://gnu.org/licenses/gpl.html>
This is free software: you are free to change and redistribute it.
There is NO WARRANTY, to the extent permitted by law.  Type "show copying"
and "show warranty" for details.
This GDB was configured as "x86_64-redhat-linux-gnu".
For bug reporting instructions, please see:
<http://www.gnu.org/software/gdb/bugs/>...
Reading symbols from /usr/sbin/httpd...Reading symbols from
/usr/lib/debug/usr/sbin/httpd.debug...done.
done.
[New LWP 31035]
[Thread debugging using libthread_db enabled]
Using host libthread_db library "/lib64/libthread_db.so.1".
Core was generated by `/usr/sbin/httpd -DFOREGROUND'.
Program terminated with signal 11, Segmentation fault.
#0  0x00007f02e0d53f23 in sljit_remove_free_block (free_block=0x7f02d178ad38,
free_block=0x7f02d178ad38) at sljit/sljitExecAllocator.c:165
165                     free_block->next->prev = free_block->prev;
(gdb) 
(gdb) 
(gdb) 
(gdb) where
#0  0x00007f02e0d53f23 in sljit_remove_free_block (free_block=0x7f02d178ad38,
free_block=0x7f02d178ad38) at sljit/sljitExecAllocator.c:165
#1  sljit_free_exec (ptr=0x7f02d178ab10) at sljit/sljitExecAllocator.c:273
#2  0x00007f02e0d70eba in sljit_free_code (code=<optimized out>) at sljit/sljitLir.c:397
#3  _pcre_jit_free (executable_funcs=0x7f02e1dcff50) at pcre_jit_compile.c:8419
#4  0x00007f02e0d72a1c in pcre_free_study (extra=0x7f02e205e9b0) at pcre_study.c:1557
#5  0x00007f02da9ecfc3 in php_free_pcre_cache (data=<optimized out>) at
/usr/src/debug/php-7.0.10/ext/pcre/php_pcre.c:113
#6  0x00007f02dad312e1 in zend_hash_destroy (ht=0x7f02db655720 <pcre_globals>) at
/usr/src/debug/php-7.0.10/Zend/zend_hash.c:1284
#7  0x00007f02da9ecf49 in zm_globals_dtor_pcre (pcre_globals=<optimized out>) at
/usr/src/debug/php-7.0.10/ext/pcre/php_pcre.c:136
#8  0x00007f02dad274a9 in module_destructor (module=module@entry=0x7f02e1cfae30) at
/usr/src/debug/php-7.0.10/Zend/zend_API.c:2516
#9  0x00007f02dad1fffc in module_destructor_zval (zv=<optimized out>) at
/usr/src/debug/php-7.0.10/Zend/zend.c:615
#10 0x00007f02dad31e08 in _zend_hash_del_el_ex (prev=<optimized out>, p=<optimized out>,
idx=<optimized out>, ht=<optimized out>)
    at /usr/src/debug/php-7.0.10/Zend/zend_hash.c:1026
#11 _zend_hash_del_el (p=0x7f02e1d15c00, idx=4, ht=0x7f02db65c440 <module_registry>) at
/usr/src/debug/php-7.0.10/Zend/zend_hash.c:1050
#12 zend_hash_graceful_reverse_destroy (ht=ht@entry=0x7f02db65c440 <module_registry>) at
/usr/src/debug/php-7.0.10/Zend/zend_hash.c:1502
#13 0x00007f02dad258cc in zend_destroy_modules () at /usr/src/debug/php-7.0.10/Zend/zend_API.c:1984
#14 0x00007f02dad20f65 in zend_shutdown () at /usr/src/debug/php-7.0.10/Zend/zend.c:840
#15 0x00007f02dacc5a6b in php_module_shutdown () at /usr/src/debug/php-7.0.10/main/main.c:2362
#16 0x00007f02dacc5b29 in php_module_shutdown_wrapper (sapi_globals=<optimized out>) at
/usr/src/debug/php-7.0.10/main/main.c:2330
#17 0x00007f02dada7681 in php_apache_child_shutdown (tmp=<optimized out>) at
/usr/src/debug/php-7.0.10/sapi/apache2handler/sapi_apache2.c:399
#18 0x00007f02dfeaa1ae in apr_pool_destroy () from /lib64/libapr-1.so.0
#19 0x00007f02dcc1223c in clean_child_exit (code=code@entry=0) at prefork.c:221
#20 0x00007f02dcc126e7 in child_main (child_num_arg=child_num_arg@entry=17) at prefork.c:728
#21 0x00007f02dcc12a55 in make_child (s=0x7f02e1b40320, slot=slot@entry=17) at prefork.c:810
#22 0x00007f02dcc12ab6 in startup_children (number_to_start=83) at prefork.c:828
#23 0x00007f02dcc137c0 in prefork_run (_pconf=<optimized out>, plog=0x7f02e1b44358,
s=0x7f02e1b40320) at prefork.c:986
#24 0x00007f02e11d75be in ap_run_mpm (pconf=pconf@entry=0x7f02e1b17138, plog=0x7f02e1b44358,
s=0x7f02e1b40320) at mpm_common.c:96
#25 0x00007f02e11d0b46 in main (argc=2, argv=0x7ffcd95b0788) at main.c:777

------------------------------------------------------------------------
[2016-08-21 10:28:11] cmb@php.net

> PCRE Library Version => 8.38 2015-11-23

Thanks.  That version should be fine.

I assume that the segfault caused by sljit_remove_free_block ()
occurred due to the JIT stack being too small. That has been
corrected as of PHP 7.0.6[1], so please try with a a newer version
and pcre.jit=1.

[1] <https://github.com/php/php-src/commit/e23a4122>

------------------------------------------------------------------------


The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at

    https://bugs.php.net/bug.php?id=71982


--
Edit this bug report at https://bugs.php.net/bug.php?id=71982&edit=1


Thread (11 messages)

« previous php.bugs (#220061) next »