Bug #77114 [Com]: php-fpm master segfaults in fpm_event_epoll_wait/fpm_event_fire

From: Date: Wed, 10 Jul 2019 03:09:53 +0000
Subject: Bug #77114 [Com]: php-fpm master segfaults in fpm_event_epoll_wait/fpm_event_fire
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-221673@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=77114&edit=1 ID: 77114 Comment by: mnikulin at plesk dot com Reported by: nvizovitin at plesk dot com Summary: php-fpm master segfaults in fpm_event_epoll_wait/fpm_event_fire Status: Open Type: Bug Package: FPM related Operating System: CentOS 7 PHP Version: 7.2.11 Block user comment: N Private report: N New Comment: Bug #77185 suggests a way to reproduce the issue. With older libc (e.g. in CentOS-7) the following environment variable may be set to certainly catch use after free cases MALLOC_PERTURB_=165 The patch fpm-race-condition.patch attached to the Bug #65398 does not eliminate the problem. Previous Comments: ------------------------------------------------------------------------ [2019-02-27 03:03:40] mnikulin at plesk dot com Related To: Bug #75112 ------------------------------------------------------------------------ [2019-01-23 04:41:39] mnikulin at plesk dot com Related To: Bug #65398 ------------------------------------------------------------------------ [2019-01-22 07:39:42] mnikulin at plesk dot com Related To: Bug #77185 ------------------------------------------------------------------------ [2019-01-21 08:09:14] mnikulin at plesk dot com Related To: Bug #62418 ------------------------------------------------------------------------ [2019-01-18 11:41:38] mnikulin at plesk dot com It seems that the following quick hack with delayed bury at least significantly improves stability. --- sapi/fpm/fpm/fpm_events.c.orig 2019-01-18 11:09:38.000000000 +0000 +++ sapi/fpm/fpm/fpm_events.c 2019-01-18 11:12:53.000000000 +0000 @@ -51,6 +51,14 @@ } /* }}} */ +static struct fpm_event_s children_bury_timer; + +static void fpm_postponed_children_bury(struct fpm_event_s *ev, short which, void *arg) /* {{{ */ +{ + fpm_children_bury(); +} +/* }}} */ + static void fpm_got_signal(struct fpm_event_s *ev, short which, void *arg) /* {{{ */ { char c; @@ -72,7 +80,8 @@ switch (c) { case 'C' : /* SIGCHLD */ zlog(ZLOG_DEBUG, "received SIGCHLD"); - fpm_children_bury(); + fpm_event_set_timer(&children_bury_timer, 0, &fpm_postponed_children_bury, NULL); + fpm_event_add(&children_bury_timer, 0); break; case 'I' : /* SIGINT */ zlog(ZLOG_DEBUG, "received SIGINT"); ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=77114 -- Edit this bug report at https://bugs.php.net/bug.php?id=77114&edit=1

« previous php.bugs (#221673) next »