Bug #77185 [Opn->Csd]: Use-after-free in FPM master event handling
| From: | nikic@php.net | Date: | Mon, 22 Jul 2019 08:40:29 +0000 |
| Subject: | Bug #77185 [Opn->Csd]: Use-after-free in FPM master event handling | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-221884@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=77185&edit=1
ID: 77185
Updated by: nikic@php.net
Reported by: php at very dot puzzling dot org
Summary: Use-after-free in FPM master event handling
-Status: Open
+Status: Closed
Type: Bug
Package: Reproducible crash
Operating System: Linux
PHP Version: master-Git-2018-11-22 (Git)
-Assigned To:
+Assigned To: nikic
Block user comment: N
Private report: N
New Comment:
Fix merged in https://github.com/php/php-src/commit/bdf24f8d6d9d495ece354d6fd2dd6ed169198a2e.
Previous Comments:
------------------------------------------------------------------------
[2019-07-10 03:09:53] mnikulin at plesk dot com
Related To: Bug #77114
------------------------------------------------------------------------
[2019-02-27 03:03:40] mnikulin at plesk dot com
Related To: Bug #75112
------------------------------------------------------------------------
[2019-01-23 04:41:39] mnikulin at plesk dot com
Related To: Bug #65398
------------------------------------------------------------------------
[2019-01-22 07:39:42] mnikulin at plesk dot com
Looks like this bug is similar to
Bug #77114 php-fpm master segfaults in fpm_event_epoll_wait/fpm_event_fire
that is not specific to reload. I have reproduced scenario
for this bug for php-fpm 7.3.1. The patch with delayed fpm_children_bury
for #77114 helps in the case of reload as well.
I believed that in the case of reload other other bugs happen more frequently.
------------------------------------------------------------------------
[2018-11-26 06:42:05] php at very dot puzzling dot org
This might actually be a duplicate of bug #65398. I am not convinced, however, that the patch
offered there is entirely correct: it is possible for a child to close its stdout or stderr
_without_ exiting, and if that were to happen the master would then loop continually (since the
event is level-triggered, not edge-triggered).
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=77185
--
Edit this bug report at https://bugs.php.net/bug.php?id=77185&edit=1