Bug #77185 [Opn->Csd]: Use-after-free in FPM master event handling

From: Date: Mon, 22 Jul 2019 08:40:29 +0000
Subject: Bug #77185 [Opn->Csd]: Use-after-free in FPM master event handling
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-221884@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=77185&edit=1 ID: 77185 Updated by: nikic@php.net Reported by: php at very dot puzzling dot org Summary: Use-after-free in FPM master event handling -Status: Open +Status: Closed Type: Bug Package: Reproducible crash Operating System: Linux PHP Version: master-Git-2018-11-22 (Git) -Assigned To: +Assigned To: nikic Block user comment: N Private report: N New Comment: Fix merged in https://github.com/php/php-src/commit/bdf24f8d6d9d495ece354d6fd2dd6ed169198a2e. Previous Comments: ------------------------------------------------------------------------ [2019-07-10 03:09:53] mnikulin at plesk dot com Related To: Bug #77114 ------------------------------------------------------------------------ [2019-02-27 03:03:40] mnikulin at plesk dot com Related To: Bug #75112 ------------------------------------------------------------------------ [2019-01-23 04:41:39] mnikulin at plesk dot com Related To: Bug #65398 ------------------------------------------------------------------------ [2019-01-22 07:39:42] mnikulin at plesk dot com Looks like this bug is similar to Bug #77114 php-fpm master segfaults in fpm_event_epoll_wait/fpm_event_fire that is not specific to reload. I have reproduced scenario for this bug for php-fpm 7.3.1. The patch with delayed fpm_children_bury for #77114 helps in the case of reload as well. I believed that in the case of reload other other bugs happen more frequently. ------------------------------------------------------------------------ [2018-11-26 06:42:05] php at very dot puzzling dot org This might actually be a duplicate of bug #65398. I am not convinced, however, that the patch offered there is entirely correct: it is possible for a child to close its stdout or stderr _without_ exiting, and if that were to happen the master would then loop continually (since the event is level-triggered, not edge-triggered). ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=77185 -- Edit this bug report at https://bugs.php.net/bug.php?id=77185&edit=1

« previous php.bugs (#221884) next »