Bug #79696 [Opn]: Child exited Segmentation fault, __strchr_sse2, putenv

From: Date: Fri, 12 Jun 2020 16:56:54 +0000
Subject: Bug #79696 [Opn]: Child exited Segmentation fault, __strchr_sse2, putenv
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-227454@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=79696&edit=1

 ID:                 79696
 Updated by:         nikic@php.net
 Reported by:        andrixnet at yahoo dot com
 Summary:            Child exited Segmentation fault, __strchr_sse2,
                     putenv
 Status:             Open
 Type:               Bug
 Package:            Apache2 related
 Operating System:   Linux Slackware-14.2
 PHP Version:        7.3.19
 Block user comment: N
 Private report:     N

 New Comment:

Given the trace, this is likely running into the fact that putenv() is not thread-safe. This has
been mostly mitigated in PHP 7.4 with https://github.com/php/php-src/commit/072eb6dd77b079a6f90ca5b155f9b0add1b5f2d4.


Previous Comments:
------------------------------------------------------------------------
[2020-06-12 16:30:21] andrixnet at yahoo dot com

Description:
------------
I have several Slackware-14.2 servers upgraded to latest security patches and with PHP-7.3 built
from source. (distro comes with 5.6).
Building PHP following instructions from this post: https://www.linuxquestions.org/questions/slackware-14/building-php-7-3-and-php-7-4-on-slackware-14-2-a-4175671161/
and references.

I run several WordPress sites with WooCommerce. They all run under HTTPS. mod_ssl according to
distro.
The same problem happened on PHP-7.1.x and persisted after upgrade to PHP-7.3.x.

I am getting intermittent errors in Apache error_log (the main server log, not the virtualhost). 

AH00051: child pid 5584 exit signal Segmentation fault (11)

In order to better analyze the situation I rebuilt Apache and PHP with debug symbols, I enabled core
dumps in Apache and opened the core dump with gdb, resulting in the trace below.

Tested with 7.3.17 and 7.3.19.

Apache runs with mpm_event module.
If I run Apache with mpm_prefork, the issue does not happen (at least during tests for several
hours). (workaround tried after reading last answer here: https://stackoverflow.com/questions/52224388/segmentation-fault-with-symfony-4-1-php-7-1-2x
)




Test script:
---------------
I cannot provide explicit test script, it happens using WordPress with WooCommerce. 
I can say that at least happens while editing products (in this app) and while visiting some other
components/pages. I am not sure how much it depends on the theme or other plugins installed in WP,
but I can reproduce this fairly certain as described.

End-user result is either a blank page (rare) or incomplete/erroneous page load (error occured
during an AJAX call)

Various other WP sites also yield this behaviour, including (but less frequent) errors in error_log
such as:
Out of memory (no timesptamp)
zend_mm_heap_corrupted (no timestamp)
and frequent 
AH00051: child pid 5584 exit signal Segmentation fault (11)

This happens on multiple servers based on Slackware-14.2 with equivalent configuration.

It started to happen roughly after WP version got to 5.4.
I do host WP sites (http only) that don't seem to yield these errors, reason unknown.
I do host custom built PHP sites that do not yield these errors, reason unknown.


Further backtraces and details of my investigation have been posted on the Slackware support forum:
https://www.linuxquestions.org/questions/slackware-14/apache-and-php-errors-mostly-when-hosting-wordpress-4175676899/




Actual result:
--------------
PHP configure:

EXTENSION_DIR=/usr/lib${LIBDIRSUFFIX}/php/extensions \
CFLAGS="$SLKCFLAGS" \
CXXFLAGS="$SLKCFLAGS -DU_USING_ICU_NAMESPACE=1" \
./configure \
  --prefix=/usr \
  --libdir=/usr/lib${LIBDIRSUFFIX} \
  --with-libdir=lib${LIBDIRSUFFIX} \
  --localstatedir=/var \
  --sysconfdir=/etc \
  --datarootdir=/usr/share \
  --datadir=/usr/share \
  --infodir=/usr/info \
  --mandir=/usr/man \
  --with-apxs2=/usr/bin/apxs \
  --enable-fpm \
  --with-fpm-user=apache \
  --with-fpm-group=apache \
  --enable-maintainer-zts \
  --enable-pcntl \
  --enable-mbregex \
  --enable-tokenizer=shared \
  --with-config-file-scan-dir=/etc/php.d \
  --with-config-file-path=/etc \
  --with-layout=PHP \
  --disable-sigchild \
  --enable-xml \
  --with-libxml-dir=/usr \
  --with-xmlrpc=shared \
  --enable-simplexml \
  --enable-xmlreader=shared \
  --enable-dom=shared \
  --enable-filter \
  --disable-debug \
  --with-openssl=shared \
  --with-pcre-regex=/usr \
  --with-zlib=shared,/usr \
  --enable-bcmath=shared \
  --with-bz2=shared,/usr \
  --enable-calendar=shared \
  --enable-ctype=shared \
  --with-curl=shared \
  --enable-dba=shared \
  --with-gdbm=/usr \
  --with-db4=/usr \
  --enable-exif=shared \
  --enable-ftp=shared \
  --with-gd=shared \
  --with-jpeg-dir=/usr \
  --with-png-dir=/usr \
  --with-zlib-dir=/usr \
  --with-xpm-dir=/usr \
  --with-freetype-dir=/usr \
  --with-gettext=shared,/usr \
  --with-gmp=shared,/usr \
  --with-iconv=shared \
  --with-imap-ssl=/usr \
  --with-imap=$IMAPLIBDIR \
  --with-ldap=shared \
  --enable-mbstring=shared \
  --enable-hash \
  --enable-mysqlnd=shared \
  --with-mysqli=shared,mysqlnd \
  --with-mysql-sock=/var/run/mysql/mysql.sock \
  --with-iodbc=shared,/usr \
  --enable-pdo=shared \
  --with-pdo-mysql=shared,mysqlnd \
  --with-pdo-sqlite=shared,/usr \
  --with-pdo-odbc=shared,iODBC,/usr \
  --with-pspell=shared,/usr \
  --with-enchant=shared,/usr \
  --enable-shmop=shared \
  --with-snmp=shared,/usr \
  --enable-soap=shared \
  --enable-sockets \
  --with-sqlite3=shared \
  --enable-sysvmsg \
  --enable-sysvsem \
  --enable-sysvshm \
  --enable-wddx=shared \
  --with-xsl=shared,/usr \
  --enable-zip=shared \
  --with-tsrm-pthreads \
  --enable-intl=shared \
  --enable-opcache \
  --enable-shared=yes \
  --enable-static=no \
  --with-gnu-ld \
  --with-pic \
  --enable-phpdbg \
  --with-sodium \
  --without-readline \
  --with-libedit \
  --with-password-argon2 \
  --build=$ARCH-slackware-linux || exit 1


The following PHP components are enabled (according to my distro): 
+extension=bcmath
+extension=bz2
+extension=calendar
+extension=ctype
+extension=curl
+extension=dba
+extension=dom
+extension=enchant
+extension=exif
+extension=ftp
+extension=gd
+extension=gettext
+extension=gmp
+extension=iconv
+extension=intl
+extension=ldap
+extension=mbstring
+extension=mysqlnd
+extension=mysqli
+extension=odbc
+extension=openssl
+zend_extension=opcache
+extension=pdo
+extension=pdo_mysql
+extension=pdo_sqlite
+extension=pdo_odbc
+extension=pspell
+extension=shmop
+extension=snmp
+extension=soap
+extension=sqlite3
+extension=tokenizer
+extension=wddx
+extension=xmlreader
+extension=xmlrpc
+extension=xsl
+extension=zip
+extension=zlib

============== Analysis of core dump =================================
Thread 1 (Thread 0x7faea5430700 (LWP 5591)):
#0  0x00007faed1b56363 in __strchr_sse2 () at /lib64/libc.so.6
#1  0x00007faed1b06848 in putenv () at /lib64/libc.so.6
#2  0x00007faec54024d6 in php_putenv_destructor (zv=0x7fae64982f80) at
/tmp/php-7.3.19/ext/standard/basic_functions.c:3483
        pe = 0x7fae64956360
#3  0x00007faec5638489 in zend_hash_destroy (ht=0x7fae8c07fba8) at
/tmp/php-7.3.19/Zend/zend_hash.c:1429
        p = 0x7fae64982f80
        end = 0x7fae64982fa0
#4  0x00007faec5404056 in zm_deactivate_basic (type=1, module_number=18) at
/tmp/php-7.3.19/ext/standard/basic_functions.c:3844
#5  0x00007faec56244c0 in zend_deactivate_modules () at /tmp/php-7.3.19/Zend/zend_API.c:2648
        module = 0x55d1cccff530
        p = 0x55d1ccfe1338
        __orig_bailout = 0x0
        __bailout =
---Type <return> to continue, or q <return> to quit---
                {{__jmpbuf = {140387650275024, -5732632193025448223, 0, 140388115631583,
140388073670400, 0, -5732632193054808351, -5732702830982076703}, __mask_was_saved = 0, __saved_mask
= {__val = {12714041233733445345, 140385301037056, 140388842331298, 140388073664552, 0, 6,
4294967295, 100, 140387649847328, 36, 140387649899096, 0, 0, 140388073664304, 140388612397665, 0}}}}
#6  0x00007faec553066c in php_request_shutdown (dummy=0x0) at /tmp/php-7.3.19/main/main.c:1902
        report_memleaks = 1 '\001'
#7  0x00007faec57bef0d in php_apache_request_dtor (r=0x7fae8800e3e0) at
/tmp/php-7.3.19/sapi/apache2handler/sapi_apache2.c:539
#8  0x00007faec57bfa3f in php_handler (r=0x7fae8800e3e0) at
/tmp/php-7.3.19/sapi/apache2handler/sapi_apache2.c:711
        ctx = 0x7fae8800c048
        conf = 0x7fae88009620
        brigade = 0x7fae880186e8
        bucket = 0x0
        rv = 0
        parent_req = 0x0
#9  0x000055d1cada7b9e in ap_run_handler (r=0x7fae8800e3e0) at config.c:170
        pHook = 0x55d1ccaed130
        n = 16
        rv = -1
#10 0x000055d1cada86db in ap_invoke_handler (r=0x7fae8800e3e0) at config.c:444
        handler = 0x0
        p = 0x7fae8800e3e0 "\bÃ\025\210®\177"
        result = 0
        old_handler = 0x7fae88016c08 "application/x-httpd-php"
        ignore = 0x55d1cad9c46e <ap_process_request_internal+2297>
"\211Eü\203}ü"
#11 0x000055d1cadc6fdb in ap_internal_redirect (new_uri=0x7fae8800e338
"/index.php?message_path=wp%3Aproduct%3Aadmin_notices&query=post%253D323%252Caction%253Dedit%252Cclassic-editor%253D&full_jp_logo_exists=false&_wpnonce=c9341fc148",
r=0x7fae8815c380)
    at http_request.c:790
        access_status = 0
        new = 0x7fae8800e3e0
#12 0x00007faec644efed in handler_redirect (r=0x7fae8815c380) at mod_rewrite.c:5259
#13 0x000055d1cada7b9e in ap_run_handler (r=0x7fae8815c380) at config.c:170
        pHook = 0x55d1ccaed130
        n = 14
        rv = -1
#14 0x000055d1cada86db in ap_invoke_handler (r=0x7fae8815c380) at config.c:444
        handler = 0x0
        p = 0x7fae8815c380 "\bÃ\025\210®\177"
        result = 0
        old_handler = 0x7faec6451260 "redirect-handler"
        ignore = 0x55d1cad9c46e <ap_process_request_internal+2297>
"\211Eü\203}ü"
#15 0x000055d1cadc60d1 in ap_process_async_request (r=0x7fae8815c380) at http_request.c:452
        c = 0x7faea0031298
        access_status = 0
#16 0x000055d1cadc2168 in ap_process_http_async_connection (c=0x7faea0031298) at http_core.c:158
        r = 0x7fae8815c380
        cs = 0x7faea0031260
#17 0x000055d1cadc2373 in ap_process_http_connection (c=0x7faea0031298) at http_core.c:252
#18 0x000055d1cadb5b3c in ap_run_process_connection (c=0x7faea0031298) at connection.c:42
        pHook = 0x55d1ccaedcb0
        n = 3
        rv = -1
#19 0x00007faed1025d43 in process_socket (thd=0x55d1ccb33448, p=0x7faea0030f68, sock=0x7faea0030ff0,
cs=0x7faea00311f0, my_child_nu---Type <return> to continue, or q <return> to quit---
m=0, my_thread_num=4) at event.c:1050
        c = 0x7faea0031298
        conn_id = 4
        clogging = 0
        rv = -1522336112
        rc = 0
#20 0x00007faed1027ee5 in worker_thread (thd=0x55d1ccb33448, dummy=0x7faea0001340) at event.c:2083
        csd = 0x7faea0030ff0
        cs = 0x7faea00311f0
        te = 0x0
        ptrans = 0x7faea0030f68
        ti = 0x7faea0001340
        process_slot = 0
        thread_slot = 4
        rv = 0
        is_idle = 0
#21 0x00007faed20a1684 in start_thread () at /lib64/libpthread.so.0
#22 0x00007faed1bd3eed in clone () at /lib64/libc.so.6




------------------------------------------------------------------------



--
Edit this bug report at https://bugs.php.net/bug.php?id=79696&edit=1


Thread (9 messages)

« previous php.bugs (#227454) next »