Bug #79696 [Com]: Child exited Segmentation fault, __strchr_sse2, putenv

From: Date: Fri, 12 Jun 2020 20:24:50 +0000
Subject: Bug #79696 [Com]: Child exited Segmentation fault, __strchr_sse2, putenv
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-227456@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=79696&edit=1 ID: 79696 Comment by: andrixnet at yahoo dot com Reported by: andrixnet at yahoo dot com Summary: Child exited Segmentation fault, __strchr_sse2, putenv Status: Open Type: Bug Package: Apache2 related Operating System: Linux Slackware-14.2 PHP Version: 7.3.19 Block user comment: N Private report: N New Comment: Further crashes with backtrace: Thread 1 (Thread 0x7f97857fa700 (LWP 16428)): #0 0x00007f97b8d3a028 in __strncmp_sse2 () at /lib64/libc.so.6 #1 0x00007f97ac5e7d0a in zif_putenv (execute_data=0x7f9746c26700, return_value=0x7f97857f5060) at /tmp/php-7.3.19/ext/standard/basic_functions.c:4231 Previous Comments: ------------------------------------------------------------------------ [2020-06-12 17:02:59] andrixnet at yahoo dot com Any chance of the fix being backported to 7.3 in a future revision? Besides WP, we are hosting sites which still need work to be 7.4 compatible. Also, what makes this be strongly related to WP? ------------------------------------------------------------------------ [2020-06-12 16:56:54] nikic@php.net Given the trace, this is likely running into the fact that putenv() is not thread-safe. This has been mostly mitigated in PHP 7.4 with https://github.com/php/php-src/commit/072eb6dd77b079a6f90ca5b155f9b0add1b5f2d4. ------------------------------------------------------------------------ [2020-06-12 16:30:21] andrixnet at yahoo dot com Description: ------------ I have several Slackware-14.2 servers upgraded to latest security patches and with PHP-7.3 built from source. (distro comes with 5.6). Building PHP following instructions from this post: https://www.linuxquestions.org/questions/slackware-14/building-php-7-3-and-php-7-4-on-slackware-14-2-a-4175671161/ and references. I run several WordPress sites with WooCommerce. They all run under HTTPS. mod_ssl according to distro. The same problem happened on PHP-7.1.x and persisted after upgrade to PHP-7.3.x. I am getting intermittent errors in Apache error_log (the main server log, not the virtualhost). AH00051: child pid 5584 exit signal Segmentation fault (11) In order to better analyze the situation I rebuilt Apache and PHP with debug symbols, I enabled core dumps in Apache and opened the core dump with gdb, resulting in the trace below. Tested with 7.3.17 and 7.3.19. Apache runs with mpm_event module. If I run Apache with mpm_prefork, the issue does not happen (at least during tests for several hours). (workaround tried after reading last answer here: https://stackoverflow.com/questions/52224388/segmentation-fault-with-symfony-4-1-php-7-1-2x ) Test script: --------------- I cannot provide explicit test script, it happens using WordPress with WooCommerce. I can say that at least happens while editing products (in this app) and while visiting some other components/pages. I am not sure how much it depends on the theme or other plugins installed in WP, but I can reproduce this fairly certain as described. End-user result is either a blank page (rare) or incomplete/erroneous page load (error occured during an AJAX call) Various other WP sites also yield this behaviour, including (but less frequent) errors in error_log such as: Out of memory (no timesptamp) zend_mm_heap_corrupted (no timestamp) and frequent AH00051: child pid 5584 exit signal Segmentation fault (11) This happens on multiple servers based on Slackware-14.2 with equivalent configuration. It started to happen roughly after WP version got to 5.4. I do host WP sites (http only) that don't seem to yield these errors, reason unknown. I do host custom built PHP sites that do not yield these errors, reason unknown. Further backtraces and details of my investigation have been posted on the Slackware support forum: https://www.linuxquestions.org/questions/slackware-14/apache-and-php-errors-mostly-when-hosting-wordpress-4175676899/ Actual result: -------------- PHP configure: EXTENSION_DIR=/usr/lib${LIBDIRSUFFIX}/php/extensions \ CFLAGS="$SLKCFLAGS" \ CXXFLAGS="$SLKCFLAGS -DU_USING_ICU_NAMESPACE=1" \ ./configure \ --prefix=/usr \ --libdir=/usr/lib${LIBDIRSUFFIX} \ --with-libdir=lib${LIBDIRSUFFIX} \ --localstatedir=/var \ --sysconfdir=/etc \ --datarootdir=/usr/share \ --datadir=/usr/share \ --infodir=/usr/info \ --mandir=/usr/man \ --with-apxs2=/usr/bin/apxs \ --enable-fpm \ --with-fpm-user=apache \ --with-fpm-group=apache \ --enable-maintainer-zts \ --enable-pcntl \ --enable-mbregex \ --enable-tokenizer=shared \ --with-config-file-scan-dir=/etc/php.d \ --with-config-file-path=/etc \ --with-layout=PHP \ --disable-sigchild \ --enable-xml \ --with-libxml-dir=/usr \ --with-xmlrpc=shared \ --enable-simplexml \ --enable-xmlreader=shared \ --enable-dom=shared \ --enable-filter \ --disable-debug \ --with-openssl=shared \ --with-pcre-regex=/usr \ --with-zlib=shared,/usr \ --enable-bcmath=shared \ --with-bz2=shared,/usr \ --enable-calendar=shared \ --enable-ctype=shared \ --with-curl=shared \ --enable-dba=shared \ --with-gdbm=/usr \ --with-db4=/usr \ --enable-exif=shared \ --enable-ftp=shared \ --with-gd=shared \ --with-jpeg-dir=/usr \ --with-png-dir=/usr \ --with-zlib-dir=/usr \ --with-xpm-dir=/usr \ --with-freetype-dir=/usr \ --with-gettext=shared,/usr \ --with-gmp=shared,/usr \ --with-iconv=shared \ --with-imap-ssl=/usr \ --with-imap=$IMAPLIBDIR \ --with-ldap=shared \ --enable-mbstring=shared \ --enable-hash \ --enable-mysqlnd=shared \ --with-mysqli=shared,mysqlnd \ --with-mysql-sock=/var/run/mysql/mysql.sock \ --with-iodbc=shared,/usr \ --enable-pdo=shared \ --with-pdo-mysql=shared,mysqlnd \ --with-pdo-sqlite=shared,/usr \ --with-pdo-odbc=shared,iODBC,/usr \ --with-pspell=shared,/usr \ --with-enchant=shared,/usr \ --enable-shmop=shared \ --with-snmp=shared,/usr \ --enable-soap=shared \ --enable-sockets \ --with-sqlite3=shared \ --enable-sysvmsg \ --enable-sysvsem \ --enable-sysvshm \ --enable-wddx=shared \ --with-xsl=shared,/usr \ --enable-zip=shared \ --with-tsrm-pthreads \ --enable-intl=shared \ --enable-opcache \ --enable-shared=yes \ --enable-static=no \ --with-gnu-ld \ --with-pic \ --enable-phpdbg \ --with-sodium \ --without-readline \ --with-libedit \ --with-password-argon2 \ --build=$ARCH-slackware-linux || exit 1 The following PHP components are enabled (according to my distro): +extension=bcmath +extension=bz2 +extension=calendar +extension=ctype +extension=curl +extension=dba +extension=dom +extension=enchant +extension=exif +extension=ftp +extension=gd +extension=gettext +extension=gmp +extension=iconv +extension=intl +extension=ldap +extension=mbstring +extension=mysqlnd +extension=mysqli +extension=odbc +extension=openssl +zend_extension=opcache +extension=pdo +extension=pdo_mysql +extension=pdo_sqlite +extension=pdo_odbc +extension=pspell +extension=shmop +extension=snmp +extension=soap +extension=sqlite3 +extension=tokenizer +extension=wddx +extension=xmlreader +extension=xmlrpc +extension=xsl +extension=zip +extension=zlib ============== Analysis of core dump ================================= Thread 1 (Thread 0x7faea5430700 (LWP 5591)): #0 0x00007faed1b56363 in __strchr_sse2 () at /lib64/libc.so.6 #1 0x00007faed1b06848 in putenv () at /lib64/libc.so.6 #2 0x00007faec54024d6 in php_putenv_destructor (zv=0x7fae64982f80) at /tmp/php-7.3.19/ext/standard/basic_functions.c:3483 pe = 0x7fae64956360 #3 0x00007faec5638489 in zend_hash_destroy (ht=0x7fae8c07fba8) at /tmp/php-7.3.19/Zend/zend_hash.c:1429 p = 0x7fae64982f80 end = 0x7fae64982fa0 #4 0x00007faec5404056 in zm_deactivate_basic (type=1, module_number=18) at /tmp/php-7.3.19/ext/standard/basic_functions.c:3844 #5 0x00007faec56244c0 in zend_deactivate_modules () at /tmp/php-7.3.19/Zend/zend_API.c:2648 module = 0x55d1cccff530 p = 0x55d1ccfe1338 __orig_bailout = 0x0 __bailout = ---Type <return> to continue, or q <return> to quit--- {{__jmpbuf = {140387650275024, -5732632193025448223, 0, 140388115631583, 140388073670400, 0, -5732632193054808351, -5732702830982076703}, __mask_was_saved = 0, __saved_mask = {__val = {12714041233733445345, 140385301037056, 140388842331298, 140388073664552, 0, 6, 4294967295, 100, 140387649847328, 36, 140387649899096, 0, 0, 140388073664304, 140388612397665, 0}}}} #6 0x00007faec553066c in php_request_shutdown (dummy=0x0) at /tmp/php-7.3.19/main/main.c:1902 report_memleaks = 1 '\001' #7 0x00007faec57bef0d in php_apache_request_dtor (r=0x7fae8800e3e0) at /tmp/php-7.3.19/sapi/apache2handler/sapi_apache2.c:539 #8 0x00007faec57bfa3f in php_handler (r=0x7fae8800e3e0) at /tmp/php-7.3.19/sapi/apache2handler/sapi_apache2.c:711 ctx = 0x7fae8800c048 conf = 0x7fae88009620 brigade = 0x7fae880186e8 bucket = 0x0 rv = 0 parent_req = 0x0 #9 0x000055d1cada7b9e in ap_run_handler (r=0x7fae8800e3e0) at config.c:170 pHook = 0x55d1ccaed130 n = 16 rv = -1 #10 0x000055d1cada86db in ap_invoke_handler (r=0x7fae8800e3e0) at config.c:444 handler = 0x0 p = 0x7fae8800e3e0 "\bÃ\025\210®\177" result = 0 old_handler = 0x7fae88016c08 "application/x-httpd-php" ignore = 0x55d1cad9c46e <ap_process_request_internal+2297> "\211Eü\203}ü" #11 0x000055d1cadc6fdb in ap_internal_redirect (new_uri=0x7fae8800e338 "/index.php?message_path=wp%3Aproduct%3Aadmin_notices&query=post%253D323%252Caction%253Dedit%252Cclassic-editor%253D&full_jp_logo_exists=false&_wpnonce=c9341fc148", r=0x7fae8815c380) at http_request.c:790 access_status = 0 new = 0x7fae8800e3e0 #12 0x00007faec644efed in handler_redirect (r=0x7fae8815c380) at mod_rewrite.c:5259 #13 0x000055d1cada7b9e in ap_run_handler (r=0x7fae8815c380) at config.c:170 pHook = 0x55d1ccaed130 n = 14 rv = -1 #14 0x000055d1cada86db in ap_invoke_handler (r=0x7fae8815c380) at config.c:444 handler = 0x0 p = 0x7fae8815c380 "\bÃ\025\210®\177" result = 0 old_handler = 0x7faec6451260 "redirect-handler" ignore = 0x55d1cad9c46e <ap_process_request_internal+2297> "\211Eü\203}ü" #15 0x000055d1cadc60d1 in ap_process_async_request (r=0x7fae8815c380) at http_request.c:452 c = 0x7faea0031298 access_status = 0 #16 0x000055d1cadc2168 in ap_process_http_async_connection (c=0x7faea0031298) at http_core.c:158 r = 0x7fae8815c380 cs = 0x7faea0031260 #17 0x000055d1cadc2373 in ap_process_http_connection (c=0x7faea0031298) at http_core.c:252 #18 0x000055d1cadb5b3c in ap_run_process_connection (c=0x7faea0031298) at connection.c:42 pHook = 0x55d1ccaedcb0 n = 3 rv = -1 #19 0x00007faed1025d43 in process_socket (thd=0x55d1ccb33448, p=0x7faea0030f68, sock=0x7faea0030ff0, cs=0x7faea00311f0, my_child_nu---Type <return> to continue, or q <return> to quit--- m=0, my_thread_num=4) at event.c:1050 c = 0x7faea0031298 conn_id = 4 clogging = 0 rv = -1522336112 rc = 0 #20 0x00007faed1027ee5 in worker_thread (thd=0x55d1ccb33448, dummy=0x7faea0001340) at event.c:2083 csd = 0x7faea0030ff0 cs = 0x7faea00311f0 te = 0x0 ptrans = 0x7faea0030f68 ti = 0x7faea0001340 process_slot = 0 thread_slot = 4 rv = 0 is_idle = 0 #21 0x00007faed20a1684 in start_thread () at /lib64/libpthread.so.0 #22 0x00007faed1bd3eed in clone () at /lib64/libc.so.6 ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=79696&edit=1

« previous php.bugs (#227456) next »