Bug #79696 [Com]: Child exited Segmentation fault, __strchr_sse2, putenv
| From: | andrixnet at yahoo dot com | Date: | Fri, 12 Jun 2020 20:24:50 +0000 |
| Subject: | Bug #79696 [Com]: Child exited Segmentation fault, __strchr_sse2, putenv | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-227456@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=79696&edit=1
ID: 79696
Comment by: andrixnet at yahoo dot com
Reported by: andrixnet at yahoo dot com
Summary: Child exited Segmentation fault, __strchr_sse2,
putenv
Status: Open
Type: Bug
Package: Apache2 related
Operating System: Linux Slackware-14.2
PHP Version: 7.3.19
Block user comment: N
Private report: N
New Comment:
Further crashes with backtrace:
Thread 1 (Thread 0x7f97857fa700 (LWP 16428)):
#0 0x00007f97b8d3a028 in __strncmp_sse2 () at /lib64/libc.so.6
#1 0x00007f97ac5e7d0a in zif_putenv (execute_data=0x7f9746c26700, return_value=0x7f97857f5060)
at /tmp/php-7.3.19/ext/standard/basic_functions.c:4231
Previous Comments:
------------------------------------------------------------------------
[2020-06-12 17:02:59] andrixnet at yahoo dot com
Any chance of the fix being backported to 7.3 in a future revision?
Besides WP, we are hosting sites which still need work to be 7.4 compatible.
Also, what makes this be strongly related to WP?
------------------------------------------------------------------------
[2020-06-12 16:56:54] nikic@php.net
Given the trace, this is likely running into the fact that putenv() is not thread-safe. This has
been mostly mitigated in PHP 7.4 with https://github.com/php/php-src/commit/072eb6dd77b079a6f90ca5b155f9b0add1b5f2d4.
------------------------------------------------------------------------
[2020-06-12 16:30:21] andrixnet at yahoo dot com
Description:
------------
I have several Slackware-14.2 servers upgraded to latest security patches and with PHP-7.3 built
from source. (distro comes with 5.6).
Building PHP following instructions from this post: https://www.linuxquestions.org/questions/slackware-14/building-php-7-3-and-php-7-4-on-slackware-14-2-a-4175671161/
and references.
I run several WordPress sites with WooCommerce. They all run under HTTPS. mod_ssl according to
distro.
The same problem happened on PHP-7.1.x and persisted after upgrade to PHP-7.3.x.
I am getting intermittent errors in Apache error_log (the main server log, not the virtualhost).
AH00051: child pid 5584 exit signal Segmentation fault (11)
In order to better analyze the situation I rebuilt Apache and PHP with debug symbols, I enabled core
dumps in Apache and opened the core dump with gdb, resulting in the trace below.
Tested with 7.3.17 and 7.3.19.
Apache runs with mpm_event module.
If I run Apache with mpm_prefork, the issue does not happen (at least during tests for several
hours). (workaround tried after reading last answer here: https://stackoverflow.com/questions/52224388/segmentation-fault-with-symfony-4-1-php-7-1-2x
)
Test script:
---------------
I cannot provide explicit test script, it happens using WordPress with WooCommerce.
I can say that at least happens while editing products (in this app) and while visiting some other
components/pages. I am not sure how much it depends on the theme or other plugins installed in WP,
but I can reproduce this fairly certain as described.
End-user result is either a blank page (rare) or incomplete/erroneous page load (error occured
during an AJAX call)
Various other WP sites also yield this behaviour, including (but less frequent) errors in error_log
such as:
Out of memory (no timesptamp)
zend_mm_heap_corrupted (no timestamp)
and frequent
AH00051: child pid 5584 exit signal Segmentation fault (11)
This happens on multiple servers based on Slackware-14.2 with equivalent configuration.
It started to happen roughly after WP version got to 5.4.
I do host WP sites (http only) that don't seem to yield these errors, reason unknown.
I do host custom built PHP sites that do not yield these errors, reason unknown.
Further backtraces and details of my investigation have been posted on the Slackware support forum:
https://www.linuxquestions.org/questions/slackware-14/apache-and-php-errors-mostly-when-hosting-wordpress-4175676899/
Actual result:
--------------
PHP configure:
EXTENSION_DIR=/usr/lib${LIBDIRSUFFIX}/php/extensions \
CFLAGS="$SLKCFLAGS" \
CXXFLAGS="$SLKCFLAGS -DU_USING_ICU_NAMESPACE=1" \
./configure \
--prefix=/usr \
--libdir=/usr/lib${LIBDIRSUFFIX} \
--with-libdir=lib${LIBDIRSUFFIX} \
--localstatedir=/var \
--sysconfdir=/etc \
--datarootdir=/usr/share \
--datadir=/usr/share \
--infodir=/usr/info \
--mandir=/usr/man \
--with-apxs2=/usr/bin/apxs \
--enable-fpm \
--with-fpm-user=apache \
--with-fpm-group=apache \
--enable-maintainer-zts \
--enable-pcntl \
--enable-mbregex \
--enable-tokenizer=shared \
--with-config-file-scan-dir=/etc/php.d \
--with-config-file-path=/etc \
--with-layout=PHP \
--disable-sigchild \
--enable-xml \
--with-libxml-dir=/usr \
--with-xmlrpc=shared \
--enable-simplexml \
--enable-xmlreader=shared \
--enable-dom=shared \
--enable-filter \
--disable-debug \
--with-openssl=shared \
--with-pcre-regex=/usr \
--with-zlib=shared,/usr \
--enable-bcmath=shared \
--with-bz2=shared,/usr \
--enable-calendar=shared \
--enable-ctype=shared \
--with-curl=shared \
--enable-dba=shared \
--with-gdbm=/usr \
--with-db4=/usr \
--enable-exif=shared \
--enable-ftp=shared \
--with-gd=shared \
--with-jpeg-dir=/usr \
--with-png-dir=/usr \
--with-zlib-dir=/usr \
--with-xpm-dir=/usr \
--with-freetype-dir=/usr \
--with-gettext=shared,/usr \
--with-gmp=shared,/usr \
--with-iconv=shared \
--with-imap-ssl=/usr \
--with-imap=$IMAPLIBDIR \
--with-ldap=shared \
--enable-mbstring=shared \
--enable-hash \
--enable-mysqlnd=shared \
--with-mysqli=shared,mysqlnd \
--with-mysql-sock=/var/run/mysql/mysql.sock \
--with-iodbc=shared,/usr \
--enable-pdo=shared \
--with-pdo-mysql=shared,mysqlnd \
--with-pdo-sqlite=shared,/usr \
--with-pdo-odbc=shared,iODBC,/usr \
--with-pspell=shared,/usr \
--with-enchant=shared,/usr \
--enable-shmop=shared \
--with-snmp=shared,/usr \
--enable-soap=shared \
--enable-sockets \
--with-sqlite3=shared \
--enable-sysvmsg \
--enable-sysvsem \
--enable-sysvshm \
--enable-wddx=shared \
--with-xsl=shared,/usr \
--enable-zip=shared \
--with-tsrm-pthreads \
--enable-intl=shared \
--enable-opcache \
--enable-shared=yes \
--enable-static=no \
--with-gnu-ld \
--with-pic \
--enable-phpdbg \
--with-sodium \
--without-readline \
--with-libedit \
--with-password-argon2 \
--build=$ARCH-slackware-linux || exit 1
The following PHP components are enabled (according to my distro):
+extension=bcmath
+extension=bz2
+extension=calendar
+extension=ctype
+extension=curl
+extension=dba
+extension=dom
+extension=enchant
+extension=exif
+extension=ftp
+extension=gd
+extension=gettext
+extension=gmp
+extension=iconv
+extension=intl
+extension=ldap
+extension=mbstring
+extension=mysqlnd
+extension=mysqli
+extension=odbc
+extension=openssl
+zend_extension=opcache
+extension=pdo
+extension=pdo_mysql
+extension=pdo_sqlite
+extension=pdo_odbc
+extension=pspell
+extension=shmop
+extension=snmp
+extension=soap
+extension=sqlite3
+extension=tokenizer
+extension=wddx
+extension=xmlreader
+extension=xmlrpc
+extension=xsl
+extension=zip
+extension=zlib
============== Analysis of core dump =================================
Thread 1 (Thread 0x7faea5430700 (LWP 5591)):
#0 0x00007faed1b56363 in __strchr_sse2 () at /lib64/libc.so.6
#1 0x00007faed1b06848 in putenv () at /lib64/libc.so.6
#2 0x00007faec54024d6 in php_putenv_destructor (zv=0x7fae64982f80) at
/tmp/php-7.3.19/ext/standard/basic_functions.c:3483
pe = 0x7fae64956360
#3 0x00007faec5638489 in zend_hash_destroy (ht=0x7fae8c07fba8) at
/tmp/php-7.3.19/Zend/zend_hash.c:1429
p = 0x7fae64982f80
end = 0x7fae64982fa0
#4 0x00007faec5404056 in zm_deactivate_basic (type=1, module_number=18) at
/tmp/php-7.3.19/ext/standard/basic_functions.c:3844
#5 0x00007faec56244c0 in zend_deactivate_modules () at /tmp/php-7.3.19/Zend/zend_API.c:2648
module = 0x55d1cccff530
p = 0x55d1ccfe1338
__orig_bailout = 0x0
__bailout =
---Type <return> to continue, or q <return> to quit---
{{__jmpbuf = {140387650275024, -5732632193025448223, 0, 140388115631583,
140388073670400, 0, -5732632193054808351, -5732702830982076703}, __mask_was_saved = 0, __saved_mask
= {__val = {12714041233733445345, 140385301037056, 140388842331298, 140388073664552, 0, 6,
4294967295, 100, 140387649847328, 36, 140387649899096, 0, 0, 140388073664304, 140388612397665, 0}}}}
#6 0x00007faec553066c in php_request_shutdown (dummy=0x0) at /tmp/php-7.3.19/main/main.c:1902
report_memleaks = 1 '\001'
#7 0x00007faec57bef0d in php_apache_request_dtor (r=0x7fae8800e3e0) at
/tmp/php-7.3.19/sapi/apache2handler/sapi_apache2.c:539
#8 0x00007faec57bfa3f in php_handler (r=0x7fae8800e3e0) at
/tmp/php-7.3.19/sapi/apache2handler/sapi_apache2.c:711
ctx = 0x7fae8800c048
conf = 0x7fae88009620
brigade = 0x7fae880186e8
bucket = 0x0
rv = 0
parent_req = 0x0
#9 0x000055d1cada7b9e in ap_run_handler (r=0x7fae8800e3e0) at config.c:170
pHook = 0x55d1ccaed130
n = 16
rv = -1
#10 0x000055d1cada86db in ap_invoke_handler (r=0x7fae8800e3e0) at config.c:444
handler = 0x0
p = 0x7fae8800e3e0 "\bÃ\025\210®\177"
result = 0
old_handler = 0x7fae88016c08 "application/x-httpd-php"
ignore = 0x55d1cad9c46e <ap_process_request_internal+2297>
"\211Eü\203}ü"
#11 0x000055d1cadc6fdb in ap_internal_redirect (new_uri=0x7fae8800e338
"/index.php?message_path=wp%3Aproduct%3Aadmin_notices&query=post%253D323%252Caction%253Dedit%252Cclassic-editor%253D&full_jp_logo_exists=false&_wpnonce=c9341fc148",
r=0x7fae8815c380)
at http_request.c:790
access_status = 0
new = 0x7fae8800e3e0
#12 0x00007faec644efed in handler_redirect (r=0x7fae8815c380) at mod_rewrite.c:5259
#13 0x000055d1cada7b9e in ap_run_handler (r=0x7fae8815c380) at config.c:170
pHook = 0x55d1ccaed130
n = 14
rv = -1
#14 0x000055d1cada86db in ap_invoke_handler (r=0x7fae8815c380) at config.c:444
handler = 0x0
p = 0x7fae8815c380 "\bÃ\025\210®\177"
result = 0
old_handler = 0x7faec6451260 "redirect-handler"
ignore = 0x55d1cad9c46e <ap_process_request_internal+2297>
"\211Eü\203}ü"
#15 0x000055d1cadc60d1 in ap_process_async_request (r=0x7fae8815c380) at http_request.c:452
c = 0x7faea0031298
access_status = 0
#16 0x000055d1cadc2168 in ap_process_http_async_connection (c=0x7faea0031298) at http_core.c:158
r = 0x7fae8815c380
cs = 0x7faea0031260
#17 0x000055d1cadc2373 in ap_process_http_connection (c=0x7faea0031298) at http_core.c:252
#18 0x000055d1cadb5b3c in ap_run_process_connection (c=0x7faea0031298) at connection.c:42
pHook = 0x55d1ccaedcb0
n = 3
rv = -1
#19 0x00007faed1025d43 in process_socket (thd=0x55d1ccb33448, p=0x7faea0030f68, sock=0x7faea0030ff0,
cs=0x7faea00311f0, my_child_nu---Type <return> to continue, or q <return> to quit---
m=0, my_thread_num=4) at event.c:1050
c = 0x7faea0031298
conn_id = 4
clogging = 0
rv = -1522336112
rc = 0
#20 0x00007faed1027ee5 in worker_thread (thd=0x55d1ccb33448, dummy=0x7faea0001340) at event.c:2083
csd = 0x7faea0030ff0
cs = 0x7faea00311f0
te = 0x0
ptrans = 0x7faea0030f68
ti = 0x7faea0001340
process_slot = 0
thread_slot = 4
rv = 0
is_idle = 0
#21 0x00007faed20a1684 in start_thread () at /lib64/libpthread.so.0
#22 0x00007faed1bd3eed in clone () at /lib64/libc.so.6
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=79696&edit=1