Bug #80533 [Opn]: xml extension leaks pthread keys on Apache reload

From: Date: Tue, 22 Dec 2020 16:01:32 +0000
Subject: Bug #80533 [Opn]: xml extension leaks pthread keys on Apache reload
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-231221@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=80533&edit=1 ID: 80533 Updated by: cmb@php.net Reported by: pp at siedziba dot pl Summary: xml extension leaks pthread keys on Apache reload Status: Open Type: Bug Package: *XML functions Operating System: Linux -PHP Version: 8.0.0 +PHP Version: 7.4 Block user comment: N Private report: N New Comment: Known issue: <https://github.com/php/php-src/commit/8742276eb3905eb97a585417000c7b8df85006d4>. Previous Comments: ------------------------------------------------------------------------ [2020-12-19 22:16:21] pp at siedziba dot pl Description: ------------ Every time Apache httpd is gracefully restarted, PHP xml module leaks one xmlFreeGlobalState pthread key. When the number of keys reaches PTHREAD_KEYS_MAX and no more can be allocated, it still seems to work, but may cause malfunctions and crashes in other code. One such case is curl extension, using libcurl compiled with NSS. If NSS can't allocate a new pthread key, it crashes Apache process with an assertion failure like this: "Assertion failure: 0 == rv, at ptthread.c:970" All Apache processes go away and it needs to be started again. Older PHP versions are also affected. I noticed the problem with Apache dying during log rotation while still using an older 7.3 release from Sury repo on CentOS 7. I started debugging the problem after upgrading to latest 7.3, 7.4 and 8.0 didn't help. I created a Dockerfile replicating the problem (URL in "Test script" field). It builds PHP 8.0.0 with latest releases of Apache httpd, libxml2 and curl on Debian 10, then proceeds to reload Apache in a loop until it dies, displaying contents of __pthread_keys array on each iteration. It starts with two xmlFreeGlobalState keys after first reload: $1 = {{seq = 1, destr = 0x7fb9a8b88640 <free_key_mem>}, {seq = 3, destr = 0x0}, {seq = 1, destr = 0x7fb9a7987e10 <xmlFreeGlobalState>}, {seq = 3, destr = 0x7fb9a7987e10 <xmlFreeGlobalState>}, {seq = 1, destr = 0x7fb9a76b90f0}, {seq = 0, destr = 0x0} <repeats 1019 times>} ...and ends with: $1 = {{seq = 1, destr = 0x7fb9a8b88640 <free_key_mem>}, {seq = 2041, destr = 0x0}, {seq = 1, destr = 0x7fb9a7987e10 <xmlFreeGlobalState>}, {seq = 3, destr = 0x7fb9a7987e10 <xmlFreeGlobalState>} <repeats 1020 times>, {seq = 1, destr = 0x7fb9a76b90f0}} [Inferior 1 (process 10) detached] Unable to attach: program terminated with signal SIGABRT, Aborted. No symbol table is loaded. Use the "file" command. /bin/sh: 1: kill: No such process Test script: --------------- https://gist.github.com/rot13/92108533811a8ab15b5e685f24449b36 Expected result: ---------------- The number of xmlFreeGlobalState keys in __pthread_keys does not increase. Apache keeps working after 1022 reloads. Actual result: -------------- The number of xmlFreeGlobalState keys in __pthread_keys increases and Apache dies. ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=80533&edit=1

« previous php.bugs (#231221) next »