Bug #71446 [Asn->Csd]: Segfault when calling getallheaders() after failed virtual call

From: Date: Tue, 16 Mar 2021 11:11:28 +0000
Subject: Bug #71446 [Asn->Csd]: Segfault when calling getallheaders() after failed virtual call
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-232769@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=71446&edit=1

 ID:                 71446
 Updated by:         cmb@php.net
 Reported by:        jussi dot nieminen at ruxit dot com
 Summary:            Segfault when calling getallheaders() after failed
                     virtual call
-Status:             Assigned
+Status:             Closed
 Type:               Bug
 Package:            Reproducible crash
 Operating System:   Ubuntu 15.10
 PHP Version:        5.6.17
 Assigned To:        cmb
 Block user comment: N
 Private report:     N

 New Comment:

Thanks for the swift replay.  I'm closing then.


Previous Comments:
------------------------------------------------------------------------
[2021-03-16 05:41:44] jussi dot nieminen at ruxit dot com

Sorry, I haven't had anything to do with PHP ever since. Back then I was investigating a crash
alert from another Apache module and ended up finding this bug in the process. I've also moved
away from working with Apache in general, so I won't be able to help you here. If you
can't reproduce the problem with the included script, I guess it's okay to close this bug.

------------------------------------------------------------------------
[2021-03-15 15:52:58] cmb@php.net

Does that segfault still happen to you with any of the actively
supported PHP versions[1]?

[1] <https://www.php.net/supported-versions.php>

------------------------------------------------------------------------
[2016-01-25 15:05:59] jussi dot nieminen at ruxit dot com

Description:
------------
I made a simple PHP script that calls another using the "virtual" function. If the second
script fails to execute (my test script contains an invalid function call) and I then call
"getallheaders()", the Apache worker will segfault:

AH00051: child pid 6094 exit signal Segmentation fault (11)

Test script:
---------------
first.php:
<html>
 <body>
 <?php virtual("/second.php"); ?><br>
 <?php print_r(getallheaders()); ?>
 </body>
</html>

second.php:
<?php foohaaa(); ?>

Expected result:
----------------
Expecting to see something like this on the page (works when I change "foohaa();" to
something valid in second.php):

Array ( [Host] => 127.0.0.1:9110 [User-Agent] => Mozilla/5.0 (X11; Ubuntu; Linux x86_64;
rv:43.0) Gecko/20100101 Firefox/43.0 [Accept] =>
text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8 [Accept-Language] =>
en-US,en;q=0.5 [Accept-Encoding] => gzip, deflate [Connection] => keep-alive [Cache-Control]
=> max-age=0 )

Actual result:
--------------
(gdb) bt
#0  zend_do_fcall_common_helper_SPEC (execute_data=0x7fd4eed070e0) at
.../php-5.6.10/Zend/zend_vm_execute.h:488
#1  0x00007fd4e6a23ad8 in execute_ex (execute_data=0x7fd4eed070e0) at
.../php-5.6.10/Zend/zend_vm_execute.h:363
#2  0x00007fd4e69eb2b0 in zend_execute_scripts (type=type@entry=8, retval=retval@entry=0x0,
file_count=file_count@entry=3) at .../php-5.6.10/Zend/zend.c:1341
#3  0x00007fd4e6989a72 in php_execute_script (primary_file=primary_file@entry=0x7fff4d33e390) at
.../php-5.6.10/main/main.c:2597
#4  0x00007fd4e6a8fc62 in php_handler (r=<optimised out>) at
.../php-5.6.10/sapi/apache2handler/sapi_apache2.c:667
#5  0x0000000000457581 in ap_run_handler ()
#6  0x000000000045803a in ap_invoke_handler ()
#7  0x0000000000475b84 in ap_process_async_request ()
#8  0x0000000000475c69 in ap_process_request ()
#9  0x0000000000471bc4 in ap_process_http_sync_connection ()
#10 0x0000000000471cd8 in ap_process_http_connection ()
#11 0x00000000004661da in ap_run_process_connection ()
#12 0x0000000000466730 in ap_process_connection ()
#13 0x00000000004803dc in child_main ()
#14 0x00000000004805d2 in make_child ()
#15 0x00000000004809bd in perform_idle_server_maintenance ()
#16 0x00000000004810c9 in prefork_run ()
#17 0x0000000000434ad3 in ap_run_mpm ()
#18 0x000000000042c9a9 in main ()


------------------------------------------------------------------------



--
Edit this bug report at https://bugs.php.net/bug.php?id=71446&edit=1


Thread (4 messages)

« previous php.bugs (#232769) next »