From: dr286 dot business at pacbell dot net
Operating system: Windows 10 x64
PHP version: 7.4.23
Package: Reproducible crash
Bug Type: Bug
Bug description:shmop_open won't attach and causes php to crash
Description:
------------
When using large values for for $key on shmop_open, only one shared
memory object can be opened. Subsequent attempts to open a shared
memory object result in the following warning:
Warning: shmop_open(): unable to attach or create shared memory segment
'No error' in php shell code on line 1
Also, when performing the operation repeatedly when this warning shows
up, PHP will crash with a memory access violation. The following is
information from the Windows Event log about the crash:
Log Name: Application
Source: Application Error
Date: 9/1/2021 7:09:47 PM
Event ID: 1000
Task Category: (100)
Level: Error
Keywords: Classic
User: N/A
Computer: HARDROCK
Description:
Faulting application name: php.exe, version: 7.4.23.0, time stamp:
0x6126106b
Faulting module name: php7ts.dll, version: 7.4.23.0, time stamp:
0x61261d0c
Exception code: 0xc0000005
Fault offset: 0x0000000000592b8f
Faulting process id: 0x23b0
Faulting application start time: 0x01d79f9f9a1cd8a1
Faulting application path: C:\Servers\php\php.exe
Faulting module path: C:\Servers\php\php7ts.dll
Report Id: 784e70c3-570d-41fc-bba4-32b2c9c2acfe
Faulting package full name:
Faulting package-relative application ID:
Event Xml:
<Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
<System>
<Provider Name="Application Error" />
<EventID Qualifiers="0">1000</EventID>
<Version>0</Version>
<Level>2</Level>
<Task>100</Task>
<Opcode>0</Opcode>
<Keywords>0x80000000000000</Keywords>
<TimeCreated SystemTime="2021-09-02T02:09:47.0466867Z" />
<EventRecordID>14012</EventRecordID>
<Correlation />
<Execution ProcessID="0" ThreadID="0" />
<Channel>Application</Channel>
<Computer>HARDROCK</Computer>
<Security />
</System>
<EventData>
<Data>php.exe</Data>
<Data>7.4.23.0</Data>
<Data>6126106b</Data>
<Data>php7ts.dll</Data>
<Data>7.4.23.0</Data>
<Data>61261d0c</Data>
<Data>c0000005</Data>
<Data>0000000000592b8f</Data>
<Data>23b0</Data>
<Data>01d79f9f9a1cd8a1</Data>
<Data>C:\Servers\php\php.exe</Data>
<Data>C:\Servers\php\php7ts.dll</Data>
<Data>784e70c3-570d-41fc-bba4-32b2c9c2acfe</Data>
<Data>
</Data>
<Data>
</Data>
</EventData>
</Event>
Below is the diff of php.ini file with all the comments and blank lines
removed. The diff was almost 500 lines long, so I just copied both
files and cleared out the comments and blank lines and diffed that. The
file compared against was php.ini-development.
--- php.ini-development Wed Sep 01 18:51:26 2021
+++ php.ini Wed Sep 01 18:51:19 2021
@@ -2 +1,0 @@
-engine = On
@@ -13 +11,0 @@
-zend.exception_ignore_args = Off
@@ -25,0 +24 @@
+html_errors = On
@@ -35 +34 @@
-;include_path = ".;c:\php\includes"
+include_path = ".;c:\servers\php\includes"
@@ -37,0 +37 @@
+extension_dir = "C:\servers\php\ext"
@@ -44,0 +45,6 @@
+extension=php_fileinfo.dll
+extension=php_openssl.dll
+extension=php_pdo_mysql.dll
+extension=php_shmop.dll
+extension=php_sockets.dll
+zend_extension="C:\servers\php\ext\php_xdebug.dll"
@@ -50 +55,0 @@
-[imap]
@@ -55,0 +61 @@
+pdo_mysql.cache_size = 2000
@@ -61,0 +68,2 @@
+[SQL]
+sql.safe_mode = Off
@@ -68,0 +77,7 @@
+[Interbase]
+ibase.allow_persistent = 1
+ibase.max_persistent = -1
+ibase.max_links = -1
+ibase.timestampformat = "%Y-%m-%d %H:%M:%S"
+ibase.dateformat = "%Y-%m-%d"
+ibase.timeformat = "%H:%M:%S"
@@ -72,0 +88 @@
+mysqli.cache_size = 2000
@@ -95 +111,2 @@
-session.use_strict_mode = 0
+session.save_path = "C:\servers\sessions"
+session.use_strict_mode = 1
@@ -103,2 +120 @@
-session.cookie_httponly =
-session.cookie_samesite =
+session.cookie_httponly = 1
@@ -131,0 +148 @@
+[mcrypt]
@@ -136 +153,3 @@
-[ffi]
\ No newline at end of file
+[Xdebug]
+xdebug.remote_enable = 1
+xdebug.remote_autostart = 1
\ No newline at end of file
Test script:
---------------
<?php
// This file demonstrates a bug in php 7.4.23 dealing with shmop_open.
// THis works just fine.
$a = shmop_open(1, 'n', 0664, 16384);
$b = shmop_open(2, 'n', 0664, 16384);
shmop_delete($a);
shmop_delete($b);
shmop_close($a);
shmop_close($b);
// This fails.
$a = shmop_open(367504384, 'n', 0664, 262144);
$b = shmop_open(367504385, 'n', 0664, 65536);
if ($b == false) {
$b = shmop_open(367504385, 'w', 0664, 65536);
}
// And this will crash php.
$c = shmop_open(367504385, 'n', 0664, 65536);
if ($c == false) {
$c = shmop_open(367504385, 'w', 0664, 65536);
}
echo "Reached the end.\n";
?>
Expected result:
----------------
It should create/attach a resource from key 367504385 without crashing.
Also, if the first call fails, a warning is expected. Normally, I would
use @ to suppress it. The second call should attach to an already
existing shared memory region.
Actual result:
--------------
C:\Servers\webdocs\test\bugs>php -f php_crash.php
PHP Warning: shmop_open(): unable to attach or create shared memory
segment 'No error' in C:\Servers\webdocs\test\bugs\php_crash.php on line
12
PHP Stack trace:
PHP 1. {main}() C:\Servers\webdocs\test\bugs\php_crash.php:0
PHP 2. shmop_open() C:\Servers\webdocs\test\bugs\php_crash.php:12
Warning: shmop_open(): unable to attach or create shared memory segment
'No error' in C:\Servers\webdocs\test\bugs\php_crash.php on line 12
Call Stack:
0.3998 395600 1. {main}()
C:\Servers\webdocs\test\bugs\php_crash.php:0
0.4003 395680 2. shmop_open()
C:\Servers\webdocs\test\bugs\php_crash.php:12
PHP Warning: shmop_open(): unable to attach or create shared memory
segment 'No error' in C:\Servers\webdocs\test\bugs\php_crash.php on line
14
PHP Stack trace:
PHP 1. {main}() C:\Servers\webdocs\test\bugs\php_crash.php:0
PHP 2. shmop_open() C:\Servers\webdocs\test\bugs\php_crash.php:14
Warning: shmop_open(): unable to attach or create shared memory segment
'No error' in C:\Servers\webdocs\test\bugs\php_crash.php on line 14
Call Stack:
0.3998 395600 1. {main}()
C:\Servers\webdocs\test\bugs\php_crash.php:0
0.4045 395688 2. shmop_open()
C:\Servers\webdocs\test\bugs\php_crash.php:14
PHP Warning: shmop_open(): unable to attach or create shared memory
segment 'No error' in C:\Servers\webdocs\test\bugs\php_crash.php on line
17
PHP Stack trace:
PHP 1. {main}() C:\Servers\webdocs\test\bugs\php_crash.php:0
PHP 2. shmop_open() C:\Servers\webdocs\test\bugs\php_crash.php:17
Warning: shmop_open(): unable to attach or create shared memory segment
'No error' in C:\Servers\webdocs\test\bugs\php_crash.php on line 17
Call Stack:
0.3998 395600 1. {main}()
C:\Servers\webdocs\test\bugs\php_crash.php:0
0.4083 395688 2. shmop_open()
C:\Servers\webdocs\test\bugs\php_crash.php:17
C:\Servers\webdocs\test\bugs>
--
Edit bug report at https://bugs.php.net/bug.php?id=81407&edit=1
--
Fix committed: https://bugs.php.net/fix.php?id=81407&r=fixed
Fixed in release: https://bugs.php.net/fix.php?id=81407&r=alreadyfixed
Need backtrace: https://bugs.php.net/fix.php?id=81407&r=needtrace
Need Reproduce Script: https://bugs.php.net/fix.php?id=81407&r=needscript
Try newer version: https://bugs.php.net/fix.php?id=81407&r=oldversion
Not developer issue: https://bugs.php.net/fix.php?id=81407&r=support
Expected behavior: https://bugs.php.net/fix.php?id=81407&r=notwrong
Not enough info: https://bugs.php.net/fix.php?id=81407&r=notenoughinfo
Submitted twice: https://bugs.php.net/fix.php?id=81407&r=submittedtwice
register_globals: https://bugs.php.net/fix.php?id=81407&r=globals
PHP version support discontinued: https://bugs.php.net/fix.php?id=81407&r=phptooold
Daylight Savings: https://bugs.php.net/fix.php?id=81407&r=dst
IIS Stability: https://bugs.php.net/fix.php?id=81407&r=isapi
Install GNU Sed: https://bugs.php.net/fix.php?id=81407&r=gnused
Floating point limitations: https://bugs.php.net/fix.php?id=81407&r=float
No Zend Extensions: https://bugs.php.net/fix.php?id=81407&r=nozend
MySQL Configuration Error: https://bugs.php.net/fix.php?id=81407&r=mysqlcfg