Bug #81597 [Com]: curl SIGSEGV with PROGRESS

From: Date: Mon, 08 Nov 2021 09:16:33 +0000
Subject: Bug #81597 [Com]: curl SIGSEGV with PROGRESS
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-237598@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=81597&edit=1 ID: 81597 Comment by: erik at coretech dot se Reported by: erik at coretech dot se Summary: curl SIGSEGV with PROGRESS Status: Open Type: Bug Package: cURL related PHP Version: 8.0.12 Block user comment: N Private report: N New Comment: curl 7.61.1 (x86_64-redhat-linux-gnu) libcurl/7.61.1 OpenSSL/1.1.1g zlib/1.2.11 brotli/1.0.6 libidn2/2.2.0 libpsl/0.20.2 (+libidn2/2.2.0) libssh/0.9.4/openssl/zlib nghttp2/1.33.0 This is the version shipped with Rocky8 Previous Comments: ------------------------------------------------------------------------ [2021-11-08 09:08:42] nikic@php.net I can't reproduce this with libcurl 7.68.0 (no crash or warnings under valgrind). Which version of curl are you using? ------------------------------------------------------------------------ [2021-11-08 09:01:19] erik at coretech dot se Description: ------------ PHP crashes randomly with SIGSEGV (about 1/2 of the times) when the code below is executed. ==805465== Thread 2: ==805465== Jump to the invalid address stated on the next line ==805465== at 0xA08E150: ??? ==805465== by 0x82DC159: start_thread (in /usr/lib64/libpthread-2.28.so) ==805465== by 0x800BDD2: clone (in /usr/lib64/libc-2.28.so) ==805465== Address 0xa08e150 is not stack'd, malloc'd or (recently) free'd ==805465== ==805465== ==805465== Process terminating with default action of signal 11 (SIGSEGV): dumping core ==805465== Access not within mapped region at address 0xA08E150 ==805465== at 0xA08E150: ??? ==805465== by 0x82DC159: start_thread (in /usr/lib64/libpthread-2.28.so) ==805465== by 0x800BDD2: clone (in /usr/lib64/libc-2.28.so) Test script: --------------- <?php class curltest { public function start() { $this->ch = curl_init(); $urlstr = "https://www.php.net/distributions/php-8.0.12.tar.gz"; curl_setopt($this->ch, CURLOPT_URL, $urlstr); curl_setopt($this->ch, CURLOPT_RETURNTRANSFER, FALSE); curl_setopt($this->ch, CURLOPT_WRITEFUNCTION, array($this, 'do_write')); curl_setopt($this->ch, CURLOPT_PROGRESSFUNCTION, array($this, 'do_progress')); curl_setopt($this->ch, CURLOPT_NOPROGRESS, FALSE); curl_setopt($this->ch, CURLOPT_NOSIGNAL, TRUE); $ret = curl_exec($this->ch); } private function do_write($ch, $data) { return strlen($data); } private function do_progress($ch, $a = NULL, $b = NULL, $c = NULL, $d = NULL) { return 1; } } $c = new curltest(); $c->start(); Expected result: ---------------- No crash Actual result: -------------- Crashes with SIGSEGV ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=81597&edit=1

« previous php.bugs (#237598) next »