Bug #81597 [Com]: curl SIGSEGV with PROGRESS
| From: | erik at coretech dot se | Date: | Mon, 08 Nov 2021 09:16:33 +0000 |
| Subject: | Bug #81597 [Com]: curl SIGSEGV with PROGRESS | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-237598@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=81597&edit=1
ID: 81597
Comment by: erik at coretech dot se
Reported by: erik at coretech dot se
Summary: curl SIGSEGV with PROGRESS
Status: Open
Type: Bug
Package: cURL related
PHP Version: 8.0.12
Block user comment: N
Private report: N
New Comment:
curl 7.61.1 (x86_64-redhat-linux-gnu) libcurl/7.61.1 OpenSSL/1.1.1g zlib/1.2.11 brotli/1.0.6
libidn2/2.2.0 libpsl/0.20.2 (+libidn2/2.2.0) libssh/0.9.4/openssl/zlib nghttp2/1.33.0
This is the version shipped with Rocky8
Previous Comments:
------------------------------------------------------------------------
[2021-11-08 09:08:42] nikic@php.net
I can't reproduce this with libcurl 7.68.0 (no crash or warnings under valgrind).
Which version of curl are you using?
------------------------------------------------------------------------
[2021-11-08 09:01:19] erik at coretech dot se
Description:
------------
PHP crashes randomly with SIGSEGV (about 1/2 of the times) when the code below is executed.
==805465== Thread 2:
==805465== Jump to the invalid address stated on the next line
==805465== at 0xA08E150: ???
==805465== by 0x82DC159: start_thread (in /usr/lib64/libpthread-2.28.so)
==805465== by 0x800BDD2: clone (in /usr/lib64/libc-2.28.so)
==805465== Address 0xa08e150 is not stack'd, malloc'd or (recently) free'd
==805465==
==805465==
==805465== Process terminating with default action of signal 11 (SIGSEGV): dumping core
==805465== Access not within mapped region at address 0xA08E150
==805465== at 0xA08E150: ???
==805465== by 0x82DC159: start_thread (in /usr/lib64/libpthread-2.28.so)
==805465== by 0x800BDD2: clone (in /usr/lib64/libc-2.28.so)
Test script:
---------------
<?php
class curltest {
public function start() {
$this->ch = curl_init();
$urlstr = "https://www.php.net/distributions/php-8.0.12.tar.gz";
curl_setopt($this->ch, CURLOPT_URL, $urlstr);
curl_setopt($this->ch, CURLOPT_RETURNTRANSFER, FALSE);
curl_setopt($this->ch, CURLOPT_WRITEFUNCTION, array($this,
'do_write'));
curl_setopt($this->ch, CURLOPT_PROGRESSFUNCTION, array($this,
'do_progress'));
curl_setopt($this->ch, CURLOPT_NOPROGRESS, FALSE);
curl_setopt($this->ch, CURLOPT_NOSIGNAL, TRUE);
$ret = curl_exec($this->ch);
}
private function do_write($ch, $data) {
return strlen($data);
}
private function do_progress($ch, $a = NULL, $b = NULL, $c = NULL, $d = NULL) {
return 1;
}
}
$c = new curltest();
$c->start();
Expected result:
----------------
No crash
Actual result:
--------------
Crashes with SIGSEGV
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=81597&edit=1