#20190 [Com]: Random mem corruption: zend_get_executed_filename() mismatch

From: Date: Thu, 31 Oct 2002 22:34:25 +0000
Subject: #20190 [Com]: Random mem corruption: zend_get_executed_filename() mismatch
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-23860@lists.php.net to get a copy of this message
ID: 20190 Comment by: mbr@freebsd.org Reported By: mbr@freebsd.org Status: Open Bug Type: Apache related Operating System: FreeBSD PHP Version: 4.3.0-dev New Comment: It looks to me that $path is composed somewhere. And a the old basedir entry was not overwritten correctly. So $path is $basedir + $called phpfile and the $basedir is plain wrong. Some hint where this happens ? Previous Comments: ------------------------------------------------------------------------ [2002-10-31 16:24:52] mbr@freebsd.org Sorry ... >There is no "/www/doc/www.bbb.imp.ch-80/html/visions/php" >exists, but this is a different customer. This should be: There is a dir "/www/doc/www.bbb.imp.ch-80 ..." but this is a different customer. ------------------------------------------------------------------------ [2002-10-31 16:23:17] mbr@freebsd.org This is a example: Correct: PG(open_basedir)=/www/doc/www.aaa.ch-80, Correct: zend_get_executed_filename() = /www/doc/www.aaa.ch-80/index.php, Wrong: path=/www/doc/www.bbb.imp.ch-80/html/visions/php//ueberuns/mannschaft.php There is no "/www/doc/www.bbb.imp.ch-80/html/visions/php" exists, but this is a different customer. The correct filename would be: "/www/doc/www.aaa.ch-80/ueberuns/mannschaft.php" Also note the two "//" slashes ... ------------------------------------------------------------------------ [2002-10-31 16:15:42] mbr@freebsd.org Ok, I think I'm a bit smarter now. zend_get_executed_filename() can only be used if zend_is_executing(TSRMLS_C) is true. That explains the uninitialisized values there. If I do a check for this, the errors go away and the segfaults are gone. Buth $path can still point to a wrong virtual server. That happens in 1/500 requests, and the thing is random. I try to solve this now. Martin ------------------------------------------------------------------------ [2002-10-31 15:47:14] mbr@freebsd.org Hi, >should be critical, and now you say it's fixed. >So what's the real thing here? It seems that we hit two different bugs. I've seen that bug 19292 was fixed for the part when a safe_mode include dir was involved. But here the problem is more complex. Some global php variables seem to be corrupted, or not properly initialised. I'm still in gdb and try to find out why. Martin ------------------------------------------------------------------------ [2002-10-31 11:57:24] sniper@php.net If you try a snapshot, put the version correctly here. Also, you added comment to http://bugs.php.net/bug.php?id=19292 that it should be critical, and now you say it's fixed. So what's the real thing here? ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at http://bugs.php.net/20190 -- Edit this bug report at http://bugs.php.net/?id=20190&edit=1

« previous php.bugs (#23860) next »