#20268 [Com]: PHP (module or CLI) crashes with Bus Error on startup

From: Date: Thu, 07 Nov 2002 09:20:33 +0000
Subject: #20268 [Com]: PHP (module or CLI) crashes with Bus Error on startup
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-24267@lists.php.net to get a copy of this message
ID: 20268 Comment by: j-devenish@users.sourceforge.net Reported By: bdabney@dallasnews.com Status: Open Bug Type: Zend Engine 2 problem Operating System: Solaris 9 PHP Version: 4CVS-2002-11-05 New Comment: Hi, I found this same problem under Solaris 8 using PHP 4.3.0pre2. For me, this is due to 64-bit uncleanliness. Since the CLI is required during PEAR installation, I did get an obvious interruption to make install. Therefore, make install is the "litmus test" I used to find the following three problems. (1) One problem seems to be an inconsistency between Zend and PHP. There are many 'globals' structs in PHP that specify int storage for configuration values, along with the OnUpdateInt callback. However, Zend defines OnUpdateInt to operate on longs. OnUpdateINT sounds like a misnomer for something that works with longs. Also, OnUpdateInt uses zend_atoi, which returns an int type, not long. So perhaps it really is a Zend problem. This matters (e.g. on LP64 platforms) where sizeof(int)!=sizeof(long). I changed OnUpdateInt in zend_ini.c by modifying p from long* to int* and loading of config now works fine for me. --- Zend/zend_ini.c 2002-09-23 20:00:39.000000000 +0800 +++ Zend/zend_ini.c 2002-11-07 15:16:29.521055000 +0800 @@ -429,18 +429,18 @@ ZEND_API ZEND_INI_MH(OnUpdateInt) { - long *p; + int *p; #ifndef ZTS char *base = (char *) mh_arg2; #else char *base; base = (char *) ts_resource(*((int *) mh_arg2)); #endif - p = (long *) (base+(size_t) mh_arg1); + p = (int *) (base+(size_t) mh_arg1); *p = zend_atoi(new_value, new_value_length); return SUCCESS; } (2) Another problem shown in this pstack during PEAR installation: 100114084 php_stdiop_cast (ffffffff, 3, 7fff6734, 100114040, 100113fa0, 1005e2388) + 44 100114790 _php_stream_cast (1005e2388, 1, 7fff6734, 1, 2, 2) + 1b0 10009a95c zif_flock (2, 1005de668, 0, 1, 7fff75b0, 10009a8e0) + 7c 100146af8 execute (100343728, 7fff7dd0, 100338c50, 7fff7eb8, 1002cf700, 100343728) + 2278 100146870 execute (10057e6c8, 7fff8430, a8, 7fff84e0, 1002cf700, 10057e6c8) + 1ff0 100146870 execute (1003434a8, 7fff9a80, 7e0, 7fffa268, 1002cf700, 1003434a8) + 1ff0 100146870 execute (100536a58, 7fffa540, 100338c18, 7fffb5e8, 1002cf700, 100536a58) + 1ff0 100146870 execute (10033fae8, 100144880, 10011dd80, 1, 0, 0) + 1ff0 100137700 zend_execute_scripts (8, 0, 3, 7ffff7c0, 1002cf700, 7fffd818) + e0 100109114 php_execute_script (0, 1002cf700, 10033f528, 0, 2f, 2d) + 1d4 10014bcf0 main (0, 7ffff8b8, 7ffff8e8, 1002c9990, 100000000, 0) + 910 100021abc _start (0, 0, 0, 0, 0, 0) + 7c (Note that I have actually trimmed the address widths down for readability, though the stack itself is unmodified.) truss indicated that the value of third argument ("ret") to main/stream.c's php_stdiop_cast was an unusable address. That is also the third argument to _php_stream_cast. So, we're zif_flock, expanded from PHP_FUNCTION(flock) in ext/standard/file.[ch]. Now, fd is an int and its address is passed as a void**. So php_stdiop_cast dereferences it to a void* and then to store the int value, it is cast as (void*) to be compatible at compile time. Since sizeof(int)!=sizeof(void*), we have a problem. So I cast the point as an int* instead. --- streams.c 2002-10-24 21:14:47.000000000 +0800 +++ streams.c 2002-11-07 17:10:27.015969000 +0800 @@ -1401,7 +1401,7 @@ } if (ret) { fflush(data->file); - *ret = (void*)fd; + *(int*)ret = fd; } return SUCCESS; default: (3) Guess what. Argh. Now in php_strspn part of ./ext/standard/string.c. The last two arguments are bogus (we do have less than 6 TB of RAM in this machine). Hmmm. zend_parse_parameters returns junk into len1 and len2. Chapter 33 of the manual seems to indicate that string length is returned as an int (and in zend_API.c that does seem to be the case) so this was a bug in string.c. But this is a bit odd, since zend_parse_parameters has 'l' for electing a long argument but not an int argument. So there is this mixture of integer lengths around. I knew nothing about Zend until today so I don't know what supposed to happen here, simply that this is a way that made it work for me: --- string.c 2002-10-26 04:09:53.000000000 +0800 +++ string.c 2002-11-07 17:11:18.988027000 +0800 @@ -202,7 +202,8 @@ static void php_spn_common_handler(INTERNAL_FUNCTION_PARAMETERS, int behavior) { char *s11, *s22; - long len1, len2, start, len; + int len1, len2; + long start, len; start = 0; len = 0; Although I have applied (1), (2), and (3) and found that PHP now functions (in the five minutes since the compile finished and when I wrote this message, at least), there could be similar timebombs lurking inside if the motifs such as (2) are present in other locations. --end-- Previous Comments: ------------------------------------------------------------------------ [2002-11-05 16:29:21] bdabney@dallasnews.com The CVS version (and the 4.3.0pre2 version, same error and backtrace) core dumps on startup with this error: Bus Error (core dumped) My configure: CFLAGS="-g -m64" ./configure --with-apache=../apache_1.3.27 --with-xml --with-oci8=/usr/local/oracle/OraHome --with-zlib --enable-inline-optimization --enable-bcmath --enable-debug --with-curl Here is the backtrace: bash-2.05# gdb /usr/local/bin/php ,/core GNU gdb 5.2.1 Copyright 2002 Free Software Foundation, Inc. GDB is free software, covered by the GNU General Public License, and you are welcome to change it and/or distribute copies of it under certain conditions. Type "show copying" to see the conditions. There is absolutely no warranty for GDB. Type "show warranty" for details. This GDB was configured as "sparc-sun-solaris2.9"... /export/home/bdabney/php4/,/core: No such file or directory. (gdb) quit bash-2.05# gdb /usr/local/bin/php ./core GNU gdb 5.2.1 Copyright 2002 Free Software Foundation, Inc. GDB is free software, covered by the GNU General Public License, and you are welcome to change it and/or distribute copies of it under certain conditions. Type "show copying" to see the conditions. There is absolutely no warranty for GDB. Type "show warranty" for details. This GDB was configured as "sparc-sun-solaris2.9"... Core was generated by `/export/home/bdabney/php4/sapi/cli/php -d safe_mode=0 -d open_basedir= /export/'. Program terminated with signal 10, Bus error. Reading symbols from /usr/lib/64/libz.so.1...done. Loaded symbols for /usr/lib/64/libz.so.1 Reading symbols from /usr/lib/64/libdl.so.1...done. Loaded symbols for /usr/lib/64/libdl.so.1 Reading symbols from /usr/lib/64/libsocket.so.1...done. Loaded symbols for /usr/lib/64/libsocket.so.1 Reading symbols from /usr/lib/64/libnsl.so.1...done. Loaded symbols for /usr/lib/64/libnsl.so.1 Reading symbols from /usr/lib/64/libcrypt_i.so.1...done. Loaded symbols for /usr/lib/64/libcrypt_i.so.1 Reading symbols from /usr/lib/64/libresolv.so.2...done. Loaded symbols for /usr/lib/64/libresolv.so.2 Reading symbols from /usr/lib/64/libm.so.1...done. Loaded symbols for /usr/lib/64/libm.so.1 Reading symbols from /usr/local/lib/libcurl.so.2...done. Loaded symbols for /usr/local/lib/libcurl.so.2 Reading symbols from /usr/lib/64/libgen.so.1...done. Loaded symbols for /usr/lib/64/libgen.so.1 Reading symbols from /usr/local/oracle/OraHome/lib/libclntsh.so.9.0...done. Loaded symbols for /usr/local/oracle/OraHome/lib/libclntsh.so.9.0 Reading symbols from /usr/lib/64/libc.so.1...done. Loaded symbols for /usr/lib/64/libc.so.1 Reading symbols from /usr/lib/64/libmp.so.2...done. Loaded symbols for /usr/lib/64/libmp.so.2 Reading symbols from /usr/local/oracle/OraHome/lib/libwtc9.so...done. Loaded symbols for /usr/local/oracle/OraHome/lib/libwtc9.so ---Type <return> to continue, or q <return> to quit--- Reading symbols from /usr/lib/64/libaio.so.1...done. Loaded symbols for /usr/lib/64/libaio.so.1 Reading symbols from /usr/lib/64/librt.so.1...done. Loaded symbols for /usr/lib/64/librt.so.1 Reading symbols from /usr/lib/64/libmd5.so.1...done. Loaded symbols for /usr/lib/64/libmd5.so.1 Reading symbols from /usr/platform/SUNW,Sun-Blade-100/lib/sparcv9/libc_psr.so.1...done. Loaded symbols for /usr/platform/SUNW,Sun-Blade-100/lib/sparcv9/libc_psr.so.1 #0 0x100265bd0 in OnUpdateInt (entry=0x100407fb0, new_value=0x1002ad390 "1024", new_value_length=4, mh_arg1=0x4c, mh_arg2=0x1003f2e50, mh_arg3=0x0, stage=1) at /export/home/bdabney/php4/Zend/zend_ini.c:444 444 *p = zend_atoi(new_value, new_value_length); (gdb) bt #0 0x100265bd0 in OnUpdateInt (entry=0x100407fb0, new_value=0x1002ad390 "1024", new_value_length=4, mh_arg1=0x4c, mh_arg2=0x1003f2e50, mh_arg3=0x0, stage=1) at /export/home/bdabney/php4/Zend/zend_ini.c:444 #1 0x100264cbc in zend_register_ini_entries (ini_entry=0x1003ec008, module_number=0) at /export/home/bdabney/php4/Zend/zend_ini.c:157 #2 0x1001ea968 in php_module_startup (sf=0x1003f1e00, additional_modules=0x0, num_additional_modules=0) at /export/home/bdabney/php4/main/main.c:1068 #3 0x10027644c in main (argc=9, argv=0xffffffff7ffffad8) at /export/home/bdabney/php4/sapi/cli/php_cli.c:443 (gdb) ------------------------------------------------------------------------ -- Edit this bug report at http://bugs.php.net/?id=20268&edit=1

« previous php.bugs (#24267) next »