#23299 [Opn->Fbk]: Intermittant but reproducable corruption and crash

From: Date: Wed, 23 Apr 2003 07:52:31 +0000
Subject: #23299 [Opn->Fbk]: Intermittant but reproducable corruption and crash
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-38136@lists.php.net to get a copy of this message
ID: 23299 Updated by: sniper@php.net Reported By: bginter at ndevtech dot net -Status: Open +Status: Feedback -Bug Type: Reproducible crash +Bug Type: Scripting Engine problem Operating System: Linux 2.4.20 PHP Version: 4.3.1, STABLE-200304220130 Previous Comments: ------------------------------------------------------------------------ [2003-04-22 23:23:32] bginter at ndevtech dot net I cannot stress enough how critical this bug is to the future of our product and company. Despite the amount of code, we really are not doing anything esoteric here except using objects extensively. But I do understand you can't (easily) fix it if you can't see it happening and my response might be the same in your place. I will attempt to create a concise test case that you can reproduce on your development machines and report back as soon as possible. ------------------------------------------------------------------------ [2003-04-22 22:58:15] rasmus@php.net Wow, that sounds like an insanely complex piece of PHP code. It sounds like you are indeed hitting some odd bug, but unless you can come up with a way for us to reproduce it on our dev boxes I don't see how we can help you. ------------------------------------------------------------------------ [2003-04-22 22:40:32] bginter at ndevtech dot net There is nothing unique about this machine. It is 1250MHz Athlon, though the problem has also been encountered on an AMD Athlon(tm) XP 1900+, some 1400MHz Athlon, an Intel(R) Pentium(R) 4 CPU 1.60GHz, and at least one other box. If you would like, I can compile PHP on another machine and provide a backtrace from there as well. I did go ahead and run memtest86 like you suggested. It took 50:17 to do one pass of the standard tests. No errors were encountered. I will run a more comprehensive test if you request it. This bug has manifested in several ways, making it rather hard to isolate. The first time we saw this, I believe our method name was 'get_values()' and PHP threw a fatal error that the method 'get_valuet()' did not exist. Changing the code to call 'get_valuer()' made PHP actually execute 'get_values()'. We restarted Apache and luckily haven't seen that one since. Other times, objects have been magically replaced with another object or just parts of another object, or have garbage at the end of the object (so it will pass get_class() but none of it's methods will work, as discovered by doing a print_r). On at least one occassion, a persistant manifestation of this bug was fixed (kludged) by putting some noop code immediately before the location where it either crashed or corrupted data. Since upgrading to 4.3.1, we have experienced so many more segfaults and memory corruption issues that have not gone away after restarting Apache or inserting noop code that we decided to file a bug report. Several eyeballs have witnessed both the subtle and fatal issues on multiple servers. It has caused some distress because we have been developing a commercial program for over a year and are (were) nearing release. The other core developer of our software posted to comp.lang.php when this first started appearing: http://groups.google.com/groups?hl=en&lr=&ie=UTF-8&oe=UTF-8&selm=m3adjwnolk.fsf%40redeye.scott.priv For what it is worth, the code that crashes PHP makes extensive use of objects and has 131 currently defined classes. I hate to speculate since I am really unfamiliar with the internals of PHP but could an overlooked circular reference be tickling a bug in the hash memory management/garbage collection? I realize this won't be a trivial bug to fix. Thank you for looking into it. ------------------------------------------------------------------------ [2003-04-22 20:56:38] rasmus@php.net Anything unique about this machine? It's not an IA64 box or anything weird like that, is it? Are you sure your memory is ok and that your cpu is not overheating or something? These crashes look very flaky. For a really good memory checker that catches problems nothing else finds have a look at http://www.memtest86.com/ That probably isn't the problem, but perhaps worth a check before spending too much time digging into the code. ------------------------------------------------------------------------ [2003-04-22 13:12:30] bginter at ndevtech dot net Here are a few more that look like they may help. These are from STABLE-200304220130. Program received signal SIGSEGV, Segmentation fault. 0x404053e0 in _zval_ptr_dtor (zval_ptr=0x8849390, __zend_filename=0x404deb20 "/usr/local/src/php-4.3.1/Zend/zend_variables.c", __zend_lineno=167) at /usr/local/src/php-4.3.1/Zend/zend_execute_API.c:287 287 (*zval_ptr)->refcount--; (gdb) bt #0 0x404053e0 in _zval_ptr_dtor (zval_ptr=0x8849390, __zend_filename=0x404deb20 "/usr/local/src/php-4.3.1/Zend/zend_variables.c", __zend_lineno=167) at /usr/local/src/php-4.3.1/Zend/zend_execute_API.c:287 #1 0x4040f93d in _zval_ptr_dtor_wrapper (zval_ptr=0x8849390) at /usr/local/src/php-4.3.1/Zend/zend_variables.c:167 #2 0x4041740a in zend_hash_destroy (ht=0x89635ac) at /usr/local/src/php-4.3.1/Zend/zend_hash.c:543 #3 0x4040f5b3 in _zval_dtor (zvalue=0x893da24, __zend_filename=0x404de480 "/usr/local/src/php-4.3.1/Zend/zend_execute_API.c", __zend_lineno=289) at /usr/local/src/php-4.3.1/Zend/zend_variables.c:60 #4 0x4040540c in _zval_ptr_dtor (zval_ptr=0x8991b68, __zend_filename=0x404deb20 "/usr/local/src/php-4.3.1/Zend/zend_variables.c", __zend_lineno=167) at /usr/local/src/php-4.3.1/Zend/zend_execute_API.c:289 #5 0x4040f93d in _zval_ptr_dtor_wrapper (zval_ptr=0x8991b68) at /usr/local/src/php-4.3.1/Zend/zend_variables.c:167 #6 0x4041740a in zend_hash_destroy (ht=0x819d36c) at /usr/local/src/php-4.3.1/Zend/zend_hash.c:543 #7 0x4040f569 in _zval_dtor (zvalue=0x8930f0c, __zend_filename=0x404de480 "/usr/local/src/php-4.3.1/Zend/zend_execute_API.c", __zend_lineno=289) at /usr/local/src/php-4.3.1/Zend/zend_variables.c:51 #8 0x4040540c in _zval_ptr_dtor (zval_ptr=0x893f610, __zend_filename=0x404deb20 "/usr/local/src/php-4.3.1/Zend/zend_variables.c", __zend_lineno=167) at /usr/local/src/php-4.3.1/Zend/zend_execute_API.c:289 #9 0x4040f93d in _zval_ptr_dtor_wrapper (zval_ptr=0x893f610) at /usr/local/src/php-4.3.1/Zend/zend_variables.c:167 #10 0x4041740a in zend_hash_destroy (ht=0x8941e6c) at /usr/local/src/php-4.3.1/Zend/zend_hash.c:543 #11 0x4040f5b3 in _zval_dtor (zvalue=0x86adc34, __zend_filename=0x404de480 "/usr/local/src/php-4.3.1/Zend/zend_execute_API.c", __zend_lineno=289) at /usr/local/src/php-4.3.1/Zend/zend_variables.c:60 #12 0x4040540c in _zval_ptr_dtor (zval_ptr=0x870a5f8, __zend_filename=0x404deb20 "/usr/local/src/php-4.3.1/Zend/zend_variables.c", __zend_lineno=167) at /usr/local/src/php-4.3.1/Zend/zend_execute_API.c:289 #13 0x4040f93d in _zval_ptr_dtor_wrapper (zval_ptr=0x870a5f8) at /usr/local/src/php-4.3.1/Zend/zend_variables.c:167 #14 0x4041740a in zend_hash_destroy (ht=0x870dd3c) at /usr/local/src/php-4.3.1/Zend/zend_hash.c:543 #15 0x4040f5b3 in _zval_dtor (zvalue=0x8854d8c, __zend_filename=0x404de480 "/usr/local/src/php-4.3.1/Zend/zend_execute_API.c", __zend_lineno=289) at /usr/local/src/php-4.3.1/Zend/zend_variables.c:60 #16 0x4040540c in _zval_ptr_dtor (zval_ptr=0x82c1f10, __zend_filename=0x404deb20 "/usr/local/src/php-4.3.1/Zend/zend_variables.c", __zend_lineno=167) at /usr/local/src/php-4.3.1/Zend/zend_execute_API.c:289 #17 0x4040f93d in _zval_ptr_dtor_wrapper (zval_ptr=0x82c1f10) at /usr/local/src/php-4.3.1/Zend/zend_variables.c:167 #18 0x4041757a in zend_hash_clean (ht=0x8350d0c) at /usr/local/src/php-4.3.1/Zend/zend_hash.c:569 #19 0x404249c6 in execute (op_array=0x86951ac) at /usr/local/src/php-4.3.1/Zend/zend_execute.c:1656 #20 0x40411584 in zend_execute_scripts (type=8, retval=0x0, file_count=3) at /usr/local/src/php-4.3.1/Zend/zend.c:864 #21 0x403d66c3 in php_execute_script (primary_file=0xbffff8c8) at /usr/local/src/php-4.3.1/main/main.c:1573 #22 0x40429ad0 in apache_php_module_main (r=0x815867c, display_source_mode=0) at /usr/local/src/php-4.3.1/sapi/apache/sapi_apache.c:55 #23 0x4042aa70 in send_php (r=0x815867c, display_source_mode=0, filename=0x815a894 "/usr/local/apache/lariat/lariat2/admin/debtor/transaction_controller.php") at /usr/local/src/php-4.3.1/sapi/apache/mod_php4.c:556 #24 0x4042aaef in send_parsed_php (r=0x815867c) at /usr/local/src/php-4.3.1/sapi/apache/mod_php4.c:571 #25 0x080554e9 in ap_invoke_handler () #26 0x0806b5df in process_request_internal () #27 0x0806b646 in ap_process_request () #28 0x08061e06 in child_main () #29 0x08061fe5 in make_child () #30 0x0806215c in startup_children () #31 0x080627ed in standalone_main () #32 0x0806307c in main () #33 0x4009214f in __libc_start_main () from /lib/libc.so.6 Program received signal SIGSEGV, Segmentation fault. 0x4041bb36 in _zend_is_inconsistent (ht=0x8fcc8400, file=0x404e7400 "/usr/local/src/php4-STABLE-200304220130/Zend/zend_hash.c", line=534) at /usr/local/src/php4-STABLE-200304220130/Zend/zend_hash.c:84 84 if (ht->inconsistent==HT_OK) { (gdb) bt #0 0x4041bb36 in _zend_is_inconsistent (ht=0x8fcc8400, file=0x404e7400 "/usr/local/src/php4-STABLE-200304220130/Zend/zend_hash.c", line=534) at /usr/local/src/php4-STABLE-200304220130/Zend/zend_hash.c:84 #1 0x4041d3ce in zend_hash_destroy (ht=0x8fcc8400) at /usr/local/src/php4-STABLE-200304220130/Zend/zend_hash.c:534 #2 0x40415479 in _zval_dtor (zvalue=0x89b141c, __zend_filename=0x404e6340 "/usr/local/src/php4-STABLE-200304220130/Zend/zend_execute_API.c", __zend_lineno=291) at /usr/local/src/php4-STABLE-200304220130/Zend/zend_variables.c:51 #3 0x4040b30c in _zval_ptr_dtor (zval_ptr=0x8814738, __zend_filename=0x404e8200 "/usr/local/src/php4-STABLE-200304220130/Zend/zend_execute.h", __zend_lineno=96) at /usr/local/src/php4-STABLE-200304220130/Zend/zend_execute_API.c:291 #4 0x4042de8b in zend_ptr_stack_clear_multiple () at /usr/local/src/php4-STABLE-200304220130/Zend/zend_execute.h:96 #5 0x4042abbc in execute (op_array=0x8555f64) at /usr/local/src/php4-STABLE-200304220130/Zend/zend_execute.c:1685 #6 0x4042a854 in execute (op_array=0x84e0374) at /usr/local/src/php4-STABLE-200304220130/Zend/zend_execute.c:1650 #7 0x4042a854 in execute (op_array=0x881cb4c) at /usr/local/src/php4-STABLE-200304220130/Zend/zend_execute.c:1650 #8 0x40417494 in zend_execute_scripts (type=8, retval=0x0, file_count=3) at /usr/local/src/php4-STABLE-200304220130/Zend/zend.c:864 #9 0x403dba2e in php_execute_script (primary_file=0xbffff8c8) at /usr/local/src/php4-STABLE-200304220130/main/main.c:1637 #10 0x4042fb80 in apache_php_module_main (r=0x8158da4, display_source_mode=0) at /usr/local/src/php4-STABLE-200304220130/sapi/apache/sapi_apache.c:55 #11 0x40430c30 in send_php (r=0x8158da4, display_source_mode=0, filename=0x815afbc "/usr/local/apache/lariat/lariat2/admin/debtor/transaction_controller.php") at /usr/local/src/php4-STABLE-200304220130/sapi/apache/mod_php4.c:617 #12 0x40430caf in send_parsed_php (r=0x8158da4) at /usr/local/src/php4-STABLE-200304220130/sapi/apache/mod_php4.c:632 #13 0x080554e9 in ap_invoke_handler () #14 0x0806b5df in process_request_internal () #15 0x0806b646 in ap_process_request () #16 0x08061e06 in child_main () #17 0x08061fe5 in make_child () #18 0x0806215c in startup_children () #19 0x080627ed in standalone_main () #20 0x0806307c in main () #21 0x4009214f in __libc_start_main () from /lib/libc.so.6 Program received signal SIGSEGV, Segmentation fault. 0x404026a3 in shutdown_memory_manager (silent=1, clean_cache=0) at /usr/local/src/php4-STABLE-200304220130/Zend/zend_alloc.c:514 514 if (!iterator->cached (gdb) bt #0 0x404026a3 in shutdown_memory_manager (silent=1, clean_cache=0) at /usr/local/src/php4-STABLE-200304220130/Zend/zend_alloc.c:514 #1 0x403da291 in php_request_shutdown (dummy=0x0) at /usr/local/src/php4-STABLE-200304220130/main/main.c:991 #2 0x4042fbf8 in apache_php_module_main (r=0x8158da4, display_source_mode=0) at /usr/local/src/php4-STABLE-200304220130/sapi/apache/sapi_apache.c:61 #3 0x40430c30 in send_php (r=0x8158da4, display_source_mode=0, filename=0x815afbc "/usr/local/apache/lariat/lariat2/admin/debtor/transaction_controller.php") at /usr/local/src/php4-STABLE-200304220130/sapi/apache/mod_php4.c:617 #4 0x40430caf in send_parsed_php (r=0x8158da4) at /usr/local/src/php4-STABLE-200304220130/sapi/apache/mod_php4.c:632 #5 0x080554e9 in ap_invoke_handler () #6 0x0806b5df in process_request_internal () #7 0x0806b646 in ap_process_request () #8 0x08061e06 in child_main () #9 0x08061fe5 in make_child () #10 0x0806215c in startup_children () #11 0x080627ed in standalone_main () #12 0x0806307c in main () #13 0x4009214f in __libc_start_main () from /lib/libc.so.6 Thank you. ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at http://bugs.php.net/23299 -- Edit this bug report at http://bugs.php.net/?id=23299&edit=1

« previous php.bugs (#38136) next »