#23299 [Opn->Fbk]: Intermittant but reproducable corruption and crash
| From: | sniper@php.net | Date: | Wed, 23 Apr 2003 07:52:31 +0000 |
| Subject: | #23299 [Opn->Fbk]: Intermittant but reproducable corruption and crash | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-38136@lists.php.net to get a copy of this message | ||
ID: 23299
Updated by: sniper@php.net
Reported By: bginter at ndevtech dot net
-Status: Open
+Status: Feedback
-Bug Type: Reproducible crash
+Bug Type: Scripting Engine problem
Operating System: Linux 2.4.20
PHP Version: 4.3.1, STABLE-200304220130
Previous Comments:
------------------------------------------------------------------------
[2003-04-22 23:23:32] bginter at ndevtech dot net
I cannot stress enough how critical this bug is to the future of our
product and company. Despite the amount of code, we really are not
doing anything esoteric here except using objects extensively.
But I do understand you can't (easily) fix it if you can't see it
happening and my response might be the same in your place. I will
attempt to create a concise test case that you can reproduce on your
development machines and report back as soon as possible.
------------------------------------------------------------------------
[2003-04-22 22:58:15] rasmus@php.net
Wow, that sounds like an insanely complex piece of PHP code. It sounds
like you are indeed hitting some odd bug, but unless you can come up
with a way for us to reproduce it on our dev boxes I don't see how we
can help you.
------------------------------------------------------------------------
[2003-04-22 22:40:32] bginter at ndevtech dot net
There is nothing unique about this machine. It is 1250MHz Athlon,
though the problem has also been encountered on an AMD Athlon(tm) XP
1900+, some 1400MHz Athlon, an Intel(R) Pentium(R) 4 CPU 1.60GHz, and
at least one other box.
If you would like, I can compile PHP on another machine and provide a
backtrace from there as well. I did go ahead and run memtest86 like
you suggested. It took 50:17 to do one pass of the standard tests. No
errors were encountered. I will run a more comprehensive test if you
request it.
This bug has manifested in several ways, making it rather hard to
isolate. The first time we saw this, I believe our method name was
'get_values()' and PHP threw a fatal error that the method
'get_valuet()' did not exist. Changing the code to call 'get_valuer()'
made PHP actually execute 'get_values()'. We restarted Apache and
luckily haven't seen that one since.
Other times, objects have been magically replaced with another object
or just parts of another object, or have garbage at the end of the
object (so it will pass get_class() but none of it's methods will work,
as discovered by doing a print_r). On at least one occassion, a
persistant manifestation of this bug was fixed (kludged) by putting
some noop code immediately before the location where it either crashed
or corrupted data.
Since upgrading to 4.3.1, we have experienced so many more segfaults
and memory corruption issues that have not gone away after restarting
Apache or inserting noop code that we decided to file a bug report.
Several eyeballs have witnessed both the subtle and fatal issues on
multiple servers. It has caused some distress because we have been
developing a commercial program for over a year and are (were) nearing
release.
The other core developer of our software posted to comp.lang.php when
this first started appearing:
http://groups.google.com/groups?hl=en&lr=&ie=UTF-8&oe=UTF-8&selm=m3adjwnolk.fsf%40redeye.scott.priv
For what it is worth, the code that crashes PHP makes extensive use of
objects and has 131 currently defined classes. I hate to speculate
since I am really unfamiliar with the internals of PHP but could an
overlooked circular reference be tickling a bug in the hash memory
management/garbage collection?
I realize this won't be a trivial bug to fix. Thank you for looking
into it.
------------------------------------------------------------------------
[2003-04-22 20:56:38] rasmus@php.net
Anything unique about this machine? It's not an IA64 box or anything
weird like that, is it? Are you sure your memory is ok and that your
cpu is not overheating or something? These crashes look very flaky.
For a really good memory checker that catches problems nothing else
finds have a look at http://www.memtest86.com/ That
probably isn't the
problem, but perhaps worth a check before spending too much time
digging into the code.
------------------------------------------------------------------------
[2003-04-22 13:12:30] bginter at ndevtech dot net
Here are a few more that look like they may help. These are from
STABLE-200304220130.
Program received signal SIGSEGV, Segmentation fault.
0x404053e0 in _zval_ptr_dtor (zval_ptr=0x8849390,
__zend_filename=0x404deb20
"/usr/local/src/php-4.3.1/Zend/zend_variables.c", __zend_lineno=167)
at /usr/local/src/php-4.3.1/Zend/zend_execute_API.c:287
287 (*zval_ptr)->refcount--;
(gdb) bt
#0 0x404053e0 in _zval_ptr_dtor (zval_ptr=0x8849390,
__zend_filename=0x404deb20
"/usr/local/src/php-4.3.1/Zend/zend_variables.c", __zend_lineno=167)
at /usr/local/src/php-4.3.1/Zend/zend_execute_API.c:287
#1 0x4040f93d in _zval_ptr_dtor_wrapper (zval_ptr=0x8849390) at
/usr/local/src/php-4.3.1/Zend/zend_variables.c:167
#2 0x4041740a in zend_hash_destroy (ht=0x89635ac) at
/usr/local/src/php-4.3.1/Zend/zend_hash.c:543
#3 0x4040f5b3 in _zval_dtor (zvalue=0x893da24,
__zend_filename=0x404de480
"/usr/local/src/php-4.3.1/Zend/zend_execute_API.c", __zend_lineno=289)
at /usr/local/src/php-4.3.1/Zend/zend_variables.c:60
#4 0x4040540c in _zval_ptr_dtor (zval_ptr=0x8991b68,
__zend_filename=0x404deb20
"/usr/local/src/php-4.3.1/Zend/zend_variables.c", __zend_lineno=167)
at /usr/local/src/php-4.3.1/Zend/zend_execute_API.c:289
#5 0x4040f93d in _zval_ptr_dtor_wrapper (zval_ptr=0x8991b68) at
/usr/local/src/php-4.3.1/Zend/zend_variables.c:167
#6 0x4041740a in zend_hash_destroy (ht=0x819d36c) at
/usr/local/src/php-4.3.1/Zend/zend_hash.c:543
#7 0x4040f569 in _zval_dtor (zvalue=0x8930f0c,
__zend_filename=0x404de480
"/usr/local/src/php-4.3.1/Zend/zend_execute_API.c", __zend_lineno=289)
at /usr/local/src/php-4.3.1/Zend/zend_variables.c:51
#8 0x4040540c in _zval_ptr_dtor (zval_ptr=0x893f610,
__zend_filename=0x404deb20
"/usr/local/src/php-4.3.1/Zend/zend_variables.c", __zend_lineno=167)
at /usr/local/src/php-4.3.1/Zend/zend_execute_API.c:289
#9 0x4040f93d in _zval_ptr_dtor_wrapper (zval_ptr=0x893f610) at
/usr/local/src/php-4.3.1/Zend/zend_variables.c:167
#10 0x4041740a in zend_hash_destroy (ht=0x8941e6c) at
/usr/local/src/php-4.3.1/Zend/zend_hash.c:543
#11 0x4040f5b3 in _zval_dtor (zvalue=0x86adc34,
__zend_filename=0x404de480
"/usr/local/src/php-4.3.1/Zend/zend_execute_API.c", __zend_lineno=289)
at /usr/local/src/php-4.3.1/Zend/zend_variables.c:60
#12 0x4040540c in _zval_ptr_dtor (zval_ptr=0x870a5f8,
__zend_filename=0x404deb20
"/usr/local/src/php-4.3.1/Zend/zend_variables.c", __zend_lineno=167)
at /usr/local/src/php-4.3.1/Zend/zend_execute_API.c:289
#13 0x4040f93d in _zval_ptr_dtor_wrapper (zval_ptr=0x870a5f8) at
/usr/local/src/php-4.3.1/Zend/zend_variables.c:167
#14 0x4041740a in zend_hash_destroy (ht=0x870dd3c) at
/usr/local/src/php-4.3.1/Zend/zend_hash.c:543
#15 0x4040f5b3 in _zval_dtor (zvalue=0x8854d8c,
__zend_filename=0x404de480
"/usr/local/src/php-4.3.1/Zend/zend_execute_API.c", __zend_lineno=289)
at /usr/local/src/php-4.3.1/Zend/zend_variables.c:60
#16 0x4040540c in _zval_ptr_dtor (zval_ptr=0x82c1f10,
__zend_filename=0x404deb20
"/usr/local/src/php-4.3.1/Zend/zend_variables.c", __zend_lineno=167)
at /usr/local/src/php-4.3.1/Zend/zend_execute_API.c:289
#17 0x4040f93d in _zval_ptr_dtor_wrapper (zval_ptr=0x82c1f10) at
/usr/local/src/php-4.3.1/Zend/zend_variables.c:167
#18 0x4041757a in zend_hash_clean (ht=0x8350d0c) at
/usr/local/src/php-4.3.1/Zend/zend_hash.c:569
#19 0x404249c6 in execute (op_array=0x86951ac) at
/usr/local/src/php-4.3.1/Zend/zend_execute.c:1656
#20 0x40411584 in zend_execute_scripts (type=8, retval=0x0,
file_count=3) at /usr/local/src/php-4.3.1/Zend/zend.c:864
#21 0x403d66c3 in php_execute_script (primary_file=0xbffff8c8) at
/usr/local/src/php-4.3.1/main/main.c:1573
#22 0x40429ad0 in apache_php_module_main (r=0x815867c,
display_source_mode=0) at
/usr/local/src/php-4.3.1/sapi/apache/sapi_apache.c:55
#23 0x4042aa70 in send_php (r=0x815867c, display_source_mode=0,
filename=0x815a894
"/usr/local/apache/lariat/lariat2/admin/debtor/transaction_controller.php")
at /usr/local/src/php-4.3.1/sapi/apache/mod_php4.c:556
#24 0x4042aaef in send_parsed_php (r=0x815867c) at
/usr/local/src/php-4.3.1/sapi/apache/mod_php4.c:571
#25 0x080554e9 in ap_invoke_handler ()
#26 0x0806b5df in process_request_internal ()
#27 0x0806b646 in ap_process_request ()
#28 0x08061e06 in child_main ()
#29 0x08061fe5 in make_child ()
#30 0x0806215c in startup_children ()
#31 0x080627ed in standalone_main ()
#32 0x0806307c in main ()
#33 0x4009214f in __libc_start_main () from /lib/libc.so.6
Program received signal SIGSEGV, Segmentation fault.
0x4041bb36 in _zend_is_inconsistent (ht=0x8fcc8400, file=0x404e7400
"/usr/local/src/php4-STABLE-200304220130/Zend/zend_hash.c", line=534)
at /usr/local/src/php4-STABLE-200304220130/Zend/zend_hash.c:84
84 if (ht->inconsistent==HT_OK) {
(gdb) bt
#0 0x4041bb36 in _zend_is_inconsistent (ht=0x8fcc8400, file=0x404e7400
"/usr/local/src/php4-STABLE-200304220130/Zend/zend_hash.c", line=534)
at /usr/local/src/php4-STABLE-200304220130/Zend/zend_hash.c:84
#1 0x4041d3ce in zend_hash_destroy (ht=0x8fcc8400) at
/usr/local/src/php4-STABLE-200304220130/Zend/zend_hash.c:534
#2 0x40415479 in _zval_dtor (zvalue=0x89b141c,
__zend_filename=0x404e6340
"/usr/local/src/php4-STABLE-200304220130/Zend/zend_execute_API.c",
__zend_lineno=291)
at
/usr/local/src/php4-STABLE-200304220130/Zend/zend_variables.c:51
#3 0x4040b30c in _zval_ptr_dtor (zval_ptr=0x8814738,
__zend_filename=0x404e8200
"/usr/local/src/php4-STABLE-200304220130/Zend/zend_execute.h",
__zend_lineno=96)
at
/usr/local/src/php4-STABLE-200304220130/Zend/zend_execute_API.c:291
#4 0x4042de8b in zend_ptr_stack_clear_multiple () at
/usr/local/src/php4-STABLE-200304220130/Zend/zend_execute.h:96
#5 0x4042abbc in execute (op_array=0x8555f64) at
/usr/local/src/php4-STABLE-200304220130/Zend/zend_execute.c:1685
#6 0x4042a854 in execute (op_array=0x84e0374) at
/usr/local/src/php4-STABLE-200304220130/Zend/zend_execute.c:1650
#7 0x4042a854 in execute (op_array=0x881cb4c) at
/usr/local/src/php4-STABLE-200304220130/Zend/zend_execute.c:1650
#8 0x40417494 in zend_execute_scripts (type=8, retval=0x0,
file_count=3) at
/usr/local/src/php4-STABLE-200304220130/Zend/zend.c:864
#9 0x403dba2e in php_execute_script (primary_file=0xbffff8c8) at
/usr/local/src/php4-STABLE-200304220130/main/main.c:1637
#10 0x4042fb80 in apache_php_module_main (r=0x8158da4,
display_source_mode=0) at
/usr/local/src/php4-STABLE-200304220130/sapi/apache/sapi_apache.c:55
#11 0x40430c30 in send_php (r=0x8158da4, display_source_mode=0,
filename=0x815afbc
"/usr/local/apache/lariat/lariat2/admin/debtor/transaction_controller.php")
at
/usr/local/src/php4-STABLE-200304220130/sapi/apache/mod_php4.c:617
#12 0x40430caf in send_parsed_php (r=0x8158da4) at
/usr/local/src/php4-STABLE-200304220130/sapi/apache/mod_php4.c:632
#13 0x080554e9 in ap_invoke_handler ()
#14 0x0806b5df in process_request_internal ()
#15 0x0806b646 in ap_process_request ()
#16 0x08061e06 in child_main ()
#17 0x08061fe5 in make_child ()
#18 0x0806215c in startup_children ()
#19 0x080627ed in standalone_main ()
#20 0x0806307c in main ()
#21 0x4009214f in __libc_start_main () from /lib/libc.so.6
Program received signal SIGSEGV, Segmentation fault.
0x404026a3 in shutdown_memory_manager (silent=1, clean_cache=0) at
/usr/local/src/php4-STABLE-200304220130/Zend/zend_alloc.c:514
514 if (!iterator->cached
(gdb) bt
#0 0x404026a3 in shutdown_memory_manager (silent=1, clean_cache=0) at
/usr/local/src/php4-STABLE-200304220130/Zend/zend_alloc.c:514
#1 0x403da291 in php_request_shutdown (dummy=0x0) at
/usr/local/src/php4-STABLE-200304220130/main/main.c:991
#2 0x4042fbf8 in apache_php_module_main (r=0x8158da4,
display_source_mode=0) at
/usr/local/src/php4-STABLE-200304220130/sapi/apache/sapi_apache.c:61
#3 0x40430c30 in send_php (r=0x8158da4, display_source_mode=0,
filename=0x815afbc
"/usr/local/apache/lariat/lariat2/admin/debtor/transaction_controller.php")
at
/usr/local/src/php4-STABLE-200304220130/sapi/apache/mod_php4.c:617
#4 0x40430caf in send_parsed_php (r=0x8158da4) at
/usr/local/src/php4-STABLE-200304220130/sapi/apache/mod_php4.c:632
#5 0x080554e9 in ap_invoke_handler ()
#6 0x0806b5df in process_request_internal ()
#7 0x0806b646 in ap_process_request ()
#8 0x08061e06 in child_main ()
#9 0x08061fe5 in make_child ()
#10 0x0806215c in startup_children ()
#11 0x080627ed in standalone_main ()
#12 0x0806307c in main ()
#13 0x4009214f in __libc_start_main () from /lib/libc.so.6
Thank you.
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
http://bugs.php.net/23299
--
Edit this bug report at http://bugs.php.net/?id=23299&edit=1