#23299 [Fbk->Opn]: Intermittant but reproducable corruption and crash

From: Date: Thu, 24 Apr 2003 09:10:30 +0000
Subject: #23299 [Fbk->Opn]: Intermittant but reproducable corruption and crash
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-38278@lists.php.net to get a copy of this message
ID: 23299 User updated by: bginter at ndevtech dot net Reported By: bginter at ndevtech dot net -Status: Feedback +Status: Open Bug Type: Scripting Engine problem Operating System: Linux 2.4.20 PHP Version: 4.3.2-RC New Comment: Yes, I copied and pasted the configure line. Previous Comments: ------------------------------------------------------------------------ [2003-04-24 04:07:07] sniper@php.net Was this with the configure line I told you to use? ------------------------------------------------------------------------ [2003-04-24 04:05:54] bginter at ndevtech dot net Here is the one from crash1.php in my examples: Program received signal SIGSEGV, Segmentation fault. 0x40415404 in zval_add_ref (p=0x8190a60) at /usr/local/src/php4-STABLE-200304240730/Zend/zend_variables.c:85 85 (*p)->refcount++; (gdb) bt #0 0x40415404 in zval_add_ref (p=0x8190a60) at /usr/local/src/php4-STABLE-200304240730/Zend/zend_variables.c:85 #1 0x4041dd38 in zend_hash_copy (target=0x81970dc, source=0x8193e5c, pCopyConstructor=0x404153fc <zval_add_ref>, tmp=0xbfffcbd4, size=4) at /usr/local/src/php4-STABLE-200304240730/Zend/zend_hash.c:789 #2 0x40415651 in _zval_copy_ctor (zvalue=0x81889d4, __zend_filename=0x404e8180 "/usr/local/src/php4-STABLE-200304240730/Zend/zend_execute.c", __zend_lineno=1795) at /usr/local/src/php4-STABLE-200304240730/Zend/zend_variables.c:137 #3 0x4042b131 in execute (op_array=0x8162cc4) at /usr/local/src/php4-STABLE-200304240730/Zend/zend_execute.c:1795 #4 0x40417384 in zend_execute_scripts (type=8, retval=0x0, file_count=3) at /usr/local/src/php4-STABLE-200304240730/Zend/zend.c:864 #5 0x403db91e in php_execute_script (primary_file=0xbffff8c8) at /usr/local/src/php4-STABLE-200304240730/main/main.c:1637 [...] (gdb) frame 3 #3 0x4042b131 in execute (op_array=0x8162cc4) at /usr/local/src/php4-STABLE-200304240730/Zend/zend_execute.c:1795 1795 zval_copy_ctor(varptr); (gdb) print (char *)(executor_globals.function_state_ptr->function)->common.function_name $1 = 0x0 (gdb) print (char *)executor_globals.active_op_array->function_name $2 = 0x0 (gdb) print (char *)executor_globals.active_op_array->filename $3 = 0x8162fb4 "/usr/local/apache/lariat/lariat2/test/test1/crash1.php" ------------------------------------------------------------------------ [2003-04-24 03:38:42] sniper@php.net Please try using this CVS snapshot: http://snaps.php.net/php4-STABLE-latest.tar.gz For Windows: http://snaps.php.net/win32/php4-win32-STABLE-latest.zip And use EXACTLY this configure line: ./configure \ --prefix=/usr/local/php_4.3.1 \ --with-apxs=/usr/local/apache/bin/apxs \ --enable-bcmath \ --enable-gd-native-ttf \ --with-gd \ --with-ttf \ --enable-calendar \ --with-mysql \ --with-openssl \ --with-iconv \ --enable-xml \ --with-pgsql=/usr/local/pgsql-7.3 \ --with-mcrypt \ --with-curl \ --with-zip \ --enable-ftp \ --with-zlib-dir=/usr \ --enable-debug Also, disable Zend optimizer and generate the GDB backtrace as instructed here: http://bugs.php.net/bugs-generating-backtrace.php And DO NOT ADD THE FULL backtrace here!! only the relevant part of it, usually the 15-20 first lines. ------------------------------------------------------------------------ [2003-04-23 17:56:31] bginter at ndevtech dot net I have created some example code to illustrate this bug. It's available at: http://www.lariatcentral.com/test1.tar.gz There are two cases in the file: * one consistantly causes corruption and often a crash * one consistantly always causes a segmentation fault There are several classes in this package. It may have been possible to make this example more concise but I haven't had any success doing so. There is also a file called backtrace.txt that shows the three main crashes I am seeing. I believe we are tickling this bug in a much more subtle way in our code. If we knew why this was happening we could change the code to "not do that", PHP should not be segfaulting or corrupting data. I have tested this example on two servers and it worked (corrupted/crashed) on both. You might try fiddling with the set_time_limit() to change the way the corruption is visible. Let me know how I can assist you further. Thanks. ------------------------------------------------------------------------ [2003-04-22 22:58:15] rasmus@php.net Wow, that sounds like an insanely complex piece of PHP code. It sounds like you are indeed hitting some odd bug, but unless you can come up with a way for us to reproduce it on our dev boxes I don't see how we can help you. ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at http://bugs.php.net/23299 -- Edit this bug report at http://bugs.php.net/?id=23299&edit=1

« previous php.bugs (#38278) next »