#23299 [Opn]: Intermittant but reproducable corruption and crash

From: Date: Mon, 05 May 2003 21:17:40 +0000
Subject: #23299 [Opn]: Intermittant but reproducable corruption and crash
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-39102@lists.php.net to get a copy of this message
ID: 23299 Updated by: moriyoshi@php.net Reported By: bginter at ndevtech dot net Status: Open Bug Type: Reproducible crash Operating System: Linux 2.4.20 PHP Version: 4.3.2-RC New Comment: I'm looking at crash1.php script. <?php $group = new Group; for ( $i = 0; $i < 15; $i++ ) { // uncomment this and it works // print $group->count() . "<br/>\n"; for ( $i = 0; $i < $assoc->count(); $i++ ) { // print "Getting company $i<br/>\n"; $company = $assoc->get( $i ); $group->add( $company ); } // print_d( $company ); } print_d( $company ); ?> The above part should be for ( $j = 0; $j < 15; $j++ ) { // not $i ! for ( $i = 0; $i < $assoc->count(); $i++ ) { $company = $assoc->get( $i ); Otherwise, it goes into an infinite loop when $assoc->count() is less than 15 and then PHP runs out of all the available memory to die. Previous Comments: ------------------------------------------------------------------------ [2003-05-05 15:46:22] bginter at ndevtech dot net bginter@debian:~$ gcc --version 2.95.4 bginter@debian:~$ ld -v GNU ld version 2.12.90.0.1 20020307 Debian/GNU Linux ------------------------------------------------------------------------ [2003-05-05 15:14:34] moriyoshi@php.net Which version of gcc and binutils are you using? (appears related to bug #22510 & bug #22367) ------------------------------------------------------------------------ [2003-04-28 16:27:05] bginter at ndevtech dot net This continues to happen with php4-STABLE-200304281730. How can I further assist with this bug? ------------------------------------------------------------------------ [2003-04-24 13:12:55] bginter at ndevtech dot net Have you been able to reproduce this on your development machine? ------------------------------------------------------------------------ [2003-04-24 04:14:49] bginter at ndevtech dot net The corrupt1.php in the examples I provided also creates this backtrace fairly consistently. This only happens after at least two reloads and sometimes requires me to close my browser and revisit the index.php page then corrupt1.php page while the same apache/php thread is running in gdb. Program received signal SIGSEGV, Segmentation fault. 0x400ee1c3 in memcpy () from /lib/libc.so.6 (gdb) bt #0 0x400ee1c3 in memcpy () from /lib/libc.so.6 #1 0x40402c53 in _mem_block_check (ptr=0x81792bc, silent=0, __zend_filename=0x404e64a0 "/usr/local/src/php4-STABLE-200304240730/Zend/zend_opcode.c", __zend_lineno=159, __zend_orig_filename=0x404e68c0 "/usr/local/src/php4-STABLE-200304240730/Zend/zend_variables.c", __zend_orig_lineno=44) at /usr/local/src/php4-STABLE-200304240730/Zend/zend_alloc.c:675 #2 0x40402c0e in _mem_block_check (ptr=0x81792bc, silent=1, __zend_filename=0x404e64a0 "/usr/local/src/php4-STABLE-200304240730/Zend/zend_opcode.c", __zend_lineno=159, __zend_orig_filename=0x404e68c0 "/usr/local/src/php4-STABLE-200304240730/Zend/zend_variables.c", __zend_orig_lineno=44) at /usr/local/src/php4-STABLE-200304240730/Zend/zend_alloc.c:667 #3 0x40401d64 in _efree (ptr=0x81792bc, __zend_filename=0x404e64a0 "/usr/local/src/php4-STABLE-200304240730/Zend/zend_opcode.c", __zend_lineno=159, __zend_orig_filename=0x404e68c0 "/usr/local/src/php4-STABLE-200304240730/Zend/zend_variables.c", __zend_orig_lineno=44) at /usr/local/src/php4-STABLE-200304240730/Zend/zend_alloc.c:243 #4 0x40415336 in _zval_dtor (zvalue=0x8178314, __zend_filename=0x404e64a0 "/usr/local/src/php4-STABLE-200304240730/Zend/zend_opcode.c", __zend_lineno=159) at /usr/local/src/php4-STABLE-200304240730/Zend/zend_variables.c:44 #5 0x4040e1c6 in destroy_op_array (op_array=0x8179300) at /usr/local/src/php4-STABLE-200304240730/Zend/zend_opcode.c:159 #6 0x4040dfbd in destroy_zend_function (function=0x8179300) at /usr/local/src/php4-STABLE-200304240730/Zend/zend_opcode.c:100 #7 0x4041d1c4 in zend_hash_del_key_or_index (ht=0x8118be8, arKey=0x81792f0 "print_d", nKeyLength=8, h=3787772783, flag=0) at /usr/local/src/php4-STABLE-200304240730/Zend/zend_hash.c:514 #8 0x4041dc07 in zend_hash_reverse_apply (ht=0x8118be8, apply_func=0x4040a8d0 <is_not_internal_function>) at /usr/local/src/php4-STABLE-200304240730/Zend/zend_hash.c:760 #9 0x4040adde in shutdown_executor () at /usr/local/src/php4-STABLE-200304240730/Zend/zend_execute_API.c:201 #10 0x40416ad3 in zend_deactivate () at /usr/local/src/php4-STABLE-200304240730/Zend/zend.c:649 #11 0x403da06c in php_request_shutdown (dummy=0x0) at /usr/local/src/php4-STABLE-200304240730/main/main.c:984 #12 0x4042fae8 in apache_php_module_main (r=0x815c62c, display_source_mode=0) at /usr/local/src/php4-STABLE-200304240730/sapi/apache/sapi_apache.c:61 #13 0x40430b20 in send_php (r=0x815c62c, display_source_mode=0, filename=0x815d0ec "/usr/local/apache/lariat/lariat2/test/test1/index.php") at /usr/local/src/php4-STABLE-200304240730/sapi/apache/mod_php4.c:617 #14 0x40430b9f in send_parsed_php (r=0x815c62c) at /usr/local/src/php4-STABLE-200304240730/sapi/apache/mod_php4.c:632 ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at http://bugs.php.net/23299 -- Edit this bug report at http://bugs.php.net/?id=23299&edit=1

« previous php.bugs (#39102) next »