#35140 [Com]: Segmentation fault in shutdown_memory_manager

From: Date: Sat, 10 Dec 2005 01:39:10 +0000
Subject: #35140 [Com]: Segmentation fault in shutdown_memory_manager
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-90187@lists.php.net to get a copy of this message
 ID:               35140
 Comment by:       brion at pobox dot com
 Reported By:      jfbustarret at tf1 dot fr
 Status:           No Feedback
 Bug Type:         Scripting Engine problem
 Operating System: Linux
 PHP Version:      5CVS-2005-11-10 (snap)
 New Comment:

I'm having the segfault as well, with PHP 5.1.1/Linux/Apache 
1.3 (also had under Apache 2.0; switched to 1.3 to try to 
replicate more of our non-crashing PHP 4.4 setup from other 
machines).

The system is Fedora 2/x86; compiler is GCC 3.3.3.

The segfaulting condition develops after a full day or two 
of running with relatively light load; once it's started, 
all PHP requests seem to segfault this way until Apache is 
restarted. I have not been able to find a way to trigger it 
on command yet.

I am using the APC caching module (3.0.8); will try to 
confirm with it off as well.

# ./configure  --with-apxs=/usr/local/apache/bin/apxs --
enable-memory-limit --enable-sysvsem --enable-sysvshm --
with-bz2 --enable-ctype --with-iconv --enable-exif --enable-
gettext --enable-mbstring --enable-shmop --enable-sockets --
with-zlib --with-openssl --with-curl --with-dom --with-dom-
xslt --with-dom-exslt --with-zlib --with-gd --with-mysql=/
usr/local/mysql --with-record --enable-xslt --with-xslt-
sablot --with-readline --with-xmlrpc

Apache 1.3.34 and PHP are compiled with CFLAGS='-g -O2' to 
enable debugging information, but I had the segfaults under 
the defaults as well.


Backtrace:
Program received signal SIGSEGV, Segmentation fault.
[Switching to Thread 16384 (LWP 31234)]
0x4049db7c in shutdown_memory_manager (silent=0, 
full_shutdown=0)
    at /home/brion/src/php-5.1.1/Zend/zend_alloc.c:511
511                                     
REMOVE_POINTER_FROM_LIST(ptr);
(gdb) bt
#0  0x4049db7c in shutdown_memory_manager (silent=0, 
full_shutdown=0)
    at /home/brion/src/php-5.1.1/Zend/zend_alloc.c:511
#1  0x4047bbca in php_request_shutdown (dummy=0x0)
    at /home/brion/src/php-5.1.1/main/main.c:1287
#2  0x4050d3c6 in apache_php_module_main (r=0x818a3bc, 
display_source_mode=0)
    at /home/brion/src/php-5.1.1/sapi/apache/sapi_apache.c:
59
#3  0x4050dda0 in send_php (r=0x818a3bc, 
display_source_mode=0, filename=0x0)
    at /home/brion/src/php-5.1.1/sapi/apache/mod_php5.c:644
#4  0x4050d60b in send_parsed_php (r=0x818a3bc)
    at /home/brion/src/php-5.1.1/sapi/apache/mod_php5.c:659
#5  0x08069a46 in ap_invoke_handler (r=0x818a3bc) at 
http_config.c:475
#6  0x0807943f in process_request_internal (r=0x818a3bc) at 
http_request.c:1298
#7  0x080795ef in ap_process_request (r=0x818a3bc) at 
http_request.c:1314
#8  0x08072bfc in child_main (child_num_arg=0) at 
http_main.c:4787
#9  0x08072d9f in make_child (s=0x80a397c, slot=11, now=0) 
at http_main.c:4957
#10 0x08073042 in perform_idle_server_maintenance () at 
http_main.c:5142
#11 0x080737f9 in standalone_main (argc=1, argv=0xbfffea34) 
at http_main.c:5405
#12 0x08073d22 in main (argc=1, argv=0xbfffea34) at 
http_main.c:5658
(gdb) p alloc_globals.cache[i]
$1 = {0x4214bdac, 0x4214bf7c, 0x4214bf64, 0x4214bf44, 
0x4214bdbc, 0x4214bd5c, 
  0x4214bf9c, 0x0 <repeats 249 times>}
(gdb) p i
$2 = 0
(gdb) p alloc_globals.cache[i][j]
$3 = (void *) 0x4214bdac
(gdb) p *(zend_mem_header*) alloc_globals.cache[i][j]
$4 = {pNext = 0x0, pLast = 0x10, size = 0}


Previous Comments:
------------------------------------------------------------------------

[2005-11-24 01:00:02] php-bugs at lists dot php dot net

No feedback was provided for this bug for over a week, so it is
being suspended automatically. If you are able to provide the
information that was originally requested, please do so and change
the status of the bug back to "Open".

------------------------------------------------------------------------

[2005-11-16 16:23:47] tony2001@php.net

We really need a reproduce script.

------------------------------------------------------------------------

[2005-11-16 16:08:35] jfbustarret at tf1 dot fr

I did some extensive tests with 5.1RC.

I did get a few random parsing errors :
#0  0x4070a2ad in yy_push_state (new_state=1) at
zend_language_scanner.c:6031
#1  0x4070ac97 in lex_scan (zendlval=0xbf8c5764) at
zend_language_scanner.c:4420
#2  0x407105a9 in zendlex (zendlval=0xbf8c5760) at
/soft/sources/php/php5-200511160730/Zend/zend_compile.c:3971
#3  0x40709b07 in zendparse () at zend_language_parser.c:2644

Every core I got was on the same template. Most of the time, the
template is correctly parsed, and sometimes it crashes (3 crashes in a
few thousand compiles, about the same frequency than my 5.0.5 crash).

I'll try to extract the part of the template that crashes and put it
online.

configure is the same as the beginning of the ticket, without
enable-debug (I'm unable to get core files with enable-debug). No
accelerator is used.

------------------------------------------------------------------------

[2005-11-15 23:01:28] sniper@php.net

Please try using this CVS snapshot:

  http://snaps.php.net/php5-latest.tar.gz
 
For Windows:
 
  http://snaps.php.net/win32/php5-win32-latest.zip

We're not interested in 5.0.5, we're interested if this happens with
the latest CVS.

------------------------------------------------------------------------

[2005-11-15 11:18:19] jfbustarret at tf1 dot fr

Our standard procedure for building PHP is already :
configure
make clean
make
make install
(we even rm -rf the directory & untar the source package each time)

I am trying to get a new core with 5.0.5/enable-debug & various
extensions.

------------------------------------------------------------------------

The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
    http://bugs.php.net/35140

-- 
Edit this bug report at http://bugs.php.net/?id=35140&edit=1


Thread (16 messages)

« previous php.bugs (#90187) next »