PHP 4.0 Bug #5162: core dump on un-freed mem dump
| From: | jjhuff at apptechsys dot com | Date: | Tue, 20 Jun 2000 21:56:34 +0000 |
| Subject: | PHP 4.0 Bug #5162: core dump on un-freed mem dump | ||
| Groups: | php.dev | ||
| Request: | Send a blank email to php-dev+get-21882@lists.php.net to get a copy of this message | ||
From: jjhuff@apptechsys.com
Operating system: Linux
PHP version: 4.0 Latest CVS (20/06/2000)
PHP Bug Type: Reproduceable crash
Bug description: core dump on un-freed mem dump
The module I'm loading has the line
emalloc(100);
in the function for ccmfactory_new()
I know I need to efree it. However, as a test I'm not freeing it.
At line 551 of main.c t->filename is pointing to invalid memory.
In _emalloc it is getting set to valid memory with valid data...
Let me know i you have any questions...
Attached is my gdb session:
----------------------------------------------------
Starting program: /disk2/home/jjhuff/php/php4/./php
<?
//Start the session
dl("sinaisocketphp.so");
$fact = ccmfactory_new();
?>
X-Powered-By: PHP/4.0.1-dev
Content-type: text/html
Program received signal SIGSEGV, Segmentation fault.
0x4011672a in _IO_vfprintf (s=0xbffff674, format=0x80f56c0 "%s(%d) : Freeing 0x%.8lX (%d
bytes), script=%s\n", ap=0xbffff788)
at vfprintf.c:1259
1259 vfprintf.c: No such file or directory.
(gdb) bt
#0 0x4011672a in _IO_vfprintf (s=0xbffff674, format=0x80f56c0 "%s(%d) : Freeing 0x%.8lX (%d
bytes), script=%s\n", ap=0xbffff788)
at vfprintf.c:1259
#1 0x40123566 in _IO_vsnprintf (string=0xbffff9a8 "", maxlen=512,
format=0x80f56c0 "%s(%d) : Freeing 0x%.8lX (%d bytes), script=%s\n", args=0xbffff784)
at vsnprintf.c:129
#2 0x4011cf9a in __snprintf (s=0xbffff9a8 "", maxlen=512, format=0x80f56c0 "%s(%d) :
Freeing 0x%.8lX (%d bytes), script=%s\n")
at snprintf.c:37
#3 0x805e613 in php_message_handler_for_zend (message=4, data=0x8140db8) at main.c:551
#4 0x80c665e in zend_message_dispatcher (message=4, data=0x8140db8) at zend.c:520
#5 0x80b9716 in shutdown_memory_manager (silent=0, clean_cache=0) at zend_alloc.c:416
#6 0x805e7e0 in php_request_shutdown (dummy=0x0) at main.c:669
#7 0x805dc09 in main (argc=1, argv=0xbffffcd4) at cgi_main.c:682