|
php.net | support | documentation | report a bug | advanced search | search howto | statistics | random bug | login |
[2003-04-21 16:01 UTC] bginter at ndevtech dot net
I am experiencing an intermittant but reproducable problem with data, function names, method names, and objects being corrupted and often crashing Apache. This problem has been reoccurring periodically since around PHP 4.2.0 and continues to occur in 4.3.1.
Unfortunately, the code that causes these errors to occur is quite large and attempts to create a small test case have been unsuccessful.
Some examples of the corruption are provided below:
Example 1: Script startup calling require_once().
/usr/local/apache/lariat/lariat2/find.php(14) : Fatal error - Cannot redeclare findup() (previously declared in ?M@4:14)
Example 2: Passing an array by value to a function.
Array
(
[0] => ? 9 [Corrupted]
[1] => DC
[2] => 28
[3] => 334.87
[4] => ? 9 [Corrupted]
[5] => 0.00
[6] => 1825
)
PHP is running under Apache 1.3.27 and is compiled with the following options:
./configure \
--prefix=/usr/local/php_4.3.1 \
--with-apxs=/usr/local/apache/bin/apxs \
--enable-bcmath \
--enable-gd-native-ttf \
--with-gd \
--with-ttf \
--enable-calendar \
--with-mysql \
--enable-trans-sid \
--enable-inline-optimization \
--enable-track-vars \
--enable-versioning \
--with-openssl \
--with-iconv \
--enable-xml \
--with-pgsql=/usr/local/pgsql-7.3 \
--with-mcrypt \
--with-curl \
--with-zip \
--enable-ftp \
--with-zlib-dir=/usr \
--enable-debug
Here is the backtrace:
Program received signal SIGSEGV, Segmentation fault.
0x404053e0 in object.11 () from /usr/local/apache/libexec/libphp4.so.debug
(gdb) bt
#0 0x404053e0 in object.11 () from /usr/local/apache/libexec/libphp4.so.debug
#1 0x405382cc in php4_module () from /usr/local/apache/libexec/libphp4.so.debug
#2 0x4040f93d in object.11 () from /usr/local/apache/libexec/libphp4.so.debug
#3 0x4041740a in object.11 () from /usr/local/apache/libexec/libphp4.so.debug
#4 0x4040f569 in object.11 () from /usr/local/apache/libexec/libphp4.so.debug
#5 0x4040540c in object.11 () from /usr/local/apache/libexec/libphp4.so.debug
#6 0x4040f93d in object.11 () from /usr/local/apache/libexec/libphp4.so.debug
#7 0x4041740a in object.11 () from /usr/local/apache/libexec/libphp4.so.debug
#8 0x4040f5b3 in object.11 () from /usr/local/apache/libexec/libphp4.so.debug
#9 0x4040540c in object.11 () from /usr/local/apache/libexec/libphp4.so.debug
#10 0x4040f93d in object.11 () from /usr/local/apache/libexec/libphp4.so.debug
#11 0x4041740a in object.11 () from /usr/local/apache/libexec/libphp4.so.debug
#12 0x4040f5b3 in object.11 () from /usr/local/apache/libexec/libphp4.so.debug
#13 0x4040540c in object.11 () from /usr/local/apache/libexec/libphp4.so.debug
#14 0x4040f93d in object.11 () from /usr/local/apache/libexec/libphp4.so.debug
#15 0x4041740a in object.11 () from /usr/local/apache/libexec/libphp4.so.debug
#16 0x4040f5b3 in object.11 () from /usr/local/apache/libexec/libphp4.so.debug
#17 0x4040540c in object.11 () from /usr/local/apache/libexec/libphp4.so.debug
#18 0x4040f93d in object.11 () from /usr/local/apache/libexec/libphp4.so.debug
#19 0x4041740a in object.11 () from /usr/local/apache/libexec/libphp4.so.debug
#20 0x40404ed7 in object.11 () from /usr/local/apache/libexec/libphp4.so.debug
#21 0x40410cd3 in object.11 () from /usr/local/apache/libexec/libphp4.so.debug
#22 0x403d4e5b in object.11 () from /usr/local/apache/libexec/libphp4.so.debug
#23 0x40429b48 in object.11 () from /usr/local/apache/libexec/libphp4.so.debug
#24 0x4042aa70 in object.11 () from /usr/local/apache/libexec/libphp4.so.debug
#25 0x4042aaef in object.11 () from /usr/local/apache/libexec/libphp4.so.debug
#26 0x080554e9 in ap_invoke_handler ()
#27 0x0806b5df in process_request_internal ()
#28 0x0806b646 in ap_process_request ()
#29 0x08061e06 in child_main ()
#30 0x08061fe5 in make_child ()
#31 0x0806215c in startup_children ()
#32 0x080627ed in standalone_main ()
#33 0x0806307c in main ()
#34 0x4009214f in __libc_start_main () from /lib/libc.so.6
(gdb)
Apache is linked to the following libraries:
$ ldd /usr/local/apache/bin/httpd
libm.so.6 => /lib/libm.so.6 (0x4001a000)
libcrypt.so.1 => /lib/libcrypt.so.1 (0x4003b000)
libdb.so.2 => /lib/libdb.so.2 (0x40069000)
libdl.so.2 => /lib/libdl.so.2 (0x40076000)
libc.so.6 => /lib/libc.so.6 (0x40079000)
/lib/ld-linux.so.2 => /lib/ld-linux.so.2 (0x40000000)
The PHP module is linked as follows:
$ ldd /usr/local/apache/libexec/libphp4.so.debug
libzzip-0.so.10 => /usr/local/lib/libzzip-0.so.10 (0x4031f000)
libpq.so.2 => /usr/local/pgsql-7.3/lib/libpq.so.2 (0x40325000)
libmcrypt.so.4 => /usr/lib/libmcrypt.so.4 (0x4033c000)
libltdl.so.3 => /usr/lib/libltdl.so.3 (0x40342000)
libpng.so.2 => /usr/lib/libpng.so.2 (0x40348000)
libz.so.1 => /usr/lib/libz.so.1 (0x40373000)
libcrypt.so.1 => /lib/libcrypt.so.1 (0x40382000)
libresolv.so.2 => /lib/libresolv.so.2 (0x403af000)
libm.so.6 => /lib/libm.so.6 (0x403bf000)
libdl.so.2 => /lib/libdl.so.2 (0x403e1000)
libnsl.so.1 => /lib/libnsl.so.1 (0x403e4000)
libcurl.so.2 => /usr/local/lib/libcurl.so.2 (0x403f8000)
libc.so.6 => /lib/libc.so.6 (0x40415000)
/lib/ld-linux.so.2 => /lib/ld-linux.so.2 (0x80000000)
Please let me know if I can provide any other information to help isolate the cause of this problem.
Thank you for investigating.
PatchesPull RequestsHistoryAllCommentsChangesGit/SVN commits
|
|||||||||||||||||||||||||||||||||||||
Copyright © 2001-2026 The PHP GroupAll rights reserved. |
Last updated: Tue Oct 06 20:00:02 2026 UTC |
Here is the one from crash1.php in my examples: Program received signal SIGSEGV, Segmentation fault. 0x40415404 in zval_add_ref (p=0x8190a60) at /usr/local/src/php4-STABLE-200304240730/Zend/zend_variables.c:85 85 (*p)->refcount++; (gdb) bt #0 0x40415404 in zval_add_ref (p=0x8190a60) at /usr/local/src/php4-STABLE-200304240730/Zend/zend_variables.c:85 #1 0x4041dd38 in zend_hash_copy (target=0x81970dc, source=0x8193e5c, pCopyConstructor=0x404153fc <zval_add_ref>, tmp=0xbfffcbd4, size=4) at /usr/local/src/php4-STABLE-200304240730/Zend/zend_hash.c:789 #2 0x40415651 in _zval_copy_ctor (zvalue=0x81889d4, __zend_filename=0x404e8180 "/usr/local/src/php4-STABLE-200304240730/Zend/zend_execute.c", __zend_lineno=1795) at /usr/local/src/php4-STABLE-200304240730/Zend/zend_variables.c:137 #3 0x4042b131 in execute (op_array=0x8162cc4) at /usr/local/src/php4-STABLE-200304240730/Zend/zend_execute.c:1795 #4 0x40417384 in zend_execute_scripts (type=8, retval=0x0, file_count=3) at /usr/local/src/php4-STABLE-200304240730/Zend/zend.c:864 #5 0x403db91e in php_execute_script (primary_file=0xbffff8c8) at /usr/local/src/php4-STABLE-200304240730/main/main.c:1637 [...] (gdb) frame 3 #3 0x4042b131 in execute (op_array=0x8162cc4) at /usr/local/src/php4-STABLE-200304240730/Zend/zend_execute.c:1795 1795 zval_copy_ctor(varptr); (gdb) print (char *)(executor_globals.function_state_ptr->function)->common.function_name $1 = 0x0 (gdb) print (char *)executor_globals.active_op_array->function_name $2 = 0x0 (gdb) print (char *)executor_globals.active_op_array->filename $3 = 0x8162fb4 "/usr/local/apache/lariat/lariat2/test/test1/crash1.php"The corrupt1.php in the examples I provided also creates this backtrace fairly consistently. This only happens after at least two reloads and sometimes requires me to close my browser and revisit the index.php page then corrupt1.php page while the same apache/php thread is running in gdb. Program received signal SIGSEGV, Segmentation fault. 0x400ee1c3 in memcpy () from /lib/libc.so.6 (gdb) bt #0 0x400ee1c3 in memcpy () from /lib/libc.so.6 #1 0x40402c53 in _mem_block_check (ptr=0x81792bc, silent=0, __zend_filename=0x404e64a0 "/usr/local/src/php4-STABLE-200304240730/Zend/zend_opcode.c", __zend_lineno=159, __zend_orig_filename=0x404e68c0 "/usr/local/src/php4-STABLE-200304240730/Zend/zend_variables.c", __zend_orig_lineno=44) at /usr/local/src/php4-STABLE-200304240730/Zend/zend_alloc.c:675 #2 0x40402c0e in _mem_block_check (ptr=0x81792bc, silent=1, __zend_filename=0x404e64a0 "/usr/local/src/php4-STABLE-200304240730/Zend/zend_opcode.c", __zend_lineno=159, __zend_orig_filename=0x404e68c0 "/usr/local/src/php4-STABLE-200304240730/Zend/zend_variables.c", __zend_orig_lineno=44) at /usr/local/src/php4-STABLE-200304240730/Zend/zend_alloc.c:667 #3 0x40401d64 in _efree (ptr=0x81792bc, __zend_filename=0x404e64a0 "/usr/local/src/php4-STABLE-200304240730/Zend/zend_opcode.c", __zend_lineno=159, __zend_orig_filename=0x404e68c0 "/usr/local/src/php4-STABLE-200304240730/Zend/zend_variables.c", __zend_orig_lineno=44) at /usr/local/src/php4-STABLE-200304240730/Zend/zend_alloc.c:243 #4 0x40415336 in _zval_dtor (zvalue=0x8178314, __zend_filename=0x404e64a0 "/usr/local/src/php4-STABLE-200304240730/Zend/zend_opcode.c", __zend_lineno=159) at /usr/local/src/php4-STABLE-200304240730/Zend/zend_variables.c:44 #5 0x4040e1c6 in destroy_op_array (op_array=0x8179300) at /usr/local/src/php4-STABLE-200304240730/Zend/zend_opcode.c:159 #6 0x4040dfbd in destroy_zend_function (function=0x8179300) at /usr/local/src/php4-STABLE-200304240730/Zend/zend_opcode.c:100 #7 0x4041d1c4 in zend_hash_del_key_or_index (ht=0x8118be8, arKey=0x81792f0 "print_d", nKeyLength=8, h=3787772783, flag=0) at /usr/local/src/php4-STABLE-200304240730/Zend/zend_hash.c:514 #8 0x4041dc07 in zend_hash_reverse_apply (ht=0x8118be8, apply_func=0x4040a8d0 <is_not_internal_function>) at /usr/local/src/php4-STABLE-200304240730/Zend/zend_hash.c:760 #9 0x4040adde in shutdown_executor () at /usr/local/src/php4-STABLE-200304240730/Zend/zend_execute_API.c:201 #10 0x40416ad3 in zend_deactivate () at /usr/local/src/php4-STABLE-200304240730/Zend/zend.c:649 #11 0x403da06c in php_request_shutdown (dummy=0x0) at /usr/local/src/php4-STABLE-200304240730/main/main.c:984 #12 0x4042fae8 in apache_php_module_main (r=0x815c62c, display_source_mode=0) at /usr/local/src/php4-STABLE-200304240730/sapi/apache/sapi_apache.c:61 #13 0x40430b20 in send_php (r=0x815c62c, display_source_mode=0, filename=0x815d0ec "/usr/local/apache/lariat/lariat2/test/test1/index.php") at /usr/local/src/php4-STABLE-200304240730/sapi/apache/mod_php4.c:617 #14 0x40430b9f in send_parsed_php (r=0x815c62c) at /usr/local/src/php4-STABLE-200304240730/sapi/apache/mod_php4.c:632I'm looking at crash1.php script. <?php $group = new Group; for ( $i = 0; $i < 15; $i++ ) { // uncomment this and it works // print $group->count() . "<br/>\n"; for ( $i = 0; $i < $assoc->count(); $i++ ) { // print "Getting company $i<br/>\n"; $company = $assoc->get( $i ); $group->add( $company ); } // print_d( $company ); } print_d( $company ); ?> The above part should be for ( $j = 0; $j < 15; $j++ ) { // not $i ! for ( $i = 0; $i < $assoc->count(); $i++ ) { $company = $assoc->get( $i ); Otherwise, it goes into an infinite loop when $assoc->count() is less than 15 and then PHP runs out of all the available memory to die.