php.net |  support |  documentation |  report a bug |  advanced search |  search howto |  statistics |  random bug |  login
Bug #2916 segfault on file($someurl) and odd response
Submitted: 1999-12-04 18:58 UTC Modified: 2000-07-23 23:12 UTC
From: sroberts at snap dot com Assigned:
Status: Closed Package: Reproducible Crash
PHP Version: 4.0 Latest CVS (04/12/1999) OS: Solaris 2.5.1
Private report: No CVE-ID: None
View Developer Edit
Welcome! If you don't have a Git account, you can't do anything here.
If you reported this bug, you can edit this bug over here.
(description)
Block user comment
Status: Assign to:
Package:
Bug Type:
Summary:
From: sroberts at snap dot com
New email:
PHP Version: OS:

 

 [1999-12-04 18:58 UTC] sroberts at snap dot com
Both symptoms come from trivial test program :

<?php
$foo = file("http://www.snap.com/");
echo "<pre>" . htmlspecialchars($foo[0]) . "</pre>";
?>

Symptom 1 : For most URLs it reports

Warning: Invalid URL specified, http://www.snap.com/ in /home/simonr/public_html/testget.php on line 5

There's nothing wrong with the URL.

Symptom 2 : Sometimes

A couple of times it took a long time (30s?) before segfaulting apache : I can't seem to reproduce it reliably, but here's the backtrace from one instance if it helps...

(gdb) bt
#0  0xef620cdc in seg3 ()
#1  0x4d194 in _emalloc (size=10439360, __zend_filename=0x20e2c8 "", __zend_lineno=16, __zend_orig_filename=0x1020e2c0 "", __zend_orig_lineno=48) at zend_alloc.c:153
#2  0x4d750 in _estrndup (s=0xef8222f8 "", length=278839264, __zend_filename=0x1625e0 "url.c", __zend_lineno=111, __zend_orig_filename=0x0, __zend_orig_lineno=0) at zend_alloc.c:279
#3  0xa4634 in url_parse (string=0x20e2d8 "http://palladium:11000/~simonr/links.html") at url.c:111
#4  0x4a164 in php3_fopen_url_wrapper (path=0x20e2d8 "http://palladium:11000/~simonr/links.html", mode=0x15f9e0 "r", options=4, issock=0xefffd03c, socketd=0xefffd038, opened_path=0x0) at fopen-wrappers.c:450
#5  0x49cd0 in php3_fopen_wrapper (path=0x20e2d8 "http://palladium:11000/~simonr/links.html", mode=0x15f9e0 "r", options=4, issock=0xefffd03c, socketd=0xefffd038, opened_path=0x0) at fopen-wrappers.c:193
#6  0x825b4 in php3_file (ht=-8212, return_value=0xeffff0e0, list=0x1d3e58, plist=0x1d3e84, this_ptr=0x0, return_value_used=1) at file.c:538
#7  0xc2c50 in execute (op_array=0x211128) at zend_execute.c:1476
#8  0x47478 in php_execute_script (primary_file=0xeffff6d8) at main.c:1226
#9  0x63dec in apache_php_module_main (r=0x201f28, fd=19, display_source_mode=0) at sapi_apache.c:88
#10 0x452f4 in send_php ()
#11 0x4534c in send_parsed_php ()
#12 0xd1b5c in ap_invoke_handler ()
#13 0xedfa0 in process_request_internal ()
#14 0xee024 in ap_process_request ()
#15 0xe1bf8 in child_main ()
#16 0xe1f84 in make_child ()
#17 0xe20a8 in startup_children ()
#18 0xe2a98 in standalone_main ()
#19 0xe3680 in main ()

Patches

Pull Requests

History

AllCommentsChangesGit/SVN commitsRelated reports
 [1999-12-04 21:45 UTC] sroberts at snap dot com
No more info on the crash, it hasn't done it since, but it might be related. The URL is rejected in url_parse() quite late in the game - when it's attempting to extract the username/pass/host/port from the url-string. I'm looking closer now.
 [1999-12-04 21:59 UTC] sroberts at snap dot com
Added some debugging to the code, and it started working! Damn. I'm trying another snapshot of the CVS, maybe it was just a bad build or something...
 [1999-12-04 23:20 UTC] sroberts at snap dot com
Ok, I got it working, but something odd is still up. It might be a chaotic thing to do with the build, but when I added debugging stuff to it seemed to right itself.

The line that I considered most (url.c: ())

if ((err=regcomp(&re, "^(([^@:]+)(:([^@:]+))?@)?([^:@]+)(:([^:@]+))?", REG_EXTENDED))
  || (err=regexec(&re, result, 10, subs, 0))) {
    /* FAILURE */
}

Now, I'm wondering if the order of evaluation is guaranteed in this circumstance, and whether the second part might be executed even if the first part fails (hence overwriting err).

*shrug*


 [2000-07-23 02:04 UTC] zak at cvs dot php dot net
contacting user
 [2000-07-23 23:08 UTC] sroberts at snap dot com
As commented, unable to reproduce anymore. I could have caught CVS at a bad time. Close bug, I'll refile if I observe it again.
 
PHP Copyright © 2001-2026 The PHP Group
All rights reserved.
Last updated: Sun Oct 11 10:00:01 2026 UTC