php.net |  support |  documentation |  report a bug |  advanced search |  search howto |  statistics |  random bug |  login
Bug #1849 segfault in _php3_hash_environment / php3_treat_data / zend_hash_add_or_update
Submitted: 1999-07-23 11:03 UTC Modified: 1999-08-07 18:59 UTC
From: sascha at schumann dot cx Assigned:
Status: Closed Package: Reproducible Crash
PHP Version: 4.0 Latest CVS (23/07/1999) OS: Linux 2.2.10
Private report: No CVE-ID: None
Welcome back! If you're the original bug submitter, here's where you can edit the bug or add additional notes.
If you forgot your password, you can retrieve your password here.
Password:
Status:
Package:
Bug Type:
Summary:
From: sascha at schumann dot cx
New email:
PHP Version: OS:

 

 [1999-07-23 11:03 UTC] sascha at schumann dot cx
With track_vars enabled, I get the following backtrace:

(gdb) bt
#0  0x400bc016 in chunk_alloc (ar_ptr=0x40147140, nb=96) at malloc.c:2783
#1  0x400bb82e in __libc_malloc (bytes=92) at malloc.c:2616
#2  0x401a1445 in _emalloc (size=49, filename=0x401d2c40 "zend_hash.c",
    lineno=175) at zend_alloc.c:124
#3  0x401ac83a in zend_hash_add_or_update (ht=0x401f30d4,
    arKey=0x401c6bdf "HTTP_GET_VARS", nKeyLength=14, pData=0xbffff42c,
    nDataSize=4, pDest=0x0, flag=2) at zend_hash.c:175
#4  0x4019d51b in php3_treat_data (arg=1, str=0x0) at post.c:326
#5  0x40176d23 in _php3_hash_environment () at main.c:919
#6  0x40177453 in php_execute_script (primary_file=0xbffff4dc) at main.c:1095
#7  0x40177a49 in apache_php_module_main (r=0x80b912c, fd=19,
    display_source_mode=0) at main.c:1160
#8  0x40175693 in send_php (r=0x80b912c, display_source_mode=0,
    filename=0x80b9c14 "/home/sas/httpd/htdocs/sess.php") at ./mod_php4.c:311
#9  0x40175b08 in send_parsed_php (r=0x80b912c) at ./mod_php4.c:323
#10 0x8063463 in ap_invoke_handler (r=0x80b912c) at http_config.c:508
#11 0x80726fb in process_request_internal (r=0x80b912c) at http_request.c:1212
#12 0x8072a6c in ap_process_request (r=0x80b912c) at http_request.c:1228
#13 0x806b300 in child_main (child_num_arg=0) at http_main.c:3851
#14 0x806b592 in startup_children (number_to_start=5) at http_main.c:3976
#15 0x806bd47 in standalone_main (argc=1, argv=0xbffff724) at http_main.c:4290
#16 0x806c682 in main (argc=1, argv=0xbffff724) at http_main.c:4591

The script follows:

<?php_track_vars?>
<?session_name("csl");
session_register("count");
if(is_array($HTTP_COOKIE_VARS))
    for(reset($HTTP_COOKIE_VARS); $key = key($HTTP_COOKIE_VARS); next($HTTP_COOKIE_VARS)) echo "$key=".$HTTP_COOKIE_VARS[$key]."<p>";
?>
<html><head><title>Show =sid is always present</title>
</head><body>
message is <?=$message;?><br>
count is <?=++$count;?><br>
sid is <?=sid;?><br>
<a href="<?=$PHP_SELF;?>?message=count+was+<?=$count;?>">Call self</a><p>
<a href="sess.phps">the source</a>

The setup in question is complete standard (Apache 1.3.6, current CVS of php4, libzend). No extra options beside --enable-debug and --with-apxs have been used (the apxs vars were corrected manually).

Patches

Pull Requests

History

AllCommentsChangesGit/SVN commitsRelated reports
 [1999-08-07 16:07 UTC] zeev at cvs dot php dot net
Does that still happen?
 [1999-08-07 18:59 UTC] sas at cvs dot php dot net
Nope, at least I cannot reproduce it anymore:

Apache (current cvs, marked as 1.3.8-dev (?))
libzend/php4 (current cvs)
 
PHP Copyright © 2001-2026 The PHP Group
All rights reserved.
Last updated: Sun Oct 11 02:00:01 2026 UTC