php.net |  support |  documentation |  report a bug |  advanced search |  search howto |  statistics |  random bug |  login
Bug #2916 segfault on file($someurl) and odd response
Submitted: 1999-12-04 18:58 UTC Modified: 2000-07-23 23:12 UTC
From: sroberts at snap dot com Assigned:
Status: Closed Package: Reproducible Crash
PHP Version: 4.0 Latest CVS (04/12/1999) OS: Solaris 2.5.1
Private report: No CVE-ID: None
Welcome back! If you're the original bug submitter, here's where you can edit the bug or add additional notes.
If you forgot your password, you can retrieve your password here.
Password:
Status:
Package:
Bug Type:
Summary:
From: sroberts at snap dot com
New email:
PHP Version: OS:

 

 [1999-12-04 18:58 UTC] sroberts at snap dot com
Both symptoms come from trivial test program :

<?php
$foo = file("http://www.snap.com/");
echo "<pre>" . htmlspecialchars($foo[0]) . "</pre>";
?>

Symptom 1 : For most URLs it reports

Warning: Invalid URL specified, http://www.snap.com/ in /home/simonr/public_html/testget.php on line 5

There's nothing wrong with the URL.

Symptom 2 : Sometimes

A couple of times it took a long time (30s?) before segfaulting apache : I can't seem to reproduce it reliably, but here's the backtrace from one instance if it helps...

(gdb) bt
#0  0xef620cdc in seg3 ()
#1  0x4d194 in _emalloc (size=10439360, __zend_filename=0x20e2c8 "", __zend_lineno=16, __zend_orig_filename=0x1020e2c0 "", __zend_orig_lineno=48) at zend_alloc.c:153
#2  0x4d750 in _estrndup (s=0xef8222f8 "", length=278839264, __zend_filename=0x1625e0 "url.c", __zend_lineno=111, __zend_orig_filename=0x0, __zend_orig_lineno=0) at zend_alloc.c:279
#3  0xa4634 in url_parse (string=0x20e2d8 "http://palladium:11000/~simonr/links.html") at url.c:111
#4  0x4a164 in php3_fopen_url_wrapper (path=0x20e2d8 "http://palladium:11000/~simonr/links.html", mode=0x15f9e0 "r", options=4, issock=0xefffd03c, socketd=0xefffd038, opened_path=0x0) at fopen-wrappers.c:450
#5  0x49cd0 in php3_fopen_wrapper (path=0x20e2d8 "http://palladium:11000/~simonr/links.html", mode=0x15f9e0 "r", options=4, issock=0xefffd03c, socketd=0xefffd038, opened_path=0x0) at fopen-wrappers.c:193
#6  0x825b4 in php3_file (ht=-8212, return_value=0xeffff0e0, list=0x1d3e58, plist=0x1d3e84, this_ptr=0x0, return_value_used=1) at file.c:538
#7  0xc2c50 in execute (op_array=0x211128) at zend_execute.c:1476
#8  0x47478 in php_execute_script (primary_file=0xeffff6d8) at main.c:1226
#9  0x63dec in apache_php_module_main (r=0x201f28, fd=19, display_source_mode=0) at sapi_apache.c:88
#10 0x452f4 in send_php ()
#11 0x4534c in send_parsed_php ()
#12 0xd1b5c in ap_invoke_handler ()
#13 0xedfa0 in process_request_internal ()
#14 0xee024 in ap_process_request ()
#15 0xe1bf8 in child_main ()
#16 0xe1f84 in make_child ()
#17 0xe20a8 in startup_children ()
#18 0xe2a98 in standalone_main ()
#19 0xe3680 in main ()

Patches

Pull Requests

History

AllCommentsChangesGit/SVN commitsRelated reports
 [1999-12-04 21:45 UTC] sroberts at snap dot com
No more info on the crash, it hasn't done it since, but it might be related. The URL is rejected in url_parse() quite late in the game - when it's attempting to extract the username/pass/host/port from the url-string. I'm looking closer now.
 [1999-12-04 21:59 UTC] sroberts at snap dot com
Added some debugging to the code, and it started working! Damn. I'm trying another snapshot of the CVS, maybe it was just a bad build or something...
 [1999-12-04 23:20 UTC] sroberts at snap dot com
Ok, I got it working, but something odd is still up. It might be a chaotic thing to do with the build, but when I added debugging stuff to it seemed to right itself.

The line that I considered most (url.c: ())

if ((err=regcomp(&re, "^(([^@:]+)(:([^@:]+))?@)?([^:@]+)(:([^:@]+))?", REG_EXTENDED))
  || (err=regexec(&re, result, 10, subs, 0))) {
    /* FAILURE */
}

Now, I'm wondering if the order of evaluation is guaranteed in this circumstance, and whether the second part might be executed even if the first part fails (hence overwriting err).

*shrug*


 [2000-07-23 02:04 UTC] zak at cvs dot php dot net
contacting user
 [2000-07-23 23:08 UTC] sroberts at snap dot com
As commented, unable to reproduce anymore. I could have caught CVS at a bad time. Close bug, I'll refile if I observe it again.
 
PHP Copyright © 2001-2026 The PHP Group
All rights reserved.
Last updated: Sun Oct 11 06:00:01 2026 UTC