php.net |  support |  documentation |  report a bug |  advanced search |  search howto |  statistics |  random bug |  login
Bug #5381 Crash after successful request
Submitted: 2000-07-05 16:54 UTC Modified: 2000-08-21 04:12 UTC
From: tom dot anheyer at berlinonline dot de Assigned:
Status: Closed Package: Reproducible Crash
PHP Version: 4.0.1pl2 OS: Linux 2.2.14,Apache 1.3.11
Private report: No CVE-ID: None
Welcome back! If you're the original bug submitter, here's where you can edit the bug or add additional notes.
If you forgot your password, you can retrieve your password here.
Password:
Status:
Package:
Bug Type:
Summary:
From: tom dot anheyer at berlinonline dot de
New email:
PHP Version: OS:

 

 [2000-07-05 16:54 UTC] tom dot anheyer at berlinonline dot de
the script uses mysql,string functions,preg,...
here is the backtrace:

#0  0x4029da69 in _zval_ptr_dtor ()
#1  0x402ac523 in zend_hash_destroy ()
#2  0x402a6926 in _zval_dtor ()
#3  0x4029da84 in _zval_ptr_dtor ()
#4  0x402ac523 in zend_hash_destroy ()
#5  0x4029fa0e in destroy_op_array ()
#6  0x4029f8e1 in destroy_zend_function ()
#7  0x402ac724 in zend_hash_apply_deleter ()
#8  0x402ac9be in zend_hash_apply ()
#9  0x4029d825 in shutdown_executor ()
#10 0x402a7986 in zend_deactivate ()
#11 0x402bb569 in php_request_shutdown ()

an strace log:

gettimeofday({962722525, 978364}, NULL) = 0
times({tms_utime=140, tms_stime=13, tms_cutime=0, tms_cstime=0}) = 162949660
alarm(30)                               = 0
shutdown(9, 1 /* send */)               = 0
select(10, [9], NULL, NULL, {2, 0})     = 1 (in [9], left {1, 940000})
read(9, "", 512)                        = 0
close(9)                                = 0
alarm(0)                                = 30
sigaction(SIGUSR1, {0x8081e10, [], 0x6}, {SIG_IGN}) = 0
alarm(0)                                = 0
munmap(0x40248000, 16420)               = 0
munmap(0x40552000, 30024)               = 0
sigaction(SIGPIPE, {SIG_IGN}, {SIG_IGN}) = 0
fcntl(11, F_SETFL, O_RDONLY|O_NONBLOCK) = 0
read(11, 0x81f1a28, 8192)               = -1 EAGAIN (Resource temporarily unavai
lable)
fcntl(11, F_SETFL, O_RDONLY)            = 0
write(11, "\1\0\0\0\1", 5)              = 5
shutdown(11, 2 /* send and receive */)  = 0
close(11)                               = 0
sigaction(SIGPIPE, {SIG_IGN}, {SIG_IGN}) = 0
munmap(0x4052b000, 135168)              = 0
--- SIGSEGV (Segmentation fault) ---
+++ killed by SIGSEGV +++

#12 0x402b8b09 in php_apache_request_shutdown ()
#13 0x8075f24 in run_cleanups ()
#14 0x80731df in ap_clear_pool ()
#15 0x807328e in ap_destroy_pool ()
#16 0x80731b9 in ap_clear_pool ()
#17 0x807f8fa in child_main ()
#18 0x808024f in startup_children ()
#19 0x8080a76 in standalone_main ()
#20 0x80814cd in main ()

Patches

Pull Requests

History

AllCommentsChangesGit/SVN commitsRelated reports
 [2000-07-06 17:20 UTC] tom dot anheyer at berlinonline dot de
some more info:

php crashes in:
0x402a5969 in _zval_ptr_dtor (zval_ptr=0x81f78a0) at zend_execute_API.c:270
270             (*zval_ptr)->refcount--;

compile flags:
./configure \
	--with-apxs=/usr/sbin/apxs  --with-mysql=/usr \
	--with-gd=/usr --with-config-file-path=/home/httpd/conf \
	--enable-track-vars --enable-memory-limit \
	--enable-sysvsem --enable-sysvshm \
	--disable-xml --disable-debug \
	--enable-inline-optimization
CC=egcs
CFLAGS=-O6 -march=i686 -mpentiumpro -g -DLINUX=2 -DDEV_RANDOM=/dev/random -DMOD_SSL=205100 -DUSE_HSREGEX -DEAPI -DEAPI_MM -DUSE_EXPAT -I../lib/expat-lite

 [2000-07-07 11:23 UTC] tom dot anheyer at berlinonline dot de
I have found the reason for the crash. The script runs perfectly if I don't call the following function. Maybe it is a problem with the static array's or preg_replace().  

My script works fine after a rewrite of the function using get_html_translation_table() and strtr().

$html2iso = array(
  '"'   => '"',
  ' '   => CHR(160), // ' '
  '¡'  => CHR(161), // '?'
  '¢'   => CHR(162), // '?'
  '£'  => CHR(163), // '?'
  '¤' => CHR(164), // '?'
  '¥'    => CHR(165), // '?'
  '¦' => CHR(166), // '?'
  '§'   => CHR(167), // '?'
  '¨'    => CHR(168), // '?'
  '©'   => CHR(169), // '?'
  'ª'   => CHR(170), // '?'
  '«'  => CHR(171), // '?'
  '¬'    => CHR(172), // '?'
  '­'    => CHR(173), // '?'
  '®'    => CHR(174), // '?'
  '¯'   => CHR(175), // '?'
  '°'    => CHR(176), // '?'
  '±' => CHR(177), // '?'
  '²'   => CHR(178), // '?'
  '³'   => CHR(179), // '?'
  '´'  => CHR(180), // '?'
  'µ'  => CHR(181), // '?'
  '¶'   => CHR(182), // '?'
  '·' => CHR(183), // '?'
  '¸'  => CHR(184), // '?'
  '¹'   => CHR(185), // '?'
  'º'   => CHR(186), // '?'
  '»'  => CHR(187), // '?'
  '¼' => CHR(188), // '?'
  '½' => CHR(189), // '?'
  '¾' => CHR(190), // '?'
  '¿' => CHR(191), // '?'

  'À' => CHR(192), // '?'
  'Á' => CHR(193), // '?'
  'Â'  => CHR(194), // '?'
  'Ã' => CHR(195), // '?'
  'Ä'   => CHR(196), // '?'
  'Å'  => CHR(197), // '?'
  'Æ'  => CHR(198), // '?'
  'Ç' => CHR(199), // '?'
  'È' => CHR(200), // '?'
  'É' => CHR(201), // '?'
  'Ê'  => CHR(202), // '?'
  'Ë'   => CHR(203), // '?'
  'Ì' => CHR(204), // '?'
  'Í' => CHR(205), // '?'
  'Î'  => CHR(206), // '?'
  'Ï'   => CHR(207), // '?'
  'Ð'    => CHR(208), // '?'
  'Ñ' => CHR(209), // '?'
  'Ò' => CHR(210), // '?'
  'Ó' => CHR(211), // '?'
  'Ô'  => CHR(212), // '?'
  'Õ' => CHR(213), // '?'
  'Ö'   => CHR(214), // '?'
  '×'  => CHR(215), // '?'
  'Ø' => CHR(216), // '?'
  'Ù' => CHR(217), // '?'
  'Ú' => CHR(218), // '?'
  'Û'  => CHR(219), // '?'
  'Ü'   => CHR(220), // '?'
  'Ý' => CHR(221), // '?'
  'Þ'  => CHR(222), // '?'
  'ß'  => CHR(223), // '?'

  'à' => CHR(224), // '?'
  'á' => CHR(225), // '?'
  'â'  => CHR(226), // '?'
  'ã' => CHR(227), // '?'
  'ä'   => CHR(228), // '?'
  'å'  => CHR(229), // '?'
  'æ'  => CHR(230), // '?'
  'ç' => CHR(231), // '?'
  'è' => CHR(232), // '?'
  'é' => CHR(233), // '?'
  'ê'  => CHR(234), // '?'
  'ë'   => CHR(235), // '?'
  'ì' => CHR(236), // '?'
  'í' => CHR(237), // '?'
  'î'  => CHR(238), // '?'
  'ï'   => CHR(239), // '?'
  'ð'    => CHR(240), // '?'
  'ñ' => CHR(241), // '?'
  'ò' => CHR(242), // '?'
  'ó' => CHR(243), // '?'
  'ô'  => CHR(244), // '?'
  'õ' => CHR(245), // '?'
  'ö'   => CHR(246), // '?'
  '÷' => CHR(247), // '?'
  'ø' => CHR(248), // '?'
  'ù' => CHR(249), // '?'
  'ú' => CHR(250), // '?'
  'û'  => CHR(251), // '?'
  'ü'   => CHR(252), // '?'
  'ý' => CHR(253), // '?'
  'þ'  => CHR(254), // '?'
  'ÿ'   => CHR(255)  // '?'
  );


function strip_entities($str)
{
  global $html2iso;
  static $entities, $isochars;

  if (! isset($entities))
    {
      reset($html2iso);
      while( list($key, $value) = each($html2iso))
        {
          $entities[] = "/$key/"; // Perl pattern
          $isochars[] = $value;    // replacement
        }    
    }

  return preg_replace( $entities, $isochars, $str);
}


 [2000-07-27 21:29 UTC] waldschrott@php.net
Please verify that it?s still happening using the latest version from CVS or snaps.php.net.

Also you could provide the string you?re using it on....
 [2000-07-28 10:33 UTC] tom dot anheyer at berlinonline dot de
the crash still happens in the latest snapshot (php4-200007272345) and only if I use the function above.

A sample call aof the function:

strip_entities('WISSENSCHAFT - Die Sucht hat viele Vorboten Die Sucht hat viele Vorboten Münchner Studie: Jeder zweite junge Erwachsene hat schon illegale Drogen genommen von Nicola Siegmund-Schultze I mmer häufiger und immer früher greifen Jugendliche zu legalen und illegalen Drogen. Das ..')
 [2000-07-28 11:22 UTC] waldschrott@php.net
It?s either the preg_ array stuff or static arrays in combination then, perhaps
 [2000-08-19 15:52 UTC] waldschrott@php.net
could check if it still crashes with a new version from CVS and if yes could you provide a backtrace...?
 [2000-08-21 04:12 UTC] tom dot anheyer at berlinonline dot de
I have tested my script with snapshoot php4-200008202345.
The bug is gone. No Segfaults anymore. 
 
PHP Copyright © 2001-2026 The PHP Group
All rights reserved.
Last updated: Sat Oct 10 12:00:01 2026 UTC