ID: 43295
Updated by: [EMAIL PROTECTED]
Reported By: pioklo at serveradmin dot pl
-Status: Open
+Status: Feedback
Bug Type: CGI related
Operating System: Debian 4.0 kernel 2.6.23.1
PHP Version: 5.2.5
New Comment:
First of all: Disable ALL 3rd party shared extensions. (Like xcache for
starters) If after that you're still able to reproduce this, generate a
clean backtrace.
Previous Comments:
------------------------------------------------------------------------
[2007-11-14 19:50:22] pioklo at serveradmin dot pl
ns78:~/root/php-5.2.5/sapi/cgi# /usr/local/bin/php-cgi -m
[PHP Modules]
cgi-fcgi
ctype
date
dom
exif
fileinfo
filter
ftp
gd
gettext
hash
iconv
json
libxml
mbstring
mysql
pcre
PDO
pdo_sqlite
posix
Reflection
session
SimpleXML
sockets
SPL
SQLite
standard
tokenizer
XCache
xml
xmlreader
xmlwriter
zlib
[Zend Modules]
XCache
Segmentation fault (core dumped)
ns78:~/root/php-5.2.5/sapi/cgi# gdb /usr/local/bin/php-cgi core
GNU gdb 6.4.90-debian
Copyright (C) 2006 Free Software Foundation, Inc.
GDB is free software, covered by the GNU General Public License, and
you are
welcome to change it and/or distribute copies of it under certain
conditions.
Type "show copying" to see the conditions.
There is absolutely no warranty for GDB. Type "show warranty" for
details.
This GDB was configured as "i486-linux-gnu"...Using host libthread_db
library "/lib/tls/libthread_db.so.1".
warning: Can't read pathname for load map: Input/output error.
Reading symbols from /lib/tls/libcrypt.so.1...done.
Loaded symbols for /lib/tls/libcrypt.so.1
Reading symbols from /lib/tls/librt.so.1...done.
Loaded symbols for /lib/tls/librt.so.1
Reading symbols from
/usr/local/mysql/lib/mysql/libmysqlclient.so.15...done.
Loaded symbols for /usr/local/mysql/lib/mysql/libmysqlclient.so.15
Reading symbols from /usr/lib/libz.so.1...done.
Loaded symbols for /usr/lib/libz.so.1
Reading symbols from /usr/local/lib/libiconv.so.2...done.
Loaded symbols for /usr/local/lib/libiconv.so.2
Reading symbols from /usr/local/lib/libfreetype.so.6...done.
Loaded symbols for /usr/local/lib/libfreetype.so.6
Reading symbols from /usr/local/lib/libpng.so.3...done.
Loaded symbols for /usr/local/lib/libpng.so.3
Reading symbols from /lib/tls/libresolv.so.2...done.
Loaded symbols for /lib/tls/libresolv.so.2
Reading symbols from /lib/tls/libm.so.6...done.
Loaded symbols for /lib/tls/libm.so.6
Reading symbols from /lib/tls/libdl.so.2...done.
Loaded symbols for /lib/tls/libdl.so.2
Reading symbols from /lib/tls/libnsl.so.1...done.
Loaded symbols for /lib/tls/libnsl.so.1
Reading symbols from /usr/lib/libxml2.so.2...done.
Loaded symbols for /usr/lib/libxml2.so.2
Reading symbols from /lib/tls/libc.so.6...done.
Loaded symbols for /lib/tls/libc.so.6
Reading symbols from /lib/tls/libpthread.so.0...done.
Loaded symbols for /lib/tls/libpthread.so.0
Reading symbols from /lib/ld-linux.so.2...done.
Loaded symbols for /lib/ld-linux.so.2
Reading symbols from
/usr/local/lib/php/extensions/no-debug-non-zts-20060613/fileinfo.so...done.
Loaded symbols for
/usr/local/lib/php/extensions/no-debug-non-zts-20060613/fileinfo.so
Reading symbols from /usr/lib/libmagic.so.1...done.
Loaded symbols for /usr/lib/libmagic.so.1
Reading symbols from /lib/tls/libnss_files.so.2...done.
Loaded symbols for /lib/tls/libnss_files.so.2
Core was generated by `/usr/local/bin/php-cgi -m'.
Program terminated with signal 11, Segmentation fault.
#0 0xb7978db0 in ?? ()
(gdb) bt full
#0 0xb7978db0 in ?? ()
No symbol table info available.
#1 <signal handler called>
No symbol table info available.
#2 0xb7978e00 in ?? ()
No symbol table info available.
#3 0x082ee8e2 in module_destructor (module=0x86ce280) at
/root/root/php-5.2.5/Zend/zend_API.c:1916
No locals.
#4 0x082f4967 in zend_hash_apply_deleter (ht=0x85fd2e0, p=0x86ce250)
at /root/root/php-5.2.5/Zend/zend_hash.c:611
retval = <value optimized out>
#5 0x082f4be7 in zend_hash_graceful_reverse_destroy (ht=0x85fd2e0) at
/root/root/php-5.2.5/Zend/zend_hash.c:646
p = (Bucket *) 0xb7978e00
#6 0x082eb3ae in zend_shutdown () at
/root/root/php-5.2.5/Zend/zend.c:733
No locals.
#7 0x082aba6f in php_module_shutdown () at
/root/root/php-5.2.5/main/main.c:1887
No locals.
#8 0x08365bdf in main (argc=2, argv=0xbff614b4) at
/root/root/php-5.2.5/sapi/cgi/cgi_main.c:2055
sec = <value optimized out>
usec = <value optimized out>
free_query_string = 0
exit_status = 0
cgi = 0
c = <value optimized out>
i = <value optimized out>
len = <value optimized out>
file_handle = {type = 0 '\0', filename = 0x0, opened_path =
0x0, handle = {fd = 0, fp = 0x0, stream = {
handle = 0x0, reader = 0xbff61460, closer = 0xb7ff34f8, fteller =
0x806c723, interactive = 24641422}},
free_filename = 0 '\0'}
retval = <value optimized out>
s = 0x0
behavior = 1
no_headers = 0
orig_optind = 1
orig_optarg = 0x0
script_file = 0x0
ini_entries_len = 0
max_requests = 500
requests = 0
fastcgi = 0
bindpath = 0x0
fcgi_fd = <value optimized out>
request = {listen_socket = 0, fd = 0, id = 0, keep = 0, in_len
= 0, in_pad = 0, out_hdr = 0x0, out_pos = 0x0,
out_buf = '\0' <repeats 4612 times>,
"\200\002°ˇ(\004öżi\220ţˇĎ\024ݎ\214\002°ˇô/˙ˇŕ1˙ˇ\000\000\000\000¨\006öż\2346ţˇĹ\024ݎ¸Vġ",
'\0' <repeats 16 times>, "Ď\024ݎ\000\000\000\000
0˙ˇ", '\0' <repeats 14 times>, "°ˇ", '\0' <repeats 16
times>, "¸Vġ", '\0' <repeats 24 times>,
"\200\002°ˇ°\004öżi\220ţˇ\223\032ąˇ\214\002°ˇô/˙ˇŕ1˙ˇ\000\000\000\0000\aöż\2346ţˇ",
'\0' <repeats 24 times>, "\223\032ąˇ\000\000\000\000
0˙ˇ", '\0' <repeats 12 times>, "¸ü١", '\0' <repeats
40 times>...,
---Type <return> to continue, or q <return> to quit---
reserved = "-smp-19102007-1", env = {nTableSize = 0, nTableMask = 0,
nNumOfElements = 0, nNextFreeElement = 0,
pInternalPointer = 0x0, pListHead = 0x0, pListTail = 0x0, arBuckets
= 0x0, pDestructor = 0x23000000,
persistent = 49 '1', nApplyCount = 32 ' ', bApplyProtection = 83
'S'}}
repeats = 1
benchmark = 0
start = {tv_sec = 134802161, tv_usec = -1208012812}
end = {tv_sec = 140313464, tv_usec = -1074392040}
status = 0
(gdb) up
#1 <signal handler called>
(gdb)
#2 0xb7978e00 in ?? ()
(gdb)
#3 0x082ee8e2 in module_destructor (module=0x86ce280) at
/root/root/php-5.2.5/Zend/zend_API.c:1916
1916 module->module_shutdown_func(module->type,
module->module_number TSRMLS_CC);
(gdb)
#4 0x082f4967 in zend_hash_apply_deleter (ht=0x85fd2e0, p=0x86ce250)
at /root/root/php-5.2.5/Zend/zend_hash.c:611
611 ht->pDestructor(p->pData);
(gdb)
#5 0x082f4be7 in zend_hash_graceful_reverse_destroy (ht=0x85fd2e0) at
/root/root/php-5.2.5/Zend/zend_hash.c:646
646 zend_hash_apply_deleter(ht, p);
(gdb)
#6 0x082eb3ae in zend_shutdown () at
/root/root/php-5.2.5/Zend/zend.c:733
733 zend_hash_graceful_reverse_destroy(&module_registry);
(gdb)
#7 0x082aba6f in php_module_shutdown () at
/root/root/php-5.2.5/main/main.c:1887
1887 zend_shutdown(TSRMLS_C);
(gdb)
#8 0x08365bdf in main (argc=2, argv=0xbff614b4) at
/root/root/php-5.2.5/sapi/cgi/cgi_main.c:2055
2055 php_module_shutdown(TSRMLS_C);
(gdb)
Initial frame selected; you cannot go up.
(gdb)
I dont know what is going on
We have replace all RAM on server today..
Regards,
Piotr
------------------------------------------------------------------------
[2007-11-14 15:14:49] pioklo at serveradmin dot pl
Core was generated by `/usr/local/bin/php-cgi'.
Program terminated with signal 11, Segmentation fault.
#0 _zend_mm_free_int (heap=0x85fe120, p=<value optimized out>) at
/root/root/php-5.2.5/Zend/zend_alloc.c:1944
1944 if (ZEND_MM_IS_FREE_BLOCK(next_block)) {
(gdb) bt
#0 _zend_mm_free_int (heap=0x85fe120, p=<value optimized out>) at
/root/root/php-5.2.5/Zend/zend_alloc.c:1944
#1 0x082b408b in sapi_deactivate () at
/root/root/php-5.2.5/main/SAPI.c:445
#2 0x082ac205 in php_request_shutdown (dummy=0x0) at
/root/root/php-5.2.5/main/main.c:1494
#3 0x083666b7 in main (argc=1, argv=0xbfdbe404) at
/root/root/php-5.2.5/sapi/cgi/cgi_main.c:1972
(gdb) bt full
#0 _zend_mm_free_int (heap=0x85fe120, p=<value optimized out>) at
/root/root/php-5.2.5/Zend/zend_alloc.c:1944
mm_block = (zend_mm_block *) 0xb7a1d264
next_block = (zend_mm_block *) 0x24033fd4
size = 1818324336
#1 0x082b408b in sapi_deactivate () at
/root/root/php-5.2.5/main/SAPI.c:445
No locals.
#2 0x082ac205 in php_request_shutdown (dummy=0x0) at
/root/root/php-5.2.5/main/main.c:1494
__bailout = {{__jmpbuf = {140495672, 141680200, 0, -1076117416,
-1076117616, 137019746}, __mask_was_saved = 0,
__saved_mask = {__val = {141694888, 3080939744, 3218849788,
3081418205, 3082261752, 141658448, 8, 9, 392, 4096,
3218849820, 3082256372, 0, 0, 0, 3082256372, 3082261696,
3080679456, 3218849848, 3081444831, 3082261696, 57,
3082256372, 57, 3080679456, 3218849880, 3081459254, 141658456,
3080679456, 57, 141658456, 141680200}}}}
report_memleaks = 1 '\001'
#3 0x083666b7 in main (argc=1, argv=0xbfdbe404) at
/root/root/php-5.2.5/sapi/cgi/cgi_main.c:1972
path_translated = 0x8718958
"/home/admin/domains/poszkole.pl/public_html/beta/gry.php"
free_query_string = 0
exit_status = 0
cgi = <value optimized out>
c = <value optimized out>
i = <value optimized out>
len = <value optimized out>
file_handle = {type = 2 '\002',
filename = 0xb79f7020
"\204jĄˇe/admin/domains/poszkole.pl/public_html/beta/gry.php",
opened_path = 0x0, handle = {
fd = 141694888, fp = 0x87217a8, stream = {handle = 0x87217a8,
reader = 0xbfdbe3b0, closer = 0xb7f3c4f8,
fteller = 0x806c723, interactive = 24641422}}, free_filename = 0
'\0'}
retval = <value optimized out>
s = 0x0
behavior = 1
no_headers = 0
orig_optind = 1
orig_optarg = 0x0
script_file = 0x0
ini_entries_len = <value optimized out>
max_requests = 50000
requests = 322
fastcgi = 1
bindpath = 0x0
fcgi_fd = <value optimized out>
request = {listen_socket = 0, fd = 7, id = 1, keep = 1, in_len
= 0, in_pad = 0, out_hdr = 0x0,
out_pos = 0xbfdbc154 "\001\006",
out_buf = "\001\006\000\001\r\v\005\000\n\t\t\t\n\t\t</div>\n\t\t<div
class=\"block right goog\">\n\t\t\t<script
type=\"text/javascript\"><!--\r\ngoogle_ad_client =
\"pub-4042275753879057\";\r\ngoogle_ad_width = 120;\r\ngoogle_ad_height
= 600;\r\ngoogle_ad_fo"..., reserved = '\0' <repeats 15 times>, env =
{nTableSize = 32, nTableMask = 31, nNumOfElements = 28,
nNextFreeElement = 0, pInternalPointer = 0x85fe370, pListHead =
0x85fe370, pListTail = 0x8713000,
arBuckets = 0x8721a20, pDestructor = 0x83631a0 <fcgi_free_var>,
persistent = 1 '\001', nApplyCount = 0 '\0',
bApplyProtection = 1 '\001'}}
repeats = 1
---Type <return> to continue, or q <return> to quit---
benchmark = 0
start = {tv_sec = 134802161, tv_usec = -1208762380}
end = {tv_sec = 140313464, tv_usec = -1076108440}
status = 0
(gdb) up
#1 0x082b408b in sapi_deactivate () at
/root/root/php-5.2.5/main/SAPI.c:445
445 efree(SG(sapi_headers).mimetype);
(gdb) up
#2 0x082ac205 in php_request_shutdown (dummy=Cannot access memory at
address 0x8
) at /root/root/php-5.2.5/main/main.c:1494
1494 sapi_deactivate(TSRMLS_C);
(gdb) up
#3 0x083666b7 in main (argc=0, argv=0x0) at
/root/root/php-5.2.5/sapi/cgi/cgi_main.c:1972
1972 php_request_shutdown((void *) 0);
(gdb)
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
http://bugs.php.net/43295
--
Edit this bug report at http://bugs.php.net/?id=43295&edit=1