zend_signal_handler_defer crashes on apache shutdown #10015
Description
Activity
Indeed, possibly a duplicate of https://bugs.php.net/bug.php?id=78619.
Anyhow, since PHP 8.0 is no longer actively supported, does this happen on PHP 8.1 too?
- added and removed
on Nov 28, 2022 Might also be related to #8789.
I can reproduce it with PHP 8.1 too. It's actually very easy:
cp /etc/apache2/2.4/samples-conf.d/php8.1.conf /etc/apache2/2.4/conf.d/ /usr/apache2/2.4/bin/apachectl start cat > /var/apache2/2.4/htdocs/phpinfo.php <<EOF <?php phpinfo(); ?> EOF wget localhost/phpinfo.php& /usr/apache2/2.4/bin/apachectl graceful# cat /var/apache2/2.4/logs/error_log [Thu Dec 01 15:05:16.261105 2022] [mpm_event:notice] [pid 7077:tid 1] AH00489: Apache/2.4.54 (Unix) PHP/8.1.9 configured -- resuming normal operations [Thu Dec 01 15:05:16.261856 2022] [core:notice] [pid 7077:tid 1] AH00094: Command line: '/usr/apache2/2.4/bin/httpd' [Thu Dec 01 15:05:25.824091 2022] [mpm_event:notice] [pid 7077:tid 1] AH00493: SIGUSR1 received. Doing graceful restart [Thu Dec 01 15:05:25.880343 2022] [mpm_event:notice] [pid 7077:tid 1] AH00489: Apache/2.4.54 (Unix) PHP/8.1.9 configured -- resuming normal operations [Thu Dec 01 15:05:25.880432 2022] [core:notice] [pid 7077:tid 1] AH00094: Command line: '/usr/apache2/2.4/bin/httpd' [Thu Dec 01 15:05:32.888902 2022] [core:notice] [pid 7077:tid 1] AH00051: child pid 7079 exit signal Segmentation fault (11), possible coredump in /usr/apache2/2.4Reacted by Christoph M. BeckerSeems to be the same issue as #9649: the signal is delivered to a thread that didn't execute PHP yet. It crashes when
zend_signal_handler_deferaccess thread globals.0x00007f338867185e in zend_signal_handler_defer (signo=1, siginfo=0x7f3341ffa0b0, context=0x7f3341ff9f80) at /php-src/Zend/zend_signal.c:96 96 if (EXPECTED(SIGG(active))) { (gdb) bt #0 0x00007f338867185e in zend_signal_handler_defer (signo=1, siginfo=0x7f3341ffa0b0, context=0x7f3341ff9f80) at /php-src/Zend/zend_signal.c:96 #1 <signal handler called> #2 0x00007f338961cfde in epoll_wait (epfd=8, events=0x7f33889a9620, maxevents=52, timeout=5000) at ../sysdeps/unix/sysv/linux/epoll_wait.c:30 #3 0x00007f33897476b0 in ?? () from /lib/x86_64-linux-gnu/libapr-1.so.0 #4 0x00007f3389383be8 in ?? () from /usr/lib/apache2/modules/mod_mpm_event.so #5 0x00007f338958bb43 in start_thread (arg=<optimized out>) at ./nptl/pthread_create.c:442 #6 0x00007f338961da00 in clone3 () at ../sysdeps/unix/sysv/linux/x86_64/clone3.S:81 (gdb) list 91 zend_signal_handler(signo, siginfo, context); 92 return; 93 } 94 #endif 95 96 if (EXPECTED(SIGG(active))) { 97 if (UNEXPECTED(SIGG(depth) == 0)) { /* try to handle signal */ 98 if (UNEXPECTED(SIGG(blocked))) { 99 SIGG(blocked) = 0; 100 }
This has been fixed in master by #9766, however in hindsight this may not be ideal in this context.
Reacted by Christoph M. Becker- added a commit that references this issue
on Jan 14, 2023 This has been fixed in master by #9766, however in hindsight this may not be ideal in this context.
I have applied above pull request and I indeed cannot reproduce the issue (with PHP 8.2).
Will this be back ported to versions 8.1 and 8.2?
Description
Core dump is generated during Apache shutdown.
Seems to be the same incarnation of:
https://bugs.php.net/bug.php?id=78619
This time on Solaris:
PHP Version
PHP 8.0
Operating System
Solaris 11.4