Bug 47070 - Segmentation fault in ap_rflush
Summary: Segmentation fault in ap_rflush
Status: RESOLVED INVALID
Alias: None
Product: Apache httpd-1.3
Classification: Unclassified
Component: core (show other bugs)
Version: 1.3.41
Hardware: PC FreeBSD
: P2 normal (vote)
Target Milestone: ---
Assignee: Apache HTTPD Bugs Mailing List
URL:
Keywords:
Depends on:
Blocks:
 
Reported: 2009-04-21 22:50 UTC by kostjn
Modified: 2009-04-21 23:56 UTC (History)
0 users



Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description kostjn 2009-04-21 22:50:15 UTC
I`m get crash apache.
Backtrace 
GNU gdb 6.1.1 [FreeBSD]
Copyright 2004 Free Software Foundation, Inc.
GDB is free software, covered by the GNU General Public License, and you are
welcome to change it and/or distribute copies of it under certain conditions.
Type "show copying" to see the conditions.
There is absolutely no warranty for GDB.  Type "show warranty" for details.
This GDB was configured as "i386-marcel-freebsd"...

warning: exec file is newer than core file.
Core was generated by `httpd'.
Program terminated with signal 11, Segmentation fault.
Reading symbols from /lib/libcrypt.so.3...done.
Loaded symbols for /lib/libcrypt.so.3
Reading symbols from /usr/local/lib/libexpat.so.6...done.
Loaded symbols for /usr/local/lib/libexpat.so.6
Reading symbols from /lib/libutil.so.5...done.
Loaded symbols for /lib/libutil.so.5
Reading symbols from /usr/local/lib/libsqlite3.so.8...done.
Loaded symbols for /usr/local/lib/libsqlite3.so.8
Reading symbols from /lib/libc.so.6...done.
Loaded symbols for /lib/libc.so.6
Reading symbols from /usr/local/libexec/apache/mod_env.so...done.
Loaded symbols for /usr/local/libexec/apache/mod_env.so
Reading symbols from /usr/local/libexec/apache/mod_log_config.so...done.
Loaded symbols for /usr/local/libexec/apache/mod_log_config.so
Reading symbols from /usr/local/libexec/apache/mod_mime_magic.so...done.
Loaded symbols for /usr/local/libexec/apache/mod_mime_magic.so
Reading symbols from /usr/local/libexec/apache/mod_mime.so...done.
Loaded symbols for /usr/local/libexec/apache/mod_mime.so
Reading symbols from /usr/local/libexec/apache/mod_negotiation.so...done.
Loaded symbols for /usr/local/libexec/apache/mod_negotiation.so
Reading symbols from /usr/local/libexec/apache/mod_status.so...done.
Loaded symbols for /usr/local/libexec/apache/mod_status.so
Reading symbols from /usr/local/libexec/apache/mod_info.so...done.
Loaded symbols for /usr/local/libexec/apache/mod_info.so
Reading symbols from /usr/local/libexec/apache/mod_include.so...done.
Loaded symbols for /usr/local/libexec/apache/mod_include.so
Reading symbols from /usr/local/libexec/apache/mod_autoindex.so...done.
Loaded symbols for /usr/local/libexec/apache/mod_autoindex.so
Reading symbols from /usr/local/libexec/apache/mod_dir.so...done.
Loaded symbols for /usr/local/libexec/apache/mod_dir.so
Reading symbols from /usr/local/libexec/apache/mod_cgi.so...done.
Loaded symbols for /usr/local/libexec/apache/mod_cgi.so
Reading symbols from /usr/local/libexec/apache/mod_actions.so...done.
Loaded symbols for /usr/local/libexec/apache/mod_actions.so
Reading symbols from /usr/local/libexec/apache/mod_speling.so...done.
Loaded symbols for /usr/local/libexec/apache/mod_speling.so
Reading symbols from /usr/local/libexec/apache/mod_alias.so...done.
Loaded symbols for /usr/local/libexec/apache/mod_alias.so
Reading symbols from /usr/local/libexec/apache/mod_rewrite.so...done.
Loaded symbols for /usr/local/libexec/apache/mod_rewrite.so
Reading symbols from /usr/local/libexec/apache/mod_access.so...done.
Loaded symbols for /usr/local/libexec/apache/mod_access.so
Reading symbols from /usr/local/libexec/apache/mod_auth.so...done.
Loaded symbols for /usr/local/libexec/apache/mod_auth.so
Reading symbols from /usr/local/libexec/apache/mod_expires.so...done.
Loaded symbols for /usr/local/libexec/apache/mod_expires.so
Reading symbols from /usr/local/libexec/apache/mod_headers.so...done.
Loaded symbols for /usr/local/libexec/apache/mod_headers.so
Reading symbols from /usr/local/libexec/apache/mod_setenvif.so...done.
Loaded symbols for /usr/local/libexec/apache/mod_setenvif.so
Reading symbols from /usr/local/libexec/apache/libphp5.so...done.
Loaded symbols for /usr/local/libexec/apache/libphp5.so
Reading symbols from /usr/lib/libssl.so.4...done.
Loaded symbols for /usr/lib/libssl.so.4
Reading symbols from /lib/libcrypto.so.4...done.
Loaded symbols for /lib/libcrypto.so.4
Reading symbols from /lib/libm.so.4...done.
Loaded symbols for /lib/libm.so.4
Reading symbols from /usr/local/lib/libxml2.so.5...done.
Loaded symbols for /usr/local/lib/libxml2.so.5
Reading symbols from /lib/libz.so.3...done.
Loaded symbols for /lib/libz.so.3
Reading symbols from /usr/local/lib/libiconv.so.3...done.
Loaded symbols for /usr/local/lib/libiconv.so.3
Reading symbols from /usr/local/libexec/apache/mod_extract_forwarded.so...done.
Loaded symbols for /usr/local/libexec/apache/mod_extract_forwarded.so
Reading symbols from /usr/local/php5/lib/php/20060613/ZendExtensionManager.so...done.
Loaded symbols for /usr/local/php5/lib/php/20060613/ZendExtensionManager.so
Reading symbols from /usr/local/php5/lib/php/20060613/bcmath.so...done.
Loaded symbols for /usr/local/php5/lib/php/20060613/bcmath.so
Reading symbols from /usr/local/php5/lib/php/20060613/bz2.so...done.
Loaded symbols for /usr/local/php5/lib/php/20060613/bz2.so
Reading symbols from /usr/lib/libbz2.so.2...done.
Loaded symbols for /usr/lib/libbz2.so.2
Reading symbols from /usr/local/php5/lib/php/20060613/calendar.so...done.
Loaded symbols for /usr/local/php5/lib/php/20060613/calendar.so
Reading symbols from /usr/local/php5/lib/php/20060613/ctype.so...done.
Loaded symbols for /usr/local/php5/lib/php/20060613/ctype.so
Reading symbols from /usr/local/php5/lib/php/20060613/curl.so...done.
Loaded symbols for /usr/local/php5/lib/php/20060613/curl.so
Reading symbols from /usr/local/lib/libcurl.so.5...done.
Loaded symbols for /usr/local/lib/libcurl.so.5
Reading symbols from /usr/local/php5/lib/php/20060613/dba.so...done.
Loaded symbols for /usr/local/php5/lib/php/20060613/dba.so
Reading symbols from /usr/local/php5/lib/php/20060613/dbase.so...done.
Loaded symbols for /usr/local/php5/lib/php/20060613/dbase.so
Reading symbols from /usr/local/php5/lib/php/20060613/dom.so...done.
Loaded symbols for /usr/local/php5/lib/php/20060613/dom.so
Reading symbols from /usr/local/php5/lib/php/20060613/exif.so...done.
Loaded symbols for /usr/local/php5/lib/php/20060613/exif.so
Reading symbols from /usr/local/php5/lib/php/20060613/ftp.so...done.
Loaded symbols for /usr/local/php5/lib/php/20060613/ftp.so
Reading symbols from /usr/local/php5/lib/php/20060613/gd.so...done.
Loaded symbols for /usr/local/php5/lib/php/20060613/gd.so
Reading symbols from /usr/local/lib/libt1.so.5...done.
Loaded symbols for /usr/local/lib/libt1.so.5
Reading symbols from /usr/local/lib/libfreetype.so.9...done.
Loaded symbols for /usr/local/lib/libfreetype.so.9
Reading symbols from /usr/local/lib/libpng.so.5...done.
Loaded symbols for /usr/local/lib/libpng.so.5
Reading symbols from /usr/local/lib/libjpeg.so.9...done.
Loaded symbols for /usr/local/lib/libjpeg.so.9
Reading symbols from /usr/local/php5/lib/php/20060613/gettext.so...done.
Loaded symbols for /usr/local/php5/lib/php/20060613/gettext.so
Reading symbols from /usr/local/lib/libintl.so.8...done.
Loaded symbols for /usr/local/lib/libintl.so.8
Reading symbols from /usr/local/php5/lib/php/20060613/iconv.so...done.
Loaded symbols for /usr/local/php5/lib/php/20060613/iconv.so
Reading symbols from /usr/local/php5/lib/php/20060613/mbstring.so...done.
Loaded symbols for /usr/local/php5/lib/php/20060613/mbstring.so
Reading symbols from /usr/local/php5/lib/php/20060613/mcrypt.so...done.
Loaded symbols for /usr/local/php5/lib/php/20060613/mcrypt.so
Reading symbols from /usr/local/lib/libmcrypt.so.8...done.
Loaded symbols for /usr/local/lib/libmcrypt.so.8
Reading symbols from /usr/local/lib/libltdl.so.4...done.
Loaded symbols for /usr/local/lib/libltdl.so.4
Reading symbols from /usr/local/php5/lib/php/20060613/mhash.so...done.
Loaded symbols for /usr/local/php5/lib/php/20060613/mhash.so
Reading symbols from /usr/local/lib/libmhash.so.2...done.
Loaded symbols for /usr/local/lib/libmhash.so.2
Reading symbols from /usr/local/php5/lib/php/20060613/mysql.so...done.
Loaded symbols for /usr/local/php5/lib/php/20060613/mysql.so
Reading symbols from /usr/local/lib/mysql/libmysqlclient.so.14...done.
Loaded symbols for /usr/local/lib/mysql/libmysqlclient.so.14
Reading symbols from /usr/local/php5/lib/php/20060613/zlib.so...done.
Loaded symbols for /usr/local/php5/lib/php/20060613/zlib.so
Reading symbols from /usr/local/php5/lib/php/20060613/pdo.so...done.
Loaded symbols for /usr/local/php5/lib/php/20060613/pdo.so
Reading symbols from /usr/local/php5/lib/php/20060613/pdo_sqlite.so...done.
Loaded symbols for /usr/local/php5/lib/php/20060613/pdo_sqlite.so
Reading symbols from /usr/local/php5/lib/php/20060613/pdo_mysql.so...done.
Loaded symbols for /usr/local/php5/lib/php/20060613/pdo_mysql.so
Reading symbols from /usr/local/php5/lib/php/20060613/posix.so...done.
Loaded symbols for /usr/local/php5/lib/php/20060613/posix.so
Reading symbols from /usr/local/php5/lib/php/20060613/readline.so...done.
Loaded symbols for /usr/local/php5/lib/php/20060613/readline.so
Reading symbols from /usr/lib/libhistory.so.6...done.
Loaded symbols for /usr/lib/libhistory.so.6
Reading symbols from /lib/libreadline.so.6...done.
Loaded symbols for /lib/libreadline.so.6
Reading symbols from /lib/libncurses.so.6...done.
Loaded symbols for /lib/libncurses.so.6
Reading symbols from /usr/local/php5/lib/php/20060613/session.so...done.
Loaded symbols for /usr/local/php5/lib/php/20060613/session.so
Reading symbols from /usr/local/php5/lib/php/20060613/simplexml.so...done.
Loaded symbols for /usr/local/php5/lib/php/20060613/simplexml.so
Reading symbols from /usr/local/php5/lib/php/20060613/soap.so...done.
Loaded symbols for /usr/local/php5/lib/php/20060613/soap.so
Reading symbols from /usr/local/php5/lib/php/20060613/sockets.so...done.
Loaded symbols for /usr/local/php5/lib/php/20060613/sockets.so
Reading symbols from /usr/local/php5/lib/php/20060613/spl.so...done.
Loaded symbols for /usr/local/php5/lib/php/20060613/spl.so
Reading symbols from /usr/local/php5/lib/php/20060613/tokenizer.so...done.
Loaded symbols for /usr/local/php5/lib/php/20060613/tokenizer.so
Reading symbols from /usr/local/php5/lib/php/20060613/xml.so...done.
Loaded symbols for /usr/local/php5/lib/php/20060613/xml.so
Reading symbols from /usr/local/php5/lib/php/20060613/wddx.so...done.
Loaded symbols for /usr/local/php5/lib/php/20060613/wddx.so
Reading symbols from /usr/local/php5/lib/php/20060613/xmlreader.so...done.
Loaded symbols for /usr/local/php5/lib/php/20060613/xmlreader.so
Reading symbols from /usr/local/php5/lib/php/20060613/xmlrpc.so...done.
Loaded symbols for /usr/local/php5/lib/php/20060613/xmlrpc.so
Reading symbols from /usr/local/php5/lib/php/20060613/xmlwriter.so...done.
Loaded symbols for /usr/local/php5/lib/php/20060613/xmlwriter.so
Reading symbols from /usr/local/php5/lib/php/20060613/xsl.so...done.
Loaded symbols for /usr/local/php5/lib/php/20060613/xsl.so
Reading symbols from /usr/local/lib/libexslt.so.8...done.
Loaded symbols for /usr/local/lib/libexslt.so.8
Reading symbols from /usr/local/lib/libxslt.so.2...done.
Loaded symbols for /usr/local/lib/libxslt.so.2
Reading symbols from /usr/local/php5/lib/php/20060613/zip.so...done.
Loaded symbols for /usr/local/php5/lib/php/20060613/zip.so
Reading symbols from /usr/local/php5/lib/php/20060613/mysqli.so...done.
Loaded symbols for /usr/local/php5/lib/php/20060613/mysqli.so
Reading symbols from /usr/local/php5/lib/php/20060613/hash.so...done.
Loaded symbols for /usr/local/php5/lib/php/20060613/hash.so
Reading symbols from /usr/local/php5/lib/php/20060613/json.so...done.
Loaded symbols for /usr/local/php5/lib/php/20060613/json.so
Reading symbols from /usr/local/php5/lib/php/20060613/eaccelerator.so...done.
Loaded symbols for /usr/local/php5/lib/php/20060613/eaccelerator.so
Reading symbols from /usr/local/php5/lib/php/20060613/Optimizer/php-5.2.x/ZendOptimizer.so...done.
Loaded symbols for /usr/local/php5/lib/php/20060613/Optimizer/php-5.2.x/ZendOptimizer.so
Reading symbols from /libexec/ld-elf.so.1...done.
Loaded symbols for /libexec/ld-elf.so.1
#0  ap_rflush (r=0x842a3bc) at http_protocol.c:2824
2824	http_protocol.c: No such file or directory.
	in http_protocol.c
(gdb) btfull
Undefined command: "btfull".  Try "help".
(gdb) bt full
#0  ap_rflush (r=0x842a3bc) at http_protocol.c:2824
No locals.
#1  0x383d9474 in sapi_flush () at /home/subadm/ports/lang/php5/work/php-5.2.8/main/SAPI.c:922
No locals.
#2  0x383d3102 in php_module_shutdown () at /home/subadm/ports/lang/php5/work/php-5.2.8/main/main.c:1904
No locals.
#3  0x383d31bb in php_module_shutdown_wrapper (sapi_globals=0x385329c0)
    at /home/subadm/ports/lang/php5/work/php-5.2.8/main/main.c:1877
No locals.
#4  0x08053ff3 in ap_child_exit_modules (p=0x841d00c, s=0x808d034) at http_config.c:1637
	m = (module *) 0x38532880
#5  0x0805945d in clean_child_exit (code=0) at http_main.c:546
No locals.
#6  0x0805a91b in child_main (child_num_arg=138580020) at http_main.c:4927
	conn_io = (BUFF *) 0x8
	r = (request_rec *) 0xc3
	clen = 16
	sa_server = {sa_len = 16 '\020', sa_family = 2 '\002', 
  sa_data = "\000P\177\000\000\001\000\000\000\000\000\000\000"}
	sa_client = {sa_len = 16 '\020', sa_family = 2 '\002', 
  sa_data = "Т\037\177\000\000\001\000\000\000\000\000\000\000"}
#7  0x0805ae77 in make_child (s=0x1e, slot=123, now=944275504) at http_main.c:5071
	pid = 0
#8  0x0805c2d6 in standalone_main (argc=0, argv=0x38488030) at http_main.c:5272
	ps = (parent_score *) 0x1
	remaining_children_to_start = 0
#9  0x0805cd10 in main (argc=1, argv=0xbfbfeca0) at http_main.c:5795
	c = 0
	sock_in = -1077941088
	sock_out = 940043145
	s = 0x0

-------------------------------------------------------------------------
uname -a
FreeBSD point.z8.ru 6.4-RELEASE-p3 FreeBSD 6.4-RELEASE-p3 #0: Mon Mar 23 15:01:39 MSK 2009     root@build.pht:/usr/src/sys/i386/compile/VH_6.4_32_01  i386
-------------------------------------------------------------------------
/usr/local/sbin/httpd -V
Server version: Apache/1.3.41 (Unix)
Server built:   Apr 21 2009 09:35:38
Server's Module Magic Number: 19990320:18
Server compiled with....
 -D BIG_SECURITY_HOLE
 -D HAVE_MMAP
 -D USE_MMAP_SCOREBOARD
 -D USE_MMAP_FILES
 -D HAVE_FLOCK_SERIALIZED_ACCEPT
 -D SINGLE_LISTEN_UNSERIALIZED_ACCEPT
 -D DYNAMIC_MODULE_LIMIT=64
 -D HARD_SERVER_LIMIT=512
 -D SO_ACCEPTFILTER
 -D ACCEPT_FILTER_NAME="httpready"
 -D HTTPD_ROOT="/usr/local"
 -D SUEXEC_BIN="/usr/local/sbin/suexec"
 -D DEFAULT_PIDLOG="/var/run/httpd.pid"
 -D DEFAULT_SCOREBOARD="/var/run/httpd.scoreboard"
 -D DEFAULT_LOCKFILE="/var/run/httpd.lock"
 -D DEFAULT_ERRORLOG="/var/log/httpd-error.log"
 -D TYPES_CONFIG_FILE="etc/apache/mime.types"
 -D SERVER_CONFIG_FILE="etc/apache/httpd.conf"
 -D ACCESS_CONFIG_FILE="etc/apache/access.conf"
 -D RESOURCE_CONFIG_FILE="etc/apache/srm.conf"
------------------------------------------------------------
I`m write simple patch to avoid this problem

--- /usr/ports/www/apache13/work/apache_1.3.41/src/main/http_protocol.c	2006-07-12 12:16:05.000000000 +0400
+++ ./src/main/http_protocol.c	2009-04-21 09:33:44.000000000 +0400
@@ -2820,6 +2820,9 @@
 
 API_EXPORT(int) ap_rflush(request_rec *r)
 {
+	if (r->connection == NULL){
+		return EOF;
+	}
     if (ap_bflush(r->connection->client) < 0) {
         if (!r->connection->aborted) {
             ap_log_rerror(APLOG_MARK, APLOG_INFO, r,
Comment 1 Nick Kew 2009-04-21 23:56:19 UTC
Your traceback shows ap_rflush being called during shutdown.  There is no valid request_rec, so of course it segfaults.  The bug is in the caller, which is PHP.