From: victork at sekindo dot com
Operating system: Linux(CentOS 5)
PHP version: 5.4.21
Package: MySQLi related
Bug Type: Bug
Bug description:Segfault calling bind_param() on mysqli
Description:
------------
Full problem description:
Calling mysql_stmt::bind_result() without storing it's result value in a
variable on PHP using MySQLi module built against libmysl causing
segmentation fault.
Notes:
If my mysqli is linked against libmysqlng no crashing occurs
If PHP debugger module(Like XDebug or Nusphere DBG) is active no
crashing occurs(Looks like a timing issue ...)
If return value of mysql_stmt::bind_result() is stored($res =
$stmt->bind_result(&$name);) no crashing occurs.
PHP code(Zend/zend_vm_execute.h)
if (fbc->type == ZEND_INTERNAL_FUNCTION) { <---- For internal PHP
routines
....
if (!zend_execute_internal) {
553 /* saves one function call if
zend_execute_internal is not used */
554
fbc->internal_function.handler(opline->extended_value, ret->var.ptr,
&ret->var.ptr, EX(object), RETURN_VALUE_USED(opline) TSRMLS_CC);
555 } else {
556 zend_execute_internal(execute_data,
NULL, RETURN_VALUE_USED(opline) TSRMLS_CC);
557 }
558
559 if (!RETURN_VALUE_USED(opline)) {
[***segfault_560]
zval_ptr_dtor(&ret->var.ptr);
561 }
Tested affected PHP versions: 5.4.20 and 5.4.21
Unaffected PHP version: PHP 5.1.6 with patches and backports from
RedHat/CentOS team.
Short Script To Reproduce(Please read the notes above):
php -r '$link = new mysqli("127.0.0.1", "root", "ew89sjw0aj",
"mysql");
$stmt = $link->stmt_init();$stmt->prepare("SELECT User FROM user WHERE
password=\"\"");$stmt->execute(); $stmt->bind_result($testArg);
$stmt->fetch(); $stmt->close(); echo $testArg;'
If query like "SELECT 10" is used(Without tables) no crashing occurs.
PHP configuration(IUS repository package):
'./configure' '--build=x86_64-redhat-linux-gnu'
'--host=x86_64-redhat-linux-gnu' '--target=x86_64-redhat-linux-gnu'
'--program-prefix=' '--prefix=/usr' '--exec-prefix=/usr'
'--bindir=/usr/bin' '--sbindir=/usr/sbin' '--sysconfdir=/etc'
'--datadir=/usr/share' '--includedir=/usr/include'
'--libdir=/usr/lib64'
'--libexecdir=/usr/libexec' '--localstatedir=/var'
'--sharedstatedir=/usr/com' '--mandir=/usr/share/man'
'--infodir=/usr/share/info' '--cache-file=../config.cache'
'--with-libdir=lib64' '--with-config-file-path=/etc'
'--with-config-file-scan-dir=/etc/php.d' '--disable-debug'
'--with-pic'
'--disable-rpath' '--without-pear' '--with-bz2'
'--with-exec-dir=/usr/bin' '--with-freetype-dir=/usr'
'--with-png-dir=/usr' '--with-xpm-dir=/usr' '--enable-gd-native-ttf'
'--with-t1lib=/usr' '--without-gdbm' '--with-gettext'
'--with-gmp'
'--with-iconv' '--with-jpeg-dir=/usr' '--with-openssl'
'--with-pcre-regex' '--with-zlib' '--with-layout=GNU'
'--enable-exif'
'--enable-ftp' '--enable-magic-quotes' '--enable-sockets'
'--with-kerberos' '--enable-ucd-snmp-hack' '--enable-shmop'
'--enable-calendar' '--with-libxml-dir=/usr' '--enable-xml'
'--with-system-tzdata' '--with-mhash' '--enable-force-cgi-redirect'
'--libdir=/usr/lib64/php' '--enable-pcntl' '--with-imap=shared'
'--with-imap-ssl' '--enable-mbstring=shared' '--enable-mbregex'
'--with-gd=shared' '--enable-bcmath=shared' '--enable-dba=shared'
'--with-db4=/usr' '--with-xmlrpc=shared' '--with-ldap=shared'
'--with-ldap-sasl' '--enable-mysqlnd=shared'
'--with-mysql=shared,mysqlnd' '--with-mysqli=shared,mysqlnd'
'--with-mysql-sock=/var/lib/mysql/mysql.sock'
'--with-interbase=shared,/usr/lib64/firebird'
'--with-pdo-firebird=shared,/usr/lib64/firebird' '--enable-dom=shared'
'--with-pgsql=shared' '--enable-wddx=shared' '--with-snmp=shared,/usr'
'--enable-soap=shared' '--with-xsl=shared,/usr'
'--enable-xmlreader=shared' '--enable-xmlwriter=shared'
'--with-curl=shared,/usr' '--enable-fastcgi' '--enable-pdo=shared'
'--with-pdo-odbc=shared,unixODBC,/usr' '--with-pdo-mysql=shared,mysqlnd'
'--with-pdo-pgsql=shared,/usr' '--with-pdo-sqlite=shared,/usr'
'--with-pdo-dblib=shared,/usr' '--without-sqlite3'
'--enable-json=shared' '--enable-zip=shared' '--without-readline'
'--with-libedit' '--with-pspell=shared' '--enable-phar=shared'
'--with-mcrypt=shared,/usr' '--with-tidy=shared,/usr'
'--with-mssql=shared,/usr' '--enable-sysvmsg=shared'
'--enable-sysvshm=shared' '--enable-sysvsem=shared'
'--enable-posix=shared' '--with-unixODBC=shared,/usr'
'--enable-fileinfo=shared' '--enable-intl=shared'
'--with-icu-dir=/usr'
'--with-enchant=shared,/usr' '--with-recode=shared,/usr'
All external modules except mysqli has been disabled during testing to
exclude possibility of modules collision(Crashes with all modules and
with only mysqli).
php.ini changes:
Increased limits of POST,memory,etc
Script timeout set to unlimited.
Include path enhanced with our project folder
pre/post autoinclude for xhprof files added.
GDB backtrace and info:
Program received signal SIGSEGV, Segmentation fault.
zend_do_fcall_common_helper_SPEC (execute_data=0x2aaaaaacf060) at
/usr/src/debug/php-5.4.21/Zend/zend_vm_execute.h:649
649 zval_ptr_dtor(&ret->var.ptr);
(gdb) bt
#0 zend_do_fcall_common_helper_SPEC (execute_data=0x2aaaaaacf060) at
/usr/src/debug/php-5.4.21/Zend/zend_vm_execute.h:649
#1 0x000000000060a9de in execute (op_array=0x2aaaaab05ec0) at
/usr/src/debug/php-5.4.21/Zend/zend_vm_execute.h:410
#2 0x00000000005d565e in zend_execute_scripts (type=8, retval=0x0,
file_count=3) at /usr/src/debug/php-5.4.21/Zend/zend.c:1319
#3 0x000000000057af48 in php_execute_script
(primary_file=0x7fffffffd6d0) at
/usr/src/debug/php-5.4.21/main/main.c:2502
#4 0x000000000067d06d in do_cli (argc=2, argv=0x7fffffffea08) at
/usr/src/debug/php-5.4.21/sapi/cli/php_cli.c:989
#5 0x000000000067d9ed in main (argc=2, argv=0x7fffffffea08) at
/usr/src/debug/php-5.4.21/sapi/cli/php_cli.c:1365
(gdb) print &ret->var.ptr
$1 = (zval **) 0x2aaa00000008
(gdb) print ret->var.ptr
Cannot access memory at address 0x2aaa00000008
Test script:
---------------
php -r '$link = new mysqli("127.0.0.1", "root", "ew89sjw0aj",
"mysql");
$stmt = $link->stmt_init();$stmt->prepare("SELECT User FROM user WHERE
password=\"\"");$stmt->execute(); $stmt->bind_result($testArg);
$stmt->fetch(); $stmt->close(); echo $testArg;'
Expected result:
----------------
root
Actual result:
--------------
Segmentation fault
--
Edit bug report at https://bugs.php.net/bug.php?id=66043&edit=1
--
Try a snapshot (PHP 5.4): https://bugs.php.net/fix.php?id=66043&r=trysnapshot54
Try a snapshot (PHP 5.5): https://bugs.php.net/fix.php?id=66043&r=trysnapshot55
Try a snapshot (trunk): https://bugs.php.net/fix.php?id=66043&r=trysnapshottrunk
Fixed in SVN: https://bugs.php.net/fix.php?id=66043&r=fixed
Fixed in release: https://bugs.php.net/fix.php?id=66043&r=alreadyfixed
Need backtrace: https://bugs.php.net/fix.php?id=66043&r=needtrace
Need Reproduce Script: https://bugs.php.net/fix.php?id=66043&r=needscript
Try newer version: https://bugs.php.net/fix.php?id=66043&r=oldversion
Not developer issue: https://bugs.php.net/fix.php?id=66043&r=support
Expected behavior: https://bugs.php.net/fix.php?id=66043&r=notwrong
Not enough info: https://bugs.php.net/fix.php?id=66043&r=notenoughinfo
Submitted twice: https://bugs.php.net/fix.php?id=66043&r=submittedtwice
register_globals: https://bugs.php.net/fix.php?id=66043&r=globals
PHP 4 support discontinued: https://bugs.php.net/fix.php?id=66043&r=php4
Daylight Savings: https://bugs.php.net/fix.php?id=66043&r=dst
IIS Stability: https://bugs.php.net/fix.php?id=66043&r=isapi
Install GNU Sed: https://bugs.php.net/fix.php?id=66043&r=gnused
Floating point limitations: https://bugs.php.net/fix.php?id=66043&r=float
No Zend Extensions: https://bugs.php.net/fix.php?id=66043&r=nozend
MySQL Configuration Error: https://bugs.php.net/fix.php?id=66043&r=mysqlcfg