Bug #68276 [NEW]: Reproducible memory corruption: pgsql conflicts with openssl extension
| From: | dmitry dot koterov at gmail dot com | Date: | Tue, 21 Oct 2014 14:38:47 +0000 |
| Subject: | Bug #68276 [NEW]: Reproducible memory corruption: pgsql conflicts with openssl extension | ||
| Groups: | php.bugs | ||
| Request: | Send a blank email to php-bugs+get-188228@lists.php.net to get a copy of this message | ||
From: dmitry dot koterov at gmail dot com
Operating system: Ubuntu 14
PHP version: 5.5.18
Package: PostgreSQL related
Bug Type: Bug
Bug description:Reproducible memory corruption: pgsql conflicts with openssl extension
Description:
------------
Long story short: pgsql extension does not call libpg's PQinitSSL nor
PQinitOpenSSL inside itself, though it is REQUIRED by libpq if OpenSSL
is used elsewhere (e.g. in "openssl" PHP extension).
When openssl & pgsql extensions are used in the same script, php process
sometimes crashes with a coredump (rarely reproducible). The core file
shows an access violation in pgsql extension (at
"efree(notice->message);" line), but the bug is caused NOT by this code,
it is caused by a deep memory corruption which influences the above code
(one of such influences).
I've found a 100% reproducible case for this bug, but with a bit
different result. See the test script below: if you run it in a x86_64
machine, PHP 5.3 or 5.4+, PostgreSQL 9.1 or 9.3+ (at least), you see a
strange error message.
If you play with the test buffer size (decrease it from 160K to e.g.
10K), the problem disappears. If no openssl extension is used (just
remove the call to "openssl_pkey_get_public"), the problem disappears as
well.
Why do I suspect that the problem is in the pgsql extension code?
Because pgsql extension does not call PQinitSSL nor PQinitOpenSSL from
libpg, but libpq requires these calls if it is used in an environment
which already uses OpenSSL library: according to
http://www.postgresql.org/docs/9.1/static/libpq-ssl.html
"If your
application initializes libssl and/or libcrypto libraries and libpq is
built with SSL support, you should call PQinitOpenSSL to tell libpq that
the libssl and/or libcrypto libraries have been initialized by your
application, so that libpq will not also initialize those libraries."
P.S.
Here is the same-looking note from 2009:
http://linux.m2osw.com/postgresql_openssl_conflict
Test script:
---------------
<?php
// su - postgres -c psql
// # create database test;
// # create role test with password 'test' login;
// Also be sure that ssl=true is set in postgresql.conf!
$sql = "SELECT repeat('a', 160000)";
$c = pg_connect("host='127.0.0.1' dbname='test' user='test'
password='test' sslmode='require'");
$r = openssl_pkey_get_public('a');
if ($r = pg_query($sql)) echo "OK\n"; else echo pg_last_error($c);
Expected result:
----------------
OK
Actual result:
--------------
PHP Warning: pg_query(): Query failed: SSL error: no start line in
/root/a.php on line 8
Sometimes (very-very rare) it crashes the php5-fpm process, see a
backtrace for e.g. PHP 5.3 below (I did not test the crash itself at PHP
5.4+, but I tested the "SSL error: no start line" in all PHP versions,
and the roots of these two behaviors are same). Note that there is
nothing wrong with notice->message, it's a memory corruption happened
long time before, and seems this memory corruption spreads over multiple
requests to the same php-fpm process, because the crash is reproduced
more frequently when I run the test script above than when I do not run
it at all.
Program terminated with signal 11, Segmentation fault.
#0 0x00000000006ba1e3 in _zend_mm_free_canary_int (heap=0x2519320,
p=0x73d7f11b0c14b99c) at
/build/buildd/php5-5.3.10/Zend/zend_alloc_canary.c:2086
2086 /build/buildd/php5-5.3.10/Zend/zend_alloc_canary.c: No such file or
directory.
(gdb) bt
#0 0x00000000006ba1e3 in _zend_mm_free_canary_int (heap=0x2519320,
p=0x73d7f11b0c14b99c) at
/build/buildd/php5-5.3.10/Zend/zend_alloc_canary.c:2086
#1 0x00007f8e033a5231 in _php_pgsql_notice_ptr_dtor (ptr=0x2519320) at
/build/buildd/php5-5.3.10/ext/pgsql/pgsql.c:835
#2 0x00000000006a7ed0 in zend_hash_clean (ht=0x7f8e035bb168) at
/build/buildd/php5-5.3.10/Zend/zend_hash.c:761
#3 0x00007f8e033a9dc0 in zm_deactivate_pgsql (type=38900512,
module_number=202684828) at
/build/buildd/php5-5.3.10/ext/pgsql/pgsql.c:1034
#4 0x00000000006a132c in module_registry_cleanup (module=0x2519320) at
/build/buildd/php5-5.3.10/Zend/zend_API.c:2168
#5 0x00000000006a82ac in zend_hash_reverse_apply (ht=0xde83e0,
apply_func=0x6a1310 <module_registry_cleanup>) at
/build/buildd/php5-5.3.10/Zend/zend_hash.c:959
#6 0x000000000069a0f0 in zend_deactivate_modules () at
/build/buildd/php5-5.3.10/Zend/zend.c:939
#7 0x0000000000647105 in php_request_shutdown (dummy=0x2519320) at
/build/buildd/php5-5.3.10/main/main.c:1638
#8 0x000000000042b71c in main (argc=41420936, argv=0x2780628) at
/build/buildd/php5-5.3.10/sapi/fpm/fpm/fpm_main.c:1913
(gdb) up
#1 0x00007f8e033a5231 in _php_pgsql_notice_ptr_dtor (ptr=0x2519320) at
/build/buildd/php5-5.3.10/ext/pgsql/pgsql.c:835
835 efree(notice->message);
--
Edit bug report at https://bugs.php.net/bug.php?id=68276&edit=1
--
Try a snapshot (PHP 5.4): https://bugs.php.net/fix.php?id=68276&r=trysnapshot54
Try a snapshot (PHP 5.5): https://bugs.php.net/fix.php?id=68276&r=trysnapshot55
Try a snapshot (trunk): https://bugs.php.net/fix.php?id=68276&r=trysnapshottrunk
Fixed in SVN: https://bugs.php.net/fix.php?id=68276&r=fixed
Fixed in release: https://bugs.php.net/fix.php?id=68276&r=alreadyfixed
Need backtrace: https://bugs.php.net/fix.php?id=68276&r=needtrace
Need Reproduce Script: https://bugs.php.net/fix.php?id=68276&r=needscript
Try newer version: https://bugs.php.net/fix.php?id=68276&r=oldversion
Not developer issue: https://bugs.php.net/fix.php?id=68276&r=support
Expected behavior: https://bugs.php.net/fix.php?id=68276&r=notwrong
Not enough info: https://bugs.php.net/fix.php?id=68276&r=notenoughinfo
Submitted twice: https://bugs.php.net/fix.php?id=68276&r=submittedtwice
register_globals: https://bugs.php.net/fix.php?id=68276&r=globals
PHP 4 support discontinued: https://bugs.php.net/fix.php?id=68276&r=php4
Daylight Savings: https://bugs.php.net/fix.php?id=68276&r=dst
IIS Stability: https://bugs.php.net/fix.php?id=68276&r=isapi
Install GNU Sed: https://bugs.php.net/fix.php?id=68276&r=gnused
Floating point limitations: https://bugs.php.net/fix.php?id=68276&r=float
No Zend Extensions: https://bugs.php.net/fix.php?id=68276&r=nozend
MySQL Configuration Error: https://bugs.php.net/fix.php?id=68276&r=mysqlcfg