Bug #69975 [Csd]: PHP segfaults when accessing nvarchar(max) defined columns

From: Date: Thu, 02 Jul 2015 22:38:09 +0000
Subject: Bug #69975 [Csd]: PHP segfaults when accessing nvarchar(max) defined columns
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-194093@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=69975&edit=1

 ID:                 69975
 Updated by:         cmb@php.net
 Reported by:        jgeert1 at its dot jnj dot com
 Summary:            PHP segfaults when accessing nvarchar(max) defined
                     columns
 Status:             Closed
 Type:               Bug
 Package:            ODBC related
 Operating System:   Windows Server 2012R2
 PHP Version:        5.5.26
 Assigned To:        cmb
 Block user comment: N
 Private report:     N

 New Comment:

The fix for this bug has been committed for PHP 5.6 and master.

You can download the latest Windows snapshot from
<http://windows.php.net/snapshots/>. Note that
it might take some
time for the next snapshot to be built.
 
Thank you for the report, and for helping us make PHP better.

I have not been able to reproduce #67437, and therefore didn't
cater to it; see also the commit message.


Previous Comments:
------------------------------------------------------------------------
[2015-07-02 22:30:03] cmb@php.net

Automatic comment on behalf of cmb
Revision: http://git.php.net/?p=php-src.git;a=commit;h=16db4d1462bf3eacb93c0cd940f799160a284b24
Log: Fix #69975: PHP segfaults when accessing nvarchar(max) defined columns

------------------------------------------------------------------------
[2015-07-02 21:04:28] cmb@php.net

I've tested with odbcver=0x0350 and 0x0351 and got segfaults, too.

Actually the problem is rather clear in the meantime. According to
MSDN[1] nvarchar(max) has a maximum size of 2GB. Even if the
driver would report this as displaylength, so much memory could
usually not be allocated. Apparently, nvarchar(max) has to be
treated the same as SQL_WLONGVARCHAR. The SQL Server driver does
this, but not the SQL Server Native Client 11.0 driver
(2011.110.3000.0). The fix appears to be a no-brainer (similar to
the attached draft patch, but additionally setting .coltype to
SQL_WLONGVARCHAR, and of course fixing the assignment in the if
condition).

I can confirm that #68964 is already fixed. An ntext column is
reported as SQL_WLONGVARCHAR by both drivers (ODBCVER 03x00 as
well as 0x351).

Interestingly, bug #67437 suggests that some drivers report a size
of ~ 2GB for nvarchar(max). I'll have a closer look on that.

[1] <https://msdn.microsoft.com/en-us/library/ms186939(v=sql.120).aspx>

------------------------------------------------------------------------
[2015-07-02 20:04:44] ab@php.net

@jgeert1, ahh, you're right. Still, it could be a driver mess.

@cmb, have you tried to raise the ODBCVER? See ext/odbc/config.w32, IMHO 3.5 could be done for
master, if there's no other solution. Still many issues with 3.0 and older. But on the other
hand, if you can fix it with 3.0, so be.

Thanks.

------------------------------------------------------------------------
[2015-07-02 16:59:23] cmb@php.net

I have now set up a testing environment with SQL Server 2014 and
can reproduce the issue. My patch was way too short-sighted (it
prevents the segfault, but does return empty strings). I'll have
to investigate further.

------------------------------------------------------------------------
[2015-07-02 14:24:05] jgeert1 at its dot jnj dot com

Wow that was fast :-)
What do I need to do to get a compiled version for Windows 64-bit?
Thanks.

------------------------------------------------------------------------


The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at

    https://bugs.php.net/bug.php?id=69975


--
Edit this bug report at https://bugs.php.net/bug.php?id=69975&edit=1


Thread (17 messages)

« previous php.bugs (#194093) next »