Bug #70272 [Opn]: Segfault in pdo_mysql

From: Date: Fri, 14 Aug 2015 17:13:58 +0000
Subject: Bug #70272 [Opn]: Segfault in pdo_mysql
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-195211@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=70272&edit=1 ID: 70272 Updated by: laruence@php.net Reported by: laruence@php.net Summary: Segfault in pdo_mysql Status: Open Type: Bug Package: Scripting Engine problem PHP Version: 7.0.0beta3 Block user comment: N Private report: N New Comment: and a quick fix could be(however it is ugly, I will try to think about a more general fix before I commit this). diff --git a/ext/pdo/pdo_dbh.c b/ext/pdo/pdo_dbh.c index ec5f33f..3055be0 100644 --- a/ext/pdo/pdo_dbh.c +++ b/ext/pdo/pdo_dbh.c @@ -537,6 +537,13 @@ static PHP_METHOD(PDO, prepare) PDO_HANDLE_DBH_ERR(); RETURN_FALSE; } + + /* this is a tricky way to make sure stmt object is always dtor before dhb */ + if (UNEXPECTED(Z_OBJ_HANDLE_P(return_value) < Z_OBJ_HANDLE_P(getThis()))) { + zend_object_store_set_object(return_value, dbh_obj); + zend_object_store_set_object(getThis(), Z_OBJ_P(return_value)); + } + stmt = Z_PDO_STMT_P(return_value); /* unconditionally keep this for later reference */ @@ -1075,6 +1082,12 @@ static PHP_METHOD(PDO, query) } return; } + /* this is a tricky way to make sure stmt object is always dtor before dhb */ + if (UNEXPECTED(Z_OBJ_HANDLE_P(return_value) < Z_OBJ_HANDLE_P(getThis()))) { + zend_object_store_set_object(return_value, dbh_obj); + zend_object_store_set_object(getThis(), Z_OBJ_P(return_value)); + } + stmt = Z_PDO_STMT_P(return_value); /* unconditionally keep this for later reference */ Previous Comments: ------------------------------------------------------------------------ [2015-08-14 17:12:57] laruence@php.net Description: ------------ A segfault can be see if the STMT object have smaller object handle than the DBH object. the reason is we destroy objects in shutdown in reverse order, so, if the STMT object have smaller handle(means is will be access later then dbh object). a segfault can be see in shutdown Test script: --------------- <?php $a = new Stdclass(); $a->a = &$a; $b = new StdClass(); $db = new PDO("mysql:host=127.0.01;dbname=test", "root"); $b = NULL; $a->c = $db; $a->b = $db->prepare("select 1"); gc_disable(); ?> Expected result: ---------------- no segfault Actual result: -------------- segfault with backtrace: Program received signal SIGSEGV, Segmentation fault. 0x0000000000737a8b in pdo_mysql_stmt_dtor (stmt=0x7ffff06761c0) at /home/huixinchen/opensource/trunk/ext/pdo_mysql/mysql_statement.c:93 93 while (mysql_more_results(S->H->server)) { (gdb) bt #0 0x0000000000737a8b in pdo_mysql_stmt_dtor (stmt=0x7ffff06761c0) at /home/huixinchen/opensource/trunk/ext/pdo_mysql/mysql_statement.c:93 #1 0x0000000000730de3 in php_pdo_free_statement (stmt=0x7ffff06761c0) at /home/huixinchen/opensource/trunk/ext/pdo/pdo_stmt.c:2320 #2 0x0000000000730fc7 in pdo_dbstmt_free_storage (std=0x7ffff0676310) at /home/huixinchen/opensource/trunk/ext/pdo/pdo_stmt.c:2356 #3 0x0000000000a45573 in zend_objects_store_free_object_storage (objects=0x13f4dd0 <executor_globals+816>) at /home/huixinchen/opensource/trunk/Zend/zend_objects_API.c:102 #4 0x00000000009e1aaa in shutdown_executor () at /home/huixinchen/opensource/trunk/Zend/zend_execute_API.c:356 #5 0x00000000009f9b14 in zend_deactivate () at /home/huixinchen/opensource/trunk/Zend/zend.c:969 #6 0x000000000096456d in php_request_shutdown (dummy=0x0) at /home/huixinchen/opensource/trunk/main/main.c:1814 #7 0x0000000000aba5f5 in do_cli (argc=2, argv=0x13f8e50) at /home/huixinchen/opensource/trunk/sapi/cli/php_cli.c:1139 #8 0x0000000000abae68 in main (argc=2, argv=0x13f8e50) at /home/huixinchen/opensource/trunk/sapi/cli/php_cli.c:1338 (gdb) ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=70272&edit=1

« previous php.bugs (#195211) next »