Bug #70272 [Opn]: Segfault in pdo_mysql
| From: | laruence@php.net | Date: | Fri, 14 Aug 2015 17:13:58 +0000 |
| Subject: | Bug #70272 [Opn]: Segfault in pdo_mysql | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-195211@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=70272&edit=1
ID: 70272
Updated by: laruence@php.net
Reported by: laruence@php.net
Summary: Segfault in pdo_mysql
Status: Open
Type: Bug
Package: Scripting Engine problem
PHP Version: 7.0.0beta3
Block user comment: N
Private report: N
New Comment:
and a quick fix could be(however it is ugly, I will try to think about a more general fix before I
commit this).
diff --git a/ext/pdo/pdo_dbh.c b/ext/pdo/pdo_dbh.c
index ec5f33f..3055be0 100644
--- a/ext/pdo/pdo_dbh.c
+++ b/ext/pdo/pdo_dbh.c
@@ -537,6 +537,13 @@ static PHP_METHOD(PDO, prepare)
PDO_HANDLE_DBH_ERR();
RETURN_FALSE;
}
+
+ /* this is a tricky way to make sure stmt object is always dtor before dhb */
+ if (UNEXPECTED(Z_OBJ_HANDLE_P(return_value) < Z_OBJ_HANDLE_P(getThis()))) {
+ zend_object_store_set_object(return_value, dbh_obj);
+ zend_object_store_set_object(getThis(), Z_OBJ_P(return_value));
+ }
+
stmt = Z_PDO_STMT_P(return_value);
/* unconditionally keep this for later reference */
@@ -1075,6 +1082,12 @@ static PHP_METHOD(PDO, query)
}
return;
}
+ /* this is a tricky way to make sure stmt object is always dtor before dhb */
+ if (UNEXPECTED(Z_OBJ_HANDLE_P(return_value) < Z_OBJ_HANDLE_P(getThis()))) {
+ zend_object_store_set_object(return_value, dbh_obj);
+ zend_object_store_set_object(getThis(), Z_OBJ_P(return_value));
+ }
+
stmt = Z_PDO_STMT_P(return_value);
/* unconditionally keep this for later reference */
Previous Comments:
------------------------------------------------------------------------
[2015-08-14 17:12:57] laruence@php.net
Description:
------------
A segfault can be see if the STMT object have smaller object handle than the DBH object.
the reason is we destroy objects in shutdown in reverse order, so, if the STMT object have smaller
handle(means is will be access later then dbh object). a segfault can be see in shutdown
Test script:
---------------
<?php
$a = new Stdclass();
$a->a = &$a;
$b = new StdClass();
$db = new PDO("mysql:host=127.0.01;dbname=test", "root");
$b = NULL;
$a->c = $db;
$a->b = $db->prepare("select 1");
gc_disable();
?>
Expected result:
----------------
no segfault
Actual result:
--------------
segfault with backtrace:
Program received signal SIGSEGV, Segmentation fault.
0x0000000000737a8b in pdo_mysql_stmt_dtor (stmt=0x7ffff06761c0)
at /home/huixinchen/opensource/trunk/ext/pdo_mysql/mysql_statement.c:93
93 while (mysql_more_results(S->H->server)) {
(gdb) bt
#0 0x0000000000737a8b in pdo_mysql_stmt_dtor (stmt=0x7ffff06761c0)
at /home/huixinchen/opensource/trunk/ext/pdo_mysql/mysql_statement.c:93
#1 0x0000000000730de3 in php_pdo_free_statement (stmt=0x7ffff06761c0)
at /home/huixinchen/opensource/trunk/ext/pdo/pdo_stmt.c:2320
#2 0x0000000000730fc7 in pdo_dbstmt_free_storage (std=0x7ffff0676310)
at /home/huixinchen/opensource/trunk/ext/pdo/pdo_stmt.c:2356
#3 0x0000000000a45573 in zend_objects_store_free_object_storage (objects=0x13f4dd0
<executor_globals+816>)
at /home/huixinchen/opensource/trunk/Zend/zend_objects_API.c:102
#4 0x00000000009e1aaa in shutdown_executor () at
/home/huixinchen/opensource/trunk/Zend/zend_execute_API.c:356
#5 0x00000000009f9b14 in zend_deactivate () at /home/huixinchen/opensource/trunk/Zend/zend.c:969
#6 0x000000000096456d in php_request_shutdown (dummy=0x0) at
/home/huixinchen/opensource/trunk/main/main.c:1814
#7 0x0000000000aba5f5 in do_cli (argc=2, argv=0x13f8e50) at
/home/huixinchen/opensource/trunk/sapi/cli/php_cli.c:1139
#8 0x0000000000abae68 in main (argc=2, argv=0x13f8e50) at
/home/huixinchen/opensource/trunk/sapi/cli/php_cli.c:1338
(gdb)
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=70272&edit=1