Bug #70949 [Asn->Csd]: SQL Result Sets With NULL Can Cause Fatal Memory Errors

From: Date: Fri, 27 Nov 2015 07:53:29 +0000
Subject: Bug #70949 [Asn->Csd]: SQL Result Sets With NULL Can Cause Fatal Memory Errors
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-197454@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=70949&edit=1 ID: 70949 Updated by: laruence@php.net Reported by: s7g2vp2 at yahoo dot co dot uk Summary: SQL Result Sets With NULL Can Cause Fatal Memory Errors -Status: Assigned +Status: Closed Type: Bug Package: MySQLi related Operating System: Windows Server 2012 PHP Version: 7.0.0RC7 Assigned To: laruence Block user comment: N Private report: N New Comment: Automatic comment on behalf of laruence@gmail.com Revision: http://git.php.net/?p=php-src.git;a=commit;h=a347b0be48d892c105198b23868f37a0d4f92dee Log: Fixed bug #70949 (SQL Result Sets With NULL Can Cause Fatal Memory Errors) Previous Comments: ------------------------------------------------------------------------ [2015-11-24 09:04:16] laruence@php.net it accept txt files, or if you prefer mail, you can mail to me. thanks ------------------------------------------------------------------------ [2015-11-24 07:06:28] s7g2vp2 at yahoo dot co dot uk yes. how do I upload it? I only see an option to attach a patch. ------------------------------------------------------------------------ [2015-11-24 05:58:42] laruence@php.net can you provide a test script and a sh to fill database ? ------------------------------------------------------------------------ [2015-11-22 17:29:21] s7g2vp2 at yahoo dot co dot uk I have spent some more time investigating this and my original diagnoses is wrong as now, I cannot fix the problem using the method I originally stated. If I check the Apache error log I see that PHP has crashed with a fatal memory error: PHP Fatal error: Allowed memory size of 805306368 bytes exhausted (tried to allocate 1028538193632 bytes) The crash occurs in a loop that concatenates a php variable using data fetched from the result set. The SQL Statement is: SELECT sr.id, sr.groupcode, (SELECT group_concat(sr2.groupcode) FROM SHIPPINGRATES sr2 WHERE sr2.parentid = sr.id), sr.companycode, sr.code, sr.shippingmethodcode, sr.shippingzonecode, sm.name, sz.name, sr.productcode, pr.name, sr.info, sr.rate, sr.active FROM SHIPPINGRATES sr LEFT JOIN SHIPPINGMETHODS sm ON sm.code = sr.shippingmethodcode LEFT JOIN SHIPPINGZONES sz ON sz.code = sr.shippingzonecode LEFT JOIN PRODUCTS pr ON pr.code = sr.productcode WHERE sr.parentid = 0 ORDER BY sr.companycode, sr.code LIMIT 100 OFFSET 0 The 3rd column of the result set (group_concat) returns NULL for rows 1, 2, 3 and 7. It is during the processing of row 7 in the loop that causes the crash. The function includes a line that sets the cursor to read-only: $stmt->attr_set(MYSQLI_STMT_ATTR_CURSOR_TYPE, MYSQLI_CURSOR_TYPE_READ_ONLY); If I remove that line the crash does not occur. If I use IFNULL in the SQL statement to return an empty value instead of a NULL, the crash does not occur. If I just return NULL for the 3rd column the crash does not occur. so... The problem appears to be related to NULL, group_concat and read-only cursors. My guess is this is some type of memory corruption. I have tried disabling opcache but that has not made any difference. I can re-create this in a standalone script but it also requires a database. I can provide a script and MySQL dump but I don't know how I should attach these. Regards, Kev. ps. I am running 64 bit Apache 2.4.16 from Apache Lounge and the 64 bit version of PHP7 RC7 via the Apache module. ------------------------------------------------------------------------ [2015-11-21 00:24:11] rasmus@php.net Are you getting a MySQL error? A common cause of this is that you are sending something than a positive integer as the offset. For example, if you are doing something like: $offset = ceil($page * 10); $offset is now a float because ceil() always returns a float and the driver will pass that as something like "10.0" which will make offset fail. Make sure you cast any offsets you substitute into your query to an int first. eg. $offset = (int)ceil($page * 10); ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=70949 -- Edit this bug report at https://bugs.php.net/bug.php?id=70949&edit=1

« previous php.bugs (#197454) next »