Bug #71387 [Opn]: Segfault in php_mysqlnd_rowp_read_text_protocol_aux()
| From: | bugs dot php dot net at ss dot st dot tc | Date: | Sat, 16 Jan 2016 09:11:32 +0000 |
| Subject: | Bug #71387 [Opn]: Segfault in php_mysqlnd_rowp_read_text_protocol_aux() | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-198708@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=71387&edit=1
ID: 71387
User updated by: bugs dot php dot net at ss dot st dot tc
Reported by: bugs dot php dot net at ss dot st dot tc
Summary: Segfault in
php_mysqlnd_rowp_read_text_protocol_aux()
Status: Open
Type: Bug
-Package: mysql
+Package: MySQLi related
Operating System: Gentoo Linux
PHP Version: 7.0.2
Block user comment: N
Private report: N
New Comment:
(mistakenly set package to mysql instead of mysqli)
Previous Comments:
------------------------------------------------------------------------
[2016-01-16 09:08:59] bugs dot php dot net at ss dot st dot tc
Worth mentioning that value of variable
len in mysqlnd_wireprotocol.c:1670 was 8 (and
that looks pretty normal among other values of len that we saw), which makes variable
p a suspect.
------------------------------------------------------------------------
[2016-01-16 08:37:43] bugs dot php dot net at ss dot st dot tc
Description:
------------
Tested in 7.0.0, 7.0.1 and 7.0.2.
The problem doesn't happen when PHP is compiled with --enable-debug option, so here's all
we've got:
#0 0x00000000007482aa in php_mysqlnd_rowp_read_text_protocol_aux ()
#1 0x00000000007508b2 in ?? ()
#2 0x00000000007517c5 in ?? ()
#3 0x00000000007520f6 in ?? ()
#4 0x00000000005d2618 in zif_mysqli_fetch_all ()
#5 0x000000000089027b in ?? ()
#6 0x000000000084a55b in execute_ex ()
#7 0x00000000008beb9e in zend_execute ()
#8 0x00000000007e6d5a in zend_execute_scripts ()
#9 0x0000000000765858 in php_execute_script ()
#10 0x00000000008c0e24 in ?? ()
#11 0x000000000046bf09 in main ()
We figured segfault happens on this line: https://github.com/php/php-src/blob/php-7.0.2/ext/mysqlnd/mysqlnd_wireprotocol.c#L1670
but didn't dig deeper.
After we removed as much as possible from our php script, we managed to narrow the problem down to
just one query that was performed in a loop:
select id, f1, f2 from table where id>{$some_id} and f1 is not null order by id limit 100
The script always segfaults after a certain amount of queries done.
As soon as we change something in that query (add or remove field, change limit to 99 or 101), the
number of performed queries before segfault changes (yet keeps steady as long as we don't touch
the query anymore). For instance, with limit 100 it constantly takes 35 queries to segfault. With
limit 101 we need 93 iterations. Without field "f2" it takes 83 iterations. With limit=102
segfault doesn't happen at all. And so on. We've also tried to add more mysql queries to
another server/tables/databases, this also affects on the moment segfault happens, but it always
keeps steady until we change something else. Could be a stack corruption, or something like that.
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=71387&edit=1