Bug #71863 [Com]: Segfault when EXPLAIN with "Unknown column" error

From: Date: Mon, 11 Apr 2016 14:36:28 +0000
Subject: Bug #71863 [Com]: Segfault when EXPLAIN with "Unknown column" error
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-200478@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=71863&edit=1 ID: 71863 Comment by: reyad dot attiyat at gmail dot com Reported by: Azq2 at ya dot ru Summary: Segfault when EXPLAIN with "Unknown column" error Status: Assigned Type: Bug Package: MySQLi related Operating System: Ubuntu 14.04 PHP Version: master-Git-2016-03-20 (Git) Assigned To: mysql Block user comment: N Private report: N New Comment: I also encountered this crash when dealing with errors in MySQL SELECT queries. I'm running PHP 7.1 (master) on Debian linux. The error seems to caused by a null function table pointer. The result set error_info struct is not initialized with callbacks and segfaults when the COPY_CLIENT_ERROR macro is called. The patch potentially fixes this issue by copying the error_info struct of the row packet into the the result set error_info struct. Previous Comments: ------------------------------------------------------------------------ [2016-03-20 19:31:23] Azq2 at ya dot ru Description: ------------ If execute "explain ..." query with non-existent keys - occure segfault. (my english very ugly, i from Ukraine) Test script: --------------- <?php $req = mysqli_connect('127.0.0.1', 'root', 'qwerty'); // <-- must be valid mysql server and user/password // create db and table for test mysqli_query($req, "CREATE DATABASE IF NOT EXISTS test42") or die(mysqli_error($req)); mysqli_select_db($req, 'test42') or die(mysqli_error($req)); mysqli_query($req, "DROP TABLE IF EXISTS users") or die(mysqli_error($req)); mysqli_query($req, "CREATE TABLE users (id INT UNSIGNED NOT NULL DEFAULT 0)") or die(mysqli_error($req)); // segfault if EXPLAIN + "Unknown column" error mysqli_query($req, "EXPLAIN SELECT id FROM users WHERE owner_id = '2' AND object_id = '1' AND type = '0'") or die(mysqli_error($req)); Expected result: ---------------- $ php -v PHP 5.5.17 (cli) (built: Sep 21 2014 19:56:50) Copyright (c) 1997-2014 The PHP Group Zend Engine v2.5.0, Copyright (c) 1998-2014 Zend Technologies with Zend OPcache v7.0.4-dev, Copyright (c) 1999-2014, by Zend Technologies $ php 1111.php PHP Warning: mysqli_query(): (42S22/1054): Unknown column 'owner_id' in 'where clause' in /root/1111.php on line 11 Warning: mysqli_query(): (42S22/1054): Unknown column 'owner_id' in 'where clause' in /root/1111.php on line 11 Unknown column 'owner_id' in 'where clause' Actual result: -------------- (gdb) bt #0 0x0000000000791fc4 in mysqlnd_mysqlnd_res_store_result_fetch_data_pub ( conn=0x7fffee66b008, result=<optimized out>, meta=<optimized out>, row_buffers=0x7fffee67c008, binary_protocol=<optimized out>) at /home/azq2/build/php-src/ext/mysqlnd/mysqlnd_result.c:1394 #1 0x0000000000794dde in mysqlnd_mysqlnd_res_store_result_pub ( result=0x7fffee65c8c8, conn=0x7fffee66b008, flags=<optimized out>) at /home/azq2/build/php-src/ext/mysqlnd/mysqlnd_result.c:1445 #2 0x0000000000782238 in mysqlnd_mysqlnd_conn_data_store_result_pub ( conn=0x7fffee66b008, flags=<optimized out>) at /home/azq2/build/php-src/ext/mysqlnd/mysqlnd_connection.c:1967 #3 0x000000000066688a in zif_mysqli_query (execute_data=<optimized out>, return_value=0x7fffee614180) at /home/azq2/build/php-src/ext/mysqli/mysqli_nonapi.c:613 #4 0x0000000000852fcd in ZEND_DO_ICALL_SPEC_RETVAL_USED_HANDLER () at /home/azq2/build/php-src/Zend/zend_vm_execute.h:641 #5 0x000000000083b6eb in execute_ex (ex=<optimized out>) at /home/azq2/build/php-src/Zend/zend_vm_execute.h:424 #6 0x0000000000891f37 in zend_execute (op_array=0x7fffee683000, op_array@entry=0x7fffee684620, return_value=return_value@entry=0x7fffee614030) at /home/azq2/build/php-src/Zend/zend_vm_execute.h:468 #7 0x00000000007fe2d4 in zend_execute_scripts (type=type@entry=8, retval=0x7fffee614030, retval@entry=0x0, file_count=file_count@entry=3) ---Type <return> to continue, or q <return> to quit--- at /home/azq2/build/php-src/Zend/zend.c:1427 #8 0x00000000007a18c8 in php_execute_script ( primary_file=primary_file@entry=0x7fffffffc890) at /home/azq2/build/php-src/main/main.c:2487 #9 0x00000000008941d8 in do_cli (argc=2, argv=0x1189950) at /home/azq2/build/php-src/sapi/cli/php_cli.c:974 #10 0x0000000000444e20 in main (argc=2, argv=0x1189950) at /home/azq2/build/php-src/sapi/cli/php_cli.c:1344 ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=71863&edit=1

« previous php.bugs (#200478) next »