Edit report at https://bugs.php.net/bug.php?id=70565&edit=1
ID: 70565
Comment by: phofstetter at sensational dot ch
Reported by: reyad dot attiyat at gmail dot com
Summary: PDO DBLIB MSSql Segmentaion Fault with Prepared
Statements
Status: Open
Type: Bug
Package: PDO DBlib
Operating System: Windows 7
PHP Version: 7.0Git-2015-09-23 (Git)
Block user comment: N
Private report: N
New Comment:
This is very likely a duplicate of #71943 which is fixed in 7.0.6
Previous Comments:
------------------------------------------------------------------------
[2015-11-19 23:44:51] maxiwheat at gmail dot com
Well, I wrote too fast, we're still having issues with this, even with the patch :-/
------------------------------------------------------------------------
[2015-11-19 20:18:07] maxiwheat at gmail dot com
We have the same issue here. The code works perfectly with PHP 5.6 but in PHP 7 it breaks. What do
something like that :
- Create PDO object
- Make a prepared statement (EXEC a Stored Proc with 16 parameters)
- Bind params with ->bindValue
- Execute (returns data correctly)
- Make an other prepared statement (EXEC same Stored Proc, I know I could reuse the same statement,
but I've been able to produce this bug that way)
- Bind params with ->bindValue
- Execute (it crashes, sometimes segfault, sometimes the query gets truncated and fails on SQL
Server)
The provided patch fix this bug
------------------------------------------------------------------------
[2015-11-17 14:29:35] phofstetter at sensational dot ch
I can confirm that this problem also exists on OSX with FreeTDS 0.95.21 and I can also confirm that
the attached patch solves the crash.
Also, the backtraces in lldb are all over the place depending on how the PHP code looks, but the
crash is always in emalloc().
------------------------------------------------------------------------
[2015-09-24 14:16:09] reyad dot attiyat at gmail dot com
I have changed the test script to not use utf-8 chars but instead just pass a 0 and same
segmentation fault occurs during allocation.
Backtrace:
php7ts.dll!_emalloc(unsigned __int64 size) Line 2414 C
php7ts.dll!dblib_handle_quoter(_pdo_dbh_t * dbh, const char * unquoted, unsigned __int64
unquotedlen, char * * quoted, unsigned __int64 * quotedlen, pdo_param_type paramtype) Line 184 C
php7ts.dll!pdo_parse_params(_pdo_stmt_t * stmt, char * inquery, unsigned __int64 inquery_len, char
* * outquery, unsigned __int64 * outquery_len) Line 263 C
php7ts.dll!zim_PDOStatement_execute(_zend_execute_data * execute_data, _zval_struct *
return_value) Line 495 C
php7ts.dll!ZEND_DO_FCALL_SPEC_HANDLER(_zend_execute_data * execute_data) Line 850 C
php7ts.dll!execute_ex(_zend_execute_data * ex) Line 413 C
php7ts.dll!zend_execute(_zend_op_array * op_array, _zval_struct * return_value) Line 455 C
php7ts.dll!zend_execute_scripts(int type, _zval_struct * retval, int file_count, ...) Line 1429 C
php7ts.dll!php_execute_script(_zend_file_handle * primary_file) Line 2471 C
php.exe!do_cli(int argc, char * * argv) Line 972 C
php.exe!main(int argc, char * * argv) Line 1342 C
------------------------------------------------------------------------
[2015-09-23 20:17:25] reyad dot attiyat at gmail dot com
Also noticed in PHP 5.16 code they use safe_emalloc() in the dblib_handle_quoter() function.
https://github.com/php/php-src/blob/PHP-5.6.14/ext/pdo_dblib/dblib_driver.c
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=70565
--
Edit this bug report at https://bugs.php.net/bug.php?id=70565&edit=1