Bug #71573 [Com]: Segfault (core dumped) if paramno beyond bound
| From: | caribe at candcsolution dot com | Date: | Fri, 13 May 2016 18:02:50 +0000 |
| Subject: | Bug #71573 [Com]: Segfault (core dumped) if paramno beyond bound | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-201075@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=71573&edit=1
ID: 71573
Comment by: caribe at candcsolution dot com
Reported by: johan at x-tnd dot be
Summary: Segfault (core dumped) if paramno beyond bound
Status: Closed
Type: Bug
Package: PDO PgSQL
Operating System: Linux CentoOS 7
PHP Version: 7.0.3
Assigned To: laruence
Block user comment: N
Private report: N
New Comment:
Hi Laurence,
Thanks for working on this bug. I applied your patch by hand to 7.0.4, and it still seems to be
broken for me. Here's the stack trace I'm seeing in gdb from my most recent crash:
GNU gdb (GDB) Red Hat Enterprise Linux 7.6.1-80.el7
Copyright (C) 2013 Free Software Foundation, Inc.
License GPLv3+: GNU GPL version 3 or later <http://gnu.org/licenses/gpl.html>
This is free software: you are free to change and redistribute it.
There is NO WARRANTY, to the extent permitted by law. Type "show copying"
and "show warranty" for details.
This GDB was configured as "x86_64-redhat-linux-gnu".
For bug reporting instructions, please see:
<http://www.gnu.org/software/gdb/bugs/>...
Reading symbols from /usr/lib/php5/bin/php...done.
[New LWP 22169]
[Thread debugging using libthread_db enabled]
Using host libthread_db library "/lib64/libthread_db.so.1".
Program terminated with signal 11, Segmentation fault.
#0 resetPQExpBuffer (str=str@entry=0x7f7bf2a8ba20) at pqexpbuffer.c:154
154 str->data[0] = '\0';
(gdb) bt
#0 resetPQExpBuffer (str=str@entry=0x7f7bf2a8ba20) at pqexpbuffer.c:154
#1 0x00007f7c04019bdd in PQsendQueryStart (conn=conn@entry=0x7f7bf2a8b6c8) at fe-exec.c:1351
#2 0x00007f7c0401b561 in PQsendQuery (conn=conn@entry=0x7f7bf2a8b6c8,
query=query@entry=0x7f7bf2dc3e60 "DEALLOCATE pdo_stmt_00000003") at fe-exec.c:1114
#3 0x00007f7c0401cab0 in PQexec (conn=0x7f7bf2a8b6c8, query=0x7f7bf2dc3e60 "DEALLOCATE
pdo_stmt_00000003") at fe-exec.c:1828
#4 0x0000000000640d03 in pgsql_stmt_dtor (stmt=0x7f7bf2d9dc40) at
/home/build/php-7.0.4/ext/pdo_pgsql/pgsql_statement.c:64
#5 0x000000000063c7fa in php_pdo_free_statement (stmt=0x7f7bf2d9dc40) at
/home/build/php-7.0.4/ext/pdo/pdo_stmt.c:2316
#6 0x000000000083ce31 in zend_objects_store_free_object_storage (objects=<optimized out>) at
/home/build/php-7.0.4/Zend/zend_objects_API.c:103
#7 0x00000000007f102c in shutdown_executor () at /home/build/php-7.0.4/Zend/zend_execute_API.c:357
#8 0x0000000000801313 in zend_deactivate () at /home/build/php-7.0.4/Zend/zend.c:967
#9 0x0000000000795127 in php_request_shutdown (dummy=dummy@entry=0x0) at
/home/build/php-7.0.4/main/main.c:1823
#10 0x0000000000892d82 in do_cli (argc=4, argv=0x1e18250) at
/home/build/php-7.0.4/sapi/cli/php_cli.c:1142
#11 0x0000000000441f87 in main (argc=4, argv=0x1e18250) at
/home/build/php-7.0.4/sapi/cli/php_cli.c:1345
Is this expected with 7.0.4? This definitely seems to be a GC issue to me as this only happens in
my CLI app on shutdown and destruct. From the digging I was able to do it seemed like things were
getting double free()'d somewhere because the crash appears to be on the dtor trying to clean
up objects that are already cleaned up.
I'm not anywhere near as versed on the internals of PHP and PDO as you are, but the submitted
patch seemed to be angled more toward missing elements of a bound statement in PDO and not toward
this apparent GC/destruct issue.
Previous Comments:
------------------------------------------------------------------------
[2016-05-11 03:13:05] laruence@php.net
Automatic comment on behalf of laruence@gmail.com
Revision: http://git.php.net/?p=php-src.git;a=commit;h=66ad4fc393d687f4ca255dd3788529856942bbaa
Log: Fixed bug #71573 (Segfault (core dumped) if paramno beyond bound)
------------------------------------------------------------------------
[2016-04-24 09:22:17] deadem at gmail dot com
I've got it:
$pdo = new PDO("pgsql:host=localhost;dbname=BASE", "USER", "PASS",
[]);
$statement = $pdo->prepare('select *, ?, \'?\' from "text"');
$statement->execute([ 'test', 'test', 'test' ]);
------------------------------------------------------------------------
[2016-04-16 20:55:27] mfischer@php.net
I'm adding this here too due the similarity of the stacktrace with printfPQExpBuffer I'm
getting; however in my case it's on Ubuntu with opcache, specifically opcache.fast_shutdown=1
will reproducible lead to a crash using CakePHP 2.8.3. Unfortunately I'm not able to create a
small reproducible script. I originally repoted this at https://github.com/oerdnj/deb.sury.org/issues/322
.
Program received signal SIGSEGV, Segmentation fault.
resetPQExpBuffer (str=str@entry=0x7fb575b5fe10) at
/build/postgresql-9.5-DVsMQj/postgresql-9.5-9.5.2/build/../src/interfaces/libpq/pqexpbuffer.c:152
152
/build/postgresql-9.5-DVsMQj/postgresql-9.5-9.5.2/build/../src/interfaces/libpq/pqexpbuffer.c: No
such file or directory.
(gdb) bt
#0 resetPQExpBuffer (str=str@entry=0x7fb575b5fe10) at
/build/postgresql-9.5-DVsMQj/postgresql-9.5-9.5.2/build/../src/interfaces/libpq/pqexpbuffer.c:152
#1 0x00007fb568e99cf7 in PQsendQueryStart (conn=conn@entry=0x7fb575b5fab8) at
/build/postgresql-9.5-DVsMQj/postgresql-9.5-9.5.2/build/../src/interfaces/libpq/fe-exec.c:1352
#2 0x00007fb568e9b6cb in PQsendQuery (conn=conn@entry=0x7fb575b5fab8,
query=query@entry=0x7fb575ba2550 "DEALLOCATE pdo_stmt_00000007")
at
/build/postgresql-9.5-DVsMQj/postgresql-9.5-9.5.2/build/../src/interfaces/libpq/fe-exec.c:1115
#3 0x00007fb568e9cd21 in PQexec (conn=0x7fb575b5fab8, query=0x7fb575ba2550 "DEALLOCATE
pdo_stmt_00000007")
at
/build/postgresql-9.5-DVsMQj/postgresql-9.5-9.5.2/build/../src/interfaces/libpq/fe-exec.c:1829
#4 0x00007fb5690c0733 in pgsql_stmt_dtor (stmt=0x7fb55dc72380) at
/build/php7.0-kNWWO9/php7.0-7.0.5/ext/pdo_pgsql/pgsql_statement.c:64
#5 0x00007fb574f39d6a in php_pdo_free_statement (stmt=0x7fb55dc72380) at
/build/php7.0-kNWWO9/php7.0-7.0.5/ext/pdo/pdo_stmt.c:2316
#6 0x00007fb57845b941 in zend_objects_store_del (object=0x7fb55dc724d0) at
/build/php7.0-kNWWO9/php7.0-7.0.5/Zend/zend_objects_API.c:182
#7 0x00007fb578421926 in _zval_dtor_func_for_ptr (p=<optimized out>) at
/build/php7.0-kNWWO9/php7.0-7.0.5/Zend/zend_variables.c:109
#8 0x00007fb578421959 in i_zval_ptr_dtor (zval_ptr=0x7fb575a98920) at
/build/php7.0-kNWWO9/php7.0-7.0.5/Zend/zend_variables.h:58
#9 _zval_dtor_func_for_ptr (p=0x7fb575a98918) at
/build/php7.0-kNWWO9/php7.0-7.0.5/Zend/zend_variables.c:122
#10 0x00007fb578457014 in i_zval_ptr_dtor (zval_ptr=0x7fb575a60928) at
/build/php7.0-kNWWO9/php7.0-7.0.5/Zend/zend_variables.h:58
#11 zend_object_std_dtor (object=0x7fb575a60800) at
/build/php7.0-kNWWO9/php7.0-7.0.5/Zend/zend_objects.c:69
#12 0x00007fb57845b5a0 in zend_objects_store_free_object_storage (objects=0x7fb575b5fe10,
objects@entry=0x7fb578804530 <executor_globals+816>)
at /build/php7.0-kNWWO9/php7.0-7.0.5/Zend/zend_objects_API.c:103
#13 0x00007fb578414913 in shutdown_executor () at
/build/php7.0-kNWWO9/php7.0-7.0.5/Zend/zend_execute_API.c:357
#14 0x00007fb5784231c5 in zend_deactivate () at /build/php7.0-kNWWO9/php7.0-7.0.5/Zend/zend.c:967
#15 0x00007fb5783c5ee1 in php_request_shutdown (dummy=<optimized out>) at
/build/php7.0-kNWWO9/php7.0-7.0.5/main/main.c:1826
#16 0x00007fb5782b89c6 in main (argc=<optimized out>, argv=<optimized out>) at
/build/php7.0-kNWWO9/php7.0-7.0.5/sapi/fpm/fpm/fpm_main.c:1996
------------------------------------------------------------------------
[2016-04-10 02:28:36] laruence@php.net
but if no reproduce script(or scripts), I can not do much thing here :<
------------------------------------------------------------------------
[2016-04-09 18:46:54] mbeccati@php.net
Apparently GC-related (see last comments), so I can't do much about it myself. I hope Xinchen
can pick it up.
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=71573
--
Edit this bug report at https://bugs.php.net/bug.php?id=71573&edit=1