Bug #70565 [Opn->Dup]: PDO DBLIB MSSql Segmentaion Fault with Prepared Statements

From: Date: Mon, 12 Sep 2016 21:26:26 +0000
Subject: Bug #70565 [Opn->Dup]: PDO DBLIB MSSql Segmentaion Fault with Prepared Statements
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-203980@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=70565&edit=1 ID: 70565 Updated by: adambaratz@php.net Reported by: reyad dot attiyat at gmail dot com Summary: PDO DBLIB MSSql Segmentaion Fault with Prepared Statements -Status: Open +Status: Duplicate Type: Bug Package: PDO DBlib Operating System: Windows 7 PHP Version: 7.0Git-2015-09-23 (Git) Block user comment: N Private report: N New Comment: Thank you for your bug report. This issue has already been fixed in the latest released version of PHP, which you can download at http://www.php.net/downloads.php Yes, this was fixed with #71943. Previous Comments: ------------------------------------------------------------------------ [2016-04-29 13:34:45] phofstetter at sensational dot ch This is very likely a duplicate of #71943 which is fixed in 7.0.6 ------------------------------------------------------------------------ [2015-11-19 23:44:51] maxiwheat at gmail dot com Well, I wrote too fast, we're still having issues with this, even with the patch :-/ ------------------------------------------------------------------------ [2015-11-19 20:18:07] maxiwheat at gmail dot com We have the same issue here. The code works perfectly with PHP 5.6 but in PHP 7 it breaks. What do something like that : - Create PDO object - Make a prepared statement (EXEC a Stored Proc with 16 parameters) - Bind params with ->bindValue - Execute (returns data correctly) - Make an other prepared statement (EXEC same Stored Proc, I know I could reuse the same statement, but I've been able to produce this bug that way) - Bind params with ->bindValue - Execute (it crashes, sometimes segfault, sometimes the query gets truncated and fails on SQL Server) The provided patch fix this bug ------------------------------------------------------------------------ [2015-11-17 14:29:35] phofstetter at sensational dot ch I can confirm that this problem also exists on OSX with FreeTDS 0.95.21 and I can also confirm that the attached patch solves the crash. Also, the backtraces in lldb are all over the place depending on how the PHP code looks, but the crash is always in emalloc(). ------------------------------------------------------------------------ [2015-09-24 14:16:09] reyad dot attiyat at gmail dot com I have changed the test script to not use utf-8 chars but instead just pass a 0 and same segmentation fault occurs during allocation. Backtrace: php7ts.dll!_emalloc(unsigned __int64 size) Line 2414 C php7ts.dll!dblib_handle_quoter(_pdo_dbh_t * dbh, const char * unquoted, unsigned __int64 unquotedlen, char * * quoted, unsigned __int64 * quotedlen, pdo_param_type paramtype) Line 184 C php7ts.dll!pdo_parse_params(_pdo_stmt_t * stmt, char * inquery, unsigned __int64 inquery_len, char * * outquery, unsigned __int64 * outquery_len) Line 263 C php7ts.dll!zim_PDOStatement_execute(_zend_execute_data * execute_data, _zval_struct * return_value) Line 495 C php7ts.dll!ZEND_DO_FCALL_SPEC_HANDLER(_zend_execute_data * execute_data) Line 850 C php7ts.dll!execute_ex(_zend_execute_data * ex) Line 413 C php7ts.dll!zend_execute(_zend_op_array * op_array, _zval_struct * return_value) Line 455 C php7ts.dll!zend_execute_scripts(int type, _zval_struct * retval, int file_count, ...) Line 1429 C php7ts.dll!php_execute_script(_zend_file_handle * primary_file) Line 2471 C php.exe!do_cli(int argc, char * * argv) Line 972 C php.exe!main(int argc, char * * argv) Line 1342 C ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=70565 -- Edit this bug report at https://bugs.php.net/bug.php?id=70565&edit=1

« previous php.bugs (#203980) next »