Bug #72489 [ReO->Ver]: PHP Crashes When Modifying Array Containing MySQLi Result Data

From: Date: Sat, 17 Sep 2016 10:16:45 +0000
Subject: Bug #72489 [ReO->Ver]: PHP Crashes When Modifying Array Containing MySQLi Result Data
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-204090@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=72489&edit=1

 ID:                 72489
 Updated by:         nikic@php.net
 Reported by:        s7g2vp2 at yahoo dot co dot uk
 Summary:            PHP Crashes When Modifying Array Containing MySQLi
                     Result Data
-Status:             Re-Opened
+Status:             Verified
 Type:               Bug
 Package:            MySQLi related
 Operating System:   Windows Server 2012r2
 PHP Version:        7.0.8
 Block user comment: N
 Private report:     N

 New Comment:

Sorry, I made a mistake in the configuration. I was able to reproduce the issue on PHP 7.0
(including HEAD), but was *not* able to reproduce it on PHP 7.1.


Previous Comments:
------------------------------------------------------------------------
[2016-09-17 10:08:40] nikic@php.net

I wasn't able to reproduce the issue using the provided reproduce script on Ubuntu 16.04. I
tried both current master and PHP 7.0.8 specifically.

------------------------------------------------------------------------
[2016-08-29 18:12:59] s7g2vp2 at yahoo dot co dot uk

Hi.

Just checking to see if you now have everything to re-produce the bug.

Thanks.

------------------------------------------------------------------------
[2016-08-18 14:18:09] s7g2vp2 at yahoo dot co dot uk

We have finally managed to reproduce the problem outside of our application. I have updated the case
summary as the trigger turns out to be something different to what I originally thought.

There appears to be more than one version of the problem as different code can trigger a crash in
different places. 

I have included a sample script below which should allow you to reproduce the problem (tested on
MS-Windows and Mac OS X).




<?php

$dbHost = "127.0.0.1";
$dbUserName = "";
$dbPassword = "";
$dbDatabase = "";

$dbObj = new mysqli($dbHost, $dbUserName, $dbPassword, $dbDatabase);

$tableDropSQL = "DROP TABLE php7bug";

$dbObj->query($tableDropSQL);

$tableCreateSQL = "CREATE TABLE php7bug (id INT(6) UNSIGNED AUTO_INCREMENT PRIMARY KEY, code
VARCHAR(30) NOT NULL)";

if ($dbObj->query($tableCreateSQL) === TRUE)
{
    echo "Table MyGuests created successfully\n";

	$seedSQL = "INSERT INTO php7bug (code) VALUES ('code1');";
	$seedSQL .= "INSERT INTO php7bug (code) VALUES ('code2');";
	$seedSQL .= "INSERT INTO php7bug (code) VALUES ('code3');";

	if ($dbObj->multi_query($seedSQL) === TRUE)
	{
	    echo "New records created successfully\n";
	}
}


$dbObj = new mysqli($dbHost, $dbUserName, $dbPassword, $dbDatabase);

$expectedRecords = 3;

$id = 1;

$subRow = array();

if ($stmt2 = $dbObj->prepare("SELECT id, code FROM php7bug"))
{
	$stmt2->attr_set(MYSQLI_STMT_ATTR_CURSOR_TYPE, MYSQLI_CURSOR_TYPE_READ_ONLY);

	if ($stmt2->execute())
	{
		$stmt2->bind_result($subRow['id'], $subRow['code']);

		$count = 1;

		while ($stmt2->fetch())
		{
			error_log("row: " . $count++ . " of " . $expectedRecords . "\n");

			// DOESN'T CAUSE SEGFAULT
			// $subRow['code'] = array();

			// DOESN'T CAUSE SEGFAULT
			// $subRow['code'] = array('id' => 1);

			// DOESN'T CAUSE SEGFAULT
			// $subRow['code'] = array('id' => $id);

			// CAUSES SEGFAULT - NEVER REACHES "Finished 1"
			$testArray = array('id' => $id);
			$subRow['code'] = $testArray;

			// CAUSES SEGFAULT - NEVER REACHES "Finished 2"
			// $subRow['code'] = array('id' => $id);
			// $testArray = array('id' => $id);
			// $subRow['code'] = $testArray;


			// CAUSES SEGFAULT - NEVER REACHES "Finished 1"
			// $metaData = array();
			// $metaData['id'] = $id;
			// $subRow['code'] = $metaData;

		}
	}
}

echo "Finished 1\n";

// this is the line which crashes the script	
$newArray = array();
	
echo "Finished 2\n";
	
?>

------------------------------------------------------------------------
[2016-08-18 13:47:42] cmb@php.net

Re-opened on OP request.

------------------------------------------------------------------------
[2016-08-07 04:22:27] php-bugs at lists dot php dot net

No feedback was provided. The bug is being suspended because
we assume that you are no longer experiencing the problem.
If this is not the case and you are able to provide the
information that was requested earlier, please do so and
change the status of the bug back to "Re-Opened". Thank you.

------------------------------------------------------------------------


The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at

    https://bugs.php.net/bug.php?id=72489


--
Edit this bug report at https://bugs.php.net/bug.php?id=72489&edit=1


Thread (19 messages)

« previous php.bugs (#204090) next »