Edit report at https://bugs.php.net/bug.php?id=72489&edit=1
ID: 72489
Comment by: nikic@php.net
Reported by: s7g2vp2 at yahoo dot co dot uk
Summary: PHP Crashes When Modifying Array Containing MySQLi
Result Data
Status: Verified
Type: Bug
Package: MySQLi related
Operating System: Windows Server 2012r2
PHP Version: 7.0.8
Block user comment: N
Private report: N
New Comment:
The offending line is https://github.com/php/php-src/blob/master/ext/mysqlnd/mysqlnd_ps.c#L817,
which performs a zval_dtor instead of a zval_ptr_dtor.
Instead of fixing this particular case, I think we should apply https://github.com/php/php-src/commit/ded69ee6e6039d56ee7b65b1a578ed1e3d1859da
to PHP-7.0 to avoid this class of problems with zval_dtor in general.
Previous Comments:
------------------------------------------------------------------------
[2016-09-17 10:16:44] nikic@php.net
Sorry, I made a mistake in the configuration. I was able to reproduce the issue on PHP 7.0
(including HEAD), but was *not* able to reproduce it on PHP 7.1.
------------------------------------------------------------------------
[2016-09-17 10:08:40] nikic@php.net
I wasn't able to reproduce the issue using the provided reproduce script on Ubuntu 16.04. I
tried both current master and PHP 7.0.8 specifically.
------------------------------------------------------------------------
[2016-08-29 18:12:59] s7g2vp2 at yahoo dot co dot uk
Hi.
Just checking to see if you now have everything to re-produce the bug.
Thanks.
------------------------------------------------------------------------
[2016-08-18 14:18:09] s7g2vp2 at yahoo dot co dot uk
We have finally managed to reproduce the problem outside of our application. I have updated the case
summary as the trigger turns out to be something different to what I originally thought.
There appears to be more than one version of the problem as different code can trigger a crash in
different places.
I have included a sample script below which should allow you to reproduce the problem (tested on
MS-Windows and Mac OS X).
<?php
$dbHost = "127.0.0.1";
$dbUserName = "";
$dbPassword = "";
$dbDatabase = "";
$dbObj = new mysqli($dbHost, $dbUserName, $dbPassword, $dbDatabase);
$tableDropSQL = "DROP TABLE php7bug";
$dbObj->query($tableDropSQL);
$tableCreateSQL = "CREATE TABLE php7bug (id INT(6) UNSIGNED AUTO_INCREMENT PRIMARY KEY, code
VARCHAR(30) NOT NULL)";
if ($dbObj->query($tableCreateSQL) === TRUE)
{
echo "Table MyGuests created successfully\n";
$seedSQL = "INSERT INTO php7bug (code) VALUES ('code1');";
$seedSQL .= "INSERT INTO php7bug (code) VALUES ('code2');";
$seedSQL .= "INSERT INTO php7bug (code) VALUES ('code3');";
if ($dbObj->multi_query($seedSQL) === TRUE)
{
echo "New records created successfully\n";
}
}
$dbObj = new mysqli($dbHost, $dbUserName, $dbPassword, $dbDatabase);
$expectedRecords = 3;
$id = 1;
$subRow = array();
if ($stmt2 = $dbObj->prepare("SELECT id, code FROM php7bug"))
{
$stmt2->attr_set(MYSQLI_STMT_ATTR_CURSOR_TYPE, MYSQLI_CURSOR_TYPE_READ_ONLY);
if ($stmt2->execute())
{
$stmt2->bind_result($subRow['id'], $subRow['code']);
$count = 1;
while ($stmt2->fetch())
{
error_log("row: " . $count++ . " of " . $expectedRecords . "\n");
// DOESN'T CAUSE SEGFAULT
// $subRow['code'] = array();
// DOESN'T CAUSE SEGFAULT
// $subRow['code'] = array('id' => 1);
// DOESN'T CAUSE SEGFAULT
// $subRow['code'] = array('id' => $id);
// CAUSES SEGFAULT - NEVER REACHES "Finished 1"
$testArray = array('id' => $id);
$subRow['code'] = $testArray;
// CAUSES SEGFAULT - NEVER REACHES "Finished 2"
// $subRow['code'] = array('id' => $id);
// $testArray = array('id' => $id);
// $subRow['code'] = $testArray;
// CAUSES SEGFAULT - NEVER REACHES "Finished 1"
// $metaData = array();
// $metaData['id'] = $id;
// $subRow['code'] = $metaData;
}
}
}
echo "Finished 1\n";
// this is the line which crashes the script
$newArray = array();
echo "Finished 2\n";
?>
------------------------------------------------------------------------
[2016-08-18 13:47:42] cmb@php.net
Re-opened on OP request.
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=72489
--
Edit this bug report at https://bugs.php.net/bug.php?id=72489&edit=1