Bug #72489 [Ver->Csd]: PHP Crashes When Modifying Array Containing MySQLi Result Data

From: Date: Sat, 17 Sep 2016 20:58:04 +0000
Subject: Bug #72489 [Ver->Csd]: PHP Crashes When Modifying Array Containing MySQLi Result Data
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-204099@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=72489&edit=1

 ID:                 72489
 Updated by:         nikic@php.net
 Reported by:        s7g2vp2 at yahoo dot co dot uk
 Summary:            PHP Crashes When Modifying Array Containing MySQLi
                     Result Data
-Status:             Verified
+Status:             Closed
 Type:               Bug
 Package:            MySQLi related
 Operating System:   Windows Server 2012r2
 PHP Version:        7.0.8
-Assigned To:        
+Assigned To:        nikic
 Block user comment: N
 Private report:     N

 New Comment:

Fixed by https://github.com/php/php-src/commit/896814e139d8dead8193f0e44cdc4ba3d8a002c7
and https://github.com/php/php-src/commit/01759c43463c30b57c15e32c5f4b454fba81f039.


Previous Comments:
------------------------------------------------------------------------
[2016-09-17 10:20:39] nikic@php.net

The offending line is https://github.com/php/php-src/blob/master/ext/mysqlnd/mysqlnd_ps.c#L817,
which performs a zval_dtor instead of a zval_ptr_dtor.

Instead of fixing this particular case, I think we should apply https://github.com/php/php-src/commit/ded69ee6e6039d56ee7b65b1a578ed1e3d1859da
to PHP-7.0 to avoid this class of problems with zval_dtor in general.

------------------------------------------------------------------------
[2016-09-17 10:16:44] nikic@php.net

Sorry, I made a mistake in the configuration. I was able to reproduce the issue on PHP 7.0
(including HEAD), but was *not* able to reproduce it on PHP 7.1.

------------------------------------------------------------------------
[2016-09-17 10:08:40] nikic@php.net

I wasn't able to reproduce the issue using the provided reproduce script on Ubuntu 16.04. I
tried both current master and PHP 7.0.8 specifically.

------------------------------------------------------------------------
[2016-08-29 18:12:59] s7g2vp2 at yahoo dot co dot uk

Hi.

Just checking to see if you now have everything to re-produce the bug.

Thanks.

------------------------------------------------------------------------
[2016-08-18 14:18:09] s7g2vp2 at yahoo dot co dot uk

We have finally managed to reproduce the problem outside of our application. I have updated the case
summary as the trigger turns out to be something different to what I originally thought.

There appears to be more than one version of the problem as different code can trigger a crash in
different places. 

I have included a sample script below which should allow you to reproduce the problem (tested on
MS-Windows and Mac OS X).




<?php

$dbHost = "127.0.0.1";
$dbUserName = "";
$dbPassword = "";
$dbDatabase = "";

$dbObj = new mysqli($dbHost, $dbUserName, $dbPassword, $dbDatabase);

$tableDropSQL = "DROP TABLE php7bug";

$dbObj->query($tableDropSQL);

$tableCreateSQL = "CREATE TABLE php7bug (id INT(6) UNSIGNED AUTO_INCREMENT PRIMARY KEY, code
VARCHAR(30) NOT NULL)";

if ($dbObj->query($tableCreateSQL) === TRUE)
{
    echo "Table MyGuests created successfully\n";

	$seedSQL = "INSERT INTO php7bug (code) VALUES ('code1');";
	$seedSQL .= "INSERT INTO php7bug (code) VALUES ('code2');";
	$seedSQL .= "INSERT INTO php7bug (code) VALUES ('code3');";

	if ($dbObj->multi_query($seedSQL) === TRUE)
	{
	    echo "New records created successfully\n";
	}
}


$dbObj = new mysqli($dbHost, $dbUserName, $dbPassword, $dbDatabase);

$expectedRecords = 3;

$id = 1;

$subRow = array();

if ($stmt2 = $dbObj->prepare("SELECT id, code FROM php7bug"))
{
	$stmt2->attr_set(MYSQLI_STMT_ATTR_CURSOR_TYPE, MYSQLI_CURSOR_TYPE_READ_ONLY);

	if ($stmt2->execute())
	{
		$stmt2->bind_result($subRow['id'], $subRow['code']);

		$count = 1;

		while ($stmt2->fetch())
		{
			error_log("row: " . $count++ . " of " . $expectedRecords . "\n");

			// DOESN'T CAUSE SEGFAULT
			// $subRow['code'] = array();

			// DOESN'T CAUSE SEGFAULT
			// $subRow['code'] = array('id' => 1);

			// DOESN'T CAUSE SEGFAULT
			// $subRow['code'] = array('id' => $id);

			// CAUSES SEGFAULT - NEVER REACHES "Finished 1"
			$testArray = array('id' => $id);
			$subRow['code'] = $testArray;

			// CAUSES SEGFAULT - NEVER REACHES "Finished 2"
			// $subRow['code'] = array('id' => $id);
			// $testArray = array('id' => $id);
			// $subRow['code'] = $testArray;


			// CAUSES SEGFAULT - NEVER REACHES "Finished 1"
			// $metaData = array();
			// $metaData['id'] = $id;
			// $subRow['code'] = $metaData;

		}
	}
}

echo "Finished 1\n";

// this is the line which crashes the script	
$newArray = array();
	
echo "Finished 2\n";
	
?>

------------------------------------------------------------------------


The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at

    https://bugs.php.net/bug.php?id=72489


--
Edit this bug report at https://bugs.php.net/bug.php?id=72489&edit=1


Thread (19 messages)

« previous php.bugs (#204099) next »