Bug #71387 [Com]: Segfault in php_mysqlnd_rowp_read_text_protocol_aux()

From: Date: Mon, 10 Oct 2016 21:19:53 +0000
Subject: Bug #71387 [Com]: Segfault in php_mysqlnd_rowp_read_text_protocol_aux()
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-204581@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=71387&edit=1 ID: 71387 Comment by: jbboehr at gmail dot com Reported by: bugs dot php dot net at ss dot st dot tc Summary: Segfault in php_mysqlnd_rowp_read_text_protocol_aux() Status: No Feedback Type: Bug Package: MySQLi related Operating System: Gentoo Linux PHP Version: 7.0.2 Block user comment: N Private report: N New Comment: Not 100% sure it's related, but I've run into an issue in the same function. PHP 7.0.8-0ubuntu0.16.04.3 (cli) ( NTS ) Copyright (c) 1997-2016 The PHP Group Zend Engine v3.0.0, Copyright (c) 1998-2016 Zend Technologies with Zend OPcache v7.0.8-0ubuntu0.16.04.3, Copyright (c) 1999-2016, by Zend Technologies The first time I ran valgrind, I got this: ==16316== Process terminating with default action of signal 11 (SIGSEGV) ==16316== at 0x682D2A9: raise (pt-raise.c:35) ==16316== by 0x17174A2E: nr_signal_reraise (util_signals.c:40) ==16316== by 0x682D3CF: ??? (in /lib/x86_64-linux-gnu/libpthread-2.23.so) ==16316== by 0x343C43: _emalloc (in /usr/bin/php7.0) ==16316== by 0x9A55F26: php_mysqlnd_rowp_read_text_protocol_aux (in /usr/lib/php/20151012/mysqlnd.so) ==16316== by 0x9A5D3F0: ??? (in /usr/lib/php/20151012/mysqlnd.so) ==16316== by 0x9A5D8A4: ??? (in /usr/lib/php/20151012/mysqlnd.so) ==16316== by 0x16F0FE73: php_mysqli_fetch_into_hash (in /usr/lib/php/20151012/mysqli.so) ==16316== by 0x356C99: dtrace_execute_internal (in /usr/bin/php7.0) ==16316== by 0x3EB93F: ??? (in /usr/bin/php7.0) ==16316== by 0x3A6F8A: execute_ex (in /usr/bin/php7.0) ==16316== by 0x356B30: dtrace_execute_ex (in /usr/bin/php7.0) One of the next times, after futzing with the code to try and get more information, I got this one: ==3636== Process terminating with default action of signal 11 (SIGSEGV) ==3636== at 0x682D2A9: raise (pt-raise.c:35) ==3636== by 0x17174A2E: nr_signal_reraise (util_signals.c:40) ==3636== by 0x682D3CF: ??? (in /lib/x86_64-linux-gnu/libpthread-2.23.so) ==3636== by 0x343C43: _emalloc (in /usr/bin/php7.0) ==3636== by 0x343EC0: _ecalloc (in /usr/bin/php7.0) ==3636== by 0x215D12: timelib_get_time_zone_info (in /usr/bin/php7.0) ==3636== by 0x217C35: timelib_set_timezone (in /usr/bin/php7.0) ==3636== by 0x217157: timelib_update_ts (in /usr/bin/php7.0) ==3636== by 0x1F2B43: zif_strtotime (in /usr/bin/php7.0) ==3636== by 0x356C99: dtrace_execute_internal (in /usr/bin/php7.0) ==3636== by 0x3EB93F: ??? (in /usr/bin/php7.0) ==3636== by 0x3A6F8A: execute_ex (in /usr/bin/php7.0) These both happen in a loop of several hundred queries. So far I've failed to make a reduced test case. Previous Comments: ------------------------------------------------------------------------ [2016-02-07 04:22:18] php-bugs at lists dot php dot net No feedback was provided. The bug is being suspended because we assume that you are no longer experiencing the problem. If this is not the case and you are able to provide the information that was requested earlier, please do so and change the status of the bug back to "Re-Opened". Thank you. ------------------------------------------------------------------------ [2016-01-25 04:22:21] laruence@php.net Thank you for this bug report. To properly diagnose the problem, we need a short but complete example script to be able to reproduce this bug ourselves. A proper reproducing script starts with <?php and ends with ?>, is max. 10-20 lines long and does not require any external resources such as databases, etc. If the script requires a database to demonstrate the issue, please make sure it creates all necessary tables, stored procedures etc. Please avoid embedding huge scripts into the report. ------------------------------------------------------------------------ [2016-01-16 09:18:48] php at etc dot chkgo dot com Not sure if it would help, but f1 is varbinary(32000). And if we select concat(f1, f1) instead of just f1, segfault does not happen. It also does not happen if we include something like: $x = str_repeat('XXXXXXXXXXXXXXXXXXXXXXX', 1000); echo strlen($x); // without echo segfault still happens into the loop. So any minor change to the code which affects memory may change the picture. ------------------------------------------------------------------------ [2016-01-16 09:11:31] bugs dot php dot net at ss dot st dot tc (mistakenly set package to mysql instead of mysqli) ------------------------------------------------------------------------ [2016-01-16 09:08:59] bugs dot php dot net at ss dot st dot tc Worth mentioning that value of variable len in mysqlnd_wireprotocol.c:1670 was 8 (and that looks pretty normal among other values of len that we saw), which makes variable p a suspect. ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=71387 -- Edit this bug report at https://bugs.php.net/bug.php?id=71387&edit=1

« previous php.bugs (#204581) next »