Bug #71387 [Com]: Segfault in php_mysqlnd_rowp_read_text_protocol_aux()
| From: | jbboehr at gmail dot com | Date: | Mon, 10 Oct 2016 21:19:53 +0000 |
| Subject: | Bug #71387 [Com]: Segfault in php_mysqlnd_rowp_read_text_protocol_aux() | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-204581@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=71387&edit=1
ID: 71387
Comment by: jbboehr at gmail dot com
Reported by: bugs dot php dot net at ss dot st dot tc
Summary: Segfault in
php_mysqlnd_rowp_read_text_protocol_aux()
Status: No Feedback
Type: Bug
Package: MySQLi related
Operating System: Gentoo Linux
PHP Version: 7.0.2
Block user comment: N
Private report: N
New Comment:
Not 100% sure it's related, but I've run into an issue in the same function.
PHP 7.0.8-0ubuntu0.16.04.3 (cli) ( NTS )
Copyright (c) 1997-2016 The PHP Group
Zend Engine v3.0.0, Copyright (c) 1998-2016 Zend Technologies
with Zend OPcache v7.0.8-0ubuntu0.16.04.3, Copyright (c) 1999-2016, by Zend Technologies
The first time I ran valgrind, I got this:
==16316== Process terminating with default action of signal 11 (SIGSEGV)
==16316== at 0x682D2A9: raise (pt-raise.c:35)
==16316== by 0x17174A2E: nr_signal_reraise (util_signals.c:40)
==16316== by 0x682D3CF: ??? (in /lib/x86_64-linux-gnu/libpthread-2.23.so)
==16316== by 0x343C43: _emalloc (in /usr/bin/php7.0)
==16316== by 0x9A55F26: php_mysqlnd_rowp_read_text_protocol_aux (in
/usr/lib/php/20151012/mysqlnd.so)
==16316== by 0x9A5D3F0: ??? (in /usr/lib/php/20151012/mysqlnd.so)
==16316== by 0x9A5D8A4: ??? (in /usr/lib/php/20151012/mysqlnd.so)
==16316== by 0x16F0FE73: php_mysqli_fetch_into_hash (in /usr/lib/php/20151012/mysqli.so)
==16316== by 0x356C99: dtrace_execute_internal (in /usr/bin/php7.0)
==16316== by 0x3EB93F: ??? (in /usr/bin/php7.0)
==16316== by 0x3A6F8A: execute_ex (in /usr/bin/php7.0)
==16316== by 0x356B30: dtrace_execute_ex (in /usr/bin/php7.0)
One of the next times, after futzing with the code to try and get more information, I got this one:
==3636== Process terminating with default action of signal 11 (SIGSEGV)
==3636== at 0x682D2A9: raise (pt-raise.c:35)
==3636== by 0x17174A2E: nr_signal_reraise (util_signals.c:40)
==3636== by 0x682D3CF: ??? (in /lib/x86_64-linux-gnu/libpthread-2.23.so)
==3636== by 0x343C43: _emalloc (in /usr/bin/php7.0)
==3636== by 0x343EC0: _ecalloc (in /usr/bin/php7.0)
==3636== by 0x215D12: timelib_get_time_zone_info (in /usr/bin/php7.0)
==3636== by 0x217C35: timelib_set_timezone (in /usr/bin/php7.0)
==3636== by 0x217157: timelib_update_ts (in /usr/bin/php7.0)
==3636== by 0x1F2B43: zif_strtotime (in /usr/bin/php7.0)
==3636== by 0x356C99: dtrace_execute_internal (in /usr/bin/php7.0)
==3636== by 0x3EB93F: ??? (in /usr/bin/php7.0)
==3636== by 0x3A6F8A: execute_ex (in /usr/bin/php7.0)
These both happen in a loop of several hundred queries. So far I've failed to make a reduced
test case.
Previous Comments:
------------------------------------------------------------------------
[2016-02-07 04:22:18] php-bugs at lists dot php dot net
No feedback was provided. The bug is being suspended because
we assume that you are no longer experiencing the problem.
If this is not the case and you are able to provide the
information that was requested earlier, please do so and
change the status of the bug back to "Re-Opened". Thank you.
------------------------------------------------------------------------
[2016-01-25 04:22:21] laruence@php.net
Thank you for this bug report. To properly diagnose the problem, we
need a short but complete example script to be able to reproduce
this bug ourselves.
A proper reproducing script starts with <?php and ends with ?>,
is max. 10-20 lines long and does not require any external
resources such as databases, etc. If the script requires a
database to demonstrate the issue, please make sure it creates
all necessary tables, stored procedures etc.
Please avoid embedding huge scripts into the report.
------------------------------------------------------------------------
[2016-01-16 09:18:48] php at etc dot chkgo dot com
Not sure if it would help, but f1 is varbinary(32000). And if we select concat(f1, f1) instead of
just f1, segfault does not happen. It also does not happen if we include something like:
$x = str_repeat('XXXXXXXXXXXXXXXXXXXXXXX', 1000);
echo strlen($x); // without echo segfault still happens
into the loop. So any minor change to the code which affects memory may change the picture.
------------------------------------------------------------------------
[2016-01-16 09:11:31] bugs dot php dot net at ss dot st dot tc
(mistakenly set package to mysql instead of mysqli)
------------------------------------------------------------------------
[2016-01-16 09:08:59] bugs dot php dot net at ss dot st dot tc
Worth mentioning that value of variable
len in mysqlnd_wireprotocol.c:1670 was 8 (and
that looks pretty normal among other values of len that we saw), which makes variable
p a suspect.
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=71387
--
Edit this bug report at https://bugs.php.net/bug.php?id=71387&edit=1