Bug #73085 [Opn->Dup]: oci_execute segfault

From: Date: Thu, 13 Oct 2016 04:47:35 +0000
Subject: Bug #73085 [Opn->Dup]: oci_execute segfault
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-204658@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=73085&edit=1 ID: 73085 Updated by: sixd@php.net Reported by: sergei dot solomonov at gmail dot com Summary: oci_execute segfault -Status: Open +Status: Duplicate Type: Bug Package: OCI8 related Operating System: Ubuntu 15.04 PHP Version: 7.1.0RC1 Block user comment: N Private report: N New Comment: Seems fixed by the patch in bug #71148. Previous Comments: ------------------------------------------------------------------------ [2016-09-15 05:07:16] sergei dot solomonov at gmail dot com Description: ------------ PHP v7.1.0RC1 on Ubuntu 15.04. Looks like all 7.* versions affected, but works fine with php 5.5 and 5.6 versions. Default php.ini-development config was used. Test script demonstrates some strange oci_execute / oci_bind_by_name behaviour. Code intentionally simplified and may look strange. Example below leads to segfault after $stmt->execute();. Some slight changes or reordering lines / commands may lead to other result. Also it may be related to https://bugs.php.net/bug.php?id=73080 Test script: --------------- <?php class Statement { private $stmt; function __construct($sql) { $this->connection = oci_connect('user', 'password', 'db', 'UTF8'); $this->stmt = oci_parse($this->connection, $sql); } function execute() { oci_execute($this->stmt); } function runOciFunctionAndHandleResult($funcName, array $funcArgs) { call_user_func_array("oci_$funcName", $funcArgs); } function bind($name, &$variable) { $args = func_get_args(); // without this assigning result to variable works fine! // $args not used here, because original code a bit simplified to demonstration strange behaviour $this->runOciFunctionAndHandleResult( 'bind_by_name', [$this->stmt, ":$name", &$variable] ); } function bindParams(array $bindParams = []) { foreach ($bindParams as $bvName => &$bvValue) { $this->bind($bvName, $bvValue[0]); } } } $stmt = new Statement( 'declare lp1 varchar2(1000); lp2 varchar2(1000); begin lp1 := :p1; lp2 := :p2; end;' ); $stmt->bindParams(['p1' => ['xxxxxxxxxxxxxxxxxxxxxxxx']]); // 24 or more chars would lead to segfault $stmt->bind('p2', $code); $stmt->execute(); Actual result: -------------- Segmentation fault (core dumped) ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=73085&edit=1

« previous php.bugs (#204658) next »