Bug #77849 [Opn]: Unexpected segfault attempting to use cloned PDO object
| From: | johannes@php.net | Date: | Fri, 05 Apr 2019 21:59:26 +0000 |
| Subject: | Bug #77849 [Opn]: Unexpected segfault attempting to use cloned PDO object | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-220336@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=77849&edit=1
ID: 77849
Updated by: johannes@php.net
Reported by: jordan dot ledoux at gmail dot com
Summary: Unexpected segfault attempting to use cloned PDO
object
Status: Open
Type: Bug
Package: PDO Core
Operating System: Ubuntu (AWS AMI)
PHP Version: 7.X
Block user comment: N
Private report: N
New Comment:
Since there is no internal API to clone or refcount the dbh a clone can not work without driver API
change (and even then it is questionable since we can't really clone the network state)
Patch seems fine, except that the test mises a cleanup
Previous Comments:
------------------------------------------------------------------------
[2019-04-05 19:53:20] camporter1 at gmail dot com
Explicitly set clone_obj on PDO dbh objects to NULL to prevent cloning in the attached pull request.
However, I'm not sure if there are existing use cases where cloning PDO objects does not
segfault?
------------------------------------------------------------------------
[2019-04-05 18:52:59]
The following pull request has been associated:
Patch Name: [PDO] Disable cloning of PDO handle/connection objects to avoid segfault
On GitHub: https://github.com/php/php-src/pull/4011
Patch: https://github.com/php/php-src/pull/4011.patch
------------------------------------------------------------------------
[2019-04-05 18:16:06] jordan dot ledoux at gmail dot com
Updated version and package information to reflect reproduced conditions:
7.2.17 -> 7.X
PDO MySQL -> PDO Core
------------------------------------------------------------------------
[2019-04-05 06:54:27] jordan dot ledoux at gmail dot com
This bug has been reproduced in all versions of 7.X:
https://3v4l.org/MRCHQ
------------------------------------------------------------------------
[2019-04-05 01:19:36] jordan dot ledoux at gmail dot com
Description:
------------
I encountered a segfault after attempting to use the query() method on the PDO class after it had
been unexpectedly cloned. This was actually done on 7.2.16, but I don't have the ability to
test it on other version at the moment.
Test script:
---------------
<?php
$dsn = 'mysql:dbname=testdb;host=127.0.0.1';
$user = 'testuser';
$pass = 'testpass';
$db1 = new PDO($dsn, $user, $pass);
$result1 = $db1->query("SELECT COUNT(*) FROM
testtable"); // Will return
PDOStatement object
$db2 = clone $db1;
$result2 = $db2->query("SELECT COUNT(*) FROM testtable"); // Will segfault
Expected result:
----------------
Since there is no case I can think of where cloning a PDO object is necessary, I think that maybe
throwing an exception of clone is used on a PDO object would be an acceptable solution, however as
I'm not an active participant in internals I defer to the judgement of those implementing.
This patch can be accomplished in user space as well (though obviously not the perfect solution) by
extending the PDO object and implementing a __clone() method that always throws an exception.
Actual result:
--------------
Segmentation Fault
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=77849&edit=1