Bug #77734 [Opn->Dup]: Seg Fault caused by php_mysqlnd_free_field_metadata

From: Date: Tue, 07 May 2019 09:16:35 +0000
Subject: Bug #77734 [Opn->Dup]: Seg Fault caused by php_mysqlnd_free_field_metadata
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-220724@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=77734&edit=1

 ID:                 77734
 Updated by:         sjon@php.net
 Reported by:        scott at exussum dot co dot uk
 Summary:            Seg Fault caused by php_mysqlnd_free_field_metadata
-Status:             Open
+Status:             Duplicate
 Type:               Bug
 Package:            PDO MySQL
 Operating System:   Ubuntu 18.04
 PHP Version:        7.3.3
 Block user comment: N
 Private report:     N

 New Comment:

duplicate of bug #77955 (which has a better backtrace)


Previous Comments:
------------------------------------------------------------------------
[2019-05-07 08:02:41] sjon at hortensius dot net

I think this bug is duplicated by #77955 which has a better stacktrace with debug-symbols

------------------------------------------------------------------------
[2019-04-15 10:48:34] scott at exussum dot co dot uk

Anything else I can do for debugging ? I can make it happen fairly often

------------------------------------------------------------------------
[2019-04-15 10:15:42] nikic@php.net

Unfortunately these all look like false positives (the ??? are likely from PCRE JIT and
zend_string_equal_val is expected) and valgrind itself crashed before it got to anything interesting
:(

------------------------------------------------------------------------
[2019-04-15 10:06:29] scott at exussum dot co dot uk

I dont have all debug symbols, working on getting more

This is the trace though - hope it helps in some way ?

==32515== Conditional jump or move depends on uninitialised value(s)
==32515==    at 0x421F165: ???
==32515==    by 0x2324D8F7: ???
==32515==    by 0x2324D8F7: ???
==32515==    by 0x2324D91D: ???
==32515==    by 0x9A3F4FF: ???
==32515==    by 0x2324D8F7: ???
==32515== 
+------------------------------------+
==32515== Conditional jump or move depends on uninitialised value(s)
==32515==    at 0x421F144: ???
==32515==    by 0x228FE0E7: ???
==32515==    by 0x228FE0E7: ???
==32515==    by 0x228FE0EB: ???
==32515==    by 0x9A3F4FF: ???
==32515==    by 0x228FE0E7: ???
==32515== 
==32515== Conditional jump or move depends on uninitialised value(s)
==32515==    at 0x3C7C92: zend_string_equal_val (zend_string.c:403)
==32515==    by 0x40DCFC: zend_string_equal_content (zend_string.h:310)
==32515==    by 0x40DCFC: zend_fast_equal_strings (zend_operators.h:734)
==32515==    by 0x40DCFC: ZEND_IS_EQUAL_SPEC_CV_CV_HANDLER (zend_vm_execute.h:48290)
==32515==    by 0x42730C: execute_ex (zend_vm_execute.h:60509)
==32515==    by 0x38FBA5: zend_call_function (zend_execute_API.c:756)
==32515==    by 0x2CA422: zif_array_filter (array.c:6059)
==32515==    by 0x42B7B4: ZEND_DO_FCALL_BY_NAME_SPEC_RETVAL_USED_HANDLER (zend_vm_execute.h:892)
==32515==    by 0x42B7B4: execute_ex (zend_vm_execute.h:55481)
==32515==    by 0x38FBA5: zend_call_function (zend_execute_API.c:756)
==32515==    by 0x2CDF54: zif_call_user_func_array (basic_functions.c:4942)
==32515==    by 0x42B7B4: ZEND_DO_FCALL_BY_NAME_SPEC_RETVAL_USED_HANDLER (zend_vm_execute.h:892)
==32515==    by 0x42B7B4: execute_ex (zend_vm_execute.h:55481)
==32515==    by 0x42DC69: zend_execute (zend_vm_execute.h:60881)
==32515==    by 0x39E3F2: zend_execute_scripts (zend.c:1568)
==32515==    by 0x33CD0F: php_execute_script (main.c:2630)
==32515== 
==32515== Conditional jump or move depends on uninitialised value(s)
==32515==    at 0x210DA389: ???
==32515==    by 0x21014C47: ???
==32515==    by 0x21014C47: ???
==32515==    by 0x21015AB0: ???
==32515==    by 0x9A3F4FF: ???
==32515==    by 0x21014C47: ???
==32515== 
==32515== Conditional jump or move depends on uninitialised value(s)
==32515==    at 0x210DA389: ???
==32515==    by 0x23661DD7: ???
==32515==    by 0x23661DD7: ???
==32515==    by 0x23662C3B: ???
==32515==    by 0x9A3F4FF: ???
==32515==    by 0x23661DD7: ???
==32515== 

vex: the `impossible' happened:
   isZeroU
vex storage: T total 3415284120 bytes allocated
vex storage: P total 640 bytes allocated

valgrind: the 'impossible' happened:
   LibVEX called failure_exit().

host stacktrace:
==32515==    at 0x38083F48: ??? (in /usr/lib/valgrind/memcheck-amd64-linux)
==32515==    by 0x38084064: ??? (in /usr/lib/valgrind/memcheck-amd64-linux)
==32515==    by 0x380842A1: ??? (in /usr/lib/valgrind/memcheck-amd64-linux)
==32515==    by 0x380842CA: ??? (in /usr/lib/valgrind/memcheck-amd64-linux)
==32515==    by 0x3809F682: ??? (in /usr/lib/valgrind/memcheck-amd64-linux)
==32515==    by 0x38145428: ??? (in /usr/lib/valgrind/memcheck-amd64-linux)
==32515==    by 0x3815256D: ??? (in /usr/lib/valgrind/memcheck-amd64-linux)
==32515==    by 0x38156692: ??? (in /usr/lib/valgrind/memcheck-amd64-linux)
==32515==    by 0x381572C6: ??? (in /usr/lib/valgrind/memcheck-amd64-linux)
==32515==    by 0x38159188: ??? (in /usr/lib/valgrind/memcheck-amd64-linux)
==32515==    by 0x3815A1D6: ??? (in /usr/lib/valgrind/memcheck-amd64-linux)
==32515==    by 0x3814320C: ??? (in /usr/lib/valgrind/memcheck-amd64-linux)
==32515==    by 0x380A1C0B: ??? (in /usr/lib/valgrind/memcheck-amd64-linux)
==32515==    by 0x380D296B: ??? (in /usr/lib/valgrind/memcheck-amd64-linux)
==32515==    by 0x380D45CF: ??? (in /usr/lib/valgrind/memcheck-amd64-linux)
==32515==    by 0x380E3946: ??? (in /usr/lib/valgrind/memcheck-amd64-linux)

sched status:
  running_tid=1

Thread 1: status = VgTs_Runnable (lwpid 32515)
==32515==    at 0xBAAE4C0: ??? (in /lib/x86_64-linux-gnu/libcrypto.so.1.0.0)
==32515==    by 0xBA8D13F: EC_POINT_mul (in /lib/x86_64-linux-gnu/libcrypto.so.1.0.0)
==32515==    by 0x8E8304CBD4DD2CFF: ???
==32515==    by 0x2148606F: ???
==32515==    by 0xBA95B39: EC_KEY_generate_key (in /lib/x86_64-linux-gnu/libcrypto.so.1.0.0)
==32515==    by 0xB76DD24: ??? (in /lib/x86_64-linux-gnu/libssl.so.1.0.0)
==32515==    by 0xB771967: ??? (in /lib/x86_64-linux-gnu/libssl.so.1.0.0)
==32515==    by 0xB77B145: ??? (in /lib/x86_64-linux-gnu/libssl.so.1.0.0)
==32515==    by 0x1B322514: ??? (in /usr/lib/x86_64-linux-gnu/libpq.so.5.8)
==32515==    by 0x1B30DEA7: PQconnectPoll (in /usr/lib/x86_64-linux-gnu/libpq.so.5.8)
==32515==    by 0x1B30EAAD: ??? (in /usr/lib/x86_64-linux-gnu/libpq.so.5.8)
==32515==    by 0x1B30F426: PQconnectdb (in /usr/lib/x86_64-linux-gnu/libpq.so.5.8)
==32515==    by 0x1B0F9302: pdo_pgsql_handle_factory (pgsql_driver.c:1225)
==32515==    by 0xA0330DD: zim_PDO_dbh_constructor (pdo_dbh.c:356)
==32515==    by 0x42D597: ZEND_DO_FCALL_SPEC_RETVAL_UNUSED_HANDLER (zend_vm_execute.h:980)
==32515==    by 0x42D597: execute_ex (zend_vm_execute.h:55485)
==32515==    by 0x38FBA5: zend_call_function (zend_execute_API.c:756)
==32515==    by 0x2CDD71: zif_call_user_func (basic_functions.c:4916)
==32515==    by 0x42B7B4: ZEND_DO_FCALL_BY_NAME_SPEC_RETVAL_USED_HANDLER (zend_vm_execute.h:892)
==32515==    by 0x42B7B4: execute_ex (zend_vm_execute.h:55481)
==32515==    by 0x38FBA5: zend_call_function (zend_execute_API.c:756)
==32515==    by 0x3D097F: zend_std_call_issetter (zend_object_handlers.c:316)
==32515==    by 0x3D3F98: zend_std_has_property (zend_object_handlers.c:1659)
==32515==    by 0x3E337C: ZEND_ISSET_ISEMPTY_PROP_OBJ_SPEC_UNUSED_CONST_HANDLER
(zend_vm_execute.h:32444)
==32515==    by 0x428388: execute_ex (zend_vm_execute.h:58895)
==32515==    by 0x38FBA5: zend_call_function (zend_execute_API.c:756)
==32515==    by 0x2CDF54: zif_call_user_func_array (basic_functions.c:4942)
==32515==    by 0x42B7B4: ZEND_DO_FCALL_BY_NAME_SPEC_RETVAL_USED_HANDLER (zend_vm_execute.h:892)
==32515==    by 0x42B7B4: execute_ex (zend_vm_execute.h:55481)
==32515==    by 0x42DC69: zend_execute (zend_vm_execute.h:60881)
==32515==    by 0x39E3F2: zend_execute_scripts (zend.c:1568)
==32515==    by 0x33CD0F: php_execute_script (main.c:2630)
==32515==    by 0x430108: do_cli (php_cli.c:997)
==32515==    by 0x1F68DB: main (php_cli.c:1389)

------------------------------------------------------------------------
[2019-04-15 08:41:22] nikic@php.net

Would it be possible for you to run the CLI script under "USE_ZEND_ALLOC=0 valgrind php
script.php" and provide the resulting log?

------------------------------------------------------------------------


The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at

    https://bugs.php.net/bug.php?id=77734


--
Edit this bug report at https://bugs.php.net/bug.php?id=77734&edit=1


Thread (8 messages)

« previous php.bugs (#220724) next »