Bug #77734 [Opn->Dup]: Seg Fault caused by php_mysqlnd_free_field_metadata
Edit report at https://bugs.php.net/bug.php?id=77734&edit=1
ID: 77734
Updated by: sjon@php.net
Reported by: scott at exussum dot co dot uk
Summary: Seg Fault caused by php_mysqlnd_free_field_metadata
-Status: Open
+Status: Duplicate
Type: Bug
Package: PDO MySQL
Operating System: Ubuntu 18.04
PHP Version: 7.3.3
Block user comment: N
Private report: N
New Comment:
duplicate of bug #77955 (which has a better backtrace)
Previous Comments:
------------------------------------------------------------------------
[2019-05-07 08:02:41] sjon at hortensius dot net
I think this bug is duplicated by #77955 which has a better stacktrace with debug-symbols
------------------------------------------------------------------------
[2019-04-15 10:48:34] scott at exussum dot co dot uk
Anything else I can do for debugging ? I can make it happen fairly often
------------------------------------------------------------------------
[2019-04-15 10:15:42] nikic@php.net
Unfortunately these all look like false positives (the ??? are likely from PCRE JIT and
zend_string_equal_val is expected) and valgrind itself crashed before it got to anything interesting
:(
------------------------------------------------------------------------
[2019-04-15 10:06:29] scott at exussum dot co dot uk
I dont have all debug symbols, working on getting more
This is the trace though - hope it helps in some way ?
==32515== Conditional jump or move depends on uninitialised value(s)
==32515== at 0x421F165: ???
==32515== by 0x2324D8F7: ???
==32515== by 0x2324D8F7: ???
==32515== by 0x2324D91D: ???
==32515== by 0x9A3F4FF: ???
==32515== by 0x2324D8F7: ???
==32515==
+------------------------------------+
==32515== Conditional jump or move depends on uninitialised value(s)
==32515== at 0x421F144: ???
==32515== by 0x228FE0E7: ???
==32515== by 0x228FE0E7: ???
==32515== by 0x228FE0EB: ???
==32515== by 0x9A3F4FF: ???
==32515== by 0x228FE0E7: ???
==32515==
==32515== Conditional jump or move depends on uninitialised value(s)
==32515== at 0x3C7C92: zend_string_equal_val (zend_string.c:403)
==32515== by 0x40DCFC: zend_string_equal_content (zend_string.h:310)
==32515== by 0x40DCFC: zend_fast_equal_strings (zend_operators.h:734)
==32515== by 0x40DCFC: ZEND_IS_EQUAL_SPEC_CV_CV_HANDLER (zend_vm_execute.h:48290)
==32515== by 0x42730C: execute_ex (zend_vm_execute.h:60509)
==32515== by 0x38FBA5: zend_call_function (zend_execute_API.c:756)
==32515== by 0x2CA422: zif_array_filter (array.c:6059)
==32515== by 0x42B7B4: ZEND_DO_FCALL_BY_NAME_SPEC_RETVAL_USED_HANDLER (zend_vm_execute.h:892)
==32515== by 0x42B7B4: execute_ex (zend_vm_execute.h:55481)
==32515== by 0x38FBA5: zend_call_function (zend_execute_API.c:756)
==32515== by 0x2CDF54: zif_call_user_func_array (basic_functions.c:4942)
==32515== by 0x42B7B4: ZEND_DO_FCALL_BY_NAME_SPEC_RETVAL_USED_HANDLER (zend_vm_execute.h:892)
==32515== by 0x42B7B4: execute_ex (zend_vm_execute.h:55481)
==32515== by 0x42DC69: zend_execute (zend_vm_execute.h:60881)
==32515== by 0x39E3F2: zend_execute_scripts (zend.c:1568)
==32515== by 0x33CD0F: php_execute_script (main.c:2630)
==32515==
==32515== Conditional jump or move depends on uninitialised value(s)
==32515== at 0x210DA389: ???
==32515== by 0x21014C47: ???
==32515== by 0x21014C47: ???
==32515== by 0x21015AB0: ???
==32515== by 0x9A3F4FF: ???
==32515== by 0x21014C47: ???
==32515==
==32515== Conditional jump or move depends on uninitialised value(s)
==32515== at 0x210DA389: ???
==32515== by 0x23661DD7: ???
==32515== by 0x23661DD7: ???
==32515== by 0x23662C3B: ???
==32515== by 0x9A3F4FF: ???
==32515== by 0x23661DD7: ???
==32515==
vex: the `impossible' happened:
isZeroU
vex storage: T total 3415284120 bytes allocated
vex storage: P total 640 bytes allocated
valgrind: the 'impossible' happened:
LibVEX called failure_exit().
host stacktrace:
==32515== at 0x38083F48: ??? (in /usr/lib/valgrind/memcheck-amd64-linux)
==32515== by 0x38084064: ??? (in /usr/lib/valgrind/memcheck-amd64-linux)
==32515== by 0x380842A1: ??? (in /usr/lib/valgrind/memcheck-amd64-linux)
==32515== by 0x380842CA: ??? (in /usr/lib/valgrind/memcheck-amd64-linux)
==32515== by 0x3809F682: ??? (in /usr/lib/valgrind/memcheck-amd64-linux)
==32515== by 0x38145428: ??? (in /usr/lib/valgrind/memcheck-amd64-linux)
==32515== by 0x3815256D: ??? (in /usr/lib/valgrind/memcheck-amd64-linux)
==32515== by 0x38156692: ??? (in /usr/lib/valgrind/memcheck-amd64-linux)
==32515== by 0x381572C6: ??? (in /usr/lib/valgrind/memcheck-amd64-linux)
==32515== by 0x38159188: ??? (in /usr/lib/valgrind/memcheck-amd64-linux)
==32515== by 0x3815A1D6: ??? (in /usr/lib/valgrind/memcheck-amd64-linux)
==32515== by 0x3814320C: ??? (in /usr/lib/valgrind/memcheck-amd64-linux)
==32515== by 0x380A1C0B: ??? (in /usr/lib/valgrind/memcheck-amd64-linux)
==32515== by 0x380D296B: ??? (in /usr/lib/valgrind/memcheck-amd64-linux)
==32515== by 0x380D45CF: ??? (in /usr/lib/valgrind/memcheck-amd64-linux)
==32515== by 0x380E3946: ??? (in /usr/lib/valgrind/memcheck-amd64-linux)
sched status:
running_tid=1
Thread 1: status = VgTs_Runnable (lwpid 32515)
==32515== at 0xBAAE4C0: ??? (in /lib/x86_64-linux-gnu/libcrypto.so.1.0.0)
==32515== by 0xBA8D13F: EC_POINT_mul (in /lib/x86_64-linux-gnu/libcrypto.so.1.0.0)
==32515== by 0x8E8304CBD4DD2CFF: ???
==32515== by 0x2148606F: ???
==32515== by 0xBA95B39: EC_KEY_generate_key (in /lib/x86_64-linux-gnu/libcrypto.so.1.0.0)
==32515== by 0xB76DD24: ??? (in /lib/x86_64-linux-gnu/libssl.so.1.0.0)
==32515== by 0xB771967: ??? (in /lib/x86_64-linux-gnu/libssl.so.1.0.0)
==32515== by 0xB77B145: ??? (in /lib/x86_64-linux-gnu/libssl.so.1.0.0)
==32515== by 0x1B322514: ??? (in /usr/lib/x86_64-linux-gnu/libpq.so.5.8)
==32515== by 0x1B30DEA7: PQconnectPoll (in /usr/lib/x86_64-linux-gnu/libpq.so.5.8)
==32515== by 0x1B30EAAD: ??? (in /usr/lib/x86_64-linux-gnu/libpq.so.5.8)
==32515== by 0x1B30F426: PQconnectdb (in /usr/lib/x86_64-linux-gnu/libpq.so.5.8)
==32515== by 0x1B0F9302: pdo_pgsql_handle_factory (pgsql_driver.c:1225)
==32515== by 0xA0330DD: zim_PDO_dbh_constructor (pdo_dbh.c:356)
==32515== by 0x42D597: ZEND_DO_FCALL_SPEC_RETVAL_UNUSED_HANDLER (zend_vm_execute.h:980)
==32515== by 0x42D597: execute_ex (zend_vm_execute.h:55485)
==32515== by 0x38FBA5: zend_call_function (zend_execute_API.c:756)
==32515== by 0x2CDD71: zif_call_user_func (basic_functions.c:4916)
==32515== by 0x42B7B4: ZEND_DO_FCALL_BY_NAME_SPEC_RETVAL_USED_HANDLER (zend_vm_execute.h:892)
==32515== by 0x42B7B4: execute_ex (zend_vm_execute.h:55481)
==32515== by 0x38FBA5: zend_call_function (zend_execute_API.c:756)
==32515== by 0x3D097F: zend_std_call_issetter (zend_object_handlers.c:316)
==32515== by 0x3D3F98: zend_std_has_property (zend_object_handlers.c:1659)
==32515== by 0x3E337C: ZEND_ISSET_ISEMPTY_PROP_OBJ_SPEC_UNUSED_CONST_HANDLER
(zend_vm_execute.h:32444)
==32515== by 0x428388: execute_ex (zend_vm_execute.h:58895)
==32515== by 0x38FBA5: zend_call_function (zend_execute_API.c:756)
==32515== by 0x2CDF54: zif_call_user_func_array (basic_functions.c:4942)
==32515== by 0x42B7B4: ZEND_DO_FCALL_BY_NAME_SPEC_RETVAL_USED_HANDLER (zend_vm_execute.h:892)
==32515== by 0x42B7B4: execute_ex (zend_vm_execute.h:55481)
==32515== by 0x42DC69: zend_execute (zend_vm_execute.h:60881)
==32515== by 0x39E3F2: zend_execute_scripts (zend.c:1568)
==32515== by 0x33CD0F: php_execute_script (main.c:2630)
==32515== by 0x430108: do_cli (php_cli.c:997)
==32515== by 0x1F68DB: main (php_cli.c:1389)
------------------------------------------------------------------------
[2019-04-15 08:41:22] nikic@php.net
Would it be possible for you to run the CLI script under "USE_ZEND_ALLOC=0 valgrind php
script.php" and provide the resulting log?
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=77734
--
Edit this bug report at https://bugs.php.net/bug.php?id=77734&edit=1
Thread (8 messages)