Bug #79270 [Fbk->Opn]: segfault in libodbc.so.2.0.0 with ReflectionFunction($functio)->getParameters()

From: Date: Tue, 20 Oct 2020 11:09:43 +0000
Subject: Bug #79270 [Fbk->Opn]: segfault in libodbc.so.2.0.0 with ReflectionFunction($functio)->getParameters()
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-229790@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=79270&edit=1

 ID:                 79270
 Updated by:         cmb@php.net
 Reported by:        martin dot aschenbrenner at erwinmueller dot de
 Summary:            segfault in libodbc.so.2.0.0 with
                     ReflectionFunction($functio)->getParameters()
-Status:             Feedback
+Status:             Open
 Type:               Bug
 Package:            PDO ODBC
 Operating System:   Linux Ubuntu 18.04 x86_64
 PHP Version:        7.3.14
-Assigned To:        cmb
+Assigned To:        
 Block user comment: N
 Private report:     N

 New Comment:

Thanks for the stack backtrace!  Apparently, there is a serious
issue when the statement handle is freed during shutdown[1].  I
still cannot reproduce this, and from looking at the
implementation, I cannot find anything obviously wrong.  Maybe an
ODBC trace of running the script can bring some insights.  On the
other hand, the fact that this would be related to constructing a
ReflectionFunction, hints at a more general memory management
issue.  This might be debuggable using valgrind; you can find a
description in the phpinternalsbook[2] (just ignore the C code
snippets and respective details).

[1] <https://github.com/php/php-src/blob/php-7.4.11/ext/pdo_odbc/odbc_stmt.c#L148>
[2] <http://www.phpinternalsbook.com/php7/memory_management/memory_debugging.html#before-starting>


Previous Comments:
------------------------------------------------------------------------
[2020-10-19 16:10:19] alexander dot stix at erwinmueller dot de

#0  0x00007f36ff9e2a50 in ?? () from /lib/x86_64-linux-gnu/libodbc.so.2
#1  0x000056403f7559f2 in odbc_stmt_dtor (stmt=<optimized out>) at
/tmp/php-7.4.11/ext/pdo_odbc/odbc_stmt.c:148
#2  0x000056403f74f5cd in php_pdo_free_statement (stmt=0x7f36fcc98300) at
/tmp/php-7.4.11/ext/pdo/pdo_stmt.c:2272
#3  0x000056403f94cbc2 in zend_objects_store_free_object_storage
(objects=objects@entry=0x5640407820e8 <executor_globals+840>,
fast_shutdown=fast_shutdown@entry=1 '\001') at /tmp/php-7.4.11/Zend/zend_objects_API.c:104
#4  0x000056403f907055 in shutdown_executor () at /tmp/php-7.4.11/Zend/zend_execute_API.c:342
#5  0x000056403f916993 in zend_deactivate () at /tmp/php-7.4.11/Zend/zend.c:1198
#6  0x000056403f8b4d6b in php_request_shutdown (dummy=<optimized out>) at
/tmp/php-7.4.11/main/main.c:1921
#7  0x000056403f9a0454 in do_cli (argc=2, argv=0x5640415f1910) at
/tmp/php-7.4.11/sapi/cli/php_cli.c:1132
#8  0x000056403f5a7698 in main (argc=2, argv=0x5640415f1910) at
/tmp/php-7.4.11/sapi/cli/php_cli.c:1359

------------------------------------------------------------------------
[2020-10-19 07:50:50] cmb@php.net

I cannot reproduce the reported behavior with a non debug build.
Could you please provide a stack backtrace[1], so we have at least
some idea what might be wrong there?

[1] <https://bugs.php.net/bugs-generating-backtrace.php>

------------------------------------------------------------------------
[2020-10-16 21:30:18] alexander dot stix at erwinmueller dot de

It also happens with the CLI SAPI.

------------------------------------------------------------------------
[2020-10-16 21:15:20] cmb@php.net

Thanks!  Would that also happen with the CLI SAPI, or is this FPM specific?

------------------------------------------------------------------------
[2020-10-16 21:10:23] alexander dot stix at erwinmueller dot de

I was able to consistently reproduce this behaviour with php-7.4.11 fpm but not when having the
--enable-debug option enabled

------------------------------------------------------------------------


The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at

    https://bugs.php.net/bug.php?id=79270


--
Edit this bug report at https://bugs.php.net/bug.php?id=79270&edit=1


Thread (19 messages)

« previous php.bugs (#229790) next »