Bug #79270 [Com]: segfault in libodbc.so.2.0.0 with ReflectionFunction($functio)->getParameters()

From: Date: Tue, 10 Nov 2020 01:18:25 +0000
Subject: Bug #79270 [Com]: segfault in libodbc.so.2.0.0 with ReflectionFunction($functio)->getParameters()
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-230246@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=79270&edit=1

 ID:                 79270
 Comment by:         alexander dot stix at erwinmueller dot de
 Reported by:        martin dot aschenbrenner at erwinmueller dot de
 Summary:            segfault in libodbc.so.2.0.0 with
                     ReflectionFunction($functio)->getParameters()
 Status:             Assigned
 Type:               Bug
 Package:            PDO ODBC
 Operating System:   Linux Ubuntu 18.04 x86_64
 PHP Version:        7.3.14
 Assigned To:        cmb
 Block user comment: N
 Private report:     N

 New Comment:

The attached patch didn't fix the issue.


Previous Comments:
------------------------------------------------------------------------
[2020-11-09 14:17:20] cmb@php.net

The following pull request has been associated:

Patch Name: Fix #79270: segfault in libodbc.so.2.0.0
On GitHub:  https://github.com/php/php-src/pull/6413
Patch:      https://github.com/php/php-src/pull/6413.patch

------------------------------------------------------------------------
[2020-11-05 11:48:20] cmb@php.net

Could you please try the attached bug79270.patch?

------------------------------------------------------------------------
[2020-11-05 11:47:30] cmb@php.net

The following patch has been added/updated:

Patch Name: bug79270.patch
Revision:   1604576850
URL:        https://bugs.php.net/patch-display.php?bug=79270&patch=bug79270.patch&revision=1604576850

------------------------------------------------------------------------
[2020-11-05 11:38:50] cmb@php.net

> […] supposed to call the free_object handlers of the objects in
> reverse order of their creation […]

I just learned that this is not true.  I'll have a closer look.

------------------------------------------------------------------------
[2020-11-05 11:20:28] cmb@php.net

Thanks for the valgrind report.  I've moved the full report to a
Gist[1] to keep this ticket more lucid.  I'm ignoring the
Conditional jump or move depends on uninitialised value(s) in
zend_string_equal_val() , because these only occur under valgrind
and might be false positives.  So the first relevant items are:

==2860== Conditional jump or move depends on uninitialised value(s)
==2860==    at 0x9440B70: my_SQLFreeStmtExtended (in /usr/lib/x86_64-linux-gnu/odbc/libmyodbc8w.so)
==2860==    by 0x9441014: my_SQLFreeStmt (in /usr/lib/x86_64-linux-gnu/odbc/libmyodbc8w.so)
==2860==    by 0x9433993: free_connection_stmts (in /usr/lib/x86_64-linux-gnu/odbc/libmyodbc8w.so)
==2860==    by 0x94339B0: SQLDisconnect (in /usr/lib/x86_64-linux-gnu/odbc/libmyodbc8w.so)
==2860==    by 0x58703D9: SQLDisconnect (in /usr/lib/x86_64-linux-gnu/libodbc.so.2.0.0)
==2860==    by 0x504AF1: odbc_handle_closer (odbc_driver.c:131)
==2860==    by 0x4F6B68: dbh_free (pdo_dbh.c:1515)
==2860==    by 0x6FDBC1: zend_objects_store_free_object_storage (zend_objects_API.c:104)
==2860==    by 0x6B8054: shutdown_executor (zend_execute_API.c:342)
==2860==    by 0x6C7992: zend_deactivate (zend.c:1198)
==2860==    by 0x665D6A: php_request_shutdown (main.c:1921)
==2860==    by 0x751453: do_cli (php_cli.c:1132)
==2860== 
==2860== Invalid read of size 4
==2860==    at 0x589BE37: ??? (in /usr/lib/x86_64-linux-gnu/libodbc.so.2.0.0)
==2860==    by 0x58769F7: ??? (in /usr/lib/x86_64-linux-gnu/libodbc.so.2.0.0)
==2860==    by 0x5069F1: odbc_stmt_dtor (odbc_stmt.c:148)
==2860==    by 0x5005CC: php_pdo_free_statement (pdo_stmt.c:2272)
==2860==    by 0x6FDBC1: zend_objects_store_free_object_storage (zend_objects_API.c:104)
==2860==    by 0x6B8054: shutdown_executor (zend_execute_API.c:342)
==2860==    by 0x6C7992: zend_deactivate (zend.c:1198)
==2860==    by 0x665D6A: php_request_shutdown (main.c:1921)
==2860==    by 0x751453: do_cli (php_cli.c:1132)
==2860==    by 0x358697: main (php_cli.c:1359)

That shows that the issue happens during shutdown, namely in
zend_objects_store_free_object_storage() which is supposed to call
the free_object handlers of the objects in reverse order of their
creation, i.e. first the statement and then the database handle.
For some reason, in your case dbh_free() is called before
php_pdo_free_statement(), though, causing a crash.

[1] <https://gist.github.com/cmb69/337c02a21d6d7a9fd29f8d725f052945>

------------------------------------------------------------------------


The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at

    https://bugs.php.net/bug.php?id=79270


--
Edit this bug report at https://bugs.php.net/bug.php?id=79270&edit=1


Thread (19 messages)

« previous php.bugs (#230246) next »