Edit report at https://bugs.php.net/bug.php?id=80909&edit=1
ID: 80909
Comment by: calvin at cmpct dot info
Reported by: calvin at cmpct dot info
Summary: Memory leak and possible double free using PDO_ODBC
Status: Open
Type: Bug
Package: PDO ODBC
Operating System: Debian 9
PHP Version: master-Git-2021-03-26 (Git)
Block user comment: N
Private report: N
New Comment:
FWIW, I can still reproduce this on 8.2 master (b582427ff53db38cac3e23d3c990814da418038c), but I
think the symptom might have changed.
Test program using MariaDB's ODBC driver (so we can discount IBM's weird driver), running
on Fedora 35:
```
<?php
$connection = new PDO('odbc:Driver=MariaDB;Database=<DB here>',
'username', 'password', array(PDO::ATTR_PERSISTENT => true));
```
Gets:
```
$ /tmp/php/bin/php ../test-pdo-odbc-mariadb.php
[Tue Feb 15 11:04:47 2022] Script: '/home/calvin/src/test-pdo-odbc-mariadb.php'
/home/calvin/src/php-src/Zend/zend_smart_str.c(164) : Freeing 0x00007f2daa285300 (224 bytes),
script=/home/calvin/src/test-pdo-odbc-mariadb.php
=== Total 1 memory leaks detected ===
munmap_chunk(): invalid pointer
Aborted (core dumped)
```
The address of the leaked pointer changes, and it only leaks if the connection is successful; it
will always crash with munmap_chunk() regardless. USE_ZEND_ALLOC=0 seems to make it work, but
probably by covering it up.
Previous Comments:
------------------------------------------------------------------------
[2021-05-04 22:48:55] calvin at cmpct dot info
I'm poking this in GDB and I think it's the connection string (or a chunk of it)
that's getting leaked. Transcript from my session: https://gist.githubusercontent.com/NattyNarwhal/69359a88979e254b6f9eb9e91512c522/raw/ddeed94e65f4401092b9ba8586dfc883b9c44fd0/gistfile1.txt
------------------------------------------------------------------------
[2021-05-04 20:16:11] calvin at cmpct dot info
Just FWIW, I can reproduce this issue on Fedora with MariaDB's ODBC driver, and with all other
drivers disabled in odbcinst.ini. I don't think this is an ODBC driver issue as a result.
------------------------------------------------------------------------
[2021-03-30 18:24:59] calvin at cmpct dot info
Let me know if you need access to a system/the driver. I wonder if this is a possible IBM driver bug
and PHP is taking the blame here, but it's odd I can only repro on Linux if so.
------------------------------------------------------------------------
[2021-03-30 17:54:03] cmb@php.net
FWIW, I cannot reproduce this on Windows (SQLServer).
------------------------------------------------------------------------
[2021-03-26 19:41:14] calvin at cmpct dot info
GDB:
Program received signal SIGABRT, Aborted.
__GI_raise (sig=sig@entry=6) at ../sysdeps/unix/sysv/linux/raise.c:51
51 ../sysdeps/unix/sysv/linux/raise.c: No such file or directory.
(gdb) where
#0 __GI_raise (sig=sig@entry=6) at ../sysdeps/unix/sysv/linux/raise.c:51
#1 0x00007ffff63db42a in __GI_abort () at abort.c:89
#2 0x00007ffff6417c00 in __libc_message (do_abort=do_abort@entry=2, fmt=fmt@entry=0x7ffff650cfd0
"*** Error in `%s': %s: 0x%s ***\n") at ../sysdeps/posix/libc_fatal.c:175
#3 0x00007ffff641dfc6 in malloc_printerr (action=3, str=0x7ffff6509b58 "free(): invalid
size", ptr=<optimized out>, ar_ptr=<optimized out>) at malloc.c:5049
#4 0x00007ffff641e80e in _int_free (av=0x7ffff6740b00 <main_arena>, p=0x7ffff30792f0,
have_lock=0) at malloc.c:3905
#5 0x000055555580ae35 in dbh_free (dbh=0x5555568e67d0, free_persistent=true) at
/home/calvin/php-src/ext/pdo/pdo_dbh.c:1450
#6 0x000055555580b231 in php_pdo_pdbh_dtor (res=0x555556907360) at
/home/calvin/php-src/ext/pdo/pdo_dbh.c:1514
#7 0x0000555555a88235 in plist_entry_destructor (zv=0x7fffffffe2f0) at
/home/calvin/php-src/Zend/zend_list.c:195
#8 0x0000555555a83231 in _zend_hash_del_el_ex (ht=0x555556772e88 <executor_globals+616>,
idx=0, p=0x5555568fdff0, prev=0x0) at /home/calvin/php-src/Zend/zend_hash.c:1352
#9 0x0000555555a832fd in _zend_hash_del_el (ht=0x555556772e88 <executor_globals+616>, idx=0,
p=0x5555568fdff0) at /home/calvin/php-src/Zend/zend_hash.c:1375
#10 0x0000555555a84b18 in zend_hash_graceful_reverse_destroy (ht=0x555556772e88
<executor_globals+616>) at /home/calvin/php-src/Zend/zend_hash.c:1829
#11 0x0000555555a88347 in zend_destroy_rsrc_list (ht=0x555556772e88 <executor_globals+616>) at
/home/calvin/php-src/Zend/zend_list.c:228
#12 0x0000555555a6b8d7 in zend_shutdown () at /home/calvin/php-src/Zend/zend.c:1087
#13 0x00005555559d7257 in php_module_shutdown () at /home/calvin/php-src/main/main.c:2371
#14 0x0000555555bc0c3b in main (argc=2, argv=0x55555678b670) at
/home/calvin/php-src/sapi/cli/php_cli.c:1387
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=80909
--
Edit this bug report at https://bugs.php.net/bug.php?id=80909&edit=1