Edit report at https://bugs.php.net/bug.php?id=80909&edit=1
ID: 80909
Comment by: calvin at cmpct dot info
Reported by: calvin at cmpct dot info
Summary: Memory leak and possible double free using PDO_ODBC
Status: Open
Type: Bug
Package: PDO ODBC
Operating System: Debian 9
PHP Version: master-Git-2021-03-26 (Git)
Block user comment: N
Private report: N
New Comment:
I can confirm it's the constructed connection string (if you supply UID/PWD as args for the PDO
ctor instead of on the connection string itself) that's leaking:
```
(gdb) break main.c:1604
Breakpoint 1 at 0x965f35: file /home/calvin/src/php-src/main/main.c, line 1604.
(gdb) run
Starting program: /tmp/php/bin/php ../test-pdo-odbc-mariadb.php
This GDB supports auto-downloading debuginfo from the following URLs:
https://debuginfod.fedoraproject.org/
Enable debuginfod for this session? (y or [n]) y
Debuginfod has been enabled.
To make this setting permanent, add 'set debuginfod enabled on' to .gdbinit.
[Thread debugging using libthread_db enabled]
Using host libthread_db library "/lib64/libthread_db.so.1".
[Tue Feb 15 11:15:16 2022] Script: '/home/calvin/src/test-pdo-odbc-mariadb.php'
Breakpoint 1, php_message_handler_for_zend (message=4, data=0x7fffffffbe70) at
/home/calvin/src/php-src/main/main.c:1604
1604 snprintf(memory_leak_buf, 512, "%s(%" PRIu32 ") : Freeing "
ZEND_ADDR_FMT " (%zu bytes), script=%s\n", t->filename, t->lineno,
(size_t)t->addr, t->size, SAFE_FILENAME(SG(request_info).path_translated));
(gdb) p t
$1 = (zend_leak_info *) 0x7fffffffbe70
(gdb) p *t
$2 = {addr = 0x7ffff7685300, size = 224, filename = 0x14bf478
"/home/calvin/src/php-src/Zend/zend_smart_str.c", orig_filename = 0x0, lineno = 164,
orig_lineno = 0}
(gdb) p (char*)0x7ffff7685300
$3 = 0x7ffff7685300
"Driver=MariaDB;Database=<database>;UID=<UID>;PWD=<Password>"
```
Previous Comments:
------------------------------------------------------------------------
[2022-02-15 15:07:46] calvin at cmpct dot info
FWIW, I can still reproduce this on 8.2 master (b582427ff53db38cac3e23d3c990814da418038c), but I
think the symptom might have changed.
Test program using MariaDB's ODBC driver (so we can discount IBM's weird driver), running
on Fedora 35:
```
<?php
$connection = new PDO('odbc:Driver=MariaDB;Database=<DB here>',
'username', 'password', array(PDO::ATTR_PERSISTENT => true));
```
Gets:
```
$ /tmp/php/bin/php ../test-pdo-odbc-mariadb.php
[Tue Feb 15 11:04:47 2022] Script: '/home/calvin/src/test-pdo-odbc-mariadb.php'
/home/calvin/src/php-src/Zend/zend_smart_str.c(164) : Freeing 0x00007f2daa285300 (224 bytes),
script=/home/calvin/src/test-pdo-odbc-mariadb.php
=== Total 1 memory leaks detected ===
munmap_chunk(): invalid pointer
Aborted (core dumped)
```
The address of the leaked pointer changes, and it only leaks if the connection is successful; it
will always crash with munmap_chunk() regardless. USE_ZEND_ALLOC=0 seems to make it work, but
probably by covering it up.
------------------------------------------------------------------------
[2021-05-04 22:48:55] calvin at cmpct dot info
I'm poking this in GDB and I think it's the connection string (or a chunk of it)
that's getting leaked. Transcript from my session: https://gist.githubusercontent.com/NattyNarwhal/69359a88979e254b6f9eb9e91512c522/raw/ddeed94e65f4401092b9ba8586dfc883b9c44fd0/gistfile1.txt
------------------------------------------------------------------------
[2021-05-04 20:16:11] calvin at cmpct dot info
Just FWIW, I can reproduce this issue on Fedora with MariaDB's ODBC driver, and with all other
drivers disabled in odbcinst.ini. I don't think this is an ODBC driver issue as a result.
------------------------------------------------------------------------
[2021-03-30 18:24:59] calvin at cmpct dot info
Let me know if you need access to a system/the driver. I wonder if this is a possible IBM driver bug
and PHP is taking the blame here, but it's odd I can only repro on Linux if so.
------------------------------------------------------------------------
[2021-03-30 17:54:03] cmb@php.net
FWIW, I cannot reproduce this on Windows (SQLServer).
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=80909
--
Edit this bug report at https://bugs.php.net/bug.php?id=80909&edit=1