Bug #80909 [Com]: Memory leak and possible double free using PDO_ODBC

From: Date: Tue, 15 Feb 2022 15:17:59 +0000
Subject: Bug #80909 [Com]: Memory leak and possible double free using PDO_ODBC
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-239814@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=80909&edit=1

 ID:                 80909
 Comment by:         calvin at cmpct dot info
 Reported by:        calvin at cmpct dot info
 Summary:            Memory leak and possible double free using PDO_ODBC
 Status:             Open
 Type:               Bug
 Package:            PDO ODBC
 Operating System:   Debian 9
 PHP Version:        master-Git-2021-03-26 (Git)
 Block user comment: N
 Private report:     N

 New Comment:

I can confirm it's the constructed connection string (if you supply UID/PWD as args for the PDO
ctor instead of on the connection string itself) that's leaking:

```
(gdb) break main.c:1604
Breakpoint 1 at 0x965f35: file /home/calvin/src/php-src/main/main.c, line 1604.
(gdb) run
Starting program: /tmp/php/bin/php ../test-pdo-odbc-mariadb.php

This GDB supports auto-downloading debuginfo from the following URLs:
https://debuginfod.fedoraproject.org/ 
Enable debuginfod for this session? (y or [n]) y
Debuginfod has been enabled.
To make this setting permanent, add 'set debuginfod enabled on' to .gdbinit.
[Thread debugging using libthread_db enabled]
Using host libthread_db library "/lib64/libthread_db.so.1".
[Tue Feb 15 11:15:16 2022]  Script:  '/home/calvin/src/test-pdo-odbc-mariadb.php'

Breakpoint 1, php_message_handler_for_zend (message=4, data=0x7fffffffbe70) at
/home/calvin/src/php-src/main/main.c:1604
1604						snprintf(memory_leak_buf, 512, "%s(%" PRIu32 ") :  Freeing "
ZEND_ADDR_FMT " (%zu bytes), script=%s\n", t->filename, t->lineno,
(size_t)t->addr, t->size, SAFE_FILENAME(SG(request_info).path_translated));
(gdb) p t
$1 = (zend_leak_info *) 0x7fffffffbe70
(gdb) p *t
$2 = {addr = 0x7ffff7685300, size = 224, filename = 0x14bf478
"/home/calvin/src/php-src/Zend/zend_smart_str.c", orig_filename = 0x0, lineno = 164,
orig_lineno = 0}
(gdb) p (char*)0x7ffff7685300
$3 = 0x7ffff7685300
"Driver=MariaDB;Database=<database>;UID=<UID>;PWD=<Password>"
```


Previous Comments:
------------------------------------------------------------------------
[2022-02-15 15:07:46] calvin at cmpct dot info

FWIW, I can still reproduce this on 8.2 master (b582427ff53db38cac3e23d3c990814da418038c), but I
think the symptom might have changed.

Test program using MariaDB's ODBC driver (so we can discount IBM's weird driver), running
on Fedora 35:

```
<?php

$connection = new PDO('odbc:Driver=MariaDB;Database=<DB here>',
'username', 'password', array(PDO::ATTR_PERSISTENT => true));

```

Gets:

```
$ /tmp/php/bin/php ../test-pdo-odbc-mariadb.php 
[Tue Feb 15 11:04:47 2022]  Script:  '/home/calvin/src/test-pdo-odbc-mariadb.php'
/home/calvin/src/php-src/Zend/zend_smart_str.c(164) :  Freeing 0x00007f2daa285300 (224 bytes),
script=/home/calvin/src/test-pdo-odbc-mariadb.php
=== Total 1 memory leaks detected ===
munmap_chunk(): invalid pointer
Aborted (core dumped)
```

The address of the leaked pointer changes, and it only leaks if the connection is successful; it
will always crash with munmap_chunk() regardless. USE_ZEND_ALLOC=0 seems to make it work, but
probably by covering it up.

------------------------------------------------------------------------
[2021-05-04 22:48:55] calvin at cmpct dot info

I'm poking this in GDB and I think it's the connection string (or a chunk of it)
that's getting leaked. Transcript from my session: https://gist.githubusercontent.com/NattyNarwhal/69359a88979e254b6f9eb9e91512c522/raw/ddeed94e65f4401092b9ba8586dfc883b9c44fd0/gistfile1.txt

------------------------------------------------------------------------
[2021-05-04 20:16:11] calvin at cmpct dot info

Just FWIW, I can reproduce this issue on Fedora  with MariaDB's ODBC driver, and with all other
drivers disabled in odbcinst.ini. I don't think this is an ODBC driver issue as a result.

------------------------------------------------------------------------
[2021-03-30 18:24:59] calvin at cmpct dot info

Let me know if you need access to a system/the driver. I wonder if this is a possible IBM driver bug
and PHP is taking the blame here, but it's odd I can only repro on Linux if so.

------------------------------------------------------------------------
[2021-03-30 17:54:03] cmb@php.net

FWIW, I cannot reproduce this on Windows (SQLServer).

------------------------------------------------------------------------


The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at

    https://bugs.php.net/bug.php?id=80909


--
Edit this bug report at https://bugs.php.net/bug.php?id=80909&edit=1


Thread (10 messages)

« previous php.bugs (#239814) next »