php / php/php-src

Assertion failure at link_errno_read in ext/mysqli/mysqli_prop.c

Open
#22,854 0 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Bug Extension: mysqli Status: Verified
Dominant language
C
Stars
40.4k
Forks
8.1k
Avg merge
2d 13h
Merged PRs (30d)
96

Description

Description

#17900

The following code:

<?php
try {
try { $cls = new mysqli(); } catch (\Throwable $_e) { $cls = new stdClass(); }
$path = $argv[1] ?? __FILE__;
if (is_file($path)) {
$code = file_get_contents($path);
if ($code !== false) {
eval('?>' . $code);
}
}
var_dump(get_defined_vars());
try { $cls->connect($fusion,$fusion,$fusion,$fusion,$fusion,$fusion); } catch (\Throwable $e) {};
} catch (\Throwable $_ffl_e) {}

Resulted in this output:

php: /home/fuzz/WorkSpace/fusion-fuzz/projects/php/php-src/ext/mysqli/mysqli_prop.c:225: zend_result link_errno_read(mysqli_object *, zval *, _Bool): Assertion `p' failed.
Aborted (core dumped)

To reproduce:

/home/fuzz/WorkSpace/fusion-fuzz/projects/php/php-src/sapi/cli/php  ./test.php

Commit:

55c4eb2a1b859c04c1eab8b17b15825e656e5a83

Configurations:

CC="clang-12" CXX="clang++-12" CFLAGS="-DZEND_VERIFY_TYPE_INFERENCE" CXXFLAGS="-DZEND_VERIFY_TYPE_INFERENCE" ./configure --enable-debug --enable-address-sanitizer --enable-undefined-sanitizer --enable-re2c-cgoto --enable-fpm --enable-litespeed --enable-phpdbg-debug --enable-zts --enable-bcmath --enable-calendar --enable-dba --enable-dl-test --enable-exif --enable-ftp --enable-gd --enable-gd-jis-conv --enable-mbstring --enable-pcntl --enable-shmop --enable-soap --enable-sockets --enable-sysvmsg --enable-zend-test --with-zlib --with-bz2 --with-curl --with-enchant --with-gettext --with-gmp --with-mhash --with-ldap --with-libedit --with-readline --with-snmp --with-sodium --with-xsl --with-zip --with-mysqli --with-pdo-mysql --with-pdo-pgsql --with-pgsql --with-sqlite3 --with-pdo-sqlite --with-webp --with-jpeg --with-freetype --enable-sigchild --with-readline --with-pcre-jit --with-iconv

Operating System:

Ubuntu 20.04 Host, Docker 0599jiangyc/flowfusion:latest

This bug was found by fusion-fuzz

PHP Version
nightly
Operating System

No response

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start with ext/mysqli/mysqli_prop.c at line 225 and reproduce the assertion using the supplied PHP script and debug CLI command. Trace link_errno_read through the mysqli connect call and compare the reported state with the reproducer; done means the script no longer aborts with this assertion under the stated configuration.

Written by the indexing model from the issue text.

Assessment

Tech stack
c
Domain
databases
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Quiet
Clarity
Needs clarification
Newbie friendliness
45/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.