Conversation
lazerg
force-pushed
the
fix/gh-23756-pdo-closecursor-during-step
branch
from
September 19, 2026 01:34
3ea4362 to
ac4c145
Compare
devnexen
reviewed
Sep 19, 2026
| @@ -0,0 +1,24 @@ | |||
| --TEST-- | |||
Member
There was a problem hiding this comment.
nit: seems this one passes without the fix, the PR description might need some rephrasing.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
PDOStatement::closeCursor() calls sqlite3_reset() on the underlying sqlite3_stmt. When a collation callback calls it, the reset lands on the statement sqlite3_step() is still running, SQLite tears down the VDBE under itself, and the process segfaults. Re-entering execute() or fetch() from the same callback crashes the same way, through the reset in the parameter hook and the nested step.
The driver statement now records that it is being stepped, and those paths throw an Error instead of reaching SQLite. The running query still finishes, so the statement is usable afterwards. The flag is restored on a bailout too, which keeps closeCursor() working in a shutdown function after a callback called exit().
Fixes #23756