Bug #7219 Updated: Mysql-related stack fault with PHP 4.0.3
| From: | sniper@php.net | Date: | Tue, 18 Jun 2002 22:15:28 +0000 |
| Subject: | Bug #7219 Updated: Mysql-related stack fault with PHP 4.0.3 | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-11213@lists.php.net to get a copy of this message | ||
ID: 7219
Updated by: sniper@php.net
Reported By: rubein@earthlink.net
-Status: Duplicate
+Status: Bogus
Bug Type: Reproducible crash
Operating System: Win98
PHP Version: 4.0.3
New Comment:
you can cause these with any infinite recursive function for example.
The #8471 bug is Suspended..no need to have duplicates of it.
Previous Comments:
------------------------------------------------------------------------
[2001-01-09 12:48:53] derick@php.net
dup of 8471
------------------------------------------------------------------------
[2001-01-09 12:47:43] sniper@php.net
Duplicate of #8471
------------------------------------------------------------------------
[2001-01-09 12:38:01] cynic@php.net
user feedback:
----
I no longer have the offending code handy (it was buggy and has since
been fixed), however I have seriously narrowed it down to what causes
it. The following code, however, reproduces the crash in both PHP 4.0.3
and PHP 4.0.4
<?
function test() {
test();
}
test();
?>
----
PHP doesn't check for the level of recursion, so such a function will
eventually eat up all of your memory. You have to perform due checks
and break as needed.
------------------------------------------------------------------------
[2001-01-07 03:57:26] sniper@php.net
Does this happen with PHP 4.0.4 ??
--Jani
------------------------------------------------------------------------
[2000-10-15 09:51:00] rubein@earthlink.net
Actually, after more thorough testing it was determined that *this* was
the cause of the problem, a function which depended on the code of the
above function:
function secALevel($resid, $restable, $realmid, $uid, $explicit = 0) {
// Determine the parent tree
if($explicit == 1)
$plist = array(array(0 => $resid, 1 => $restable));
else
$plist = brdParentTree($resid, $restable, $realmid);
$prequery = array();
foreach($plist AS $value) {
$prequery[] = "(parent=$value[0] AND parent_table=$value[1])"; /*
CAUSES CRASHES */
}
$whereclause = implode(" OR ", $prequery);
echo "\n<BR>DEBUG: whereclause is $whereclause";
flush();
// Perform the query
if(!$result = mysql_query("SELECT value FROM access AS a,users AS u
WHERE ($whereclause) AND uid=$uid"))
htmPageError("secALevel(): Failed to retrieve access list. " .
sqlError());
$ret = AL_GUEST;
while($row = mysql_fetch_array($result, MYSQL_ASSOC)) {
if($row["level"] > $ret || ($row["level"] == AL_NEWBIE && $ret =
AL_USER)) $ret = $row["level"];
}
return $ret;
}
---
If the commented CAUSES crashes line is changed so that the string is
properly quoted (within the query, e.g.) AND has the closing
parenthesis, things work fine. E.g. replacing it with this line works:
$prequery[] = "(parent=$value[0] AND parent_table=" .
strQuote($value[1]) . ")";
(strQuote is a small function I wrote that either returns 'null' or an
escaped string with quotation marks around it, useful for turning user
input into mysql queries)
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
http://bugs.php.net/7219
--
Edit this bug report at http://bugs.php.net/?id=7219&edit=1