Bug #7219 Updated: Mysql-related stack fault with PHP 4.0.3

From: Date: Tue, 18 Jun 2002 22:15:28 +0000
Subject: Bug #7219 Updated: Mysql-related stack fault with PHP 4.0.3
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-11213@lists.php.net to get a copy of this message
ID: 7219 Updated by: sniper@php.net Reported By: rubein@earthlink.net -Status: Duplicate +Status: Bogus Bug Type: Reproducible crash Operating System: Win98 PHP Version: 4.0.3 New Comment: you can cause these with any infinite recursive function for example. The #8471 bug is Suspended..no need to have duplicates of it. Previous Comments: ------------------------------------------------------------------------ [2001-01-09 12:48:53] derick@php.net dup of 8471 ------------------------------------------------------------------------ [2001-01-09 12:47:43] sniper@php.net Duplicate of #8471 ------------------------------------------------------------------------ [2001-01-09 12:38:01] cynic@php.net user feedback: ---- I no longer have the offending code handy (it was buggy and has since been fixed), however I have seriously narrowed it down to what causes it. The following code, however, reproduces the crash in both PHP 4.0.3 and PHP 4.0.4 <? function test() { test(); } test(); ?> ---- PHP doesn't check for the level of recursion, so such a function will eventually eat up all of your memory. You have to perform due checks and break as needed. ------------------------------------------------------------------------ [2001-01-07 03:57:26] sniper@php.net Does this happen with PHP 4.0.4 ?? --Jani ------------------------------------------------------------------------ [2000-10-15 09:51:00] rubein@earthlink.net Actually, after more thorough testing it was determined that *this* was the cause of the problem, a function which depended on the code of the above function: function secALevel($resid, $restable, $realmid, $uid, $explicit = 0) { // Determine the parent tree if($explicit == 1) $plist = array(array(0 => $resid, 1 => $restable)); else $plist = brdParentTree($resid, $restable, $realmid); $prequery = array(); foreach($plist AS $value) { $prequery[] = "(parent=$value[0] AND parent_table=$value[1])"; /* CAUSES CRASHES */ } $whereclause = implode(" OR ", $prequery); echo "\n<BR>DEBUG: whereclause is $whereclause"; flush(); // Perform the query if(!$result = mysql_query("SELECT value FROM access AS a,users AS u WHERE ($whereclause) AND uid=$uid")) htmPageError("secALevel(): Failed to retrieve access list. " . sqlError()); $ret = AL_GUEST; while($row = mysql_fetch_array($result, MYSQL_ASSOC)) { if($row["level"] > $ret || ($row["level"] == AL_NEWBIE && $ret = AL_USER)) $ret = $row["level"]; } return $ret; } --- If the commented CAUSES crashes line is changed so that the string is properly quoted (within the query, e.g.) AND has the closing parenthesis, things work fine. E.g. replacing it with this line works: $prequery[] = "(parent=$value[0] AND parent_table=" . strQuote($value[1]) . ")"; (strQuote is a small function I wrote that either returns 'null' or an escaped string with quotation marks around it, useful for turning user input into mysql queries) ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at http://bugs.php.net/7219 -- Edit this bug report at http://bugs.php.net/?id=7219&edit=1

« previous php.bugs (#11213) next »