#47928 [Ver]: Crash in mysqli_stmt_fetch() with longtext column

From: Date: Sun, 19 Apr 2009 14:44:30 +0000
Subject: #47928 [Ver]: Crash in mysqli_stmt_fetch() with longtext column
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-135974@lists.php.net to get a copy of this message
ID: 47928 User updated by: jjuergens at web dot de Reported By: jjuergens at web dot de Status: Verified Bug Type: MySQLi related Operating System: * PHP Version: 5.2CVS-2009-04-19 New Comment: Yeah, you're right: Soon as I change the column-type from longtext to text, PHP doesn't crash anymore. The example you provided also crashes on my debug-enabled PHP-Version, while the Opensuse-Version (with Suoshin-Patch) throws efree()-errors until there are more than 396 characters in the textfield. I actually tried to debug the PHP-code some (with very limited knowledge) and I think that the problem is somewhere within the binding of the resultset since thats where the script stops. Previous Comments: ------------------------------------------------------------------------ [2009-04-19 14:28:19] wcshields at gmail dot com I just noticed the status of #46808 is marked as "Bogus". Unfortunately there's no history to see who marked it that way or why but I guess that explains why no action was taken on it. This issue has been reported in various forms for over two years now. The fact that such reports were written off essentially as hoaxes or pranks or just plain incompetence by everyone else speaks volumes about the lack of professionalism and due diligence by whoever is responsible for investigating such bugs. So Allelujah that someone finally bothered--years later--to actually fix it. Maybe if the PHP devs took such reports more seriously, packages like mysqli wouldn't be the horrible buggy messes that they are. ------------------------------------------------------------------------ [2009-04-19 14:11:14] jani@php.net See also bug #46808 ------------------------------------------------------------------------ [2009-04-19 14:07:02] jani@php.net Here is the shortest possible test I could come up with: <?php /* Test database and table with data: drop database crashtest; create database crashtest; use crashtest; create table crash ( test longtext ); insert into crash set test='123456789'; grant select on crashtest.* to 'test'@'localhost'; */ $dbLink=new mysqli("localhost","test","","crashtest",3306); $stmt=$dbLink->prepare("SELECT test FROM crash"); $stmt->execute(); $stmt->bind_result($foo); while($stmt->fetch()); $stmt->close(); ?> The problem seems to be with the longtext column. If that is changed to text column, everything works just fine. ------------------------------------------------------------------------ [2009-04-19 10:59:40] jani@php.net Above example causes crash also on my test server. (I removed other irrelevant comments) ------------------------------------------------------------------------ [2009-04-18 09:57:10] jjuergens at web dot de <?php //IMPORTANT: Database-Name (here: tst) needs to have exactly 3 characters! $dbLink=new mysqli("localhost","user","pass","tst",3306); $dbLink->query("CREATE TABLE IF NOT EXISTS sessionData ( sessionId varchar(60) collate utf8_unicode_ci NOT NULL, pathHash varchar(32) collate utf8_unicode_ci NOT NULL, path varchar(100) collate utf8_unicode_ci NOT NULL, data longtext collate utf8_unicode_ci NOT NULL, PRIMARY KEY (sessionId,pathHash) ) ENGINE=InnoDB DEFAULT CHARSET=utf8 COLLATE=utf8_unicode_ci"); $dbLink->query("INSERT INTO sessionData (sessionId, pathHash, path, data) VALUES ('e75c7781166e3a361b7cff546563d5e8', '633fed500f479acaaaf54be8ec9ac657', '/bla', '0018a901234001222425678901235678345612341315789012345678901234567890123423456789012223456789012345678901234567890123456789012345678901234567890123456789012345678901234567890123456789012345678901234567890123456789012345678901234567890123456789012345678901234567890123456789012345678')"); $stmt=$dbLink->prepare("SELECT * FROM sessionData WHERE sessionId=? AND pathHash=? LIMIT 1"); $arg1="e75c7781166e3a361b7cff546563d5e8"; $arg2="633fed500f479acaaaf54be8ec9ac657"; $stmt->bind_param("ss",$arg1,$arg2); $stmt->execute(); $resData=$stmt->result_metadata(); while($field=mysqli_fetch_field($resData)){ $resFields[$field->name]=null; } call_user_func_array(array($stmt,'bind_result'),$resFields); $result=array(); while($stmt->fetch()){ $tmpRes=array(); foreach($resFields as $key=>$value){ $tmpRes[$key]=$value; } array_push($result,$tmpRes); } $stmt->close(); print_r($result); ?> ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at http://bugs.php.net/47928 -- Edit this bug report at http://bugs.php.net/?id=47928&edit=1

« previous php.bugs (#135974) next »