#47928 [Ver]: Crash in mysqli_stmt_fetch() with longtext column
| From: | jjuergens at web dot de | Date: | Sun, 19 Apr 2009 14:44:30 +0000 |
| Subject: | #47928 [Ver]: Crash in mysqli_stmt_fetch() with longtext column | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-135974@lists.php.net to get a copy of this message | ||
ID: 47928
User updated by: jjuergens at web dot de
Reported By: jjuergens at web dot de
Status: Verified
Bug Type: MySQLi related
Operating System: *
PHP Version: 5.2CVS-2009-04-19
New Comment:
Yeah, you're right: Soon as I change the column-type from longtext to
text, PHP doesn't crash anymore. The example you provided also crashes
on my debug-enabled PHP-Version, while the Opensuse-Version (with
Suoshin-Patch) throws efree()-errors until there are more than 396
characters in the textfield.
I actually tried to debug the PHP-code some (with very limited
knowledge) and I think that the problem is somewhere within the binding
of the resultset since thats where the script stops.
Previous Comments:
------------------------------------------------------------------------
[2009-04-19 14:28:19] wcshields at gmail dot com
I just noticed the status of #46808 is marked as "Bogus". Unfortunately
there's no history to see who marked it that way or why but I guess that
explains why no action was taken on it.
This issue has been reported in various forms for over two years now.
The fact that such reports were written off essentially as hoaxes or
pranks or just plain incompetence by everyone else speaks volumes about
the lack of professionalism and due diligence by whoever is responsible
for investigating such bugs.
So Allelujah that someone finally bothered--years later--to actually
fix it. Maybe if the PHP devs took such reports more seriously, packages
like mysqli wouldn't be the horrible buggy messes that they are.
------------------------------------------------------------------------
[2009-04-19 14:11:14] jani@php.net
See also bug #46808
------------------------------------------------------------------------
[2009-04-19 14:07:02] jani@php.net
Here is the shortest possible test I could come up with:
<?php
/* Test database and table with data:
drop database crashtest; create database crashtest; use crashtest;
create table crash ( test longtext );
insert into crash set test='123456789';
grant select on crashtest.* to 'test'@'localhost';
*/
$dbLink=new mysqli("localhost","test","","crashtest",3306);
$stmt=$dbLink->prepare("SELECT test FROM crash");
$stmt->execute();
$stmt->bind_result($foo);
while($stmt->fetch());
$stmt->close();
?>
The problem seems to be with the longtext column. If that is changed
to text column, everything works just fine.
------------------------------------------------------------------------
[2009-04-19 10:59:40] jani@php.net
Above example causes crash also on my test server. (I removed other
irrelevant comments)
------------------------------------------------------------------------
[2009-04-18 09:57:10] jjuergens at web dot de
<?php
//IMPORTANT: Database-Name (here: tst) needs to have exactly 3
characters!
$dbLink=new mysqli("localhost","user","pass","tst",3306);
$dbLink->query("CREATE TABLE IF NOT EXISTS
sessionData (
sessionId varchar(60) collate utf8_unicode_ci NOT NULL,
pathHash varchar(32) collate utf8_unicode_ci NOT NULL,
path varchar(100) collate utf8_unicode_ci NOT NULL,
data longtext collate utf8_unicode_ci NOT NULL,
PRIMARY KEY (sessionId,pathHash)
) ENGINE=InnoDB DEFAULT CHARSET=utf8 COLLATE=utf8_unicode_ci");
$dbLink->query("INSERT INTO sessionData (sessionId,
pathHash,
path, data) VALUES
('e75c7781166e3a361b7cff546563d5e8',
'633fed500f479acaaaf54be8ec9ac657', '/bla',
'0018a901234001222425678901235678345612341315789012345678901234567890123423456789012223456789012345678901234567890123456789012345678901234567890123456789012345678901234567890123456789012345678901234567890123456789012345678901234567890123456789012345678901234567890123456789012345678')");
$stmt=$dbLink->prepare("SELECT * FROM sessionData WHERE
sessionId=?
AND pathHash=? LIMIT 1");
$arg1="e75c7781166e3a361b7cff546563d5e8";
$arg2="633fed500f479acaaaf54be8ec9ac657";
$stmt->bind_param("ss",$arg1,$arg2);
$stmt->execute();
$resData=$stmt->result_metadata();
while($field=mysqli_fetch_field($resData)){
$resFields[$field->name]=null;
}
call_user_func_array(array($stmt,'bind_result'),$resFields);
$result=array();
while($stmt->fetch()){
$tmpRes=array();
foreach($resFields as $key=>$value){
$tmpRes[$key]=$value;
}
array_push($result,$tmpRes);
}
$stmt->close();
print_r($result);
?>
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
http://bugs.php.net/47928
--
Edit this bug report at http://bugs.php.net/?id=47928&edit=1