Bug #68577 [Opn->Asn]: 'batchsize' parameter and negative values

From: Date: Mon, 29 Dec 2014 00:22:52 +0000
Subject: Bug #68577 [Opn->Asn]: 'batchsize' parameter and negative values
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-189280@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=68577&edit=1

 ID:                 68577
 Updated by:         kalle@php.net
 Reported by:        horton at tm43 dot cf
 Summary:            'batchsize' parameter and negative values
-Status:             Open
+Status:             Assigned
 Type:               Bug
 Package:            MSSQL related
 PHP Version:        Irrelevant
-Assigned To:        
+Assigned To:        kalle
 Block user comment: N
 Private report:     N

 New Comment:

I agree that we should not allow negative batchsize values, assigning this to myself and committing
a fix soon to 5.5, 5.6 & 7.0 as well as updating the documentation.


Previous Comments:
------------------------------------------------------------------------
[2014-12-09 16:12:08] horton at tm43 dot cf

Description:
------------
To make it extremely short: I believe a line within the _mssql_fetch_batch() function (in
ext/mssql/php_mssql.c) should be changed (or the documentation).

Original:

if ( i < result->batchsize || result->batchsize == 0 ) 

Patched:

if ( i < result->batchsize || result->batchsize <= 0 ) 


In the original version, if 'i' is less than 'result->batchsize' OR
'result->batchsize' is equal to '0', then the next record is copied to the
buffer and 'i' is incremented. This means, following the documentation and the most likely
intention of the author (and the IF-clause), the 'batchsize' parameter of (for example)
the 'mssql_query()' function is either a positive integer greater than zero, specifying
the number of records to be fetched and stored within the buffer OR ANY other value, meaning that
all records are fetched and stored within the buffer. 
But the source code only checks the latter case by comparing 'batchsize' to '0',
where as it should perform the comparison with '<= 0', to include negative numbers,
which can be supplied by the caller (there is no check performed anywhere against this case!).
Otherwise, by supplying a negative value, the loop is left immediately in the first run, which might
not be the intention of the author.

Thing is, I stumbled upon this oddity by inspecting the source code and cannot test it, since I have
neither a Windows PC nor a MSSQL server to connect to, so this should be verified by someone, who
does. Though I expect no problems at all, when patching this line AND modify slightly the
documentation, that 0 or any negative value for 'batchsize' leads to fetching all
records..






------------------------------------------------------------------------



--
Edit this bug report at https://bugs.php.net/bug.php?id=68577&edit=1


Thread (3 messages)

« previous php.bugs (#189280) next »