Bug #43812 [Com]: 'password' parameter in my.cnf not honored even with mysqli_options()

From: Date: Wed, 06 Jan 2016 23:06:09 +0000
Subject: Bug #43812 [Com]: 'password' parameter in my.cnf not honored even with mysqli_options()
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-198462@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=43812&edit=1

 ID:                 43812
 Comment by:         ben at redsnapper dot net
 Reported by:        graced at wingsnw dot com
 Summary:            'password' parameter in my.cnf not honored even with
                     mysqli_options()
 Status:             No Feedback
 Type:               Bug
 Package:            MySQLi related
 Operating System:   Debian lenny/sid
 PHP Version:        5.2.5
 Block user comment: N
 Private report:     N

 New Comment:

All our databases are remote. Using DNS is obviously correct, but it makes no difference if we use
either an IPv4 or DNS for the host. Localhost is a red herring here. 
"mysql --defaults-extra-file=my.cnf" works fine from commandline, and fails within php.
Now tested in both 5.6 and 7.
Compare the two following code fragments.

<?php
//This code works. It's a nasty workaround.
mb_internal_encoding('UTF-8');
$mycnf="/Users/ben/my.cnf";
$sqls = parse_ini_file($mycnf);
$sql = mysqli_init();
mysqli_real_connect($sql,$sqls['host'],$sqls['user'],$sqls['password'],$sqls['database']);
if ($rs = $sql->query("select TABLE_NAME from information_schema.columns group by
TABLE_NAME")) {
	print $rs->num_rows . "\n";
	$rs->close();
};
//


<?php
//This code fails.
mb_internal_encoding('UTF-8');
$mycnf="/Users/ben/my.cnf";
$sql = mysqli_init();
mysqli_options($sql,MYSQLI_READ_DEFAULT_FILE,$mycnf);
mysqli_real_connect($sql);
if ($rs = $sql->query("select TABLE_NAME from information_schema.columns group by
TABLE_NAME")) {
	print $rs->num_rows . "\n";
	$rs->close();
};

In my opinion, PHP shouldn't even need read access to the file - as it should pass over the
information to the mysqlclient library, which should need read access to the file.


Previous Comments:
------------------------------------------------------------------------
[2016-01-06 20:57:22] requinix@php.net

Do you have host=localhost? If so then the error message is probably referring to a missing socket
file (which it always tries to use with host=localhost). Try with host=127.0.0.1 to force a TCP
connection.

------------------------------------------------------------------------
[2016-01-06 20:53:56] ben at redsnapper dot net

<?php
mb_internal_encoding('UTF-8');
$mycnf="my.cnf";
$sql = mysqli_init();
mysqli_options($sql,MYSQLI_READ_DEFAULT_FILE,$mycnf);
mysqli_real_connect($sql);

Run on 5.6 responds with "Warning: mysqli_real_connect(): (HY000/2002): No such file or
directory in /Users/ben/test.php on line 6" - SO the error message has changed, but the effect
is no connection still.

Note that php see the file (using file_exists()).

------------------------------------------------------------------------
[2016-01-06 20:01:23] requinix@php.net

Can someone confirm this is still happening with PHP 5.6 or 7? Repro: the my.cnf file is private
(0400 with the same owner that PHP is running as), the host and username parameters are respected,
but the password is not. That means a conf file like
> [client]
> host     = "yourhost"
> user     = "yourusername"
> password = "yourpassword"
and an error message like
> Access denied for user 'yourusername'@'yourhost' (using password: NO)

For now use just the standard my.cnf file and [client] section - don't set
MYSQLI_READ_DEFAULT_FILE/GROUP.

@ben: Are you using PHP 5.6 or 7? Are you still having the problem?
@fms: (a) The error message says the host and username options are not being used. Make sure
you're using my.cnf and not a custom file, and that it's set to 0400 permissions. (b) PHP
5.4 is no longer supported - please try with 5.6 or later.

------------------------------------------------------------------------
[2016-01-06 19:11:31] fms at hy dot com dot br

Same problem on 

FreeBSD 10.2-RELEASE
PHP 5.4.45 (cli) (built: Dec  8 2015 02:46:46)
Copyright (c) 1997-2014 The PHP Group
Zend Engine v2.4.0, Copyright (c) 1998-2014 Zend Technologies

Warning: mysqli::real_connect(): (HY000/1045): Access denied for user
''@'localhost' (using password: NO) in /usr/local/share/www/index.php on line 17


[client]
user="johndoe"
password="password-john"
host=127.0.0.1
port=3306
socket=/tmp/mysql.sock
database=customers
default-character-set=utf8

------------------------------------------------------------------------
[2015-02-26 16:47:48] ben at redsnapper dot net

This problem is reproducible and has nothing to do with the read-status of the my.cnf files. We are
seeing username,host,database all being set by the my.cnf file - but not the password value.  

mysqli_real_connect(): (28000/1045): Access denied for user
'special_u'@'101.202.185.245' (using password: NO)

We have tested the same file using mysql --defaults-extra-file=my.cnf  with no problems.

------------------------------------------------------------------------


The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at

    https://bugs.php.net/bug.php?id=43812


--
Edit this bug report at https://bugs.php.net/bug.php?id=43812&edit=1


Thread (25 messages)

« previous php.bugs (#198462) next »