Edit report at https://bugs.php.net/bug.php?id=43812&edit=1
ID: 43812
Comment by: ben at redsnapper dot net
Reported by: graced at wingsnw dot com
Summary: 'password' parameter in my.cnf not honored even with
mysqli_options()
Status: Feedback
Type: Bug
Package: MySQLi related
Operating System: Debian lenny/sid
PHP Version: 5.2.5
Block user comment: N
Private report: N
New Comment:
''So if you put your settings into the global my.cnf (probably in /etc or
/usr/local/mysql*) is there a difference?''
No. I get the same errors.
To be honest, NOT implementing MYSQLI_READ_DEFAULT_FILE is a huge bug for us. Our processor cluster
uses arbitrary connection values on a per-request basis, connecting to our database cluster of over
100 database instances. We don't like having to needlessly read sensitive connection data into
user memory, and consider this lack of support to be one of our greatest security concerns. I am
under the impression that PHP/Zend considers itself to be suitable for enterprise environments.
Also, note the assertion of implementation found at http://php.net/manual/en/mysqli.options.php
It's a bug.
Previous Comments:
------------------------------------------------------------------------
[2016-01-07 04:54:34] requinix@php.net
Might as well reopen this since we're talking about it.
------------------------------------------------------------------------
[2016-01-07 04:54:13] requinix@php.net
I was looking at the source code for mysqli and mysqlnd earlier and it seemed like the
MYSQLI_READ_DEFAULT_FILE/GROUP settings were explicitly not implemented. That's why I said to
repro without using those.
So if you put your settings into the global my.cnf (probably in /etc or /usr/local/mysql*) is there
a difference?
------------------------------------------------------------------------
[2016-01-06 23:06:08] ben at redsnapper dot net
All our databases are remote. Using DNS is obviously correct, but it makes no difference if we use
either an IPv4 or DNS for the host. Localhost is a red herring here.
"mysql --defaults-extra-file=my.cnf" works fine from commandline, and fails within php.
Now tested in both 5.6 and 7.
Compare the two following code fragments.
<?php
//This code works. It's a nasty workaround.
mb_internal_encoding('UTF-8');
$mycnf="/Users/ben/my.cnf";
$sqls = parse_ini_file($mycnf);
$sql = mysqli_init();
mysqli_real_connect($sql,$sqls['host'],$sqls['user'],$sqls['password'],$sqls['database']);
if ($rs = $sql->query("select TABLE_NAME from information_schema.columns group by
TABLE_NAME")) {
print $rs->num_rows . "\n";
$rs->close();
};
//
<?php
//This code fails.
mb_internal_encoding('UTF-8');
$mycnf="/Users/ben/my.cnf";
$sql = mysqli_init();
mysqli_options($sql,MYSQLI_READ_DEFAULT_FILE,$mycnf);
mysqli_real_connect($sql);
if ($rs = $sql->query("select TABLE_NAME from information_schema.columns group by
TABLE_NAME")) {
print $rs->num_rows . "\n";
$rs->close();
};
In my opinion, PHP shouldn't even need read access to the file - as it should pass over the
information to the mysqlclient library, which should need read access to the file.
------------------------------------------------------------------------
[2016-01-06 20:57:22] requinix@php.net
Do you have host=localhost? If so then the error message is probably referring to a missing socket
file (which it always tries to use with host=localhost). Try with host=127.0.0.1 to force a TCP
connection.
------------------------------------------------------------------------
[2016-01-06 20:53:56] ben at redsnapper dot net
<?php
mb_internal_encoding('UTF-8');
$mycnf="my.cnf";
$sql = mysqli_init();
mysqli_options($sql,MYSQLI_READ_DEFAULT_FILE,$mycnf);
mysqli_real_connect($sql);
Run on 5.6 responds with "Warning: mysqli_real_connect(): (HY000/2002): No such file or
directory in /Users/ben/test.php on line 6" - SO the error message has changed, but the effect
is no connection still.
Note that php see the file (using file_exists()).
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=43812
--
Edit this bug report at https://bugs.php.net/bug.php?id=43812&edit=1