Bug #43812 [NoF->ReO]: 'password' parameter in my.cnf not honored even with mysqli_options()

From: Date: Sun, 17 Jan 2016 04:39:44 +0000
Subject: Bug #43812 [NoF->ReO]: 'password' parameter in my.cnf not honored even with mysqli_options()
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-198724@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=43812&edit=1 ID: 43812 Updated by: requinix@php.net Reported by: graced at wingsnw dot com Summary: 'password' parameter in my.cnf not honored even with mysqli_options() -Status: No Feedback +Status: Re-Opened Type: Bug Package: MySQLi related Operating System: Debian lenny/sid PHP Version: 5.2.5 Block user comment: N Private report: N Previous Comments: ------------------------------------------------------------------------ [2016-01-17 04:22:31] php-bugs at lists dot php dot net No feedback was provided. The bug is being suspended because we assume that you are no longer experiencing the problem. If this is not the case and you are able to provide the information that was requested earlier, please do so and change the status of the bug back to "Re-Opened". Thank you. ------------------------------------------------------------------------ [2016-01-07 20:30:10] ben at redsnapper dot net ''So if you put your settings into the global my.cnf (probably in /etc or /usr/local/mysql*) is there a difference?'' No. I get the same errors. To be honest, NOT implementing MYSQLI_READ_DEFAULT_FILE is a huge bug for us. Our processor cluster uses arbitrary connection values on a per-request basis, connecting to our database cluster of over 100 database instances. We don't like having to needlessly read sensitive connection data into user memory, and consider this lack of support to be one of our greatest security concerns. I am under the impression that PHP/Zend considers itself to be suitable for enterprise environments. Also, note the assertion of implementation found at http://php.net/manual/en/mysqli.options.php It's a bug. ------------------------------------------------------------------------ [2016-01-07 04:54:34] requinix@php.net Might as well reopen this since we're talking about it. ------------------------------------------------------------------------ [2016-01-07 04:54:13] requinix@php.net I was looking at the source code for mysqli and mysqlnd earlier and it seemed like the MYSQLI_READ_DEFAULT_FILE/GROUP settings were explicitly not implemented. That's why I said to repro without using those. So if you put your settings into the global my.cnf (probably in /etc or /usr/local/mysql*) is there a difference? ------------------------------------------------------------------------ [2016-01-06 23:06:08] ben at redsnapper dot net All our databases are remote. Using DNS is obviously correct, but it makes no difference if we use either an IPv4 or DNS for the host. Localhost is a red herring here. "mysql --defaults-extra-file=my.cnf" works fine from commandline, and fails within php. Now tested in both 5.6 and 7. Compare the two following code fragments. <?php //This code works. It's a nasty workaround. mb_internal_encoding('UTF-8'); $mycnf="/Users/ben/my.cnf"; $sqls = parse_ini_file($mycnf); $sql = mysqli_init(); mysqli_real_connect($sql,$sqls['host'],$sqls['user'],$sqls['password'],$sqls['database']); if ($rs = $sql->query("select TABLE_NAME from information_schema.columns group by TABLE_NAME")) { print $rs->num_rows . "\n"; $rs->close(); }; // <?php //This code fails. mb_internal_encoding('UTF-8'); $mycnf="/Users/ben/my.cnf"; $sql = mysqli_init(); mysqli_options($sql,MYSQLI_READ_DEFAULT_FILE,$mycnf); mysqli_real_connect($sql); if ($rs = $sql->query("select TABLE_NAME from information_schema.columns group by TABLE_NAME")) { print $rs->num_rows . "\n"; $rs->close(); }; In my opinion, PHP shouldn't even need read access to the file - as it should pass over the information to the mysqlclient library, which should need read access to the file. ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=43812 -- Edit this bug report at https://bugs.php.net/bug.php?id=43812&edit=1

« previous php.bugs (#198724) next »