Bug #71447 [NEW]: an query may return bad result or error "Invalid parameter number"

From: Date: Mon, 25 Jan 2016 16:10:50 +0000
Subject: Bug #71447 [NEW]: an query may return bad result or error "Invalid parameter number"
Groups: php.bugs 
Request: Send a blank email to php-bugs+get-198885@lists.php.net to get a copy of this message
From: skrol29forum+bugsphp at gmail dot com Operating system: Windows 10, Debian Cid PHP version: 5.6.17 Package: PDO PgSQL Bug Type: Bug Bug description:an query may return bad result or error "Invalid parameter number" Description: ------------ Depending to a comment in the SQL query, PDO will run it correctly or return an error, or even a wrong result. Run the test script and an error will raise while the query contains actually no PDO parameters. Then if you simply delete the character single-quote (replace "that's strange" with "thats strange") in the comment of the SQL query there will be no error. -------------- More dramatic: -------------- Replace: $pdo->query($sql_1, PDO::FETCH_NUM); With: $pdo->query($sql_2, PDO::FETCH_NUM); in order to run the second query. Take car to previously create the table and the row using the small SQL script at the head of the script. In this case, there is no error, but the query returns a wrong result (NULL instead of '8000'). If you delete the single-quote in the comment, then the result is correct. The bug occurs with Windows 10 and Debian Cid with PHP 5.6.17 but also with versions 5.6.16 and 5.6.15. Not tested on PHP 7. The bug does not occurs with PHP 5.4.3. I've tested a similar query with PDO-MySQL and there is no error. --------- PDO version with PHP 5.6.17: PostgreSQL(libpq) Version 9.4.1 Module version 1.0.2 Revision $Id: 93432550a76a2298959ec74f40d65c7195a82ad2 $ --------- Test script: --------------- /* Database structure for query #2 CREATE SCHEMA _test; CREATE TABLE _test.t_test (prms character varying(255)); INSERT INTO _test.t_test (prms) VALUES ('{"radius":8000}'); */ // connection to the PostgreSQL database $pdo = new PDO("pgsql:dbname=mydb;host=myhost", 'myusername', 'mypassword'); $sql_1 = " SELECT -- that's strange SUBSTRING( '{\"radius\":8000}'::text FROM '(?:\"radius\":)([\d\.]*)') AS zzz"; $sql_2 = " SELECT -- that's strange SUBSTRING( prms::text FROM '(?:\"radius\":)([\d\.]*)') AS zzz FROM _test.t_test"; $rs = $pdo->query($sql_1, PDO::FETCH_NUM); $rec = $rs->fetch(); var_export($rec); Expected result: ---------------- array ( 0 => '8000', ) Actual result: -------------- Query #1 returns : « PDO::query(): SQLSTATE[HY093]: Invalid parameter number: mixed named and positional parameters in ... » Query #2 returns : array ( 0 => NULL, ) -- Edit bug report at https://bugs.php.net/bug.php?id=71447&edit=1 -- Try a snapshot (PHP 5.4): https://bugs.php.net/fix.php?id=71447&r=trysnapshot54 Try a snapshot (PHP 5.5): https://bugs.php.net/fix.php?id=71447&r=trysnapshot55 Try a snapshot (trunk): https://bugs.php.net/fix.php?id=71447&r=trysnapshottrunk Fixed in SVN: https://bugs.php.net/fix.php?id=71447&r=fixed Fixed in release: https://bugs.php.net/fix.php?id=71447&r=alreadyfixed Need backtrace: https://bugs.php.net/fix.php?id=71447&r=needtrace Need Reproduce Script: https://bugs.php.net/fix.php?id=71447&r=needscript Try newer version: https://bugs.php.net/fix.php?id=71447&r=oldversion Not developer issue: https://bugs.php.net/fix.php?id=71447&r=support Expected behavior: https://bugs.php.net/fix.php?id=71447&r=notwrong Not enough info: https://bugs.php.net/fix.php?id=71447&r=notenoughinfo Submitted twice: https://bugs.php.net/fix.php?id=71447&r=submittedtwice register_globals: https://bugs.php.net/fix.php?id=71447&r=globals PHP 4 support discontinued: https://bugs.php.net/fix.php?id=71447&r=php4 Daylight Savings: https://bugs.php.net/fix.php?id=71447&r=dst IIS Stability: https://bugs.php.net/fix.php?id=71447&r=isapi Install GNU Sed: https://bugs.php.net/fix.php?id=71447&r=gnused Floating point limitations: https://bugs.php.net/fix.php?id=71447&r=float No Zend Extensions: https://bugs.php.net/fix.php?id=71447&r=nozend MySQL Configuration Error: https://bugs.php.net/fix.php?id=71447&r=mysqlcfg

« previous php.bugs (#198885) next »