Bug #73264 [NEW]: pg_convert rejects valid values for several data types

From: Date: Fri, 07 Oct 2016 11:32:12 +0000
Subject: Bug #73264 [NEW]: pg_convert rejects valid values for several data types
Groups: php.bugs 
Request: Send a blank email to php-bugs+get-204529@lists.php.net to get a copy of this message
From: hans at xs4all dot nl Operating system: Linux PHP version: Irrelevant Package: PostgreSQL related Bug Type: Bug Bug description:pg_convert rejects valid values for several data types Description: ------------ The regular expressions used in pg_convert for several data types reject many different valid values. As the test script below demonstrates: - For cidr and inet only IPv6 addresses without network mask are accepted, so networks and IPv4 are not supported. - For date and time (and timestamp) only a subset of ISO 8601 formatted strings are accepted. - For intervals only verbose syntax is accepted. The changelog of the function (http://php.net/pg_convert) states that 'unknown/unsupported data types are escaped without validation'. Maybe a better approach is to not validate these data types too and just escape them. Test script: --------------- $db = pg_connect('dbname=foo'); pg_query($db, 'create table test (_inet inet, _cidr cidr, _date date, _time time, _interval interval)'); error_reporting(0); print_r(pg_convert($db, 'test', ['_inet'=>'192.168.100.128/25'])); print_r(pg_convert($db, 'test', ['_inet'=>'192.168/24'])); print_r(pg_convert($db, 'test', ['_inet'=>'192.168/25'])); print_r(pg_convert($db, 'test', ['_inet'=>'192.168.1'])); print_r(pg_convert($db, 'test', ['_inet'=>'192168'])); print_r(pg_convert($db, 'test', ['_inet'=>'128.1'])); print_r(pg_convert($db, 'test', ['_inet'=>'128'])); print_r(pg_convert($db, 'test', ['_inet'=>'128.1.2'])); print_r(pg_convert($db, 'test', ['_inet'=>'10.1.2'])); print_r(pg_convert($db, 'test', ['_inet'=>'10.1'])); print_r(pg_convert($db, 'test', ['_inet'=>'10'])); print_r(pg_convert($db, 'test', ['_inet'=>'10.1.2.3/32'])); print_r(pg_convert($db, 'test', ['_inet'=>'2001:4f8:3:ba::/64'])); print_r(pg_convert($db, 'test', ['_inet'=>'2001:4f8:3:ba:2e0:81ff:fe22:d1f1/128'])); print_r(pg_convert($db, 'test', ['_inet'=>'2001:4f8:3:ba:2e0:81ff:fe22:d1f1'])); print_r(pg_convert($db, 'test', ['_cidr'=>'192.168.100.128/25'])); print_r(pg_convert($db, 'test', ['_cidr'=>'192.168/24'])); print_r(pg_convert($db, 'test', ['_cidr'=>'192.168/25'])); print_r(pg_convert($db, 'test', ['_cidr'=>'192.168.1'])); print_r(pg_convert($db, 'test', ['_cidr'=>'192168'])); print_r(pg_convert($db, 'test', ['_cidr'=>'128.1'])); print_r(pg_convert($db, 'test', ['_cidr'=>'128'])); print_r(pg_convert($db, 'test', ['_cidr'=>'128.1.2'])); print_r(pg_convert($db, 'test', ['_cidr'=>'10.1.2'])); print_r(pg_convert($db, 'test', ['_cidr'=>'10.1'])); print_r(pg_convert($db, 'test', ['_cidr'=>'10'])); print_r(pg_convert($db, 'test', ['_cidr'=>'10.1.2.3/32'])); print_r(pg_convert($db, 'test', ['_cidr'=>'2001:4f8:3:ba::/64'])); print_r(pg_convert($db, 'test', ['_cidr'=>'2001:4f8:3:ba:2e0:81ff:fe22:d1f1/128'])); print_r(pg_convert($db, 'test', ['_cidr'=>'2001:4f8:3:ba:2e0:81ff:fe22:d1f1'])); print_r(pg_convert($db, 'test', ['_date'=>'1999-01-08'])); print_r(pg_convert($db, 'test', ['_date'=>'January 8, 1999'])); print_r(pg_convert($db, 'test', ['_date'=>'1/8/1999'])); print_r(pg_convert($db, 'test', ['_date'=>'1/18/1999'])); print_r(pg_convert($db, 'test', ['_date'=>'01/02/03'])); print_r(pg_convert($db, 'test', ['_date'=>'1999-Jan-08'])); print_r(pg_convert($db, 'test', ['_date'=>'Jan-08-1999'])); print_r(pg_convert($db, 'test', ['_date'=>'08-Jan-1999'])); print_r(pg_convert($db, 'test', ['_date'=>'99-Jan-08'])); print_r(pg_convert($db, 'test', ['_date'=>'08-Jan-99'])); print_r(pg_convert($db, 'test', ['_date'=>'Jan-08-99'])); print_r(pg_convert($db, 'test', ['_date'=>'19990108'])); print_r(pg_convert($db, 'test', ['_date'=>'990108'])); print_r(pg_convert($db, 'test', ['_date'=>'1999008'])); print_r(pg_convert($db, 'test', ['_date'=>'J2451187'])); print_r(pg_convert($db, 'test', ['_date'=>'January 8, 99 BC'])); print_r(pg_convert($db, 'test', ['_date'=>'epoch'])); print_r(pg_convert($db, 'test', ['_date'=>'infinity'])); print_r(pg_convert($db, 'test', ['_date'=>'-infinity'])); print_r(pg_convert($db, 'test', ['_date'=>'now'])); print_r(pg_convert($db, 'test', ['_date'=>'today'])); print_r(pg_convert($db, 'test', ['_date'=>'tomorrow'])); print_r(pg_convert($db, 'test', ['_date'=>'yesterday'])); print_r(pg_convert($db, 'test', ['_time'=>'04:05:06.789'])); print_r(pg_convert($db, 'test', ['_time'=>'04:05:06'])); print_r(pg_convert($db, 'test', ['_time'=>'04:05'])); print_r(pg_convert($db, 'test', ['_time'=>'40506'])); print_r(pg_convert($db, 'test', ['_time'=>'04:05 AM'])); print_r(pg_convert($db, 'test', ['_time'=>'04:05 PM'])); print_r(pg_convert($db, 'test', ['_time'=>'04:05:06.789-8'])); print_r(pg_convert($db, 'test', ['_time'=>'04:05:06-08:00'])); print_r(pg_convert($db, 'test', ['_time'=>'04:05-08:00'])); print_r(pg_convert($db, 'test', ['_time'=>'040506-08'])); print_r(pg_convert($db, 'test', ['_time'=>'04:05:06 PST'])); print_r(pg_convert($db, 'test', ['_time'=>'2003-04-12 04:05:06 America/New_York'])); print_r(pg_convert($db, 'test', ['_time'=>'allballs'])); print_r(pg_convert($db, 'test', ['_interval'=>'1-2'])); print_r(pg_convert($db, 'test', ['_interval'=>'3 4:05:06'])); print_r(pg_convert($db, 'test', ['_interval'=>'04:5:6'])); print_r(pg_convert($db, 'test', ['_interval'=>'1 year 2 months 3 days 4 hours 5 minutes 6 seconds'])); print_r(pg_convert($db, 'test', ['_interval'=>'1 year 2 mons 3 days 4 hours 5 mins 6 secs'])); print_r(pg_convert($db, 'test', ['_interval'=>'P1Y2M3DT4H5M6S'])); print_r(pg_convert($db, 'test', ['_interval'=>'P0001-02-03T04:05:06'])); Expected result: ---------------- All values submitted to pg_convert are valid, so all return values should be printed. Actual result: -------------- Array ( ["_inet"] => E'2001:4f8:3:ba:2e0:81ff:fe22:d1f1' ) Array ( ["_cidr"] => E'2001:4f8:3:ba:2e0:81ff:fe22:d1f1' ) Array ( ["_date"] => E'1999-01-08' ) Array ( ["_time"] => E'04:05:06' ) Array ( ["_time"] => E'04:05' ) Array ( ["_interval"] => E'1 year 2 months 3 days 4 hours 5 minutes 6 seconds' ) -- Edit bug report at https://bugs.php.net/bug.php?id=73264&edit=1 -- Try a snapshot (PHP 5.4): https://bugs.php.net/fix.php?id=73264&r=trysnapshot54 Try a snapshot (PHP 5.5): https://bugs.php.net/fix.php?id=73264&r=trysnapshot55 Try a snapshot (trunk): https://bugs.php.net/fix.php?id=73264&r=trysnapshottrunk Fixed in SVN: https://bugs.php.net/fix.php?id=73264&r=fixed Fixed in release: https://bugs.php.net/fix.php?id=73264&r=alreadyfixed Need backtrace: https://bugs.php.net/fix.php?id=73264&r=needtrace Need Reproduce Script: https://bugs.php.net/fix.php?id=73264&r=needscript Try newer version: https://bugs.php.net/fix.php?id=73264&r=oldversion Not developer issue: https://bugs.php.net/fix.php?id=73264&r=support Expected behavior: https://bugs.php.net/fix.php?id=73264&r=notwrong Not enough info: https://bugs.php.net/fix.php?id=73264&r=notenoughinfo Submitted twice: https://bugs.php.net/fix.php?id=73264&r=submittedtwice register_globals: https://bugs.php.net/fix.php?id=73264&r=globals PHP 4 support discontinued: https://bugs.php.net/fix.php?id=73264&r=php4 Daylight Savings: https://bugs.php.net/fix.php?id=73264&r=dst IIS Stability: https://bugs.php.net/fix.php?id=73264&r=isapi Install GNU Sed: https://bugs.php.net/fix.php?id=73264&r=gnused Floating point limitations: https://bugs.php.net/fix.php?id=73264&r=float No Zend Extensions: https://bugs.php.net/fix.php?id=73264&r=nozend MySQL Configuration Error: https://bugs.php.net/fix.php?id=73264&r=mysqlcfg

« previous php.bugs (#204529) next »