Bug #72753 [Fbk->Asn]: ldap_search returns zero results when searching for large integers

From: Date: Tue, 10 Jan 2017 10:03:07 +0000
Subject: Bug #72753 [Fbk->Asn]: ldap_search returns zero results when searching for large integers
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-206452@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=72753&edit=1

 ID:                 72753
 User updated by:    justinasu at gmail dot com
 Reported by:        justinasu at gmail dot com
 Summary:            ldap_search returns zero results when searching for
                     large integers
-Status:             Feedback
+Status:             Assigned
 Type:               Bug
 Package:            LDAP related
 Operating System:   windows 8.1 x64
 PHP Version:        7.0.9
 Assigned To:        heiglandreas
 Block user comment: N
 Private report:     N

 New Comment:

yes, ldapsearch returns results as expected:

ldapsearch -H 'ldaps://<ldapserver>' -D 'username@domain' -b
'<base dn>' -W -s sub "(usnchanged>=4261605367)" cn sn
# search result
search: 2
result: 4 Size limit exceeded

# numResponses: 1004
# numEntries: 1000
# numReferences: 3


ldapsearch: @(#) $OpenLDAP: ldapsearch 2.4.40 (May 10 2016 23:31:28) $
       
mockbuild@worker1.bsys.centos.org:/builddir/build/BUILD/openldap-2.4.40/openldap-2.4.40/build-clients/clients/tools
        (LDAP library: OpenLDAP 20440)

php is 64bit:
var_dump(PHP_INT_SIZE);
int(8)

this bug is reproduced all the way up to php v5.5. This is the oldest version i have tried.


Previous Comments:
------------------------------------------------------------------------
[2017-01-09 21:55:13] heiglandreas@php.net

The interesting thing is that the filter is a string and is passed to the underlying LDAP-library
(usually OpenLDAP) as string. So there isn't a conversion to an integer value on PHP-side.
Therefore I'm inclined to say that the conversion to an integer is done in the underlying
LDAP-library. Can you check whether that lib is a 32bit or a 64bit build? And can you get a result
using f.e. ldapsearch instead of the ActiveDirectory explorer?

Thanks for your help!

------------------------------------------------------------------------
[2016-08-04 09:35:38] justinasu at gmail dot com

Description:
------------
<ldapserver> and <base dn> in test script should be substituted with some ldap server
that you have access to and you need to have read permission to usnchanged attribute.

when searching for entries by usnchanged which is a Microsoft proposed way of polling for changes,
the test script returns 0 results. But if you run the same filter query in Active Directory explorer
or some other tool i get many results - couple of thousand.

if the value is smaller lets say (usnchanged>=261605367) i get expected results.

i suspect that somewhere in LDAP php internals the value gets interpreted as 32bit integer and since
it's max is 4,294,967,295, the query with higher values never returns any results. usnchanged
field is 8bit INTERGER (BIGINT) in Active Directory.

tried on linux Centos 6.8 x64 the result is the same.

Test script:
---------------
$res = ldap_connect('ldap://<ldapserver>');
ldap_set_option($res, LDAP_OPT_PROTOCOL_VERSION, 3);
ldap_bind($res)

$response = ldap_search($res, '<base dn>', '(usnchanged>=4261605367)');
$result = ldap_get_entries($res, $response);

var_dump($result);

Expected result:
----------------
array with count > 0

Actual result:
--------------
array with count === 0


------------------------------------------------------------------------



--
Edit this bug report at https://bugs.php.net/bug.php?id=72753&edit=1


Thread (9 messages)

« previous php.bugs (#206452) next »