Edit report at https://bugs.php.net/bug.php?id=43812&edit=1
ID: 43812
Comment by: juan at verdnatura dot es
Reported by: graced at wingsnw dot com
Summary: 'password' parameter in my.cnf not honored even with
mysqli_options()
Status: Re-Opened
Type: Bug
Package: MySQLi related
Operating System: Debian lenny/sid
PHP Version: 5.2.5
Block user comment: N
Private report: N
New Comment:
I confirm that this still affects to debian php 7.
Someone is looking to solve it?
https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=835173
Previous Comments:
------------------------------------------------------------------------
[2016-12-12 13:14:52] hsc@php.net
This still seems to be broken on Debian 7.0's PHP 5.6.27-0+deb8u1 (with php5-mysqlnd
5.6.27+dfsg-0+deb8u1) and Ubuntu 16.10's PHP 7.0.8-3ubuntu3 (with php7.0-mysql 7.0.8-3ubuntu3).
Setup:
$ php --version
PHP 7.0.8-3ubuntu3 (cli) ( NTS )
Copyright (c) 1997-2016 The PHP Group
Zend Engine v3.0.0, Copyright (c) 1998-2016 Zend Technologies
with Zend OPcache v7.0.8-3ubuntu3, Copyright (c) 1999-2016, by Zend Technologies
$ cat dbtest.php
<?php
error_reporting(E_ALL);
$DB = mysqli_init();
$DB->options(MYSQLI_READ_DEFAULT_FILE, "/xxxxx/.my.cnf") || die();
$DB->options(MYSQLI_READ_DEFAULT_GROUP, "client") || die();
$DB->real_connect();
$ cat ~/.my.cnf
[client]
host=xxx_some_remote_host
user=xxx
password=xxx
Connect fails:
$ php dbtest.php
PHP Warning: mysqli::real_connect(): (HY000/2002): No such file or directory in /xxxxx/dbtest.php
on line 6
strace shows that the php process doesn't even try opening .my.cnf:
$ strace -e trace=file,network php dbtest.php
[...]
open("dbtest.php", O_RDONLY) = 3
[... several calls to getcwd and lstat ...]
socket(AF_LOCAL, SOCK_STREAM, 0) = 3
connect(3, {sa_family=AF_LOCAL, sun_path="/var/run/mysqld/mysqld.sock"}, 29) = -1 ENOENT
(No such file or directory)
PHP Warning: mysqli::real_connect(): (HY000/2002): No such file or directory in /xxxxx/dbtest.php
on line 6
+++ exited with 0 +++
See also:
https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=835173
http://stackoverflow.com/questions/12241333/mysql-wont-read-password-from-configuration-file
------------------------------------------------------------------------
[2016-01-17 04:22:31] php-bugs at lists dot php dot net
No feedback was provided. The bug is being suspended because
we assume that you are no longer experiencing the problem.
If this is not the case and you are able to provide the
information that was requested earlier, please do so and
change the status of the bug back to "Re-Opened". Thank you.
------------------------------------------------------------------------
[2016-01-07 20:30:10] ben at redsnapper dot net
''So if you put your settings into the global my.cnf (probably in /etc or
/usr/local/mysql*) is there a difference?''
No. I get the same errors.
To be honest, NOT implementing MYSQLI_READ_DEFAULT_FILE is a huge bug for us. Our processor cluster
uses arbitrary connection values on a per-request basis, connecting to our database cluster of over
100 database instances. We don't like having to needlessly read sensitive connection data into
user memory, and consider this lack of support to be one of our greatest security concerns. I am
under the impression that PHP/Zend considers itself to be suitable for enterprise environments.
Also, note the assertion of implementation found at http://php.net/manual/en/mysqli.options.php
It's a bug.
------------------------------------------------------------------------
[2016-01-07 04:54:34] requinix@php.net
Might as well reopen this since we're talking about it.
------------------------------------------------------------------------
[2016-01-07 04:54:13] requinix@php.net
I was looking at the source code for mysqli and mysqlnd earlier and it seemed like the
MYSQLI_READ_DEFAULT_FILE/GROUP settings were explicitly not implemented. That's why I said to
repro without using those.
So if you put your settings into the global my.cnf (probably in /etc or /usr/local/mysql*) is there
a difference?
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=43812
--
Edit this bug report at https://bugs.php.net/bug.php?id=43812&edit=1