Bug #43812 [Com]: 'password' parameter in my.cnf not honored even with mysqli_options()

From: Date: Tue, 18 Apr 2017 12:00:32 +0000
Subject: Bug #43812 [Com]: 'password' parameter in my.cnf not honored even with mysqli_options()
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-208638@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=43812&edit=1

 ID:                 43812
 Comment by:         ben at redsnapper dot net
 Reported by:        graced at wingsnw dot com
 Summary:            'password' parameter in my.cnf not honored even with
                     mysqli_options()
 Status:             Feedback
 Type:               Bug
 Package:            MySQLi related
 Operating System:   Debian lenny/sid
 PHP Version:        5.2.5
 Block user comment: N
 Private report:     N

 New Comment:

mysqli_nonapi.c  line 59.

The problem (as I understand it) is that the connect()/real_connect() function is parsing no
parameters and returning empty-strings when it calls zend_parse_parameters. So the connect() to
mysql is using (default) empty_string password value which is being understood as THE password to
use for the connection rather than what has been set via the defaults-extra-file.  So, as I
understand it, allow_null needs to be set (and needs to be the default) on the connect() methods.


Previous Comments:
------------------------------------------------------------------------
[2017-04-18 11:11:52] ben at redsnapper dot net

PHP 7.0.17 (cli) (built: Mar 18 2017 20:13:50) ( NTS )
Copyright (c) 1997-2017 The PHP Group
Zend Engine v3.0.0, Copyright (c) 1998-2017 Zend Technologies

System Version:	macOS 10.12.4 (16E195)
Kernel Version:	Darwin 16.5.0
  
mysql  Ver 14.14 Distrib 5.7.9, for osx10.9 (x86_64) using  EditLine wrapper

Following fjanisze@php.net exact files, the bug is still failing on 7.0.17

PHP Warning:  mysqli::real_connect(): (HY000/1045): Access denied for user
''@'localhost' (using password: NO) in php shell code on line 1

Warning: mysqli::real_connect(): (HY000/1045): Access denied for user
''@'localhost' (using password: NO) in php shell code on line 1

------------------------------------------------------------------------
[2017-04-18 09:36:14] fjanisze@php.net

Hi everybody,

I'm attempting to reproduce this problem with very little luck, I'm running Oracle Linux
release 3.10.0-514.10.2.el7.x86_64 with:

PHP 7.1.3 (cli) (built: Apr 18 2017 11:05:24) ( NTS DEBUG GCOV )
Copyright (c) 1997-2017 The PHP Group
Zend Engine v3.1.0, Copyright (c) 1998-2017 Zend Technologies

And MySQL 5.7.18 configured in secure mode, with the following my.conf file:

[client]
user="root"
password="Pass"
host=localhost
port=3380
socket=/tmp/mysql.sock
database=test
default-character-set=utf8

The test script is:

error_reporting(E_ALL);
$DB = mysqli_init();
$DB->options(MYSQLI_READ_DEFAULT_FILE, "./my.conf");
$DB->options(MYSQLI_READ_DEFAULT_GROUP, "client");
$DB->real_connect();

And the connection works perfectly, the my.conf file is used to fetch the authentication data.

From the log snipped from hsd@php.net the error:

connect(3, {sa_family=AF_LOCAL, sun_path="/var/run/mysqld/mysqld.sock"}, 29) = -1 ENOENT
(No such file or directory)

Looks to be related with the missing mysqld.sock file which then cause the connection failure. Was
an eventual socket file problem (missing &c) excluded already?

------------------------------------------------------------------------
[2017-03-06 16:32:16] juan at verdnatura dot es

I confirm that this still affects to debian php 7.

Someone is looking to solve it?

https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=835173

------------------------------------------------------------------------
[2016-12-12 13:14:52] hsc@php.net

This still seems to be broken on Debian 7.0's PHP 5.6.27-0+deb8u1 (with php5-mysqlnd
5.6.27+dfsg-0+deb8u1) and Ubuntu 16.10's PHP 7.0.8-3ubuntu3 (with php7.0-mysql 7.0.8-3ubuntu3).

Setup:

$ php --version
PHP 7.0.8-3ubuntu3 (cli) ( NTS )
Copyright (c) 1997-2016 The PHP Group
Zend Engine v3.0.0, Copyright (c) 1998-2016 Zend Technologies
    with Zend OPcache v7.0.8-3ubuntu3, Copyright (c) 1999-2016, by Zend Technologies
$ cat dbtest.php 
<?php
error_reporting(E_ALL);
$DB = mysqli_init();
$DB->options(MYSQLI_READ_DEFAULT_FILE, "/xxxxx/.my.cnf") || die();
$DB->options(MYSQLI_READ_DEFAULT_GROUP, "client") || die();
$DB->real_connect();
$ cat ~/.my.cnf
[client]
host=xxx_some_remote_host
user=xxx
password=xxx

Connect fails:

$ php dbtest.php
PHP Warning:  mysqli::real_connect(): (HY000/2002): No such file or directory in /xxxxx/dbtest.php
on line 6

strace shows that the php process doesn't even try opening .my.cnf:

$ strace -e trace=file,network php dbtest.php
[...]
open("dbtest.php", O_RDONLY)            = 3
[... several calls to getcwd and lstat ...]
socket(AF_LOCAL, SOCK_STREAM, 0)        = 3
connect(3, {sa_family=AF_LOCAL, sun_path="/var/run/mysqld/mysqld.sock"}, 29) = -1 ENOENT
(No such file or directory)
PHP Warning:  mysqli::real_connect(): (HY000/2002): No such file or directory in /xxxxx/dbtest.php
on line 6
+++ exited with 0 +++

See also:
https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=835173
http://stackoverflow.com/questions/12241333/mysql-wont-read-password-from-configuration-file

------------------------------------------------------------------------
[2016-01-17 04:22:31] php-bugs at lists dot php dot net

No feedback was provided. The bug is being suspended because
we assume that you are no longer experiencing the problem.
If this is not the case and you are able to provide the
information that was requested earlier, please do so and
change the status of the bug back to "Re-Opened". Thank you.

------------------------------------------------------------------------


The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at

    https://bugs.php.net/bug.php?id=43812


--
Edit this bug report at https://bugs.php.net/bug.php?id=43812&edit=1


Thread (25 messages)

« previous php.bugs (#208638) next »