Bug #77496 [Fbk->Ver]: mysqli->real_connect() overwrites MYSQLI_OPT_LOCAL_INFILE setting

From: Date: Tue, 22 Jan 2019 00:47:18 +0000
Subject: Bug #77496 [Fbk->Ver]: mysqli->real_connect() overwrites MYSQLI_OPT_LOCAL_INFILE setting
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-219116@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=77496&edit=1

 ID:                 77496
 Updated by:         requinix@php.net
 Reported by:        php at yghe dot net
 Summary:            mysqli->real_connect() overwrites
                     MYSQLI_OPT_LOCAL_INFILE setting
-Status:             Feedback
+Status:             Verified
 Type:               Bug
 Package:            MySQLi related
 Operating System:   Mac OS X Mojave 10.14.2
 PHP Version:        7.3.1
 Assigned To:        cmb
 Block user comment: N
 Private report:     N

 New Comment:

I hit Enter as a reflex, wasn't ready...

Came from the migration to mysqlnd.


Previous Comments:
------------------------------------------------------------------------
[2019-01-22 00:45:36] requinix@php.net

https://github.com/php/php-src/blob/PHP-7.3.1/ext/mysqli/mysqli_nonapi.c#L260

------------------------------------------------------------------------
[2019-01-22 00:42:25] cmb@php.net

Active support for PHP 7.1 has ended more than a month ago[1],
i.e. this branch will only receive security related fixes.  Since
this issue does not seem to be security related, please check
whether PHP 7.2 or higher are affected as well, and change the
“PHP Version” field accordingly.

[1] <http://php.net/supported-versions.php>

------------------------------------------------------------------------
[2019-01-21 15:33:05] php at yghe dot net

Description:
------------
Calls to "mysqli->options(MYSQLI_OPT_LOCAL_INFILE, ...)" before
"mysqli->real_connect()" do not seem to have any effect.

They appear to be silently overwritten when "real_connect()" sets the option value from
the "mysqli.allow_local_infile" configuration option.

Calls after "real_connect()" behave as expected.

For context, see: <https://secure.phabricator.com/T13238>

Test script:
---------------
<?php

$conn = mysqli_init();

// Call (A).
// $conn->options(MYSQLI_OPT_LOCAL_INFILE, 0);

$conn->real_connect('127.0.0.1', 'root', '',
'local_user');

// Call (B).
// $conn->options(MYSQLI_OPT_LOCAL_INFILE, 0);

$conn->query('CREATE TEMPORARY TABLE t (v LONGTEXT NOT NULL)');
$conn->query('LOAD DATA LOCAL INFILE "example.txt" INTO TABLE t');

var_dump(
  array(
    'errno' => $conn->errno,
    'error' => $conn->error,
  ));


Expected result:
----------------
When "options(MYSQLI_OPT_LOCAL_INFILE, ...)" is called at point (A) above, it should not
be silently ignored.

Possible alternative results might include:

"mysqli.allow_local_infile" is configured in "mysqli_init()" instead of
"real_connect()".

Setting "options(MYSQLI_OPT_LOCAL_INFILE, ...)" before "real_connect()"
fails/warns.

"real_connect()" does not set "MYSQLI_OPT_LOCAL_INFILE" if "options()"
has already set it.

Actual result:
--------------
Any "options(MYSQLI_OPT_LOCAL_INFILE, ...)" call at point (A) is ignored.

The actual value for the "LOAD DATA LOCAL INFILE" query at the bottom is determined only
by configuration option "mysqli.allow_local_infile" which is set on the connection inside
"real_connect()", and any later calls to "options(...)".


------------------------------------------------------------------------



--
Edit this bug report at https://bugs.php.net/bug.php?id=77496&edit=1


Thread (11 messages)

« previous php.bugs (#219116) next »