Bug #64937 [Com]: Unable to run firebird "execute block", containing :xxxx

From: Date: Tue, 26 Nov 2019 19:51:20 +0000
Subject: Bug #64937 [Com]: Unable to run firebird "execute block", containing :xxxx
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-223902@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=64937&edit=1 ID: 64937 Comment by: sim-mail at list dot ru Reported by: slavb18 at gmail dot com Summary: Unable to run firebird "execute block", containing :xxxx Status: Open Type: Bug Package: PDO Firebird PHP Version: 5.4.15 Block user comment: N Private report: N New Comment: I wrote a patch to solve these problems. The SQL preprocessing code has been ported from Firebird to handle EXECUTE STATEMENT. Both EXECUTE BLOCK work with parameters and skipping parameter markers in comments have been resolved. https://github.com/php/php-src/pull/4920 Unfortunately, there are no people who can check my code. Previous Comments: ------------------------------------------------------------------------ [2017-12-14 13:22:27] funtech dot n at gmail dot com Parameter parser in the driver is very simple, and can be tricked by quote symbol inside a comment: $q="Execute Block Returns( result varchar(100) ) as declare variable test integer=1; Begin /*'*/ select 'test' from rdb\$database where 1=:test into result; Suspend; End "; $sth=$pdo->query($q); $row=$sth->fetch(PDO::FETCH_ASSOC); ------------------------------------------------------------------------ [2017-12-04 11:03:58] valentin at microtec dot fr Never fix ? ------------------------------------------------------------------------ [2013-05-30 14:52:17] slavb18 at gmail dot com patched version opensuse build service project: https://build.opensuse.org/package/show?package=php5&project=home%3Aslavb18%3Abranches%3Adevel%3Alanguages%3Aphp rpms: http://download.opensuse.org/repositories/home:/slavb18:/branches:/devel:/languages:/php/openSUSE_12.3/ ------------------------------------------------------------------------ [2013-05-28 13:52:57] slavb18 at gmail dot com don't know if it helps, but this is working example with parametrized execute block with ibase_XXX functions $conn=ibase_connect($base, $user,$pass); $q="Execute Block ( test integer=? ) Returns( result varchar(100) ) as Begin select 'test' from rdb\$database where 1=:test into result; Suspend; End "; $qu= ibase_prepare($conn,$q); $r_sql = ibase_execute($qu,1); $row=ibase_fetch_assoc($r_sql); print_r($row); ------------------------------------------------------------------------ [2013-05-28 13:36:07] slavb18 at gmail dot com Description: ------------ Unable to run firebird unparametrized "execute block", containing :xxxx if query contains string like ":xxxx", pdo->query shows error SQLSTATE[HY000]: General error: -901 Dynamic SQL Error SQL error code = -901 undefined message number if I remove "where 1=:test", then execute block works And, also I cannot prepare and execute "paramerized" execute block if it contains :xxxxx Execute Block ( test integer=:test ) Returns( result varchar(100) ) as Begin select 'test' from rdb$database where 1=:test into result; Suspend; End I think solution is to ignore any parameters (:xxx) after Begin keyword in case of firebird Test script: --------------- $q="Execute Block Returns( result varchar(100) ) as declare variable test integer=1; Begin select 'test' from rdb\$database where 1=:test into result; Suspend; End "; $sth=$pdo->query($q); $row=$sth->fetch(PDO::FETCH_ASSOC); Expected result: ---------------- Array ( [RESULT] => test ) Actual result: -------------- SQLSTATE[HY000]: General error: -901 Dynamic SQL Error SQL error code = -901 undefined message number ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=64937&edit=1

« previous php.bugs (#223902) next »