Bug #79084 [Ver]: mysqlnd may fetch wrong column indexes with MYSQLI_BOTH
| From: | cmb@php.net | Date: | Sun, 12 Jan 2020 18:17:07 +0000 |
| Subject: | Bug #79084 [Ver]: mysqlnd may fetch wrong column indexes with MYSQLI_BOTH | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-224868@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=79084&edit=1
ID: 79084
Updated by: cmb@php.net
Reported by: rob-phpbugs at tigertech dot com
-Summary: mysqlnd may fetch with wrong column indexes
+Summary: mysqlnd may fetch wrong column indexes with
MYSQLI_BOTH
Status: Verified
Type: Bug
Package: MySQLi related
Operating System: Linux
PHP Version: 7.3.13
Block user comment: N
Private report: N
New Comment:
That same issue affects PDO core (i.e. with any driver),
so I think it's better to track that as separate ticket,
so I have filed bug #79106.
Previous Comments:
------------------------------------------------------------------------
[2020-01-12 17:29:34] cmb@php.net
The following pull request has been associated:
Patch Name: Fix #79084: mysqlnd may fetch wrong column indexes with MYSQLI_BOTH
On GitHub: https://github.com/php/php-src/pull/5080
Patch: https://github.com/php/php-src/pull/5080.patch
------------------------------------------------------------------------
[2020-01-12 14:14:44] cmb@php.net
Ah, indeed, if mysqli uses libmysql-client, the numeric indexes
are explicitly specified when inserting to the row, but if mysqlnd
is used, the values with numeric indexes are added to the row, and
as such may be wrong if column names are numeric strings. This
likely affects PDO_MySQL as well.
------------------------------------------------------------------------
[2020-01-09 18:10:45] rob-phpbugs at tigertech dot com
Ah -- I believe that is exactly what's happening. My PHP 7.2 has:
MysqlI Support => enabled
Client API library version => 10.1.41-MariaDB
And my PHP 7.3 has:
MysqlI Support => enabled
Client API library version => mysqlnd 5.0.12-dev - 20150407 - $Id:
7cc7cc96e675f6d72e5cf0f267f48e167c2abb23 $
So that must be the cause of this.
The mysqlnd version does not appear to match the documentation for mysqli fetch_array at <https://www.php.net/manual/en/mysqli-result.fetch-array.php>,
which says that it defaults to MYSQLI_BOTH. If I'm understanding correctly, that means there
should be 6 keys in the output of the previous test script, for [0], [1], [2], [2007], [2008] and
[2020].
Here's a different test script that shows a different weird result with mysqlnd, apparently
caused by the same underlying issue:
$ cat test.php
<?php
$mysqli = mysqli_connect("localhost", "test", "test",
"test");
$sql = "SELECT 0 as
test, 1 as test2, 2 as 2007, 2 as
2008, 3 as 2020";
$res = $mysqli->query($sql);
$row = $res->fetch_array();
print "mysqli version: " . $mysqli->client_info . "\n";
print_r($row);
$ php-7.2 test.php
mysqli version: 10.1.41-MariaDB
Array
(
[0] => 0
[test] => 0
[1] => 1
[test2] => 1
[2] => 2
[2007] => 2
[3] => 2
[2008] => 2
[4] => 3
[2020] => 3
)
$ php-7.3 test.php
mysqli version: mysqlnd 5.0.12-dev - 20150407 - $Id: 7cc7cc96e675f6d72e5cf0f267f48e167c2abb23 $
Array
(
[0] => 0
[test] => 0
[1] => 1
[test2] => 1
[2] => 2
[2007] => 2
[2008] => 2
[2009] => 3
[2020] => 3
)
The mysqlnd version seems wrong; it isn't filling in the expected [3] and [4] keys, and
it's added a [2009] key that should not be there.
------------------------------------------------------------------------
[2020-01-09 17:45:32] nikic@php.net
I just tried your script and get the same results on 7.2 and 7.3:
$ ~/php-7.2/sapi/cli/php t042.php
Array
(
[0] => 0
[2007] => 0
[2008] => 0
[2009] => 0
[2020] => 0
)
$ ~/php-7.3/sapi/cli/php t042.php
Array
(
[0] => 0
[2007] => 0
[2008] => 0
[2009] => 0
[2020] => 0
)
Do both PHP versions use mysqlnd (rather than libmysql)?
------------------------------------------------------------------------
[2020-01-09 17:23:28] rob-phpbugs at tigertech dot com
I'm not sure I understand what you said, for which I apologize.
Are you saying that when you run the test script on both PHP 7.2 and 7.3, it prints the same
results? Could you post what the output of the script is in both cases? Here's the output of a
test I just did:
$ cat test.php
<?php
$mysqli = mysqli_connect("localhost", "test", "[redacted]",
"test");
$sql = "SELECT 0 as 2007, 0 as 2008, 0 as 2020";
$res = $mysqli->query($sql);
$row = $res->fetch_array();
print "PHP version: " . phpversion() . "\n";
print_r($row);
$ php-7.2 test.php
PHP version: 7.2.26
Array
(
[0] => 0
[2007] => 0
[1] => 0
[2008] => 0
[2] => 0
[2020] => 0
)
$ php-7.3 test.php
PHP version: 7.3.13
Array
(
[0] => 0
[2007] => 0
[2008] => 0
[2009] => 0
[2020] => 0
)
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=79084
--
Edit this bug report at https://bugs.php.net/bug.php?id=79084&edit=1