Bug #72368 [Ver->Csd]: PdoStatement->execute() fails but does not throw an exception
Edit report at https://bugs.php.net/bug.php?id=72368&edit=1
ID: 72368
Updated by: nikic@php.net
Reported by: fredrik at neam dot se
Summary: PdoStatement->execute() fails but does not throw an
exception
-Status: Verified
+Status: Closed
Type: Bug
Package: PDO MySQL
Operating System: Any
PHP Version: 7.0.7
Block user comment: N
Private report: N
New Comment:
Automatic comment on behalf of nikita.ppv@gmail.com
Revision: http://git.php.net/?p=php-src.git;a=commit;h=9e3ba775b7de7d7647c488beb9e302d03690f955
Log: Fixed bug #72368
Previous Comments:
------------------------------------------------------------------------
[2020-12-10 15:18:02] nikic@php.net
The problem here seems to be specifically the case where a) emulated prepared statements are used
and b) there are no placeholders in the query. In that case we hit an early bailout and don't
validate the passed parameters.
------------------------------------------------------------------------
[2019-06-12 21:48:48] dan dot mara at gmail dot com
I experience this issue as well with dblib. Using SQL Server Profiler, I confirmed that it as indeed
triggering exceptions at the DB level, but they are not being thrown by PDO. It seems inconsistent,
in that I only get exceptions when executing a statement where I did something like forgetting to
bind a parameter.
The following should demontrate the issue:
$conn = new PDO('dblib:host=XXX;dbname=XXX', 'REDACTED', 'REDACTED');
$conn->setAttribute(PDO::ATTR_ERRMODE, PDO::ERRMODE_EXCEPTION);
$stmt = $conn->prepare("SELECT thistable FROM doesnotexist");
try {
$stmt->execute();
} catch (Exception $ex) {
die("I am never reached");
}
The above WILL reach SQL Server, and emit an EventClass of "Exception", but PDO does not
trickle it down to a PDOException. It's extremely unreliable.
------------------------------------------------------------------------
[2016-07-10 05:35:09] mbeccati@php.net
The following patch has been added/updated:
Patch Name: bug72368_test
Revision: 1468128909
URL: https://bugs.php.net/patch-display.php?bug=72368&patch=bug72368_test&revision=1468128909
------------------------------------------------------------------------
[2016-07-10 05:34:22] mbeccati@php.net
Moving to pdo_mysql as both pdo_sqlite and pdo_pgsql raise an exception, as expected. I haven't
tested the other drivers, but I will attach a patch that adds a PDO Common test for the issue.
------------------------------------------------------------------------
[2016-06-09 09:47:13] fredrik at neam dot se
Description:
------------
PdoStatement->execute() fails but does not throw an exception when supplying parameters to
execute() whilst not using any placeholders in the query.
Tested on PHP 7.0.7, 5.6.20 and HHVM 3.13.1
Test script:
---------------
$dbh = new PDO('###');
$dbh->setAttribute(PDO::ATTR_ERRMODE, PDO::ERRMODE_EXCEPTION);
$params = [":bar" => 1];
$sql = "SELECT 1";
$stmt = $dbh->prepare($sql);
$result = $stmt->execute($params);
Expected result:
----------------
Either ->execute() should return true and the result set be populated, or an exception should be
thrown (like it does for the below case):
$dbh = new PDO('###');
$dbh->setAttribute(PDO::ATTR_ERRMODE, PDO::ERRMODE_EXCEPTION);
$params = [":bar" => 1];
$sql = "SELECT :foo";
$stmt = $dbh->prepare($sql);
$result = $stmt->execute($params);
Actual result:
--------------
$result is false, but an exception is not thrown. The result set is empty.
This is problematic since when the error mode is set to PDO::ERRMODE_EXCEPTION, it is fair to assume
that failed statements results in thrown exceptions, so that the return variable must not be checked
after each usage of ->execute().
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=72368&edit=1
Thread (6 messages)