Bug #72368 [Ver->Csd]: PdoStatement->execute() fails but does not throw an exception

From: Date: Thu, 10 Dec 2020 15:55:02 +0000
Subject: Bug #72368 [Ver->Csd]: PdoStatement->execute() fails but does not throw an exception
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-231002@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=72368&edit=1

 ID:                 72368
 Updated by:         nikic@php.net
 Reported by:        fredrik at neam dot se
 Summary:            PdoStatement->execute() fails but does not throw an
                     exception
-Status:             Verified
+Status:             Closed
 Type:               Bug
 Package:            PDO MySQL
 Operating System:   Any
 PHP Version:        7.0.7
 Block user comment: N
 Private report:     N

 New Comment:

Automatic comment on behalf of nikita.ppv@gmail.com
Revision: http://git.php.net/?p=php-src.git;a=commit;h=9e3ba775b7de7d7647c488beb9e302d03690f955
Log: Fixed bug #72368


Previous Comments:
------------------------------------------------------------------------
[2020-12-10 15:18:02] nikic@php.net

The problem here seems to be specifically the case where a) emulated prepared statements are used
and b) there are no placeholders in the query. In that case we hit an early bailout and don't
validate the passed parameters.

------------------------------------------------------------------------
[2019-06-12 21:48:48] dan dot mara at gmail dot com

I experience this issue as well with dblib. Using SQL Server Profiler, I confirmed that it as indeed
triggering exceptions at the DB level, but they are not being thrown by PDO. It seems inconsistent,
in that I only get exceptions when executing a statement where I did something like forgetting to
bind a parameter.

The following should demontrate the issue:

$conn = new PDO('dblib:host=XXX;dbname=XXX', 'REDACTED', 'REDACTED');
$conn->setAttribute(PDO::ATTR_ERRMODE, PDO::ERRMODE_EXCEPTION);

$stmt = $conn->prepare("SELECT thistable FROM doesnotexist");
try {
	$stmt->execute();
} catch (Exception $ex) {
	die("I am never reached");
}

The above WILL reach SQL Server, and emit an EventClass of "Exception", but PDO does not
trickle it down to a PDOException. It's extremely unreliable.

------------------------------------------------------------------------
[2016-07-10 05:35:09] mbeccati@php.net

The following patch has been added/updated:

Patch Name: bug72368_test
Revision:   1468128909
URL:        https://bugs.php.net/patch-display.php?bug=72368&patch=bug72368_test&revision=1468128909

------------------------------------------------------------------------
[2016-07-10 05:34:22] mbeccati@php.net

Moving to pdo_mysql as both pdo_sqlite and pdo_pgsql raise an exception, as expected. I haven't
tested the other drivers, but I will attach a patch that adds a PDO Common test for the issue.

------------------------------------------------------------------------
[2016-06-09 09:47:13] fredrik at neam dot se

Description:
------------
PdoStatement->execute() fails but does not throw an exception when supplying parameters to
execute() whilst not using any placeholders in the query.

Tested on PHP 7.0.7, 5.6.20 and HHVM 3.13.1

Test script:
---------------
$dbh = new PDO('###');
$dbh->setAttribute(PDO::ATTR_ERRMODE, PDO::ERRMODE_EXCEPTION);
$params = [":bar" => 1];
$sql = "SELECT 1";
$stmt = $dbh->prepare($sql);
$result = $stmt->execute($params);


Expected result:
----------------
Either ->execute() should return true and the result set be populated, or an exception should be
thrown (like it does for the below case):

$dbh = new PDO('###');
$dbh->setAttribute(PDO::ATTR_ERRMODE, PDO::ERRMODE_EXCEPTION);
$params = [":bar" => 1];
$sql = "SELECT :foo";
$stmt = $dbh->prepare($sql);
$result = $stmt->execute($params);

Actual result:
--------------
$result is false, but an exception is not thrown. The result set is empty.

This is problematic since when the error mode is set to PDO::ERRMODE_EXCEPTION, it is fair to assume
that failed statements results in thrown exceptions, so that the return variable must not be checked
after each usage of ->execute(). 




------------------------------------------------------------------------



--
Edit this bug report at https://bugs.php.net/bug.php?id=72368&edit=1


Thread (6 messages)

« previous php.bugs (#231002) next »