Bug #81040 [Fbk->Nab]: Native pass-by-ref in mysqli_stmt::bind_param leaks reference

From: Date: Wed, 26 May 2021 19:56:22 +0000
Subject: Bug #81040 [Fbk->Nab]: Native pass-by-ref in mysqli_stmt::bind_param leaks reference
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-234034@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=81040&edit=1

 ID:                 81040
 Updated by:         dharman@php.net
 Reported by:        dharman@php.net
 Summary:            Native pass-by-ref in mysqli_stmt::bind_param leaks
                     reference
-Status:             Feedback
+Status:             Not a bug
 Type:               Bug
 Package:            Unknown/Other Function
 Operating System:   Windows 10
 PHP Version:        8.0.6
 Assigned To:        cmb
 Block user comment: N
 Private report:     N

 New Comment:

As explained by CMB this is not a bug, at least not when compiled with mysqlnd


Previous Comments:
------------------------------------------------------------------------
[2021-05-21 13:31:29] cmb@php.net

That "reference leak" is by design, to allow rebinding of the
parameters like demonstrated in the first example for
mysqli_stmt::execute()[1].

If MySQLi built against libmysql-client behaves differently, that
was a bug.

[1] <https://www.php.net/manual/en/mysqli-stmt.execute.php#refsect1-mysqli-stmt.execute-examples>

------------------------------------------------------------------------
[2021-05-21 12:52:37] cmb@php.net

This doesn't appear to be particularly related to PHP 8.0.

Anyway, what is the behavior with libmysql-client.  It seems to me
that would yield the expected behavior.

------------------------------------------------------------------------
[2021-05-13 16:30:51] dharman@php.net

Description:
------------
Native pass-by-reference makes elements of an array referenced. Tested with mysqli_stmt::bind_param.
This results in inadvertent changes to follow up code, e.g. results from array_diff()

I don't know if it's intended behaviour or if not then which component this is related to.
Additionally, should the reference leak through array_diff()?

Test online: https://phpize.online/?phpses=6fd2785a4408856aa1fc2aba245d05bc&sqlses=null&php_version=php8&sql_version=mysql57

Test script:
---------------
<?php

mysqli_report(MYSQLI_REPORT_ERROR | MYSQLI_REPORT_STRICT);
$mysqli = new mysqli('localhost', 'user', 'password',
'test');

function a(&$a, &$b, &$c)
{
    $a = 3;
}

$foo = [1, 2, 3];
$bar = [3, 4, 5];

$stmt = $mysqli->prepare("SELECT ?,?,?");

// What's the difference between this
$stmt->bind_param('sss', $foo[0], $foo[1], $foo[2]);
// and this
a($foo[0], $foo[1], $foo[2]);

$diff = array_diff($foo, $bar);
$foo[1] = 'hi';
var_dump($diff);

Expected result:
----------------
array(1) {
  [1] =>
  int(2)
}

Actual result:
--------------
array(1) {
  [1] =>
  string(2) "hi"
}


------------------------------------------------------------------------



--
Edit this bug report at https://bugs.php.net/bug.php?id=81040&edit=1


Thread (4 messages)

« previous php.bugs (#234034) next »