Bug #80001 [Com]: SSL connection error is not reported via mysqli::$connect_error

From: Date: Sun, 17 Jul 2022 14:58:16 +0000
Subject: Bug #80001 [Com]: SSL connection error is not reported via mysqli::$connect_error
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-241945@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=80001&edit=1

 ID:                 80001
 Comment by:         simbiat at outlook dot com
 Reported by:        morozov at tut dot by
 Summary:            SSL connection error is not reported via
                     mysqli::$connect_error
 Status:             Open
 Type:               Bug
 Package:            MySQLi related
 Operating System:   Linux
 PHP Version:        7.4.9
 Block user comment: N
 Private report:     N

 New Comment:

This is reproducible in PHP8.1 with PDO as well, but the message returned is "SQLSTATE[HY000]
[2002]  (trying to connect via (null))". Same as with original bug reported, it happens with
any SSL error. It can even be a timeout, and it still will return this message.


Previous Comments:
------------------------------------------------------------------------
[2021-06-02 15:22:26] cmb@php.net

Thanks for the swift reply!  That would be a bug.

------------------------------------------------------------------------
[2021-06-02 15:06:32] morozov at tut dot by

No, it returns false.

------------------------------------------------------------------------
[2021-06-02 10:51:27] cmb@php.net

Would that error be reported by openssl_error_string()?

------------------------------------------------------------------------
[2020-08-20 06:01:42] morozov at tut dot by

Description:
------------
According to the documentation, mysqli::$connect_error returns the last error message string from
the last call to mysqli_connect(). NULL is returned if no error occurred.


However, if the underlying connection error is related to SSL, mysqli::$connect_error remains NULL
which is incorrect.

The reproduction script tries to connect to a MySQL server running in a https://hub.docker.com/_/mysql container and relies on the
fact that the CN in the autogenerated server certificate doesn't match its hostname.

The same problem is reproducible with literally any SSL error.

Test script:
---------------
<?php

$conn = mysqli_init();

$conn->ssl_set('client-key.pem', 'client-cert.pem', 'ca.pem',
'', '');

if (!$conn->real_connect('127.0.0.1', 'root', '',
'mysql')) {
    var_dump($conn->connect_error);
    exit(1);
}


Expected result:
----------------
$conn->connect_error contains a string with an error message.

Actual result:
--------------
Warning: mysqli::real_connect(): Peer certificate
CN=MySQL_Server_8.0.18_Auto_Generated_Server_Certificate' did not match expected
CN=127.0.0.1' in /home/morozov/mysqi-tls.php on line 7

Warning: mysqli::real_connect(): Cannot connect to MySQL by using SSL in /home/morozov/mysqi-tls.php
on line 7

Warning: mysqli::real_connect(): [2002]  (trying to connect via (null)) in
/home/morozov/mysqi-tls.php on line 7

Warning: mysqli::real_connect(): (HY000/2002):  in /home/morozov/mysqi-tls.php on line 7
NULL


------------------------------------------------------------------------



--
Edit this bug report at https://bugs.php.net/bug.php?id=80001&edit=1


Thread (6 messages)

« previous php.bugs (#241945) next »