Bug #74186 [Ver->Dup]: Error if sql query has a criteria's length larger than columns' max length

From: Date: Fri, 19 Aug 2022 16:35:38 +0000
Subject: Bug #74186 [Ver->Dup]: Error if sql query has a criteria's length larger than columns' max length
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-242263@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=74186&edit=1

 ID:                 74186
 Updated by:         cmb@php.net
 Reported by:        lobo__911 at hotmail dot com
 Summary:            Error if sql query has a criteria's length larger
                     than columns' max length
-Status:             Verified
+Status:             Duplicate
 Type:               Bug
 Package:            PDO ODBC
 Operating System:   ALL
 PHP Version:        7.0.16
-Assigned To:        
+Assigned To:        cmb
 Block user comment: N
 Private report:     N

 New Comment:

Closing in favor of <https://github.com/php/php-src/issues/9372>.


Previous Comments:
------------------------------------------------------------------------
[2020-10-05 13:07:28] cmb@php.net

Related To: Bug #64828

------------------------------------------------------------------------
[2020-09-29 10:58:59] cmb@php.net

Test script:

<?php
$pdo = new PDO($dsn, $user, $pass);
$pdo->setAttribute(PDO::ATTR_ERRMODE, PDO::ERRMODE_EXCEPTION);

$pdo->exec("DROP TABLE bug74186");
$pdo->exec("CREATE TABLE bug74186 (col VARCHAR(10))");
$pdo->exec("INSERT INTO bug74186 VALUES ('something')");

$stmt = $pdo->prepare("SELECT * FROM bug74186 WHERE col = ?");
var_dump($stmt->execute([str_repeat("0123456789", 27)]));
?>

Fails with: SQLSTATE[HY010]: Function sequence error.

The problem is that we're binding the parameter[1] with the proper
ColumnSize (aka. precision) of 10[1], but then putting data into
the parameter[2] which exceeds that column size.  The ODBC Driver
for SQL Server (and maybe others as well, but not, for instance,
the MySQL ODBC 8.0 Unicode Driver; according to the ODBC
Specification 3.8 either behavior seems to be conforming) is picky
about that, and SQLPutData() actually fails with [22001] String
data, right truncation; we don't catch that error, but go on
calling SQLParamData() again, what triggers the [HY010] Function
sequence error.

The same issue occurs also if the user prepares respective DML
queries.

It is not clear *how* we should solve this.  We could either be
strict about the length of bound parameters and reject these right
away, or we could be more liberal for strict drivers by silently
truncating the parameter values.  The latter would not break BC,
but might be regarded the wrong behavior.

[1] <https://github.com/php/php-src/blob/php-7.3.23/ext/pdo_odbc/odbc_stmt.c#L379-L386>
[2] <https://github.com/php/php-src/blob/php-7.3.23/ext/pdo_odbc/odbc_stmt.c#L200-L201>

------------------------------------------------------------------------
[2017-03-01 05:29:16] lobo__911 at hotmail dot com

Description:
------------
Please, read this github issue and follow the SO question: https://github.com/Microsoft/msphpsql/issues/307



------------------------------------------------------------------------



--
Edit this bug report at https://bugs.php.net/bug.php?id=74186&edit=1


Thread (3 messages)

« previous php.bugs (#242263) next »