#23354 [Opn->Fbk]: Use of variable before registration problem

From: Date: Mon, 28 Apr 2003 14:47:01 +0000
Subject: #23354 [Opn->Fbk]: Use of variable before registration problem
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-38576@lists.php.net to get a copy of this message
 ID:               23354
 Updated by:       sniper@php.net
 Reported By:      bill dot macallister at prideindustries dot com
-Status:           Open
+Status:           Feedback
 Bug Type:         Session related
 Operating System: Linux 2.4.18-27.7.xsmp
 PHP Version:      4.3.1
 New Comment:

Please try using this CVS snapshot:

  http://snaps.php.net/php4-STABLE-latest.tar.gz
 
For Windows:
 
  http://snaps.php.net/win32/php4-win32-STABLE-latest.zip




Previous Comments:
------------------------------------------------------------------------

[2003-04-25 17:22:15] bill dot macallister at prideindustries dot com

This is as much a change in behavior as anything, but the
specific failure seems to indicate a deeper problem.

We have an application that uses out own session save handler
to store session data in a MySQL database.  This application
has been in use on a 4.2.1 system for months now.  When I 
upgraded our test system to 4.3.1 we started getting failures.
The exact error was a MySQL connection failure because of
bad authentication credentials.  The error report indicated
that the connection attempt was for webuser@localhost.  Our
Apache server runs as webuser so this is the default user.
The code generating this message is:

  $mysql_host = 'mysql-master';
  $mysql_user = 'phpuser';
  $mysql_pass = 'phppass';
  $mysql_db   = 'php_sessions';
  if ($cnx = mysql_connect ($mysql_host, 
                            $mysql_user, 
                            $mysql_pass)) {
    if ($db = mysql_select_db($mysql_db, $cnx)) {
      $ret = $cnx;
    }
  }

So, the error message really is bogus or PHP's heap is 
corrupt.

It turns out that I was able to make the error go away
by changing the code:

  $s_user_id = $user_data["user_id"];
  session_register("s_user_id");

to:

  session_register("s_user_id");
  $s_user_id = $user_data["user_id"];

It appears that in 4.2.1 you can use variables before you
register then and in 4.3.1 you cannot.

The 4.3.1 behavior is at least a bug in that PHP silently
accepts the invalid instruction sequence and corrupts its
environment so that completely unrelated parts of the 
script will fail.  If registration is required before use
I would really like to see session_register complain if
you try and do it wrong.

Bill

------------------------------------------------------------------------


-- 
Edit this bug report at http://bugs.php.net/?id=23354&edit=1



Thread (16 messages)

« previous php.bugs (#38576) next »