#23354 [Opn]: Use of variable before registration problem
| From: | bill dot macallister at prideindustries dot com | Date: | Wed, 30 Apr 2003 15:05:08 +0000 |
| Subject: | #23354 [Opn]: Use of variable before registration problem | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-38836@lists.php.net to get a copy of this message | ||
ID: 23354
User updated by: bill dot macallister at prideindustries dot com
Reported By: bill dot macallister at prideindustries dot com
Status: Open
Bug Type: Session related
Operating System: Linux 2.4.18-27.7.xsmp
PHP Version: 4.3.1
New Comment:
I don't see how to upload a file. The diff contains a lot of comment
differences. What I did was to write a perl script that stripped the
whole line comments, block delimiters, and blank lines. Then sorted
the output the output. Then I did a diff of that. Here is the
result:
d2x% diff -u php.ini-stripped-sorted php.ini-dist-stripped-sorted
--- php.ini-stripped-sorted Wed Apr 30 07:52:41 2003
+++ php.ini-dist-stripped-sorted Wed Apr 30 07:53:03 2003
@@ -1,12 +1,14 @@
allow_call_time_pass_reference=On
allow_url_fopen=On
asp_tags=Off
-'atMYSQL_PORT.
auto_append_file=
-auto_prepend_file=/usr/local/apache/php/prepend.php3
+auto_prepend_file=
bcmath.scale=0
+dbx.colnames_case="unchanged"
default_mimetype="text/html"
+default_socket_timeout=60
define_syslog_variables=Off
+disable_classes=
disable_functions=
display_errors=On
display_startup_errors=Off
@@ -15,15 +17,9 @@
engine=On
error_reporting=E_ALL&~E_NOTICE
expose_php=On
-extension_dir=./
+extension_dir="./"
file_uploads=On
gpc_order="GPC"
-highlight.bg=#FFFFFF
-highlight.comment=#FF9900
-highlight.default=#0000CC
-highlight.html=#000000
-highlight.keyword=#006600
-highlight.string=#CC0000
ifx.allow_persistent=On
ifx.blobinfile=0
ifx.byteasvarchar=0
@@ -35,19 +31,22 @@
ifx.max_persistent=-1
ifx.nullformat=0
ifx.textasvarchar=0
+ignore_repeated_errors=Off
+ignore_repeated_source=Off
implicit_flush=Off
-include_path=.:/usr/local/apache/php:/usr/local/apache/pi:/amkotron/www/php_inc
ludes
ingres.allow_persistent=On
ingres.default_database=
ingres.default_password=
ingres.default_user=
ingres.max_links=-1
ingres.max_persistent=-1
+log_errors_max_len=1024
log_errors=Off
-magic_quotes_gpc=Off
+magic_quotes_gpc=On
magic_quotes_runtime=Off
magic_quotes_sybase=Off
max_execution_time=30;Maximumexecutiontimeofeachscript,inseconds
+max_input_time=60;Maximumamountoftimeeachscriptmayspendparsingrequestdata
memory_limit=8M;Maximumamountofmemoryascriptmayconsume(8MB)
msql.allow_persistent=On
msql.max_links=-1
@@ -58,7 +57,9 @@
mssql.max_persistent=-1
mssql.min_error_severity=10
mssql.min_message_severity=10
+mssql.secure_connection=Off
mysql.allow_persistent=On
+mysql.connect_timeout=-1
mysql.default_host=
mysql.default_password=
mysql.default_port=
@@ -66,39 +67,46 @@
mysql.default_user=
mysql.max_links=-1
mysql.max_persistent=-1
+mysql.trace_mode=Off
odbc.allow_persistent=On
odbc.check_persistent=On
odbc.defaultbinmode=1
-odbc.defaultlrl=10000000
+odbc.defaultlrl=4096
odbc.max_links=-1
odbc.max_persistent=-1
output_buffering=Off
-output_handler=
-pfpro.defaulthost="test.signio.com"
+pfpro.defaulthost="test-payflow.verisign.com"
pfpro.defaultport=443
pfpro.defaulttimeout=30
pgsql.allow_persistent=On
+pgsql.auto_reset_persistent=Off
+pgsql.ignore_notice=0
+pgsql.log_notice=0
pgsql.max_links=-1
pgsql.max_persistent=-1
post_max_size=8M
-precision=14
+precision=12
register_argc_argv=On
-register_globals=On
+register_globals=Off
+report_memleaks=On
safe_mode_allowed_env_vars=PHP_
safe_mode_exec_dir=
+safe_mode_gid=Off
+safe_mode_include_dir=
safe_mode=Off
safe_mode_protected_env_vars=LD_LIBRARY_PATH
sendmail_from=me@localhost.com
session.auto_start=0
session.bug_compat_42=1
-session.bug_compat_warn=0
+session.bug_compat_warn=1
session.cache_expire=180
-session.cache_limiter=;nocache
+session.cache_limiter=nocache
session.cookie_domain=
session.cookie_lifetime=0
session.cookie_path=/
session.entropy_file=
session.entropy_length=0
+session.gc_divisor=100
session.gc_maxlifetime=1440
session.gc_probability=1
session.name=PHPSESSID
@@ -124,10 +132,10 @@
sybct.min_client_severity=10
sybct.min_server_severity=10
track_errors=Off
-upload_max_filesize=4M
-url_rewriter.tags="a=href,area=href,frame=src,input=src,form=fakeentry"
+unserialize_callback_func=
+upload_max_filesize=2M
+url_rewriter.tags="a=href,area=href,frame=src,input=src,form=,fieldset="
user_dir=
variables_order="EGPCS"
-warn_plus_overloading=Off
-y2k_compliance=Off
+y2k_compliance=On
zlib.output_compression=Off
Since you are asking about the php.ini I will take the php.ini-dist and
apply our local changes to it and let you know what happens.
Bill
Previous Comments:
------------------------------------------------------------------------
[2003-04-30 09:42:52] bill dot macallister at prideindustries dot com
The name of the snapshot that I installed is:
php4-STABLE-200304281330
The diff is pretty large. I am not sure when the last time
I installed a new php.ini was. I will poke around this interface and
see if there is a way to submit a file. If there is not then I will
add another comment with the diff, but my first attempt at pasting the
diff into this window resulted in some pretty wicked wrapping.
Bill
------------------------------------------------------------------------
[2003-04-30 06:07:41] sniper@php.net
What was the exact name of the snapshot packge you used?
What is the 'diff -u' between your php.ini and the php.ini-dist from
the snapshot like?
------------------------------------------------------------------------
[2003-04-28 10:50:17] bill dot macallister at prideindustries dot com
I tried the latest CVS snapshot and get the same behavior. That is
registering a session variable after its use causes a MySQL connect
failure in our application.
Let me know what is next.
Thanks,
Bill
------------------------------------------------------------------------
[2003-04-28 09:47:01] sniper@php.net
Please try using this CVS snapshot:
http://snaps.php.net/php4-STABLE-latest.tar.gz
For Windows:
http://snaps.php.net/win32/php4-win32-STABLE-latest.zip
------------------------------------------------------------------------
[2003-04-25 17:22:15] bill dot macallister at prideindustries dot com
This is as much a change in behavior as anything, but the
specific failure seems to indicate a deeper problem.
We have an application that uses out own session save handler
to store session data in a MySQL database. This application
has been in use on a 4.2.1 system for months now. When I
upgraded our test system to 4.3.1 we started getting failures.
The exact error was a MySQL connection failure because of
bad authentication credentials. The error report indicated
that the connection attempt was for webuser@localhost. Our
Apache server runs as webuser so this is the default user.
The code generating this message is:
$mysql_host = 'mysql-master';
$mysql_user = 'phpuser';
$mysql_pass = 'phppass';
$mysql_db = 'php_sessions';
if ($cnx = mysql_connect ($mysql_host,
$mysql_user,
$mysql_pass)) {
if ($db = mysql_select_db($mysql_db, $cnx)) {
$ret = $cnx;
}
}
So, the error message really is bogus or PHP's heap is
corrupt.
It turns out that I was able to make the error go away
by changing the code:
$s_user_id = $user_data["user_id"];
session_register("s_user_id");
to:
session_register("s_user_id");
$s_user_id = $user_data["user_id"];
It appears that in 4.2.1 you can use variables before you
register then and in 4.3.1 you cannot.
The 4.3.1 behavior is at least a bug in that PHP silently
accepts the invalid instruction sequence and corrupts its
environment so that completely unrelated parts of the
script will fail. If registration is required before use
I would really like to see session_register complain if
you try and do it wrong.
Bill
------------------------------------------------------------------------
--
Edit this bug report at http://bugs.php.net/?id=23354&edit=1