#23354 [Opn]: Use of variable before registration problem

From: Date: Wed, 30 Apr 2003 15:05:08 +0000
Subject: #23354 [Opn]: Use of variable before registration problem
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-38836@lists.php.net to get a copy of this message
ID: 23354 User updated by: bill dot macallister at prideindustries dot com Reported By: bill dot macallister at prideindustries dot com Status: Open Bug Type: Session related Operating System: Linux 2.4.18-27.7.xsmp PHP Version: 4.3.1 New Comment: I don't see how to upload a file. The diff contains a lot of comment differences. What I did was to write a perl script that stripped the whole line comments, block delimiters, and blank lines. Then sorted the output the output. Then I did a diff of that. Here is the result: d2x% diff -u php.ini-stripped-sorted php.ini-dist-stripped-sorted --- php.ini-stripped-sorted Wed Apr 30 07:52:41 2003 +++ php.ini-dist-stripped-sorted Wed Apr 30 07:53:03 2003 @@ -1,12 +1,14 @@ allow_call_time_pass_reference=On allow_url_fopen=On asp_tags=Off -'atMYSQL_PORT. auto_append_file= -auto_prepend_file=/usr/local/apache/php/prepend.php3 +auto_prepend_file= bcmath.scale=0 +dbx.colnames_case="unchanged" default_mimetype="text/html" +default_socket_timeout=60 define_syslog_variables=Off +disable_classes= disable_functions= display_errors=On display_startup_errors=Off @@ -15,15 +17,9 @@ engine=On error_reporting=E_ALL&~E_NOTICE expose_php=On -extension_dir=./ +extension_dir="./" file_uploads=On gpc_order="GPC" -highlight.bg=#FFFFFF -highlight.comment=#FF9900 -highlight.default=#0000CC -highlight.html=#000000 -highlight.keyword=#006600 -highlight.string=#CC0000 ifx.allow_persistent=On ifx.blobinfile=0 ifx.byteasvarchar=0 @@ -35,19 +31,22 @@ ifx.max_persistent=-1 ifx.nullformat=0 ifx.textasvarchar=0 +ignore_repeated_errors=Off +ignore_repeated_source=Off implicit_flush=Off -include_path=.:/usr/local/apache/php:/usr/local/apache/pi:/amkotron/www/php_inc ludes ingres.allow_persistent=On ingres.default_database= ingres.default_password= ingres.default_user= ingres.max_links=-1 ingres.max_persistent=-1 +log_errors_max_len=1024 log_errors=Off -magic_quotes_gpc=Off +magic_quotes_gpc=On magic_quotes_runtime=Off magic_quotes_sybase=Off max_execution_time=30;Maximumexecutiontimeofeachscript,inseconds +max_input_time=60;Maximumamountoftimeeachscriptmayspendparsingrequestdata memory_limit=8M;Maximumamountofmemoryascriptmayconsume(8MB) msql.allow_persistent=On msql.max_links=-1 @@ -58,7 +57,9 @@ mssql.max_persistent=-1 mssql.min_error_severity=10 mssql.min_message_severity=10 +mssql.secure_connection=Off mysql.allow_persistent=On +mysql.connect_timeout=-1 mysql.default_host= mysql.default_password= mysql.default_port= @@ -66,39 +67,46 @@ mysql.default_user= mysql.max_links=-1 mysql.max_persistent=-1 +mysql.trace_mode=Off odbc.allow_persistent=On odbc.check_persistent=On odbc.defaultbinmode=1 -odbc.defaultlrl=10000000 +odbc.defaultlrl=4096 odbc.max_links=-1 odbc.max_persistent=-1 output_buffering=Off -output_handler= -pfpro.defaulthost="test.signio.com" +pfpro.defaulthost="test-payflow.verisign.com" pfpro.defaultport=443 pfpro.defaulttimeout=30 pgsql.allow_persistent=On +pgsql.auto_reset_persistent=Off +pgsql.ignore_notice=0 +pgsql.log_notice=0 pgsql.max_links=-1 pgsql.max_persistent=-1 post_max_size=8M -precision=14 +precision=12 register_argc_argv=On -register_globals=On +register_globals=Off +report_memleaks=On safe_mode_allowed_env_vars=PHP_ safe_mode_exec_dir= +safe_mode_gid=Off +safe_mode_include_dir= safe_mode=Off safe_mode_protected_env_vars=LD_LIBRARY_PATH sendmail_from=me@localhost.com session.auto_start=0 session.bug_compat_42=1 -session.bug_compat_warn=0 +session.bug_compat_warn=1 session.cache_expire=180 -session.cache_limiter=;nocache +session.cache_limiter=nocache session.cookie_domain= session.cookie_lifetime=0 session.cookie_path=/ session.entropy_file= session.entropy_length=0 +session.gc_divisor=100 session.gc_maxlifetime=1440 session.gc_probability=1 session.name=PHPSESSID @@ -124,10 +132,10 @@ sybct.min_client_severity=10 sybct.min_server_severity=10 track_errors=Off -upload_max_filesize=4M -url_rewriter.tags="a=href,area=href,frame=src,input=src,form=fakeentry" +unserialize_callback_func= +upload_max_filesize=2M +url_rewriter.tags="a=href,area=href,frame=src,input=src,form=,fieldset=" user_dir= variables_order="EGPCS" -warn_plus_overloading=Off -y2k_compliance=Off +y2k_compliance=On zlib.output_compression=Off Since you are asking about the php.ini I will take the php.ini-dist and apply our local changes to it and let you know what happens. Bill Previous Comments: ------------------------------------------------------------------------ [2003-04-30 09:42:52] bill dot macallister at prideindustries dot com The name of the snapshot that I installed is: php4-STABLE-200304281330 The diff is pretty large. I am not sure when the last time I installed a new php.ini was. I will poke around this interface and see if there is a way to submit a file. If there is not then I will add another comment with the diff, but my first attempt at pasting the diff into this window resulted in some pretty wicked wrapping. Bill ------------------------------------------------------------------------ [2003-04-30 06:07:41] sniper@php.net What was the exact name of the snapshot packge you used? What is the 'diff -u' between your php.ini and the php.ini-dist from the snapshot like? ------------------------------------------------------------------------ [2003-04-28 10:50:17] bill dot macallister at prideindustries dot com I tried the latest CVS snapshot and get the same behavior. That is registering a session variable after its use causes a MySQL connect failure in our application. Let me know what is next. Thanks, Bill ------------------------------------------------------------------------ [2003-04-28 09:47:01] sniper@php.net Please try using this CVS snapshot: http://snaps.php.net/php4-STABLE-latest.tar.gz For Windows: http://snaps.php.net/win32/php4-win32-STABLE-latest.zip ------------------------------------------------------------------------ [2003-04-25 17:22:15] bill dot macallister at prideindustries dot com This is as much a change in behavior as anything, but the specific failure seems to indicate a deeper problem. We have an application that uses out own session save handler to store session data in a MySQL database. This application has been in use on a 4.2.1 system for months now. When I upgraded our test system to 4.3.1 we started getting failures. The exact error was a MySQL connection failure because of bad authentication credentials. The error report indicated that the connection attempt was for webuser@localhost. Our Apache server runs as webuser so this is the default user. The code generating this message is: $mysql_host = 'mysql-master'; $mysql_user = 'phpuser'; $mysql_pass = 'phppass'; $mysql_db = 'php_sessions'; if ($cnx = mysql_connect ($mysql_host, $mysql_user, $mysql_pass)) { if ($db = mysql_select_db($mysql_db, $cnx)) { $ret = $cnx; } } So, the error message really is bogus or PHP's heap is corrupt. It turns out that I was able to make the error go away by changing the code: $s_user_id = $user_data["user_id"]; session_register("s_user_id"); to: session_register("s_user_id"); $s_user_id = $user_data["user_id"]; It appears that in 4.2.1 you can use variables before you register then and in 4.3.1 you cannot. The 4.3.1 behavior is at least a bug in that PHP silently accepts the invalid instruction sequence and corrupts its environment so that completely unrelated parts of the script will fail. If registration is required before use I would really like to see session_register complain if you try and do it wrong. Bill ------------------------------------------------------------------------ -- Edit this bug report at http://bugs.php.net/?id=23354&edit=1

« previous php.bugs (#38836) next »