#37620 [Asn->Csd]: mysqli_ssl_set validation is innappropriate

From: Date: Mon, 29 May 2006 05:39:32 +0000
Subject: #37620 [Asn->Csd]: mysqli_ssl_set validation is innappropriate
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-97715@lists.php.net to get a copy of this message
ID: 37620 Updated by: georg@php.net Reported By: ap at zip dot com dot au -Status: Assigned +Status: Closed Bug Type: MySQLi related Operating System: Linux PHP Version: 5.1.4 Assigned To: georg New Comment: This bug has been fixed in CVS. Snapshots of the sources are packaged every three hours; this change will be in the next snapshot. You can grab the snapshot at http://snaps.php.net/. Thank you for the report, and for helping us make PHP better. Previous Comments: ------------------------------------------------------------------------ [2006-05-29 01:45:38] ap at zip dot com dot au Well I can't see an 'upload patch' thingy so here goes: --- ext/mysqli/mysqli_api.c.old 2006-05-29 11:34:32.000000000 +1000 +++ ext/mysqli/mysqli_api.c 2006-05-29 11:34:34.000000000 +1000 @@ -1770,7 +1770,7 @@ if (zend_parse_method_parameters(ZEND_NUM_ARGS() TSRMLS_CC, getThis(), "Osssss", &mysql_link, mysqli_link_class_entry, &ssl_parm[0], &ssl_parm_len[0], &ssl_parm[1], &ssl_parm_len[1], &ssl_parm[2], &ssl_parm_len[2], &ssl_parm[3], &ssl_parm_len[3], &ssl_parm[4], &ssl_parm_len[4]) == FAILURE) { return; } - MYSQLI_FETCH_RESOURCE(mysql, MY_MYSQL *, &mysql_link, "mysqli_link", MYSQLI_STATUS_VALID); + MYSQLI_FETCH_RESOURCE(mysql, MY_MYSQL *, &mysql_link, "mysqli_link", MYSQLI_STATUS_INITIALIZED); for (i=0; i < 5; i++) { if (!ssl_parm_len[i]) { ------------------------------------------------------------------------ [2006-05-29 01:43:09] ap at zip dot com dot au Description: ------------ When the validation code was introduced to fix bug #36802 a seemingly blind change was made to all (probably - I did not count :) the functions to validate against MYSQLI_STATUS_VALID as can be seen here: http://cvs.php.net/viewcvs.cgi/php-src/ext/mysqli/mysqli_api.c?r1=1.118.2.18&r2=1.118.2.19 This doesn't work for mysqli_ssl_set as it needs to be called before a connection to the mysql server is made and as such, judging by the documentation here: http://cvs.php.net/viewcvs.cgi/php-src/ext/mysqli/mysqli_api.c?view=log#rev1.118.2.19 MYSQLI_STATUS_INITIALIZED appears to be a better test to validate against. Have patch. Hopefully will be able to attach it once I submit it. Reproduce code: --------------- $db = mysqli_init(); mysqli_ssl_set($db,$key, $cert, $cacert, NULL,NULL); exit; Expected result: ---------------- *nothing* Actual result: -------------- Warning: mysqli_ssl_set(): invalid object or resource mysqli in test.php on line 5 ------------------------------------------------------------------------ -- Edit this bug report at http://bugs.php.net/?id=37620&edit=1

« previous php.bugs (#97715) next »