Re: PHP 4.0 Bug #4200: OCIBindByName is unable to bind strings of Zero Length

From: Date: Thu, 20 Apr 2000 16:52:20 +0000
Subject: Re: PHP 4.0 Bug #4200: OCIBindByName is unable to bind strings of Zero Length
References: 1  Groups: php.dev 
Request: Send a blank email to php-dev+get-18060@lists.php.net to get a copy of this message
On Thu, Apr 20, 2000 at 03:59:22PM -0000, jnield@impole.com wrote: > From: jnield@impole.com > Operating system: Linux 2.2.5 (Redhat 6.1+Patches) > PHP version: 4.0 Release Candidate 1 > PHP Bug Type: Oracle related > Bug description: OCIBindByName is unable to bind strings of Zero Length > > When using OCIBindByName, strings of zero length can't be bound. This is a > major problem for me because I use bind-variables for input from > the user, to prevent the input from being interpreted as SQL. > > It must be possible to insert a string of zero length. Whether that is treated as NULL > or not should be left to the database if possible. > > It seems that this change between 3.1.14 and 4.0 RC1 occurred because strings > are now being passed to the OCI C library's OCIBindByName() as type SQLT_CHR > instead of SQLT_STR. OCIBindByName() does not seem to accept a value of 0 for > 'value_sz' when the type is SQLT_CHR, and there is no '\0' at the end of > the > string to look for. > > Let me know if there's anything I can do to help. This is preventing us > from really testing RC1. > > /* EXAMPLE SCRIPT 1 (assume $conn is an open connection) */ > $val = ""; > > $stmt = OCIParse($conn, "select ''||:v_bind||'' from dual"); > OCIBindByName($stmt, ":v_bind", &$val, -1); /* comes from ->value.str.len > */ > /*** RESULT: Warning bindlength == 0 (Correct behaviour as in 3.1.14) */ > OCIExecute($stmt); > /*** RESULT: ORA-01008 not all variables bound (problem...) */ > OCIFreeStatement($stmt); > > /* EXAMPLE SCRIPT 2 */ > $stmt = OCIParse($conn, "select ''||:v_bind||'' from dual"); > OCIBindByName($stmt, ":v_bind", &$val, 0); /* Explicitly of zero length */ > /*** RESULT: ORA-01009: missing mandatory parameter */ > OCIExecute($stmt); > /*** RESULT: ORA-01008: not all variables bound */ > OCIFreeStatement($stmt); the maxlength parameter in ocibindbyname is the maximum number of chars that can be set in the bound variable! just pass in anything > 0 but set val to "". setting it to -1 has the special meaning that ocibindbyname will calculate the bind-lenght based on the current length of php-variable that is to be bound. (please make sure that you fully understand what i just said!) i'm attatching a patch that makes "bindlength == 0" and "missing mandatory parameter" go away by forcing the value_sz to atleast 1 if it is 0 just before calling the OCIBindByName() function. tell me if that's what you want and i'll commit it before 4.0 hits final! tc > > > > -- > PHP Development Mailing List <http://www.php.net/> > To unsubscribe, e-mail: php-dev-unsubscribe@lists.php.net > For additional commands, e-mail: php-dev-help@lists.php.net > To contact the list administrators, e-mail: php-list-admin@lists.php.net -- Thies C. Arntzen "One Big-Mac, Small Fries and a Coke!" Digital Collections Phone +49 40 235350 Fax +49 40 23535180 Hammerbrookstr. 93 20097 Hamburg / Germany

Index: oci8.c =================================================================== RCS file: /repository/php4/ext/oci8/oci8.c,v retrieving revision 1.69 diff -u -r1.69 oci8.c --- oci8.c 2000/04/06 21:07:40 1.69 +++ oci8.c 2000/04/20 16:49:54 @@ -2482,10 +2482,16 @@ if ((ocitype == SQLT_CHR) && (value_sz == -1)) { convert_to_string_ex(var); value_sz = (*var)->value.str.len; +#if 0 if (value_sz == 0) { php_error(E_WARNING, "bindlength == 0"); /* XXX shitty message */ RETURN_FALSE; } +#endif + } + + if (value_sz == 0) { + value_sz = 1; } convert_to_string_ex(name);
« previous php.dev (#18060) next »