PDO_DBLIB encodes passed binary data as a string, which is fragile
还没有人认领这个 Issue。
- 主要语言
- C
- 星标
- 40.4k
- 派生
- 8.2k
- 平均合并
- 2 天 13 小时
- 30 天内合并 PR
- 96
描述
Description
A user reported an issue to me where they're trying to insert binary data (a PNG file, bound as a PARAM_LOB, inserting into a varbinary column) into an SQL Server database, and unexpectedly get a syntax error back.
It looks like PDO_DBLIB doesn't actually implement binding (no param hook is implemented), so it relies on PDO to do substitution and send the fully substituted query string back to the server (I assume this is a FreeTDS, or TDS protocol limitation. It's been a long, long time since I touched SQL Server...), instead of sending the query and parameters separate. The PDO parsing defers to the driver's quoter to turn the value into a string, escaping things like ' and \. However, it seems this isn't sufficient with binary data that could have things like nulls in the middle of the string.
The following code:
<?php
try {
$image1 = base64_decode("..."); // a PNG image in this case
$pdo = new PDO("dblib:host=SQLTEST;dbname=test", "sa", "...");
if ($pdo) {
$sql = "insert into dbo.TicketImage (TicketID, Image1, Image2) VALUES (168, ?, NULL)";
$stmt = $pdo->prepare($sql);
$stmt->bindParam(1, $image1, PDO::PARAM_LOB);
$stmt->execute();
}
} catch (PDOException $e) {
var_dump($e);
}
Resulted in this output:
object(PDOException)#3 (8) {
["message":protected]=>
string(165) "SQLSTATE[HY000]: General error: 20018 Incorrect syntax near ''. [20018] (severity 15) [insert into dbo.TicketImage (TicketID, Image1, Image2) VALUES (168, '�PNG
�
]"
["string":"Exception":private]=>
string(0) ""
["code":protected]=>
string(5) "HY000"
["file":protected]=>
string(59) "/home/calvin/src/sqlserver/sql server binary blob issue.php"
["line":protected]=>
int(16)
["trace":"Exception":private]=>
array(1) {
[0]=>
array(5) {
["file"]=>
string(59) "/home/calvin/src/sqlserver/sql server binary blob issue.php"
["line"]=>
int(16)
["function"]=>
string(7) "execute"
["class"]=>
string(12) "PDOStatement"
["type"]=>
string(2) "->"
}
}
["previous":"Exception":private]=>
NULL
["errorInfo"]=>
array(5) {
[0]=>
string(5) "HY000"
[1]=>
int(20018)
[2]=>
string(127) "Incorrect syntax near ''. [20018] (severity 15) [insert into dbo.TicketImage (TicketID, Image1, Image2) VALUES (168, '�PNG
�
]"
[3]=>
int(-1)
[4]=>
int(15)
}
}
But I expected this output instead:
// success...
Other details
SQL Server version:
Microsoft SQL Server 2016 (SP2) (KB4052908) - 13.0.5026.0 (X64)
Mar 18 2018 09:11:49
Copyright (c) Microsoft Corporation
Express Edition (64-bit) on Windows Server 2016 Standard 10.0 <X64> (Build 14393: ) (Hypervisor)
FreeTDS info:
Compile-time settings (established with the "configure" script)
Version: freetds v1.3.3
freetds.conf directory: /etc
MS db-lib source compatibility: yes
Sybase binary compatibility: yes
Thread safety: yes
iconv library: yes
TDS version: auto
iODBC: no
unixodbc: yes
SSPI "trusted" logins: no
Kerberos: yes
OpenSSL: no
GnuTLS: yes
MARS: yes
The provided table:
CREATE TABLE [dbo].[TicketImage](
[TicketID] [int] NOT NULL,
[Image1] [varbinary](max) NULL,
[Image2] [varbinary](max) NULL,
CONSTRAINT [PK_TicketImage] PRIMARY KEY CLUSTERED
(
[TicketID] ASC
)WITH (PAD_INDEX = OFF, STATISTICS_NORECOMPUTE = OFF, IGNORE_DUP_KEY = OFF, ALLOW_ROW_LOCKS = ON, ALLOW_PAGE_LOCKS = ON) ON [PRIMARY]
) ON [PRIMARY] TEXTIMAGE_ON [PRIMARY]
GO
PHP Version
PHP 8.1.13
Operating System
Fedora 37
贡献指南
从这里开始
- 先读完整个 Issue,再读项目的贡献指南。
- 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
- Fork 仓库,在一个分支上完成修改。
- 提交 Pull Request,并在描述里引用这个 Issue 编号。
调研方向
首先跟踪报告中描述的 PDO_DBLIB 参数处理和 PDO 替换路径,包括驱动程序的 quoter 如何处理 PARAM_LOB 值。检查 FreeTDS/TDS 限制是否会影响可用的方法。提供的二进制 PNG 示例能够在没有语法错误的情况下插入 varbinary 列,并且已确定适当的回归覆盖范围,即视为完成。
由索引模型根据 Issue 内容生成。
评估
- 技术栈
- php, sql
- 领域
- databases
- Issue 类型
- 缺陷
- 难度
- 5/5
- 预计耗时
- 一周以上
- 活跃度
- 停滞
- 描述清晰度
- 需要澄清
- 新手友好度
- 30/100