Skip to content

Commit 3a486dd

Browse files
committed
Merge branch 'PHP-8.6'
* PHP-8.6: ext/odbc: fix cond for SQL_NO_TOTAL that led to single byte buffer (#23462)
2 parents 267c6dc + fd7f27a commit 3a486dd

2 files changed

Lines changed: 31 additions & 3 deletions

File tree

‎ext/pdo_odbc/odbc_stmt.c‎

Lines changed: 7 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -774,10 +774,14 @@ static int odbc_stmt_get_col(pdo_stmt_t *stmt, int colno, zval *result, enum pdo
774774
* changed from 256 byte to LONG_COLUMN_BUFFER_SIZE.
775775
*/
776776
ssize_t to_fetch_len;
777-
if (orig_fetched_len == SQL_NO_TOTAL) {
778-
to_fetch_len = C->datalen > (LONG_COLUMN_BUFFER_SIZE - 1) ? (LONG_COLUMN_BUFFER_SIZE - 1) : C->datalen;
779-
} else {
777+
if (orig_fetched_len == SQL_NO_TOTAL && C->datalen > (LONG_COLUMN_BUFFER_SIZE - 1)) {
778+
to_fetch_len = C->datalen;
779+
} else if (orig_fetched_len > 0) {
780+
/* implicitly not SQL_NO_TOTAL, should be OK */
780781
to_fetch_len = orig_fetched_len;
782+
} else {
783+
/* size must be > 0 to actually get data */
784+
to_fetch_len = (LONG_COLUMN_BUFFER_SIZE - 1);
781785
}
782786
ssize_t to_fetch_byte = to_fetch_len + 1;
783787
char *buf2 = emalloc(to_fetch_byte);

‎ext/pdo_odbc/tests/gh23443.phpt‎

Lines changed: 24 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,24 @@
1+
--TEST--
2+
GH-23443 (infinite loop / 100% CPU when fetching a large nvarchar(max))
3+
--EXTENSIONS--
4+
pdo_odbc
5+
--SKIPIF--
6+
<?php
7+
require 'ext/pdo/tests/pdo_test.inc';
8+
PDOTest::skip();
9+
?>
10+
--FILE--
11+
<?php
12+
require 'ext/pdo/tests/pdo_test.inc';
13+
$db = PDOTest::test_factory('ext/pdo_odbc/tests/common.phpt');
14+
15+
/*
16+
* Likely depends on ZendMM page size + string overhead that affects long
17+
* column buffer size
18+
*/
19+
$n = 4499;
20+
$row = $db->query("SELECT REPLICATE(CAST(N'A' AS nvarchar(max)), $n) AS v")->fetch(PDO::FETCH_ASSOC);
21+
echo "ok\n";
22+
?>
23+
--EXPECT--
24+
ok

0 commit comments

Comments
 (0)