php.net |  support |  documentation |  report a bug |  advanced search |  search howto |  statistics |  random bug |  login
Bug #41734 weak logic handling
Submitted: 2007-06-19 00:47 UTC Modified: 2007-06-19 08:09 UTC
From: nomad at tekops dot com Assigned:
Status: Not a bug Package: Scripting Engine problem
PHP Version: 5.2.3 OS: linux
Private report: No CVE-ID: None
Welcome back! If you're the original bug submitter, here's where you can edit the bug or add additional notes.
If you forgot your password, you can retrieve your password here.
Password:
Status:
Package:
Bug Type:
Summary:
From: nomad at tekops dot com
New email:
PHP Version: OS:

 

 [2007-06-19 00:47 UTC] nomad at tekops dot com
Description:
------------
While writing in PHP, I've been finding that your engine is not very good at keeping logic straight.  simple if() statements break it, if they are one after another.  If I put some other code between the if() statements, or nest them differently, it can figure it out.

I have written compilers and language interpreters in the past, I am accustomed to writing flaw-free code in C and assembler.  No kidding, I'm old school where we didn't have the luxury of errors, ram, or disk space.

----
In my sample code, I am simply checking the domains on an email address the user has entered into two fields on a form.

My function gives me the correct answer, that the user (in my testing, that is me) has entered an email address with a domain that is not real.  myCheckDNSRR() returns 'false'.

In the first if() statement, it misses the false and barrels onward.  the second if() statement fails as well, and barrels onward.  The end result being, customer_service gets sent an email with a bogus user email address.

If the email is bad, I just want the page to reload.  I can get fancy, later.

Reproduce code:
---------------
/* saEmail1 & saEmail2 are email addresses posted to a form and submitted to this script (contact.php) */

$eValid = false;
$eValid = myCheckDNSRR($saEmail1);     /* See if emails are valid */
if($eValid == false)
     header("Location: <removed> /pages/contact.php");
		
$eValid = myCheckDNSRR($saEmail2);
if($eValid == false)
     header("Location: <removed> /pages/contact.php");

Expected result:
----------------
$eValid = false;
$eValid = myCheckDNSRR($saEmail1);     /* See if emails are valid */
if($eValid == false)
     header("Location: <removed> /pages/contact.php");

die("$eValid: \t" . ($eValid==false?"false":"true") . "/r");

$eValid = myCheckDNSRR($saEmail2);
if($eValid == false)
     header("Location: <removed> /pages/contact.php");

----
NOTE THE ADDED 'DIE()' CALL (ABOVE)

If I add this line in, the if above it works correctly and the screen refreshes if $eValid=false, or hits die() if it is 'true'.

This tells me your engine has a flaw in the if() processing code.  I've seen this several times.


Actual result:
--------------
If you want to send me the specific file that contains the code, I will happily see if I can fix it, and let you know where the problem is.

Patches

Pull Requests

History

AllCommentsChangesGit/SVN commitsRelated reports
 [2007-06-19 08:09 UTC] johannes@php.net
Thank you for taking the time to write to us, but this is not
a bug. Please double-check the documentation available at
http://www.php.net/manual/ and the instructions on how to report
a bug at http://bugs.php.net/how-to-report.php

.
 
PHP Copyright © 2001-2026 The PHP Group
All rights reserved.
Last updated: Wed Oct 07 11:00:02 2026 UTC