|
php.net | support | documentation | report a bug | advanced search | search howto | statistics | random bug | login |
[2004-12-09 11:14 UTC] php at trafex dot nl
Description:
------------
I was trying to execute the code that you see below.
But i got the error
"Warning: mysqli_stmt::bind_param() [function.bind-param]: Number of variables doesn't match number of parameters in prepared statement in..."
So i've tried everything, but still got the same error.
I think this is a bug, and i hope it can be fixed.
I've tried the code with PHP 5.0.2 and PHP 5.0.3 RC1
But still got the same error.
For more info please mail me, thanx!
Reproduce code:
---------------
/* create a prepared statement */
$stmt = $mysqli->prepare("SELECT username FROM pm_users WHERE user_id = ?")
/* bind parameters for markers */
$stmt->bind_param('i', $user_id);
$user_id = 1;
/* execute query */
$stmt->execute();
Expected result:
----------------
Nothing at the moment, just NO error.
Actual result:
--------------
Warning: mysqli_stmt::bind_param() [function.bind-param]: Number of variables doesn't match number of parameters in prepared statement in /home/projects/pacman/_public_html/test.php on line 16
PatchesPull RequestsHistoryAllCommentsChangesGit/SVN commits
|
|||||||||||||||||||||||||||||||||||||
Copyright © 2001-2025 The PHP GroupAll rights reserved. |
Last updated: Sun Oct 26 08:00:02 2025 UTC |
Thank you for this bug report. To properly diagnose the problem, we need a short but complete example script to be able to reproduce this bug ourselves. A proper reproducing script starts with <?php and ends with ?>, is max. 10-20 lines long and does not require any external resources such as databases, etc. If possible, make the script source available online and provide an URL to it here. Try avoid embedding huge scripts into the report. Can't reproduce: <?php $mysql = new mysqli("localhost", "root", "", "test"); printf("Client version: %s\n", $mysql->client_version); printf("Server version: %s\n", $mysql->server_version); $mysql->query("DROP TABLE IF EXISTS pm_users"); $mysql->query("CREATE TABLE pm_users(username varchar(20), user_id int)"); $mysql->query("INSERT INTO pm_users VALUES ('foo', 1)"); if ($stmt = $mysql->prepare("SELECT username FROM pm_users WHERE user_id = ?")) { $stmt->bind_param('i', $user_id); $user_id = 1; $stmt->execute(); $stmt->bind_result($name); $stmt->fetch(); printf("Name: %s\n", $name); $stmt->close(); } $mysql->close(); ?> Output: Client version: 40108 Server version: 40108 Name: fooOke i've edited the script you gave for my database. This script do i use now: Code: ---------------------------------------- <?php $mysql = new mysqli("localhost", "****", "****", "test"); printf("Client version: %s\n", $mysql->client_version); printf("Server version: %s\n", $mysql->server_version); $mysql->query("DROP TABLE IF EXISTS temp_table"); $mysql->query("CREATE TABLE temp_table(username varchar(20), user_id int)"); $mysql->query("INSERT INTO temp_table VALUES ('foo', 1)"); if ($stmt = $mysql->prepare("SELECT username FROM temp_table WHERE user_id = ?")) { $stmt->bind_param('i', $user_id); $user_id = 1; $stmt->execute(); $stmt->bind_result($name); $stmt->fetch(); printf("Name: %s\n", $name); $stmt->close(); } $mysql->close(); ?> ---------------------------------------- This script outputs: ---------------------------------------- Client version: 40107 Server version: 40107 Warning: mysqli_stmt::bind_param() [function.bind-param]: Number of variables doesn't match number of parameters in prepared statement in /home/projects/pacman/_public_html/test.php on line 16 Name: ---------------------------------------- A online example can you find here: http://testing.4worx.com/test.php And the phpinfo() here: http://testing.4worx.com/phpinfo.phpUpgraded PHP to 5.0.4-10.5 and that got the mysqli_stmt_bind_param() function working again with my scripts that only had INSERT SQL queries in them. The error still persisted when binding input parameters on SELECT queries, however this can be fixed by paying close attention to syntax. DO NOT use the same syntax you would for a normal query. When sending a prepared statement it is important to omit quotation marks ('?') around the placeholders. Prepared statement don't require them for strings. EXAMPLE: $username='foo'; $id=1; $prepare="SELECT * FROM test WHERE user='?' and id=?"; $sql->stmt=mysqli_stmt_init($sql->db); mysqli_stmt_prepare($sql->stmt,$prepare); echo mysqli_stmt_param_count($sql->stmt); // returns 0 mysqli_stmt_bind_param($sql->stmt,'si',$username,$id); // throws an error That throws an error however... $username='foo'; $id=1; $prepare='SELECT * FROM test WHERE user=? and id=?'; $sql->stmt=mysqli_stmt_init($sql->db); mysqli_stmt_prepare($sql->stmt,$prepare); echo mysqli_stmt_param_count($sql->stmt); // returns 2 mysqli_stmt_bind_param($sql->stmt,'si',$username,$id); // works OK The PHP documentation is not mistaken in the examples it gives for prepared statements but perhaps it could be a little more explicit in pointing out this easy-to-make syntax error.This script (with 1 variable): ------------------------------ <?php $mysql = new mysqli("localhost", "***", "***", "test"); printf("Client version: %s\n", $mysql->client_version); printf("Server version: %s\n", $mysql->server_version); $mysql->query("DROP TABLE IF EXISTS temp_table"); $mysql->query("CREATE TABLE temp_table(username varchar(20), user_id int)"); $mysql->query("INSERT INTO temp_table VALUES ('foo', 1)"); if ($stmt = $mysql->prepare("SELECT username FROM temp_table WHERE user_id = ?")) { $stmt->bind_param('i', $user_id); $user_id = 1; $stmt->execute(); $stmt->bind_result($name); $stmt->fetch(); printf("Name: %s\n", $name); $stmt->close(); } $mysql->close(); ?> Output: ------- Client version: 40107 Server version: 50018 Name: This script (with 2 variables): ------------------------------ <?php $mysql = new mysqli("localhost", "***", "***", "test"); printf("Client version: %s\n", $mysql->client_version); printf("Server version: %s\n", $mysql->server_version); $mysql->query("DROP TABLE IF EXISTS temp_table"); $mysql->query("CREATE TABLE temp_table(username varchar(20), user_id int, user_id2 int)"); $mysql->query("INSERT INTO temp_table VALUES ('foo', 1, 2)"); if ($stmt = $mysql->prepare("SELECT username FROM temp_table WHERE user_id = ? AND user_id2 = ?")) { $stmt->bind_param('ii', $user_id, $user_id2); $user_id = 1; $user_id2 = 2; $stmt->execute(); $stmt->bind_result($name); $stmt->fetch(); printf("Name: %s\n", $name); $stmt->close(); } $mysql->close(); ?> Output: ------- Client version: 40107 Server version: 50018 Warning: mysqli_stmt::bind_param() [function.bind-param]: Number of variables doesn't match number of parameters in prepared statement in C:\wamp\www\learn\mysql.php on line 12 Name: It's weird...I am using WAMP 5 (MySQL 5.0.21 Client 40107, Apache 2 , Windows Server 2003). When i try to execute followint script i get error: Number of variables doesn't match number of parameters in prepared statement <?php $capital=1; $mysqli=new mysqli('192.168.0.1','root','*','world'); //INIT statement $stmt=$mysqli->stmt_init(); if (mysqli_connect_errno()) { printf("Connect failed: %s\n", mysqli_connect_error()); exit(); } //Create statement for Procedure $stmt=$mysqli->stmt_init(); if(!$stmt) { printf("Error creating Statement: $s\n",$mysqli->error); exit(); } $stmt=$mysqli->prepare("Select name from country where Capital = ?"); if(!$stmt) { printf("Error creating Statement: %s\n",$mysqli->errno); printf("Error creating Statement: %s\n",$mysqli->error); printf("Statement Error: %s\n",$stmt->error); exit(); } printf("No of Parameters in Statement: %d \n",$stmt->param_count); printf("Client version: %s\n", $mysqli->client_version); printf("Server version: %s\n", $mysqli->server_version); //Bind the paremeter values that are to be passed to stored procedure //This line gives error $stmt->bind_param("i",$capital); //execute the stored procedure $stmt->execute(); $stmt->bind_result($name); $stmt->fetch(); printf("Country Name: %s\n", $name); $stmt->close(); $mysqli->close(); ?>oops correction - I got it workig as follows - $vsql1 = "select userid, email from re_users u where email = ? and password = ?"; $preparedstatement1 = $gvdblink->prepare($vsql1); $preparedstatement1->bind_param('ss', $bv1, $bv2); It is funny that when I put an * (asterix) I get a warning/error. It is sad that we have to specify every column we need to retreive. This fails - $vsql1 = "select * from re_users u where email = ? and password = ?";I've had the same problem.. and my libs were new. I had: $sqlquery = "UPDATE $table SET title='?', msg='?', date='?' WHERE ID='?'"; ....... $stmt->bind_param('sssi', $_SESSION['tit'], $_SESSION['tex'], $_SESSION['dat'], $_SESSION['id']); --> ERROR - Number of variables doesn't match number of parameters in prepared statement --> SOLVE Remove the '' before and after the ? -> "UPDATE $table SET title=?, msg=?, date=? WHERE ID=?" and now he did the update ;) have funThis bug is rendering mysqli unusable to me! I can't even get it to accept something like this: $stmt = $link->prepare("SELECT ?, ?"); $stmt->bind_param("i", $this->ckey); $stmt->bind_param("i", $this->ckey); $stmt->execute(); I get the same "Number of variables doesn't match number of parameters in prepared statement in..." warning. Anybody found a solution? Is this API marginally usable?