Closed (duplicate)
Project:
Drush
Version:
8.x-6.x-dev
Component:
SQL
Priority:
Normal
Category:
Bug report
Assigned:
Issue tags:
Reporter:
Created:
23 Mar 2011 at 23:06 UTC
Updated:
18 Sep 2013 at 20:19 UTC
Jump to comment: Most recent file
Comments
Comment #1
fp commentedThe attached patch wraps the passwords within quotes:
Comment #2
msonnabaum commentedSeems reasonable.
Attached patch accomplishes the same by changing our existing escapeshellcmd to drush_escapeshellarg.
Comment #3
fp commentedGreat. Thanks.
Comment #4
hanoiiNot sure if it was because of this, but this is actually fixed in the code, latest -dev or git checkout does it, so mark it as fixed.
Comment #5
greg.1.anderson commented#2 was never committed, but by some coincidence I applied the same correction when I committed #766080: Windows support for drush: escaping the path to drush in backend invoke and elsewhere, so this issue is in fact fixed. Thanks for noticing.
Comment #7
kenorb commentedI have the same problem with drush version 4.5
Looks like the patch wasn't applied into: /usr/local/Cellar/drush/4.5/commands/sql/sql.drush.inc
Still is:
Comment #8
kenorb commentedCreated separate bug: #1348110: drush sql-connect returns ERROR 1045 (28000): Access denied
Comment #9
joelcollinsdc commentedSorry, maybe I'm missing something here, but this bug still exists in 4.5, right?
I can confirm that the patch in #2 works for me
Comment #10
greg.1.anderson commentedThe metadata on the issue was wrong. It was fixed in drush-5, but not backported to drush-4. Most of the escape-related fixes done in drush-5 for Windows support were not backported, but Mark can decide if this should be an exception or not.
Comment #11
joelcollinsdc commentedOk thanks. upon more investigation I found that this patch did more harm than good. i will try the 5 branch.
For future benefits, I found that when using this syntax: $(drush @whatever sql-connect) < myfile.sql; with database passwords that have a ! in it, the exclamation point doesn't get escaped, so i piped it through sed like so:
$(drush $whatever sql-connect | sed 's/\!/\\\!/g') < file.sql
Comment #12
msonnabaum commentedSince the patch in #2 is already in drush5, I'm committing that to 4.x.
Comment #14
tangent commentedI'm experiencing this issue with Drush 5.8 and PHP 5.3.10 on Linux. I've confirmed that the code from the patch exists in Drush.
sql-connect works fine for passwords lacking non-alphanumeric characters but the !%&' characters (these are the only ones I've tested) all result in a mysql 1045 (access denied) error.
Was there a regression or is this possibly an issue with PHP 5.3?
Comment #15
greg.1.anderson commentedI'm guessing that spaces in passwords still work, and certain special characters never worked. Could you show the output of a run with the --debug or --simulate option?
Comment #16
tangent commentedComment #17
greg.1.anderson commentedLooks like the shell escaping is okay, but perhaps MySQL expects its parameter to contain additional escaping when there are special characters. If #671906: mysql credentials leak in drush sqlc were fixed, that would take care of this issue as well.
Comment #18
greg.1.anderson commentedClosed #1737054: sql-connect and sql-cli don't work if password contains a + as a dup of this issue.
Comment #19
greg.1.anderson commentedThis issue was marked
closed (won't fix)because Drush has moved to Github.If desired, you may copy this bug to our Github project and then post a link here to the new issue. Please also change the status of this issue to
closed (duplicate).Please ask support questions on Drupal Answers.
Comment #20
tangent commentedI've recreated this issue at https://github.com/drush-ops/drush/issues/125.