7 ms·
I've been programming for over a quarter century, and I feel pretty confident that I've never written anything that could confuse 'null' with NULL. I can't ev
by DavidWoof 9y ago
I've been programming for over a quarter century, and I feel pretty confident that I've never written anything that could confuse 'null' with NULL. I can't even think of a language that would let you easily do this.
If web forms aren't accepting NULL, then somebody probably specifically programmed the word 'null' into a filter of disallowed entries. Probably to stop clerks from entering the word 'null' to mean empty string. This has nothing to do with null being a reserved word in many languages, I'll bet the forms that aren't accepting 'null' aren't accepting 'none' or 'empty' either.
- zoul 9y agoString interpolation will often end up crossing the barrier between NULL as an empty pointer value and "null" as an ordinary string.
- tyingq 9y agoHere's an example where it creeps in: https://issues.apache.org/jira/browse/FLEX-33644 https://issues.apache.org/jira/browse/FLEX-33644
- DavidWoof 9y agoOK, that's a good one. Is this ActionScript that's doing the weird xml tag interpolation? I stand corrected, this is definitely possible. Still, I bet this person's real problems stem from explicit coding.
- jey 9y agoRelevant excerpt: var nullXML:XML = <root>null</root>; if (nullXML == null) { trace("Some XML is null"); } nullXML == null is true! That's... impressive.
- tyingq 9y agoBug is still unclosed too.
- jugg1es 9y agoJavascript lets you do it if you use the equality (==) instead of the identity (===).. i think.
- faceplanted 9y agoJavascript lets you do anything wrong if you use == and not === though, I'm pretty sure the machine apocalypse is going to happen because someone types == instead of === at this point.
- TallGuyShort 9y agoAt least if the Terminators are running JavaScript they'll be pretty easy to thwart.
- unkown-unknowns 9y agoBlackhat conference talk we might see in the future: "How I achieved remote code execution on the T-1000 and singlehandedly averted the extinction of the human race"
- profmonocle 9y agoJust tested (in the node CLI console) and that doesn't seem to be the case. Edit: It's true in PHP though. :-/
- tyingq 9y ago>Edit: It's true in PHP though. :-/ Can you post exactly what you did in PHP that shows "NULL" is equal to NULL? There's quite a few approaches like ==, ===, and is_null(). I can't get any to think "NULL" is NULL, though I imagine I'm missing something.
- fenwick67 9y agonull == undefined in js.
- 9y ago
- jlebrech 9y agoI can only see that happen if eval was ever used.
- ams6110 9y agoEval used to be used a lot, because web forms send everything as strings and you need to convert them to whatever datatypes on the back end. Eval probably permeates a lot of older legacy systems.
- boondaburrah 9y agoIt's probably old DB software, the interactions between, and not the language itself.
- ajuc 9y agoIn java + operator on strings works like this: Object a = null; String s = "foo bar " + a; // s == "foo bar null" So, it's possible to get "null" as a string downstream, when some variable that should be non-nulleable - was null. If you find such a bug and incompetently fix it by checking for "null" downstream instead of checking before turning variables into strings - you have the error from the article. Especially if you check ignoring the case. BTW guess how I know it's working like that :)
- incongruity 9y agoSure – that's just casting a null type as a string. So I guess if you have a comparison that somehow casts null to a string before comparing, you could run into this issue, but that's still bad programming. I used to own null@myundergrad.edu as an email alias (with my real university, not that generic .edu, of course) and I got all sorts of interesting things... but that was very intentional on my part.
- monsieurbanana 9y agoI don't think anyone ever argued that this wasn't because of bad programming.
- ajuc 9y agoFunnily enough - it's not the null-> String conversion, it's the "+" operator. That was at one point subject of heated debate in my previous job :) See: "null".equals((String)null) //false "null".equals((String)null+"") //true System.out.print((String)null) // throws NPE System.out.println((String)null) // prints "null", I guess because it appends "\n" inside
- incongruity 9y agoRight, but that operator is implicitly casting the null object to a string type – it has to, in a strict sense... some other languages would raise an error (and many would do the same as Java).
- benmmurphy 9y agoi just checked one of the projects where i work and a search for "null" returns 32 matches. its a java project and i believe the checks came about because stuff being converted to strings and then being sent back and forth between html forms and the backend. > git grep -i '"NULL"' src |wc -l > 32
- jameshart 9y agoOften it'll be compatibility with some upstream legacy system which exposes data as CSV or tab delimited, and outputs data like this: First,Middle,Last Alice,Q,Foo Bob,NULL,Bar In a world like that, some code got written in the wrong tier to output value.toUpper() == "NULL" ? "" : value and you wind up with a web form that can't roundtrip a name that contains the word 'null'.
- crdoconnor 9y agoYAML does this. It's one of the reasons I wrote a pared down 'dumb' YAML parser that assumes scalar values are strings unless directed otherwise: https://github.com/crdoconnor/strictyaml https://github.com/crdoconnor/strictyaml
- calibas 9y agoI imagine there's many special cases where a compiler's type coercion creates an issue.
- Animats 9y agoOne place where that can easily happen is loading comma-separated value files into a database. Some CSV files are formatted with the convention that fields only appear in quotes if they contain special characters. Thus, a data value of NULL is not quoted. This loses the distinction made in SQL databases between NULL, the null value, and "NULL", the string. (I just received some files like this. One is a file that has names. If someone had a name of NULL, it would go into the database as a null.)
- MattBearman 9y agoWhen using sequel pro with a MySQL database, typing NULL into a string field will make that field null rather than 'null', which always seemed like an odd design choice to me
- brak1 9y agoIts a good compromise i think. OTherwise to update a field to null it would need a button or right clicking and selected a null option. I would expect the amount of people who actually want to enter a 'null' string is minimal...
- prance 9y agoThis reasoning is probably behind some the OP's cases...
- Semaphor 9y agoYeah, Null is no problem. But thanks to code my predecessor wrote, >null< would be.
- __s 9y agoSQL abstraction layer at work in PHP special cases the string NULL to search for 'is null' rather than search for the string. So it happens