#44181 [Opn->Bgs]: extract($a, EXTR_OVERWRITE|EXTR_REFS) can fail to create references to $a

From: Date: Sat, 25 Oct 2008 13:26:21 +0000
Subject: #44181 [Opn->Bgs]: extract($a, EXTR_OVERWRITE|EXTR_REFS) can fail to create references to $a
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-130092@lists.php.net to get a copy of this message
ID: 44181 Updated by: jani@php.net Reported By: robin_fernandes at uk dot ibm dot com -Status: Open +Status: Bogus Bug Type: Arrays related -Operating System: Windows +Operating System: * PHP Version: 5.2CVS-2008-02-20 (snap) New Comment: No need for several open reports about this issue. Previous Comments: ------------------------------------------------------------------------ [2008-02-20 09:30:23] robin_fernandes at uk dot ibm dot com I think this is because $a is passed by value, and the call to SEPARATE_ZVAL_TO_MAKE_IS_REF(entry) below splits the array element from the original array. The reference is therefore created to the element of the argument array which, after the split, is not the same as the element of the original array. From array.c: ... if (zend_u_hash_find(EG(active_symbol_table), Z_TYPE(final_name), Z_UNIVAL(final_name), Z_UNILEN(final_name) + 1, (void **) &orig_var) == SUCCESS) { SEPARATE_ZVAL_TO_MAKE_IS_REF(entry); // <-- Split! entry no longer refers to element of $a. zval_add_ref(entry); zval_ptr_dtor(orig_var); *orig_var = *entry; } else { ... I believe the root cause for this bug is the same as bug http://bugs.php.net/44182. I have submitted a patch for that bug which fixes this one too. ------------------------------------------------------------------------ [2008-02-20 09:25:43] robin_fernandes at uk dot ibm dot com Description: ------------ Using extract() with EXTR_OVERWRITE|EXTR_REFS does not create references to the array elements if the following conditions are true: - $a is referenced by some other variable (its is_ref flag is true). - A variable already exists in the current scope with a name matching the key. This is reproducible on 5.2, 5.3 and 6.0 snaps. Reproduce code: --------------- <?php $a = array('foo' => 'original.foo'); $foo = 'test'; $ref = &$a; extract($a, EXTR_OVERWRITE|EXTR_REFS); $foo = 'changed.foo'; var_dump($a['foo']); //expecting changed.foo ?> Expected result: ---------------- string(11) "changed.foo" Actual result: -------------- string(12) "original.foo" ------------------------------------------------------------------------ -- Edit this bug report at http://bugs.php.net/?id=44181&edit=1

« previous php.bugs (#130092) next »