Bug #66107 [Asn]: func_get_args change breaks by-reference in ReflectionClass::newInstanceArgs

From: Date: Tue, 10 Dec 2013 12:19:07 +0000
Subject: Bug #66107 [Asn]: func_get_args change breaks by-reference in ReflectionClass::newInstanceArgs
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-183223@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=66107&edit=1

 ID:                 66107
 Updated by:         dmitry@php.net
 Reported by:        sjon at hortensius dot net
 Summary:            func_get_args change breaks by-reference in
                     ReflectionClass::newInstanceArgs
 Status:             Assigned
 Type:               Bug
 Package:            Arrays related
 Operating System:   archlinux
 PHP Version:        5.5.6
 Assigned To:        dmitry
 Block user comment: N
 Private report:     N

 New Comment:

I've reverted changes in PHP-5.5 (not in PHP-5.6 and above).


Previous Comments:
------------------------------------------------------------------------
[2013-12-07 12:05:31] bugs dot php dot net at philippgampe dot info

This is a really nasty bug, because you cannot work around it.
Changing the interface breaks all 3rd-party code that makes use of your code.

------------------------------------------------------------------------
[2013-11-29 18:41:52] neufeind@php.net

This is a regression introduced from 5.5.5 to 5.5.6. Reading the news for 5.5.7RC1 now, it looks
like this won't be fixed anytime soon? :-(

Bug at TYPO3 for this. All current TYPO3-releases are affected and only work until 5.5.5.
http://forge.typo3.org/issues/53682

------------------------------------------------------------------------
[2013-11-25 12:40:18] dmitry@php.net

Actually, this code worked not on purpose but because of luck.
Previously, func_get_args() copied each argument making refcount == 1 and it allowed to pass it by
reference.

The following code demonstrates the real reason of the bug. The first call to call_user_func_array()
works but the second doesn't.

<?php
function foo(&$e) {
	var_dump($e);
}
call_user_func_array("foo", array(2));
$a = array(2);
call_user_func_array("foo", $a);
?>

The problem may be related to zend_fcall_info.no_separation handling.

------------------------------------------------------------------------
[2013-11-18 09:32:43] sjon at hortensius dot net

Since $e is an object it is already passed by reference; so the error is rather strange. The code
seems to check for an explicit &$e by-reference instead of an implicit variable=object=reference

------------------------------------------------------------------------
[2013-11-17 15:24:21] sjon at hortensius dot net

Description:
------------
The changelog states:

> Improved performance of array_merge() and func_get_args() by eliminating useless copying.

I think I found a bug related to this change. If it's not fixed it should at least be
documented.

Test script:
---------------
From http://3v4l.org/U40T0

<?php
class f
{
    function f(&$e){}
}

function getNew()
{
    $a = func_get_args();
    $c = array_shift($a);

    $r = new ReflectionClass($c);
    return $r->newInstanceArgs($a);
}

$e = new stdClass;

var_dump(getNew('f', $e));

Expected result:
----------------
object(f)#3 (0) {
}

Actual result:
--------------
Warning: Parameter 1 to f::f() expected to be a reference, value given in /in//in/U40T0 on line 14

Warning: ReflectionClass::newInstanceArgs(): Invocation of f's constructor failed in
/in//in/U40T0 on line 14
NULL


------------------------------------------------------------------------



-- 
Edit this bug report at https://bugs.php.net/bug.php?id=66107&edit=1


Thread (12 messages)

« previous php.bugs (#183223) next »