Bug #67043 [Csd]: substr_compare falsely reports equality on negative offset

From: Date: Wed, 09 Apr 2014 06:54:41 +0000
Subject: Bug #67043 [Csd]: substr_compare falsely reports equality on negative offset
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-185148@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=67043&edit=1

 ID:                 67043
 User updated by:    php at kirk dot at
 Reported by:        php at kirk dot at
 Summary:            substr_compare falsely reports equality on negative
                     offset
 Status:             Closed
 Type:               Bug
 Package:            Strings related
 Operating System:   any
 PHP Version:        5.5.11
 Assigned To:        datibbaw
 Block user comment: N
 Private report:     N

 New Comment:

That was fast. thanks!


Previous Comments:
------------------------------------------------------------------------
[2014-04-08 23:44:34] datibbaw@php.net

The fix for this bug has been committed.

Snapshots of the sources are packaged every three hours; this change
will be in the next snapshot. You can grab the snapshot at
http://snaps.php.net/.

 For Windows:

http://windows.php.net/snapshots/
 
Thank you for the report, and for helping us make PHP better.

Noob mistake on my part. Updated the test case to also test the aspect of substr_compare() that
deals with no explicit length given.

------------------------------------------------------------------------
[2014-04-08 17:54:14] aharvey@php.net

That does appear to be the relevant commit, per a git bisect.

Tjerk, can you have a look at this, please?

------------------------------------------------------------------------
[2014-04-08 09:53:26] php at kirk dot at

Saw this bug on multiple OSes, therefore changing OS to any.

------------------------------------------------------------------------
[2014-04-08 09:40:19] php at kirk dot at

Description:
------------
Since version 5.5.11 a substr_compare with a negative 3rd parameter (=offset, thus it should start
counting from the end of the string) incorrectly reports equality.

See http://3v4l.org/8co5P

I believe the bug could have been introduced in this commit: https://github.com/datibbaw/php-src/commit/e292391b3899ed2d80a8f44dc94074d68328c6ea

What caught my eye is the introduced cast to an unsigned integer but I don't know if this
really is the source of the bug.

Workaround: specify a length (absolute value of the negative offset)

Test script:
---------------
var_dump(substr_compare("template", "_emplate", -8));
var_dump(substr_compare("template", "_emplate", -8, 8));

Expected result:
----------------
int(21)
int(21)

Actual result:
--------------
int(0)
int(21)


------------------------------------------------------------------------



-- 
Edit this bug report at https://bugs.php.net/bug.php?id=67043&edit=1


Thread (5 messages)

« previous php.bugs (#185148) next »