Bug #68118 [Ana]: $a->foo .= 'test'; can leave $a->foo undefined

From: Date: Tue, 30 Sep 2014 16:40:19 +0000
Subject: Bug #68118 [Ana]: $a->foo .= 'test'; can leave $a->foo undefined
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-187772@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=68118&edit=1 ID: 68118 Updated by: rasmus@php.net Reported by: rasmus@php.net Summary: $a->foo .= 'test'; can leave $a->foo undefined Status: Analyzed Type: Bug Package: Class/Object related Operating System: Any PHP Version: 5.5.17 Assigned To: dmitry Block user comment: N Private report: N New Comment: I don't think letting the error handler see the new property is a problem. I can't think of an error handler flow where that is important. It seems like the cleanest way to fix this edge case. Previous Comments: ------------------------------------------------------------------------ [2014-09-30 14:10:55] nikic@php.net The problem is that zend_get_property_info_quick uses the global EG(std_property_info) in case of undefined properties (see http://lxr.php.net/xref/PHP_5_5/Zend/zend_object_handlers.c#343). If the "undefined property" notice is throw in zend_std_get_property_ptr_ptr (see http://lxr.php.net/xref/PHP_5_5/Zend/zend_object_handlers.c#757) and the error handler accesses an undefined property as well, the EG(std_property_info) value will be overwritten and the assignment will happen to the wrong property. A simple solution would be to move the notice until after the property has been created. This will slightly change the behavior though, in that the error handler will be able to see the new property (whereas currently it can't). ------------------------------------------------------------------------ [2014-09-29 15:30:22] rasmus@php.net Description: ------------ PHP 5.5 introduced a new undefined property notice for this case: $a->undefined .= 'test'; This means that if a custom error handler is in place it will be triggered, of course. There is a weird side-effect that can happen if the error handler hits the same error causing the property name to be overwritten. eg. http://3v4l.org/KGXhF Compare to: http://3v4l.org/VPmLK PHP 5.6 and PHP 7 are affected as well. Test script: --------------- <?php class test { public function __construct() { $this->test = 'meow'; } } function error_handler() { $test = new test(); return true; } set_error_handler("error_handler"); // test one class a {} $a = new a; $a->undefined .= 'test'; echo isset($a->undefined) ? 'true' : 'false'; echo "\n"; // test two $b .= 'test'; echo isset($b) ? 'true' : 'false'; echo "\n"; Expected result: ---------------- true true Actual result: -------------- false true ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=68118&edit=1

« previous php.bugs (#187772) next »