Bug #68118 [Ana]: $a->foo .= 'test'; can leave $a->foo undefined
| From: | rasmus@php.net | Date: | Tue, 30 Sep 2014 16:40:19 +0000 |
| Subject: | Bug #68118 [Ana]: $a->foo .= 'test'; can leave $a->foo undefined | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-187772@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=68118&edit=1
ID: 68118
Updated by: rasmus@php.net
Reported by: rasmus@php.net
Summary: $a->foo .= 'test'; can leave $a->foo undefined
Status: Analyzed
Type: Bug
Package: Class/Object related
Operating System: Any
PHP Version: 5.5.17
Assigned To: dmitry
Block user comment: N
Private report: N
New Comment:
I don't think letting the error handler see the new property is a problem. I can't think
of an error handler flow where that is important. It seems like the cleanest way to fix this edge
case.
Previous Comments:
------------------------------------------------------------------------
[2014-09-30 14:10:55] nikic@php.net
The problem is that zend_get_property_info_quick uses the global EG(std_property_info) in case of
undefined properties (see http://lxr.php.net/xref/PHP_5_5/Zend/zend_object_handlers.c#343).
If the "undefined property" notice is throw in zend_std_get_property_ptr_ptr (see http://lxr.php.net/xref/PHP_5_5/Zend/zend_object_handlers.c#757)
and the error handler accesses an undefined property as well, the EG(std_property_info) value will
be overwritten and the assignment will happen to the wrong property.
A simple solution would be to move the notice until after the property has been created. This will
slightly change the behavior though, in that the error handler will be able to see the new property
(whereas currently it can't).
------------------------------------------------------------------------
[2014-09-29 15:30:22] rasmus@php.net
Description:
------------
PHP 5.5 introduced a new undefined property notice for this case:
$a->undefined .= 'test';
This means that if a custom error handler is in place it will be triggered, of course. There is a
weird side-effect that can happen if the error handler hits the same error causing the property name
to be overwritten. eg.
http://3v4l.org/KGXhF
Compare to:
http://3v4l.org/VPmLK
PHP 5.6 and PHP 7 are affected as well.
Test script:
---------------
<?php
class test {
public function __construct() {
$this->test = 'meow';
}
}
function error_handler() {
$test = new test();
return true;
}
set_error_handler("error_handler");
// test one
class a {}
$a = new a;
$a->undefined .= 'test';
echo isset($a->undefined) ? 'true' : 'false';
echo "\n";
// test two
$b .= 'test';
echo isset($b) ? 'true' : 'false';
echo "\n";
Expected result:
----------------
true
true
Actual result:
--------------
false
true
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=68118&edit=1