Bug #69537 [Com]: __debugInfo with empty string for key gives error

From: Date: Fri, 08 May 2015 22:13:23 +0000
Subject: Bug #69537 [Com]: __debugInfo with empty string for key gives error
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-192595@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=69537&edit=1

 ID:                 69537
 Comment by:         ircmaxell@php.net
 Reported by:        danack@php.net
 Summary:            __debugInfo with empty string for key gives error
 Status:             Not a bug
 Type:               Bug
 Package:            Scripting Engine problem
 Operating System:   N/A
 PHP Version:        5.6.8
 Block user comment: N
 Private report:     N

 New Comment:

Reading the \0 is a bug, as that's past the end of the string (well, greater than the length
variable).

The bug isn't saying that strings starting with \0 should be accepted. It's saying that it
shouldn't even get that far.

Basically, the check at http://lxr.php.net/xref/PHP_TRUNK/Zend/zend_compile.c#1242
should also include a check against name->len:

    if (name->len == 0 || name->val[0] != '\0') {


Previous Comments:
------------------------------------------------------------------------
[2015-05-05 03:09:48] laruence@php.net

Thank you for taking the time to write to us, but this is not
a bug. Please double-check the documentation available at
http://www.php.net/manual/ and the instructions on how to
report
a bug at http://bugs.php.net/how-to-report.php



------------------------------------------------------------------------
[2015-04-29 05:22:50] laruence@php.net

the problem is, we use \0class_name\0property_name for private properties.

so, \0 has a special meaning if it's the lead char.

------------------------------------------------------------------------
[2015-04-29 05:21:57] laruence@php.net

$ sapi/cli/php -n -d error_reporting=-1 /tmp/1.php
A Object
(
    [foo] => bar
    [
Notice: Illegal member variable name in /tmp/1.php on line 14
] => bar
)

------------------------------------------------------------------------
[2015-04-28 12:35:20] danack@php.net

Hi Laruence,

Sorry, I don't understand what you mean. The tests don't cover the case when the key is
empty.

The issue also doesn't manifest when the empty key isn't the first element i.e. this:

<?php 

class A{
    function __debugInfo(){
        return [
            
            "foo" => 'bar',
            '' => 'bar',
        ];
    }
}


print_r(new A);

?>

works fine.

------------------------------------------------------------------------
[2015-04-28 02:42:56] laruence@php.net

or at least a expected side affect

------------------------------------------------------------------------


The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at

    https://bugs.php.net/bug.php?id=69537


--
Edit this bug report at https://bugs.php.net/bug.php?id=69537&edit=1


Thread (12 messages)

« previous php.bugs (#192595) next »