Bug #69778 [Opn->Ver]: array_filter() modifies var out of scope when used with cb accepting by ref
| From: | nikic@php.net | Date: | Wed, 10 Jun 2015 09:15:44 +0000 |
| Subject: | Bug #69778 [Opn->Ver]: array_filter() modifies var out of scope when used with cb accepting by ref | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-193280@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=69778&edit=1
ID: 69778
Updated by: nikic@php.net
Reported by: kernins at gmail dot com
Summary: array_filter() modifies var out of scope when used
with cb accepting by ref
-Status: Open
+Status: Verified
Type: Bug
Package: Arrays related
Operating System: Debian
PHP Version: 5.6.9
Block user comment: N
Private report: N
New Comment:
Reproduce: http://3v4l.org/K7bRf
So looks like this is 5.x only.
Previous Comments:
------------------------------------------------------------------------
[2015-06-09 00:35:53] kernins at gmail dot com
Even worse it propagates thru getters
class Foo
{
private $_arr=[' ', ' foo ', ' ', ' bar ',
'baz ', ' '];
public function getArr()
{
return $this->_arr;
}
}
$foo=new Foo();
var_dump($foo->getArr());
something($foo->getArr());
var_dump($foo->getArr());
Result is the same as above
------------------------------------------------------------------------
[2015-06-09 00:01:07] kernins at gmail dot com
Description:
------------
See the code, it explains better than words.
I've explicitly mentioned array_filter(), coz the bug is 100% reproducible with this function,
but array_walk/map() works as expected.
Confirmed on 5.6.9-1~dotdeb+7.1 and 5.4.34-1~dotdeb.0
Both are CLI, didn't tested on FPM
Test script:
---------------
$arr=[' ', ' foo ', ' ', ' bar ', 'baz
', ' '];
function something(array $arg)
{
array_filter($arg, function(&$el){return strlen($el=trim($el));});
}
var_dump($arr);
something($arr);
var_dump($arr);
Expected result:
----------------
Both var_dumps should print the original array
array(6) {
[0]=>
string(3) " "
[1]=>
string(7) " foo "
[2]=>
string(3) " "
[3]=>
string(8) " bar "
[4]=>
string(6) "baz "
[5]=>
string(2) " "
}
Actual result:
--------------
However the second var_dump actually prints the modified one
array(6) {
[0]=>
string(0) ""
[1]=>
string(3) "foo"
[2]=>
string(0) ""
[3]=>
string(3) "bar"
[4]=>
string(3) "baz"
[5]=>
string(0) ""
}
despite $arr was passed to something() by value, not reference.
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=69778&edit=1