Bug #67294 [Opn->Csd]: Operation performed on wrong property during interaction with an error handler
| From: | nikic@php.net | Date: | Thu, 27 Aug 2015 20:22:01 +0000 |
| Subject: | Bug #67294 [Opn->Csd]: Operation performed on wrong property during interaction with an error handler | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-195569@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=67294&edit=1
ID: 67294
Updated by: nikic@php.net
Reported by: pmoroney at name dot com
Summary: Operation performed on wrong property during
interaction with an error handler
-Status: Open
+Status: Closed
Type: Bug
Package: Scripting Engine problem
Operating System: Linux
PHP Version: Irrelevant
-Assigned To:
+Assigned To: nikic
Block user comment: N
Private report: N
New Comment:
This has been fixed in 5.5.19 / 5.6.3 as part of bug #68118: https://3v4l.org/ucnDH
Previous Comments:
------------------------------------------------------------------------
[2014-05-27 17:36:15] pmoroney at name dot com
After looking into that commit, it is obvious why that is the first time that this bug occurred, the
error handler wasn't triggered previous to this commit in the case of a undefined property.
I'm wondering if there is some reference to the property name that is being modified outside of
the correct scope.
------------------------------------------------------------------------
[2014-05-16 20:02:14] pmoroney at name dot com
It looks like I swapped my expected and actual results, sorry.
------------------------------------------------------------------------
[2014-05-16 19:54:57] pmoroney at name dot com
Description:
------------
When an error handler is called because of a undefined property and the error handler references a
different object property that doesn't exist, even in an isset(), the original property gets
replaced by the new property in the operation that was being performed.
I ran a git bisect to find the commit that introduced the error and found the following commit:
commit 0c6d903ce7615a7197cb997d67d98058c3ec5d6a
Author: Stanislav Malyshev <stas@php.net>
Date: Mon Feb 18 20:56:02 2013 -0800
fix bug #49348 - issue notice on get_property_ptr_ptr when used for read
Test script:
---------------
<?php
function err_handler()
{
$s = new StdClass();
isset($s->bad);
}
set_error_handler('err_handler');
$f->good += 5 ;
var_export($f);
if(isset($f->bad))
exit(1);
else
exit(0);
Expected result:
----------------
stdClass::__set_state(array(
'bad' => 5,
))
With an Exit value of 1
Actual result:
--------------
stdClass::__set_state(array(
'good' => 5,
))
With an Exit value of 0
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=67294&edit=1