Bug #67467 [Dup->Opn]: print_r with $return=true outputs its argument if it is too large

From: Date: Wed, 07 Oct 2015 09:48:29 +0000
Subject: Bug #67467 [Dup->Opn]: print_r with $return=true outputs its argument if it is too large
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-196445@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=67467&edit=1

 ID:                 67467
 Updated by:         nikic@php.net
 Reported by:        igor at wiedler dot ch
 Summary:            print_r with $return=true outputs its argument if it
                     is too large
-Status:             Duplicate
+Status:             Open
 Type:               Bug
 Package:            Output Control
 PHP Version:        5.5.13
 Block user comment: N
 Private report:     N

 New Comment:

PR for this: https://github.com/php/php-src/pull/1554

A side-effect of this change would be that if print_r is used in "print" mode and we go
out of memory, nothing will be printed (so the reverse of the issue here). I don't know if
that's a problem.

Alternatively (or additionally), we could change the OB flushing condition in http://lxr.php.net/xref/PHP_TRUNK/main/main.c#1768.
Probably the (size_t)PG(memory_limit) < zend_memory_usage(1) part of the check
doesn't do what it's supposed to, as the memory usage will always be lower than the limit
(we only *tried* to go higher and failed). We could drop this part. However this would mean we
don't flush OB on other fatal errors either. Which may or may not be a problem.


Previous Comments:
------------------------------------------------------------------------
[2014-06-20 08:41:36] arjen at react dot com

Duplicate of #66928 and #51362

------------------------------------------------------------------------
[2014-06-18 16:38:49] igor at wiedler dot ch

Description:
------------
Sufficiently large nested structures will cause print_r to output its first argument, even if the
second $return argument is true.

From a glance at how print_r works, it appears to be using output buffering internally. If the
output written to the buffer is too large, it will be implicitly flushed.

This is quite a serious problem, as one can easily expose the entire application state accidentally.

This has been reproduced in the FPM and CLI SAPIs.

Test script:
---------------
<?php
ini_set('memory_limit', '512M');
$a = [];
for ($i = 0; $i < 10000; $i++) {
    $a = [$i, $a];
}
print_r($a, true);


Expected result:
----------------
Blank.

Actual result:
--------------
Array
(
    [0] => 9999
    [1] => Array
        (
            [0] => 9998
            [1] => Array
                (
                    [0] => 9997
                    [1] => Array
                        (

...


------------------------------------------------------------------------



--
Edit this bug report at https://bugs.php.net/bug.php?id=67467&edit=1


Thread (6 messages)

« previous php.bugs (#196445) next »