Bug #70662 [Com]: Duplicate array key via undefined index error handler
Edit report at https://bugs.php.net/bug.php?id=70662&edit=1
ID: 70662
Comment by: nikic@php.net
Reported by: nikic@php.net
Summary: Duplicate array key via undefined index error
handler
Status: Open
Type: Bug
Package: Scripting Engine problem
PHP Version: 7.0.0RC4
Block user comment: N
Private report: N
New Comment:
Patch: https://github.com/php/php-src/compare/master...nikic:bug70662_2
Previous Comments:
------------------------------------------------------------------------
[2015-10-07 20:40:27] nikic@php.net
Description:
------------
In http://lxr.php.net/xref/PHP_TRUNK/Zend/zend_execute.c#1548
and multiple related places we use find+add_new. However in RW mode a notice is emitted between both
operation, which can be used to modify the array and violate add_new preconditions.
Test script:
---------------
<?php
$a = [];
set_error_handler(function() use(&$a) {
$a['b'] = 2;
});
$a['b'] += 1;
var_dump($a);
Expected result:
----------------
// One of
array(1) {
["b"]=>
int(1)
}
// or
array(1) {
["b"]=>
int(2)
}
Actual result:
--------------
array(2) {
["b"]=>
int(2)
["b"]=>
int(1)
}
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=70662&edit=1
Thread (3 messages)