Bug #70662 [Com]: Duplicate array key via undefined index error handler

From: Date: Wed, 07 Oct 2015 20:57:02 +0000
Subject: Bug #70662 [Com]: Duplicate array key via undefined index error handler
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-196462@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=70662&edit=1

 ID:                 70662
 Comment by:         nikic@php.net
 Reported by:        nikic@php.net
 Summary:            Duplicate array key via undefined index error
                     handler
 Status:             Open
 Type:               Bug
 Package:            Scripting Engine problem
 PHP Version:        7.0.0RC4
 Block user comment: N
 Private report:     N

 New Comment:

Patch: https://github.com/php/php-src/compare/master...nikic:bug70662_2


Previous Comments:
------------------------------------------------------------------------
[2015-10-07 20:40:27] nikic@php.net

Description:
------------
In http://lxr.php.net/xref/PHP_TRUNK/Zend/zend_execute.c#1548
and multiple related places we use find+add_new. However in RW mode a notice is emitted between both
operation, which can be used to modify the array and violate add_new preconditions.

Test script:
---------------
<?php

$a = [];
set_error_handler(function() use(&$a) {
    $a['b'] = 2;
});
$a['b'] += 1;
var_dump($a);


Expected result:
----------------
// One of
array(1) {
  ["b"]=>
  int(1)
}
// or
array(1) {
  ["b"]=>
  int(2)
}



Actual result:
--------------
array(2) {
  ["b"]=>
  int(2)
  ["b"]=>
  int(1)
}



------------------------------------------------------------------------



--
Edit this bug report at https://bugs.php.net/bug.php?id=70662&edit=1


Thread (3 messages)

« previous php.bugs (#196462) next »