Bug #70993 [NEW]: Array key references break argument processing
| From: | php at ontheroad dot net dot nz | Date: | Sun, 29 Nov 2015 04:35:22 +0000 |
| Subject: | Bug #70993 [NEW]: Array key references break argument processing | ||
| Groups: | php.bugs | ||
| Request: | Send a blank email to php-bugs+get-197488@lists.php.net to get a copy of this message | ||
From: php at ontheroad dot net dot nz
Operating system: Ubuntu 14.04
PHP version: 7.0.0RC8
Package: SOAP related
Bug Type: Bug
Bug description:Array key references break argument processing
Description:
------------
Using references to array keys in arguments to SOAP calls seems to break
the argument processing of SOAP arguments. This works fine in PHP 5.5
but breaks in PHP 7.0.0RC8.
PHP7.0.0RC8 configuration
'./configure' '--prefix=/usr/local/php7'
'--with-config-file-scan-dir=/usr/local/php7/etc/conf.d'
'--enable-bcmath' '--with-bz2' '--enable-calendar'
'--enable-intl'
'--enable-exif' '--enable-dba' '--enable-ftp'
'--with-gettext'
'--with-gd' '--with-jpeg-dir' '--enable-mbstring'
'--with-mcrypt'
'--with-mhash' '--enable-mysqlnd' '--with-mysql=mysqlnd'
'--with-mysql-sock=/var/run/mysqld/mysqld.sock' '--with-mysqli=mysqlnd'
'--with-pdo-mysql=mysqlnd' '--with-openssl' '--enable-pcntl'
'--with-pspell' '--enable-shmop' '--enable-soap'
'--enable-sockets'
'--enable-sysvmsg' '--enable-sysvsem' '--enable-sysvshm'
'--enable-wddx'
'--with-zlib' '--enable-zip' '--with-readline' '--with-curl'
'--enable-fpm' '--with-fpm-user=www-data' '--with-fpm-group=www-data
No modifications to php.ini.
The web services in question are not public, so I can't provide a
completely working example, however it seems like the behaviour should
be independent of the service itself (although possibly it does somehow
depend on the service definition) and it may not be related to SOAP at
all, but this is the situation in which I've seen it.
The example provides two SoapClient children which pre-process the
arguments given. Both do the same thing, but one creates assigns a
variable with a reference while one assigns a variable without. The
only difference is the reference assignment, but the one with the
reference ends up not processing the arguments at all and passing a
request without arguments.
The key line in the example is 32
(https://gist.github.com/anonymous/6d20b14d0f5fedbc04ca#file-example-php-L32bug-example-L17),
where we assign a reference to $params[0]; the array index already
exists, so it's not created by the assignment, but we can see on line 18
(https://gist.github.com/anonymous/6d20b14d0f5fedbc04ca#file-example-php-L18)
that the SoapClientFine class does exactly the same but without a
reference and it works OK.
Recompiling with --enable-debug and running valgrind as described in
https://bugs.php.net/bugs-getting-valgrind-log.php
shows no difference
between runs with the SoapClientFine and with the SoapClientBroken (0
definitely/indirectly/possibly lost, 54 blocks still reachable).
Test script:
---------------
Example is at https://gist.github.com/anonymous/6d20b14d0f5fedbc04ca
Expected/Actual results are at
https://gist.github.com/anonymous/c7bd9d0cf1c4246beb69
due to spam
detection not letting me include it below.
Expected result:
----------------
See https://gist.github.com/anonymous/c7bd9d0cf1c4246beb69
Actual result:
--------------
See https://gist.github.com/anonymous/c7bd9d0cf1c4246beb69
--
Edit bug report at https://bugs.php.net/bug.php?id=70993&edit=1
--
Try a snapshot (PHP 5.4): https://bugs.php.net/fix.php?id=70993&r=trysnapshot54
Try a snapshot (PHP 5.5): https://bugs.php.net/fix.php?id=70993&r=trysnapshot55
Try a snapshot (trunk): https://bugs.php.net/fix.php?id=70993&r=trysnapshottrunk
Fixed in SVN: https://bugs.php.net/fix.php?id=70993&r=fixed
Fixed in release: https://bugs.php.net/fix.php?id=70993&r=alreadyfixed
Need backtrace: https://bugs.php.net/fix.php?id=70993&r=needtrace
Need Reproduce Script: https://bugs.php.net/fix.php?id=70993&r=needscript
Try newer version: https://bugs.php.net/fix.php?id=70993&r=oldversion
Not developer issue: https://bugs.php.net/fix.php?id=70993&r=support
Expected behavior: https://bugs.php.net/fix.php?id=70993&r=notwrong
Not enough info: https://bugs.php.net/fix.php?id=70993&r=notenoughinfo
Submitted twice: https://bugs.php.net/fix.php?id=70993&r=submittedtwice
register_globals: https://bugs.php.net/fix.php?id=70993&r=globals
PHP 4 support discontinued: https://bugs.php.net/fix.php?id=70993&r=php4
Daylight Savings: https://bugs.php.net/fix.php?id=70993&r=dst
IIS Stability: https://bugs.php.net/fix.php?id=70993&r=isapi
Install GNU Sed: https://bugs.php.net/fix.php?id=70993&r=gnused
Floating point limitations: https://bugs.php.net/fix.php?id=70993&r=float
No Zend Extensions: https://bugs.php.net/fix.php?id=70993&r=nozend
MySQL Configuration Error: https://bugs.php.net/fix.php?id=70993&r=mysqlcfg