Bug #71756 [Opn->Csd]: Call-by-reference widens scope to uninvolved functions when used in switch
| From: | laruence@php.net | Date: | Thu, 10 Mar 2016 07:12:17 +0000 |
| Subject: | Bug #71756 [Opn->Csd]: Call-by-reference widens scope to uninvolved functions when used in switch | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-199724@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=71756&edit=1
ID: 71756
Updated by: laruence@php.net
Reported by: lang at six dot de
Summary: Call-by-reference widens scope to uninvolved
functions when used in switch
-Status: Open
+Status: Closed
Type: Bug
Package: Variables related
Operating System: Linux 7afb14e6ee75 3.16.7-35-des
PHP Version: 7.0.4
-Assigned To:
+Assigned To: laruence
Block user comment: N
Private report: N
New Comment:
The fix for this bug has been committed.
Snapshots of the sources are packaged every three hours; this change
will be in the next snapshot. You can grab the snapshot at
http://snaps.php.net/.
For Windows:
http://windows.php.net/snapshots/
Thank you for the report, and for helping us make PHP better.
Previous Comments:
------------------------------------------------------------------------
[2016-03-09 14:16:53] lang at six dot de
Description:
------------
Under very certain circumstances a call-by-reference gets out of bounds. A cascaded call of
functions, where one of them has a call-by-reference in its parameters, a change to a copy of an
hash gets unexpectedly overwritten outside of its scope. Key to this behaviour is the use of the
switch-statement in the final function call.
Additional Information:
- casting the switch-parameter to string solves the problem
- changing the switch into an if-statement also solves the problem
Test script:
---------------
<?php
function a ($option) {
b($option['bla']);
c($option);
var_dump($option);
}
function b (&$string) {
$string = 'changed';
}
function c ($option) {
switch ($option['bla']) {
case 'changed':
$copy = $option;
$copy['bla'] = 'copy';
break;
}
}
a(array('bla' => 'fasel'));
Expected result:
----------------
array(1) { ["bla"]=> string(4) "changed" }
Actual result:
--------------
array(1) { ["bla"]=> string(4) "copy" }
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=71756&edit=1