Bug #65967 [Ver->Csd]: SplObjectStorage contains corrupt member variables after garbage collection

From: Date: Fri, 18 Mar 2016 19:39:07 +0000
Subject: Bug #65967 [Ver->Csd]: SplObjectStorage contains corrupt member variables after garbage collection
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-199930@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=65967&edit=1 ID: 65967 Updated by: nikic@php.net Reported by: crog at gustavus dot edu Summary: SplObjectStorage contains corrupt member variables after garbage collection -Status: Verified +Status: Closed Type: Bug Package: SPL related Operating System: Any PHP Version: 5.2+ -Assigned To: +Assigned To: nikic Block user comment: N Private report: N New Comment: Closing, as this is fixed by the aforementioned commit. Automatic closer didn't pick that format up. Previous Comments: ------------------------------------------------------------------------ [2015-03-13 17:01:21] laruence@php.net Automatic comment on behalf of adam.scarr@99designs.com Revision: http://git.php.net/?p=php-src.git;a=commit;h=950d3d6e9b94b75b266c67bf9e3a85ae9c31905d Log: Fix bug #69227 and #65967 ------------------------------------------------------------------------ [2014-03-25 13:59:56] levim@php.net Can confirm that this affects PHP 5.2 through 5.6 alpha 3 on several OS's. ------------------------------------------------------------------------ [2014-03-02 15:25:07] adrian at foeder dot de Totally having the same issue on Windows 8, PHP 5.4.11 (Zend Server CE). Did anybody try this with igbinary? Does it happen there too? ------------------------------------------------------------------------ [2013-11-22 19:25:36] crog at gustavus dot edu Sorry, forgot links: SplObjectStorage \x00gcdata entry: http://lxr.php.net/xref/PHP_5_4/ext/spl/spl_observer.c#391 Corrupt member name example: http://3v4l.org/jfcJr ------------------------------------------------------------------------ [2013-11-22 19:18:53] crog at gustavus dot edu Good catch. When I was writing the script to trigger the issue, I was testing it through the browser. Running on the command-line, I can't trigger it there, either (despite a few efforts at making terribly large circular structures). Just to be certain, I did run the test again through the browser, ensuring our auto-append and prepends were disabled to check that it still happens (it does). Some relevant bits from phpinfo(): Build Date Nov 13 2013 09:29:31 Server API Apache 2.0 Handler Apache Version Apache/2.2.15 (Red Hat) In any event, it doesn't even matter. The problem is that SplObjectStorage adds properties that contain null bytes (which you can see by looking at the source -- it's even commented as intentional to "make tampering in user-land more difficult" (spl_observer.c:391). The negative effects of this "bug," aren't that the property exists, it's that other PHP functions explode horribly when they encounter a property containing a null byte. If that's all we're interested in observing, we can do so a lot easier (and on the command-line :D ) with the following: var_dump((object) ["\x00key" => "value"]); So, that said, I suppose this issue could be resolved by changing everything else to not choke on null bytes in property names; but it seems slightly more reasonable to change SplObjectStorage such that it doesn't store its internal data in the object itself (and/or not use a null byte in its property names). ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=65967 -- Edit this bug report at https://bugs.php.net/bug.php?id=65967&edit=1

« previous php.bugs (#199930) next »