Bug #73913 [Com]: broken strrpos with negative offset

From: Date: Thu, 12 Jan 2017 10:33:08 +0000
Subject: Bug #73913 [Com]: broken strrpos with negative offset
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-206551@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=73913&edit=1

 ID:                 73913
 Comment by:         dima at virtuman dot com
 Reported by:        proartex at mail dot ru
 Summary:            broken strrpos with negative offset
 Status:             Assigned
 Type:               Bug
 Package:            Strings related
 Operating System:   macOS Sierra 10.12.1
 PHP Version:        5.6.29
 Assigned To:        heiglandreas
 Block user comment: N
 Private report:     N

 New Comment:

Looks like the problem is related to https://github.com/php/php-src/blob/PHP-5.6.29/ext/standard/string.c#L1987

replace this one:
e = haystack + haystack_len + offset;

with this one:
e = haystack + haystack_len + offset - needle_len;

will solve the problem.


Previous Comments:
------------------------------------------------------------------------
[2017-01-11 21:57:27] heiglandreas@php.net

Looks like you're right! I dug deeper into it and it seems there is an issue when the negative
offset is smaller or equals the size of the needle.

I'm digging deeper into it.

------------------------------------------------------------------------
[2017-01-11 18:03:34] proartex at mail dot ru

1. Does strrpos("works_like_a_charm", 'charm', 15) really equals to
strrpos("works_like_a_charm", 'charm', -3)? false != 13. It is also applicable
for 3 last cases.

------------------------------------------------------------------------
[2017-01-11 17:32:03] heiglandreas@php.net

when offset is negative the search *starts* that many characters *from the end*. The search is not
excluding the last n characters. 

strrpos("aaaa", 'aa', -2) == strrpos("aaaa", 'aa', 2)
strrpos("aaaa", 'a', -1) == strrpos("aaaa", 'a', 3)
strrpos("/documents/show/5474", '/', -20) ==
strrpos("/documents/show/5474", '/', 0)
strrpos("works_like_a_charm", 'charm', -3) ==
strrpos("works_like_a_charm", 'charm', 15)
strrpos("works_like_a_charm", 'charm', -4) ==
strrpos("works_like_a_charm", 'charm', 14)


So they work as expected. 

What you want to do would be achieved by this:

strrpos(substr("aaaa", -2), "aa");

When needle is longer than the remaining string, the offset seems to be expanded to at least include
the needle.

Note also the comment on http://php.net/manual/de/function.strrpos.php#76447

------------------------------------------------------------------------
[2017-01-11 17:19:23] proartex at mail dot ru

last case must be var_dump(strrpos("works_like_a_charm", 'charm', -5)); //ER:
false, AR: 13

------------------------------------------------------------------------
[2017-01-11 17:16:36] proartex at mail dot ru

Description:
------------
It is seems broken at least in the following cases:
 - if negative offset equals to haystack length;
 - if negative offset less than needle length;
 - if needle length equals to (haystack length + negative offset)

Negative offset should not move pointer but reduce search scope on the value of offset. In that case
character placed at 0 position must not be found if search scope is reduced to empty string. Same
should be applied in boundary cases: character placed next to reduced search scope must not be found
(last case).

Test script:
---------------
<?php

var_dump(strrpos("aaaa", 'aa', -2)); //ER: 0, AR: 2
var_dump(strrpos("aaaa", 'a', -1)); //ER: 2, AR: 3
var_dump(strrpos("/documents/show/5474", '/', -20)); //ER: false, AR: 0
var_dump(strrpos("works_like_a_charm", 'charm', -3)); //ER: false, AR: 13
var_dump(strrpos("works_like_a_charm", 'charm', -4)); //ER: false, AR: 13

Expected result:
----------------
0
2
false
false
false

Actual result:
--------------
2
3
0
13
13


------------------------------------------------------------------------



--
Edit this bug report at https://bugs.php.net/bug.php?id=73913&edit=1


Thread (7 messages)

« previous php.bugs (#206551) next »