Bug #52731 [Asn->Opn]: mb_strpos reports needle position incorrectly

From: Date: Tue, 24 Oct 2017 06:33:07 +0000
Subject: Bug #52731 [Asn->Opn]: mb_strpos reports needle position incorrectly
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-212005@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=52731&edit=1 ID: 52731 Updated by: kalle@php.net Reported by: tokul at users dot sourceforge dot net Summary: mb_strpos reports needle position incorrectly -Status: Assigned +Status: Open Type: Bug Package: mbstring related PHP Version: 5.3SVN-2010-08-29 (snap) -Assigned To: moriyoshi +Assigned To: Block user comment: N Private report: N Previous Comments: ------------------------------------------------------------------------ [2016-07-31 16:15:15] cmb@php.net The $offset parameter of mb_strpos() is supposed to denote a position in characters (actually, Unicode code points in this case), not bytes. However, it's not possible to to count characters in invalid UTF-8, so the function would have to error, but actually checking for valid UTF-8 would slow down this and other related functions even for valid UTF-8. Not sure, if that's worth it. Considering that several mbstring functions handle invalid UTF-8 badly[1], it might be best to leave it as is, and document that these functions expect valid strings according to the chosen encoding. [1] E.g. mb_convert_encoding($str, 'ISO-8859-1', 'UTF-8') silently returns string(8) "?Q &???}" ------------------------------------------------------------------------ [2010-08-29 17:05:03] tokul at users dot sourceforge dot net Description: ------------ If code sets incorrect character set (utf-8 instead of big5 in test case), mb_strpos() can incorrectly report needle position in some cases. It looks like $offset is calculated one way and results are calculated in some other way. See test code. mb_substr($str,$pos1,1,'utf-8') can be used to see character that is in reported needle position. I understand that $str is not in UTF-8 charset, but position reported by mb_strpos() violates very basic strpos function behavior. Search is started after $offset position and result position is counted from string start. Result should not be lower than $offset or it should be boolean false. php5.3-201008291230 compiled with /configure --prefix=/somepath --enable-cli --disable-all --enable-mbstring Also tested PHP 5.2.0 (debian etch), 5.3.2-2 (debian squeeze) and 5.2.13 (standard PHP package). 5.2.13 and 5.3.2 results are the same. 5.2.0 results are a little bit different, but I was able to reproduce position calculation problem with more complex code. Test script: --------------- $str = "\xb7\x51 &\xb4\xa6\xb6\x7d"; $pos1 = mb_strpos($str,'&',0,'utf-8'); var_dump($pos1); $pos2 = mb_strpos($str,'&',$pos1 + 1,'utf-8'); var_dump($pos2); Expected result: ---------------- second var_dump() result should be higher than first one or should be boolean false. result should not be lower than offset. Actual result: -------------- int(2) int(2) ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=52731&edit=1

« previous php.bugs (#212005) next »