Bug #78230 [Asn->Csd]: Incorrect type check optimization
| From: | nikic@php.net | Date: | Wed, 03 Jul 2019 08:22:54 +0000 |
| Subject: | Bug #78230 [Asn->Csd]: Incorrect type check optimization | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-221601@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=78230&edit=1
ID: 78230
Updated by: nikic@php.net
Reported by: ASchmidt at Anamera dot net
Summary: Incorrect type check optimization
-Status: Assigned
+Status: Closed
Type: Bug
Package: opcache
Operating System: Win x64
PHP Version: 7.3.7RC3
Assigned To: nikic
Block user comment: N
Private report: N
New Comment:
Automatic comment on behalf of nikita.ppv@gmail.com
Revision: http://git.php.net/?p=php-src.git;a=commit;h=4892bbc167dfa0ea188baebbce538225f4a0455a
Log: Fixed bug #78230
Previous Comments:
------------------------------------------------------------------------
[2019-07-03 08:00:28] nikic@php.net
Converting
#230.T15 [bool] = TYPE_CHECK (array) #47.CV7($classes) [array of [any, ref]]
to
FREE #47.CV7($classes) [array of [any, ref]]
------------------------------------------------------------------------
[2019-07-02 21:30:11] ASchmidt at Anamera dot net
Not sure if I had made that clear enough: the crash occurs in a plug-in of the WordPress CMS. So,
it's not just a simple single PHP file.
Here the link to the plug in (there is the download link):
https://wordpress.org/plugins/megamenu/#installation
The particular code section is in "walker.class.php".
Also I have created an "out of the box" WordPress debug site, with that plug-in loaded, to
which I can supply FTP access if that would be helpful at all.
------------------------------------------------------------------------
[2019-07-02 21:06:28] nikic@php.net
Could you please provide the full source code of the relevant file? (To nikic@php.net if not
public.) This sounds like an optimization bug.
------------------------------------------------------------------------
[2019-07-02 20:04:40] ASchmidt at Anamera dot net
PS: the size of the array is small, only a handful of short strings:
array (size=6)
0 => string '' (length=0)
1 => string 'menu-item' (length=9)
2 => string 'menu-item-type-taxonomy' (length=23)
3 => string 'menu-item-object-category' (length=25)
4 => string 'align-bottom-left' (length=17)
5 => string 'menu-flyout' (length=11)
------------------------------------------------------------------------
[2019-07-02 20:01:31] ASchmidt at Anamera dot net
I have spent days trying to pinpoint this better. It's triggered if an "is_array()"
is used against a variable, if that variable was assigned from a function parameter that is an
object property holding an array, and if in the assignment an explicit coercion to an array was
performed:
$thevar = (array) $functionparm->property; // property IS an array
is_array( $thevar ); // will crash OPcache later in the code path.
It will NOT fail for:
a) is_array( $functionparm->property ) ⦠or
b) is_array( (array) $functionparm->property ) ⦠or
c) if the (array) coercion is omitted: $thevar = $functionparm->property
It will NOT crash AT THE TIME of the "is_array()", but it will crash later, if the code is
allowed to proceed from there.
For reference, here the actual code snippet with various var_dumps added to see what works, and what
does not:
static $mypass = 0;
function start_el( &$output, $item, $depth = 0, $args = array(), $id = 0 ) {
var_dump( self::$mypass, $item->classes );
var_dump( is_array( $item->classes ) );
var_dump( is_array( (array) $item->classes ) );
$myvar1 = $item->classes;
$myvar2 = (array) $item->classes;
var_dump( is_array( $myvar1 ) );
if ( 0 == self::$mypass++ ) { // It doesn't matter, if the "is_array" only executes
once.
var_dump( is_array( $myvar2 ) ); // This will trigger the crash LATER in the code.
// die( 'x'); // It will NOT crash, if the code stops here.
}
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=78230
--
Edit this bug report at https://bugs.php.net/bug.php?id=78230&edit=1