Bug #78230 [Asn->Csd]: Incorrect type check optimization

From: Date: Wed, 03 Jul 2019 08:22:54 +0000
Subject: Bug #78230 [Asn->Csd]: Incorrect type check optimization
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-221601@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=78230&edit=1 ID: 78230 Updated by: nikic@php.net Reported by: ASchmidt at Anamera dot net Summary: Incorrect type check optimization -Status: Assigned +Status: Closed Type: Bug Package: opcache Operating System: Win x64 PHP Version: 7.3.7RC3 Assigned To: nikic Block user comment: N Private report: N New Comment: Automatic comment on behalf of nikita.ppv@gmail.com Revision: http://git.php.net/?p=php-src.git;a=commit;h=4892bbc167dfa0ea188baebbce538225f4a0455a Log: Fixed bug #78230 Previous Comments: ------------------------------------------------------------------------ [2019-07-03 08:00:28] nikic@php.net Converting #230.T15 [bool] = TYPE_CHECK (array) #47.CV7($classes) [array of [any, ref]] to FREE #47.CV7($classes) [array of [any, ref]] ------------------------------------------------------------------------ [2019-07-02 21:30:11] ASchmidt at Anamera dot net Not sure if I had made that clear enough: the crash occurs in a plug-in of the WordPress CMS. So, it's not just a simple single PHP file. Here the link to the plug in (there is the download link): https://wordpress.org/plugins/megamenu/#installation The particular code section is in "walker.class.php". Also I have created an "out of the box" WordPress debug site, with that plug-in loaded, to which I can supply FTP access if that would be helpful at all. ------------------------------------------------------------------------ [2019-07-02 21:06:28] nikic@php.net Could you please provide the full source code of the relevant file? (To nikic@php.net if not public.) This sounds like an optimization bug. ------------------------------------------------------------------------ [2019-07-02 20:04:40] ASchmidt at Anamera dot net PS: the size of the array is small, only a handful of short strings: array (size=6) 0 => string '' (length=0) 1 => string 'menu-item' (length=9) 2 => string 'menu-item-type-taxonomy' (length=23) 3 => string 'menu-item-object-category' (length=25) 4 => string 'align-bottom-left' (length=17) 5 => string 'menu-flyout' (length=11) ------------------------------------------------------------------------ [2019-07-02 20:01:31] ASchmidt at Anamera dot net I have spent days trying to pinpoint this better. It's triggered if an "is_array()" is used against a variable, if that variable was assigned from a function parameter that is an object property holding an array, and if in the assignment an explicit coercion to an array was performed: $thevar = (array) $functionparm->property; // property IS an array is_array( $thevar ); // will crash OPcache later in the code path. It will NOT fail for: a) is_array( $functionparm->property ) … or b) is_array( (array) $functionparm->property ) … or c) if the (array) coercion is omitted: $thevar = $functionparm->property It will NOT crash AT THE TIME of the "is_array()", but it will crash later, if the code is allowed to proceed from there. For reference, here the actual code snippet with various var_dumps added to see what works, and what does not: static $mypass = 0; function start_el( &$output, $item, $depth = 0, $args = array(), $id = 0 ) { var_dump( self::$mypass, $item->classes ); var_dump( is_array( $item->classes ) ); var_dump( is_array( (array) $item->classes ) ); $myvar1 = $item->classes; $myvar2 = (array) $item->classes; var_dump( is_array( $myvar1 ) ); if ( 0 == self::$mypass++ ) { // It doesn't matter, if the "is_array" only executes once. var_dump( is_array( $myvar2 ) ); // This will trigger the crash LATER in the code. // die( 'x'); // It will NOT crash, if the code stops here. } ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=78230 -- Edit this bug report at https://bugs.php.net/bug.php?id=78230&edit=1

« previous php.bugs (#221601) next »