Bug #78395 [Opn]: Exception::getTrace references can modify original reference vars from stack

From: Date: Fri, 09 Aug 2019 19:50:58 +0000
Subject: Bug #78395 [Opn]: Exception::getTrace references can modify original reference vars from stack
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-222166@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=78395&edit=1 ID: 78395 Updated by: nikic@php.net Reported by: src at enobrev dot com Summary: Exception::getTrace references can modify original reference vars from stack Status: Open Type: Bug Package: *General Issues Operating System: Ubuntu 19.04 PHP Version: 7.2.21 Block user comment: N Private report: N New Comment: We should probably change this in 7.4 or master. Previous Comments: ------------------------------------------------------------------------ [2019-08-09 19:46:57] src at enobrev dot com Description: ------------ If using references while looping through the results of Exception::getTrace, changing the args of a function with a referenced parameter in the stack will change the original referenced parameter. Maybe this is considered correct and just needs to be documented, but I had assumed the result in Exception::getTrace would be a copy of the arguments, not references to the actual arguments. (this was originally discovered by https://github.com/victusfate) Test script: --------------- $a = ['array' => 'of stuff', 'toodles' => 14 ]; function boom(array &$b) { throw new Exception('kablooey'); } try { boom($a); } catch(Exception $e) { echo var_dump($a); $aStack = $e->getTrace(); foreach($aStack as &$aItem) { if(isset($aItem['args'])) { foreach($aItem['args'] as &$aArg) { $aArg = 'destroyed'; } } } echo var_dump($a); } Expected result: ---------------- array(2) { ["array"]=> string(8) "of stuff" ["toodles"]=> int(14) } array(2) { ["array"]=> string(8) "of stuff" ["toodles"]=> int(14) } Actual result: -------------- array(2) { ["array"]=> string(8) "of stuff" ["toodles"]=> int(14) } string(9) "destroyed" ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=78395&edit=1

« previous php.bugs (#222166) next »