Bug #78395 [Opn]: Exception::getTrace references can modify original reference vars from stack
| From: | nikic@php.net | Date: | Fri, 09 Aug 2019 19:50:58 +0000 |
| Subject: | Bug #78395 [Opn]: Exception::getTrace references can modify original reference vars from stack | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-222166@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=78395&edit=1
ID: 78395
Updated by: nikic@php.net
Reported by: src at enobrev dot com
Summary: Exception::getTrace references can modify original
reference vars from stack
Status: Open
Type: Bug
Package: *General Issues
Operating System: Ubuntu 19.04
PHP Version: 7.2.21
Block user comment: N
Private report: N
New Comment:
We should probably change this in 7.4 or master.
Previous Comments:
------------------------------------------------------------------------
[2019-08-09 19:46:57] src at enobrev dot com
Description:
------------
If using references while looping through the results of Exception::getTrace, changing the args of a
function with a referenced parameter in the stack will change the original referenced parameter.
Maybe this is considered correct and just needs to be documented, but I had assumed the result in
Exception::getTrace would be a copy of the arguments, not references to the actual arguments.
(this was originally discovered by https://github.com/victusfate)
Test script:
---------------
$a = ['array' => 'of stuff', 'toodles' => 14 ];
function boom(array &$b) {
throw new Exception('kablooey');
}
try {
boom($a);
} catch(Exception $e) {
echo var_dump($a);
$aStack = $e->getTrace();
foreach($aStack as &$aItem) {
if(isset($aItem['args'])) {
foreach($aItem['args'] as &$aArg) {
$aArg = 'destroyed';
}
}
}
echo var_dump($a);
}
Expected result:
----------------
array(2) {
["array"]=>
string(8) "of stuff"
["toodles"]=>
int(14)
}
array(2) {
["array"]=>
string(8) "of stuff"
["toodles"]=>
int(14)
}
Actual result:
--------------
array(2) {
["array"]=>
string(8) "of stuff"
["toodles"]=>
int(14)
}
string(9) "destroyed"
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=78395&edit=1