Bug #78956 [Opn]: ArrayObject becomes SEGV under certain conditions.
Edit report at https://bugs.php.net/bug.php?id=78956&edit=1
ID: 78956
Updated by: cmb@php.net
Reported by: zeriyoshi at gmail dot com
Summary: ArrayObject becomes SEGV under certain conditions.
Status: Open
Type: Bug
Package: SPL related
Operating System: Linux
PHP Version: 7.4.0
Block user comment: N
Private report: N
New Comment:
This looks like infinite recursion, which would be considered a
programmer error.
Previous Comments:
------------------------------------------------------------------------
[2019-12-12 16:30:25] zeriyoshi at gmail dot com
Description:
------------
Call property_exists function in offsetExists method, ArrayObject raise Segmentation fault.
Test script:
---------------
<?php
// OK (Handled with memory-size over.)
// property_exists(
// new class ([], \ArrayObject::ARRAY_AS_PROPS) extends \ArrayObject {
// public function offsetExists($index)
// {
// return $this->offsetExists($index);
// }
// },
// 'foo'
// );
// NG (SEGV)
property_exists(
new class ([], \ArrayObject::ARRAY_AS_PROPS) extends \ArrayObject {
public function offsetExists($index)
{
return property_exists($this, $index);
}
},
'foo'
);
Expected result:
----------------
Fatal error: Allowed memory size of %d bytes exhausted (tried to allocate %d bytes) in %s on line %d
Actual result:
--------------
Segmentation fault
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=78956&edit=1
Thread (3 messages)