Bug #80285 [Opn->Csd]: strspn $length argument may no longer exceed the string bounds

From: Date: Tue, 27 Oct 2020 10:45:55 +0000
Subject: Bug #80285 [Opn->Csd]: strspn $length argument may no longer exceed the string bounds
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-229940@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=80285&edit=1

 ID:                 80285
 Updated by:         nikic@php.net
 Reported by:        paul dot crovella at gmail dot com
 Summary:            strspn $length argument may no longer exceed the
                     string bounds
-Status:             Open
+Status:             Closed
 Type:               Bug
 Package:            Unknown/Other Function
 PHP Version:        8.0.0RC2
-Assigned To:        
+Assigned To:        nikic
 Block user comment: N
 Private report:     N

 New Comment:

This is the second independent report of this issue, so I've decided to undo the change in https://github.com/php/php-src/commit/d776d25a8e6763bfe8cc283a4693d7d417d50ddd.
The behavior should be strictly identical to doing a substr in advance now.


Previous Comments:
------------------------------------------------------------------------
[2020-10-26 16:11:15] paul dot crovella at gmail dot com

Description:
------------
This commit[1] changed not just out-of-bounds offsets of strspn to throw ValueError, but lengths
that exceed the string bounds as well.

Given that a positive $length argument functions as a max-length for the match attempt, the prior
behavior of accepting a length beyond the string bounds makes sense and reverting to it would
realign with substr whose length parameter serves a similar purpose.

Is something gained by breaking existing code and requiring:

strspn($subject, $mask, $start, min($length, strlen($subject) - $start))

where:

strspn($subject, $mask, $start, $length)

seemed to work fine as intended prior?

[1] https://github.com/php/php-src/commit/5d9ab53a5d53f11a18ae11ed31b17ff87c8d52a7

Test script:
---------------
<?php

var_dump(
    strspn("foo", "asdf", 0, 4),
    strspn("fffff", "asdf", 0, 4)
);

Expected result:
----------------
int(1)
int(4)

Actual result:
--------------
Fatal error: Uncaught ValueError: strspn(): Argument #4 ($length) must be contained in argument #1
($str) in /in/J05AD:4


------------------------------------------------------------------------



--
Edit this bug report at https://bugs.php.net/bug.php?id=80285&edit=1


Thread (2 messages)

« previous php.bugs (#229940) next »