Bug #80758 [NEW]: version_compare does not behave as documented (or even consistently)

From: Date: Tue, 16 Feb 2021 19:13:14 +0000
Subject: Bug #80758 [NEW]: version_compare does not behave as documented (or even consistently)
Groups: php.bugs 
Request: Send a blank email to php-bugs+get-232213@lists.php.net to get a copy of this message
From: brad dot jorsch at automattic dot com Operating system: Linux PHP version: 8.0Git-2021-02-16 (Git) Package: *General Issues Bug Type: Bug Bug description:version_compare does not behave as documented (or even consistently) Description: ------------ While I marked the version as 8.0.2, this seems to exist in many versions, in some forms back to 4.3.0 or earlier. The documentation for version_compare says that "any string not found in this list" comes before various recognized strings, including numbers. But certain strings do not follow this behavior. 1. Any non-alphanumeric character has that character treated as a . rather than it being included in the string to be compared. For example, "1.0-alpha 1" < "1.0-alpha 2" because the space is considered a ., even though as documented this should not be the case. 2. Exception: If that non-alphanumeric character comes directly after a number, it is not considered as a .. So "1.0 alpha" == "1.0 beta" because neither " alpha" nor " beta" are recognized as special strings. (see #75805) 3. Strings beginning with "a", "b", or other recognized strings are considered as being those recognized strings. (see #75806) 4. An empty string as the last component compares as less than itself. This can combine with item 1 in unexpected ways. (see #69268, and https://stackoverflow.com/a/65118939) IMO, item 1 makes sense and should be documented as such. Items 2 and 4 make no sense and should be fixed. Item 3 could go either way, but since the documentation calls out "a" being the same as "alpha" and so on that implies that "apple" should not be. The attached patch fixes 2 and 4, and 3 with the interpretation that "apple" should not be the same as "alpha". I'll leave documentation updates to you, since that's done outside of the main repo. P.S. I see cmb@php.net has a habit of closing reports like these as "not a bug" with the justification that a "PHP-standardized version string" has some sort of meaning that excludes these inputs. If you really want to continue considering this sort of thing "not a bug", you should actually document a "PHP-standardized version string" as only containing alphanumerics plus ., -, _, and + somewhere, as currently that is not defined anywhere. You should also reject invalid strings with an Error instead of silently handling them unexpectedly. But IMO restricting this to only "PHP-standardized version strings" is going against how most people actually use the method. Test script: --------------- var_dump( version_compare( "1.0 alpha", "1.0 beta" ) ); var_dump( version_compare( "1.0.apple", "1.0.coconut" ) ); var_dump( version_compare( "1.0.", "1.0." ) ); var_dump( version_compare( "1.0.*", "1.0.*" ) ); Expected result: ---------------- int(-1) int(0) int(0) int(0) Actual result: -------------- int(0) int(1) int(-1) int(-1) -- Edit bug report at https://bugs.php.net/bug.php?id=80758&edit=1 -- Fix committed: https://bugs.php.net/fix.php?id=80758&r=fixed Fixed in release: https://bugs.php.net/fix.php?id=80758&r=alreadyfixed Need backtrace: https://bugs.php.net/fix.php?id=80758&r=needtrace Need Reproduce Script: https://bugs.php.net/fix.php?id=80758&r=needscript Try newer version: https://bugs.php.net/fix.php?id=80758&r=oldversion Not developer issue: https://bugs.php.net/fix.php?id=80758&r=support Expected behavior: https://bugs.php.net/fix.php?id=80758&r=notwrong Not enough info: https://bugs.php.net/fix.php?id=80758&r=notenoughinfo Submitted twice: https://bugs.php.net/fix.php?id=80758&r=submittedtwice register_globals: https://bugs.php.net/fix.php?id=80758&r=globals PHP version support discontinued: https://bugs.php.net/fix.php?id=80758&r=phptooold Daylight Savings: https://bugs.php.net/fix.php?id=80758&r=dst IIS Stability: https://bugs.php.net/fix.php?id=80758&r=isapi Install GNU Sed: https://bugs.php.net/fix.php?id=80758&r=gnused Floating point limitations: https://bugs.php.net/fix.php?id=80758&r=float No Zend Extensions: https://bugs.php.net/fix.php?id=80758&r=nozend MySQL Configuration Error: https://bugs.php.net/fix.php?id=80758&r=mysqlcfg

« previous php.bugs (#232213) next »