Bug #78395 [Opn->Csd]: Exception::getTrace references can modify original reference vars from stack
| From: | cmb@php.net | Date: | Wed, 31 Mar 2021 10:39:28 +0000 |
| Subject: | Bug #78395 [Opn->Csd]: Exception::getTrace references can modify original reference vars from stack | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-233085@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=78395&edit=1
ID: 78395
Updated by: cmb@php.net
Reported by: src at enobrev dot com
Summary: Exception::getTrace references can modify original
reference vars from stack
-Status: Open
+Status: Closed
Type: Bug
Package: *General Issues
Operating System: Ubuntu 19.04
PHP Version: 7.2.21
-Assigned To:
+Assigned To: cmb
Block user comment: N
Private report: N
New Comment:
This is indeed fixed as of PHP 8.0.0[1].
[1] <https://3v4l.org/SunjY>
Previous Comments:
------------------------------------------------------------------------
[2019-08-09 19:50:58] nikic@php.net
We should probably change this in 7.4 or master.
------------------------------------------------------------------------
[2019-08-09 19:46:57] src at enobrev dot com
Description:
------------
If using references while looping through the results of Exception::getTrace, changing the args of a
function with a referenced parameter in the stack will change the original referenced parameter.
Maybe this is considered correct and just needs to be documented, but I had assumed the result in
Exception::getTrace would be a copy of the arguments, not references to the actual arguments.
(this was originally discovered by https://github.com/victusfate)
Test script:
---------------
$a = ['array' => 'of stuff', 'toodles' => 14 ];
function boom(array &$b) {
throw new Exception('kablooey');
}
try {
boom($a);
} catch(Exception $e) {
echo var_dump($a);
$aStack = $e->getTrace();
foreach($aStack as &$aItem) {
if(isset($aItem['args'])) {
foreach($aItem['args'] as &$aArg) {
$aArg = 'destroyed';
}
}
}
echo var_dump($a);
}
Expected result:
----------------
array(2) {
["array"]=>
string(8) "of stuff"
["toodles"]=>
int(14)
}
array(2) {
["array"]=>
string(8) "of stuff"
["toodles"]=>
int(14)
}
Actual result:
--------------
array(2) {
["array"]=>
string(8) "of stuff"
["toodles"]=>
int(14)
}
string(9) "destroyed"
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=78395&edit=1