Bug #81514 [NEW]: Using Enum as key in WeakMap triggers GC + SegFault

From: Date: Fri, 08 Oct 2021 04:25:12 +0000
Subject: Bug #81514 [NEW]: Using Enum as key in WeakMap triggers GC + SegFault
Groups: php.bugs 
Request: Send a blank email to php-bugs+get-237093@lists.php.net to get a copy of this message
From: james at lucas dot net dot au Operating system: MacOS/Linux PHP version: 8.1.0RC3 Package: Reproducible crash Bug Type: Bug Bug description:Using Enum as key in WeakMap triggers GC + SegFault Description: ------------ Enum keys in WeakMaps are Garbage collected after first retrieval (via offsetGet or foreach) which should not occur as they are singletons (per https://wiki.php.net/rfc/enumerations#splobjectstorage_and_weakmaps). After the Enum is gone from the WeakMap an additional offsetGet for the Enum key triggers a Segfault instead of Object TestEnum#1 not contained in WeakMap. This does not occur when using plain objects Test script: --------------- <?php declare(strict_types=1); echo 'WeakMap with object as key' . PHP_EOL; $map = new WeakMap(); $obj1 = new stdClass(); $map->offsetSet($obj1, 'string'); echo 'Map contains ' . count($map) . ' objects' . PHP_EOL; $map->offsetGet($obj1); echo 'Map contains ' . count($map) . ' objects' . PHP_EOL . PHP_EOL; $map->offsetGet($obj1); echo 'WeakMap with Enum as key' . PHP_EOL; enum TestEnum { case A; } $map = new WeakMap(); $map->offsetSet(TestEnum::A, 'a string'); echo 'Map contains ' . count($map) . ' objects' . PHP_EOL; $map->offsetGet(TestEnum::A); echo 'Map contains ' . count($map) . ' objects' . PHP_EOL . PHP_EOL; // <-- Map will no longer contain ENUM $map->offsetGet(TestEnum::A); // <-- Segfault Here echo "done"; Expected result: ---------------- WeakMap with object as key Map contains 1 objects Map contains 1 objects WeakMap with Enum as key Map contains 1 objects Map contains 1 objects done Actual result: -------------- WeakMap with object as key Map contains 1 objects Map contains 1 objects WeakMap with Enum as key Map contains 1 objects Map contains 0 objects Segmentation fault: 11 -- Edit bug report at https://bugs.php.net/bug.php?id=81514&edit=1 -- Fix committed: https://bugs.php.net/fix.php?id=81514&r=fixed Fixed in release: https://bugs.php.net/fix.php?id=81514&r=alreadyfixed Need backtrace: https://bugs.php.net/fix.php?id=81514&r=needtrace Need Reproduce Script: https://bugs.php.net/fix.php?id=81514&r=needscript Try newer version: https://bugs.php.net/fix.php?id=81514&r=oldversion Not developer issue: https://bugs.php.net/fix.php?id=81514&r=support Expected behavior: https://bugs.php.net/fix.php?id=81514&r=notwrong Not enough info: https://bugs.php.net/fix.php?id=81514&r=notenoughinfo Submitted twice: https://bugs.php.net/fix.php?id=81514&r=submittedtwice register_globals: https://bugs.php.net/fix.php?id=81514&r=globals PHP version support discontinued: https://bugs.php.net/fix.php?id=81514&r=phptooold Daylight Savings: https://bugs.php.net/fix.php?id=81514&r=dst IIS Stability: https://bugs.php.net/fix.php?id=81514&r=isapi Install GNU Sed: https://bugs.php.net/fix.php?id=81514&r=gnused Floating point limitations: https://bugs.php.net/fix.php?id=81514&r=float No Zend Extensions: https://bugs.php.net/fix.php?id=81514&r=nozend MySQL Configuration Error: https://bugs.php.net/fix.php?id=81514&r=mysqlcfg

« previous php.bugs (#237093) next »