[php-src] Issue #7867: FFI::cast vs FFI::memcpy
| From: | cmb69 | Date: | Mon, 03 Jan 2022 13:07:54 +0000 |
| Subject: | [php-src] Issue #7867: FFI::cast vs FFI::memcpy | ||
| Groups: | php.bugs | ||
| Request: | Send a blank email to php-bugs+get-238727@lists.php.net to get a copy of this message | ||
Issue: https://github.com/php/php-src/issues/7867
Comment Author: cmb69
There are issues regarding arrays and pointers of a certain type. While pointer arithmetic mostly
works, it looses the alignment, e.g.
````.php
$value = FFI::new('char[26]');
var_dump(
FFI::alignof($value), // int(1)
FFI::alignof($value + 0) // int(8)
);
````
But then there is the more serious issue, that casting from a pointer type to an array doesn't
properly check the size of the types, e.g.
````.php
$value = FFI::new('char[26]');
var_dump(FFI::cast('char[4]', $value + 0));
var_dump(FFI::cast('char[9]', $value + 0));
````
outputs:
````
object(FFI\CData:char[4])#3 (4) {
[0]=>
string(1) ""
[1]=>
string(1) ""
[2]=>
string(1) "E"
[3]=>
string(1) ""
}
Fatal error: Uncaught FFI\Exception: attempt to cast to larger type in %s:5
````