[php-src] Issue #8044: var_export emits debug assertion errors for `HT_ASSERT_RC1(ht);` in builds for SplFixedArray circular references

From: Date: Sat, 05 Feb 2022 20:06:07 +0000
Subject: [php-src] Issue #8044: var_export emits debug assertion errors for `HT_ASSERT_RC1(ht);` in builds for SplFixedArray circular references
Groups: php.bugs 
Request: Send a blank email to php-bugs+get-239506@lists.php.net to get a copy of this message
Issue: https://github.com/php/php-src/issues/8044
Comment Author: TysonAndre

The below snippet is not even specific to SplFixedArray, but illustrates why the HT_ASSERT_RC1 would
matter during iteration for anyone wondering. Increasing the size from 8 to 9 reallocates the memory
backing the array, and the old memory being iterated over by var_export becomes invalid.

Related to https://bugs.php.net/bug.php?id=79214

1. Maybe this should avoid emitting E_WARNING during var_export and postpone emitting them until
after var_export is finished? This would get the same result as the below snippet by increasing the
number of properties to 9 during var_export
2. Maybe use SEPARATE_ARRAY after the recursion check if the array was non-empty to make side
effects less likely?

```
$ USE_ZEND_ALLOC=0 php spl_fixedarray_var_export.php
var_export does not handle circular references
In handler

Warning: var_export does not handle circular references in
/usr/local/tyson/php-src/spl_fixedarray_var_export.php on line 9
array (
  0 => NULL,
  1 => 
  ArrayObject::__set_state(array(
  )),
  2 => NULL,
  3 => NULL,
  4 => NULL,
  5 => NULL,
  6 => NULL,
  7 => NULL,
  8 => NULL,
)
After clear

Warning: var_export does not handle circular references in
/usr/local/tyson/php-src/spl_fixedarray_var_export.php on line 12
array (
  0 => NULL,
)malloc_consolidate(): invalid chunk size
[1]    335364 abort (core dumped)  USE_ZEND_ALLOC=0 php spl_fixedarray_var_export.php
```

```php
<?php
set_error_handler(function ($errno, $errmsg) {
    echo "$errmsg\n";
    if (isset($GLOBALS['array'])) {
        $fixedArray = $GLOBALS['array'][0];
        $fixedArray->setSize(9);
        $fixedArray[1] = new ArrayObject();
        echo "In handler\n";
        var_export((array)$fixedArray);
        echo "\nAfter clear\n";
        $fixedArray->setSize(1);
        var_export((array)$fixedArray);
    }
});

$array = [];
$fixedArray = new SplFixedArray(2);
$fixedArray[0] = $fixedArray;
$i = 0;
$fixedArray[1] = (object)["a$i" => 123];
$array = [$fixedArray];
var_export($array);
```


Thread (1 message)

  • TysonAndre
« previous php.bugs (#239506) next »