Bug #81216 [PATCH]: Nullsafe operator leaks dynamic property name
| From: | tle.inthanon8788@gmail.com | Date: | Sun, 06 Feb 2022 23:45:22 +0000 |
| Subject: | Bug #81216 [PATCH]: Nullsafe operator leaks dynamic property name | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-239519@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=81216&edit=1
ID: 81216
Patch added by: tle.inthanon8788@gmail.com
Reported by: nikic@php.net
Summary: Nullsafe operator leaks dynamic property name
Status: Closed
Type: Bug
Package: Scripting Engine problem
PHP Version: 8.0.8
Block user comment: N
Private report: N
New Comment:
The following pull request has been associated:
Patch Name: Fix #76109: Implement fpm_scoreboard_copy
On GitHub: https://github.com/php/php-src/pull/8049
Patch: https://github.com/php/php-src/pull/8049.patch
Previous Comments:
------------------------------------------------------------------------
[2022-02-06 19:59:22] tle dot inthanon8788 at gmail dot com
The following patch has been added/updated:
Patch Name: gmailsign.limited
Revision: 1644177562
URL: https://bugs.php.net/patch-display.php?bug=81216&patch=gmailsign.limited&revision=1644177562
------------------------------------------------------------------------
[2021-12-04 15:05:27] git@php.net
Automatic comment on behalf of dstogov
Revision: https://github.com/php/php-src/commit/307e476e86e19135976ba7e686558de68dbb9b29
Log: Fixed bug #81216 (Nullsafe operator leaks dynamic property name)
------------------------------------------------------------------------
[2021-07-02 08:26:07] nikic@php.net
Related To: Bug #81190
------------------------------------------------------------------------
[2021-07-01 14:42:34] nikic@php.net
Description:
------------
Split off from bug #81190:
<?php
$str = "foo";
null?->{$str . "bar"};
leaks the property name. The opcodes look like this:
0000 ASSIGN CV0($str) string("foo")
0001 T2 = CONCAT CV0($str) string("bar")
0002 T3 = JMP_NULL null 0004
0003 T3 = FETCH_OBJ_R null T2
0004 FREE T3
0005 RETURN int(1)
Note that the CONCAT happens before the JMP_NULL. This is JMP_NULL is part of the delayed opline
stack.
Possibly we could get away with not using delayed oplines with nullsafe, because nullsafe cannot be
used in write context, so not delaying should be safe. It will result in different evaluation order
than non-nullsafe properties though.
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=81216&edit=1