Bug #31117 [PATCH]: Implicit cast to int of a key in an array produce an integer overflow
| From: | kusyazwan2411@gmail.com | Date: | Wed, 01 Jun 2022 13:40:00 +0000 |
| Subject: | Bug #31117 [PATCH]: Implicit cast to int of a key in an array produce an integer overflow | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-241637@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=31117&edit=1
ID: 31117
Patch added by: kusyazwan2411@gmail.com
Reported by: wiart at yahoo dot com
Summary: Implicit cast to int of a key in an array produce an
integer overflow
Status: Not a bug
Type: Bug
Package: Arrays related
Operating System: * (64 bit only!)
PHP Version: 4.3.10
Block user comment: N
Private report: N
New Comment:
The following pull request has been associated:
Patch Name: Extract functions to classes
On GitHub: https://github.com/php/web-master/pull/12
Patch: https://github.com/php/web-master/pull/12.patch
Previous Comments:
------------------------------------------------------------------------
[2004-12-16 16:17:19] iliaa@php.net
This is the expected results, PHP will not emulate an integer overflow on 64 bit systems.
------------------------------------------------------------------------
[2004-12-16 11:35:23] wiart at yahoo dot com
Description:
------------
I use in my code in an array a key that is a string only composed of numbers
("20041001103319").
The problem is that this key is automatically converted into an int by PHP and as it is a long
string, it produces an integer overflow for the array index (see the code and the Actual result)
after serialization and then unserialization.
Note that I compiled PHP 4.3.10 on my laptop (32 bits) and there is no problem at all (I can see the
Expected result), but when I compile on an AMD 64 (Opteron) machine, the wrong (Actual result) is
shown.
(I've also saw this bug with a 4.3.2 on the Opteron machine).
Problem with cast of strings into int when 64 bits ...
Note that if I try on my laptop with a shorter key (ie "2004100") that does not overflows
the int capacity, it is also automatically casted into an int.
My conclusion is "Never use as keys in arrays strings only composed of numbers". But I
think that at least a notice should be displayed for such implicit casts.
Or maybe I missed something in the documentation. In this case, sorry for the loss if time.
It is most related with Bug #28972 but in this case, we can see the difference in the treatment
between 32 and 64 bits arch.
Reproduce code:
---------------
$arr["20041001103319"] = 'test';
var_dump( $arr);
$arr_in_str = serialize($arr);
print "Now result is: $arr_in_str<BR />";
$final_arr = unserialize($arr_in_str);
print "The final unserialized array:<BR />";
var_dump($final_arr);
Expected result:
----------------
array(1) { ["20041001103319"]=> string(4) "test" }
Now result is: a:1:{s:14:"20041001103319";s:4:"test";}
The final unserialized array:
array(1) { ["20041001103319"]=> string(4) "test" }
Actual result:
--------------
array(1) { [20041001103319]=> string(4) "test" }
Now result is: a:1:{i:20041001103319;s:4:"test";}
The final unserialized array:
array(1) { [683700183]=> string(4) "test" }
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=31117&edit=1