[php-src] Issue #20370: User filters allow breaking typed properties

From: Date: Sun, 02 Nov 2025 22:08:08 +0000
Subject: [php-src] Issue #20370: User filters allow breaking typed properties
Groups: php.bugs 
Request: Send a blank email to php-bugs+get-251166@lists.php.net to get a copy of this message
Issue: https://github.com/php/php-src/issues/20370
Author: ndossche

### Description

The following code:

```php
<?php

class pass_filter
{
    public $filtername;
    public $params;
    public int $stream = 1;

    function filter($in, $out, &$consumed, $closing): int
    {
        while ($bucket=stream_bucket_make_writeable($in)) {
            $consumed += $bucket->datalen;
            stream_bucket_append($out, $bucket);
        }
        var_dump($this->stream); // resource instead of int -> type system violation
        return PSFS_PASS_ON;
    }
}

stream_filter_register("pass", "pass_filter");
$fp=fopen("php://memory", "w");
stream_filter_append($fp,  "pass");
fwrite($fp, "Thank you\n");
rewind($fp);
echo fread($fp, 1024);
```

Resulted in this output:
```
resource(5) of type (stream)
resource(5) of type (stream)
resource(5) of type (stream)
resource(5) of type (stream)
Thank you
resource(5) of type (Unknown)
```

But I expected this output instead:
```
An exception, because the property shouldn't have been set in the first place. The type system
should prevent this.
```

I discovered this because I wanted to get rid of the OBJPROP accessor, which would avoid building
the properties table. It's a bit annoying to fix this as you'd need to conditionally use
zend_update_property

### PHP Version

```plain
8.3+
```

### Operating System

_No response_


Thread (1 message)

  • ndossche
« previous php.bugs (#251166) next »