#28972 [Ver]: [] operator overflow treatment is incorrect

From: Date: Sun, 06 Mar 2005 19:34:11 +0000
Subject: #28972 [Ver]: [] operator overflow treatment is incorrect
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-74951@lists.php.net to get a copy of this message
ID: 28972 Updated by: sniper@php.net Reported By: tomas_matousek at hotmail dot com Status: Verified Bug Type: Zend Engine 2 problem Operating System: * PHP Version: 5CVS-2005-03-06 New Comment: /usr/src/php/php5/Zend/zend_execute.c(921) : Freeing 0x09F5C4B4 (16 bytes), script=t.php Previous Comments: ------------------------------------------------------------------------ [2005-03-06 20:33:58] sniper@php.net Leaks too: /usr/src/php/php_4_3/Zend/zend_execute.c(501) : Freeing 0x09ACF6A4 (12 bytes), script=t.php ------------------------------------------------------------------------ [2004-06-30 11:08:01] tomas_matousek at hotmail dot com Description: ------------ If there is an item in an array having key = 2^31-1 and you use [] operator without specifying a key it overflows and adds a new item with min. int (-2^31) in the array. This is IMHO not correct or at least not consistent with the manual where the following sentence is stated: "If you do not specify a key for a given value, then the maximum of the integer indices is taken, and the new key will be that maximum value + 1." Moreover, consider the folowing array: $a = array(2^31-2 => 1,-2^31 => 1) and use $a[] twice. You get warning: "Cannot add element to the array as the next element is already occupied". But if the array is $a = array(2^31-1 => 1,-2^31 => 1) a new item is added with a key -2^31+1 with no warning. However, if you use array_push instead [] it does never report a warning but does the same as []. IMHO it will be more correct if both [] and array_push do not add a new key and report a warning or notice if the maximal integer key reaches maximum value 2^31-1. Reproduce code: --------------- $a = array(2147483647 => 1, -2147483648 => 1); $a[] = 2; $a[] = 3; var_dump($a); $a = array(2147483646 => 1, -2147483648 => 1); $a[] = 2; $a[] = 3; var_dump($a); Expected result: ---------------- Warning: Cannot add element to array - integer key reached maximal possible value ... Warning: Cannot add element to array - integer key reached maximal possible value ... array(4) { [2147483647]=> int(1) [-2147483648]=> int(1) } Warning: Cannot add element to array - integer key reached maximal possible value ... array(3) { [2147483646]=> int(1) [-2147483648]=> int(1) [2147483647]=> int(2) } Actual result: -------------- array(4) { [2147483647]=> int(1) [-2147483648]=> int(1) [-2147483647]=> int(2) [-2147483646]=> int(3) } Warning: Cannot add element to the array as the next element is already occupied in ... array(3) { [2147483646]=> int(1) [-2147483648]=> int(1) [2147483647]=> int(2) } ------------------------------------------------------------------------ -- Edit this bug report at http://bugs.php.net/?id=28972&edit=1

« previous php.bugs (#74951) next »