#34879 [Asn->Csd]: str_replace, array_map corrupt negative array indexes

From: Date: Fri, 28 Oct 2005 15:03:39 +0000
Subject: #34879 [Asn->Csd]: str_replace, array_map corrupt negative array indexes
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-87180@lists.php.net to get a copy of this message
ID: 34879 Updated by: dmitry@php.net Reported By: brion at pobox dot com -Status: Assigned +Status: Closed Bug Type: Scripting Engine problem Operating System: Linux 64bit (AMD64) PHP Version: 5.1.0RC1, 4.4.1RC1 Assigned To: dmitry New Comment: Fixed in CVS HEAD and PHP_5_1. Previous Comments: ------------------------------------------------------------------------ [2005-10-28 14:01:54] dmitry@php.net zend_hash_get_current_key_ex() returns ulong, but add_index_...() accepts uint. On 64-bit ulong and uint have different size. So we lose part of index value. ------------------------------------------------------------------------ [2005-10-21 23:50:54] tony2001@php.net Reproducible on amd64 host. ------------------------------------------------------------------------ [2005-10-15 09:50:53] brion at pobox dot com Description: ------------ On 64-bit Opteron systems, certain functions which operate on arrays will corrupt negative integer array indexes, turning them into large positive integers. I've found at least str_replace, preg_replace, and array_map to exhibit this behavior. This bug has been inserting odd, but harmless entries into user preferences on Wikipedia, though there might be more serious problems caused by it that we haven't yet discovered. Problem confirmed on PHP 4.4.0, 4.4.1RC1, and 5.1.0RC1 running on Fedora Core 3 for x86_64; compiled PHP with gcc (GCC) 3.4.4 20050721 (Red Hat 3.4.4-2) Reproduce code: --------------- var_dump( str_replace( 'a', 'b', array( -1 => -1 ) ) ); Expected result: ---------------- Running on our 32-bit Linux systems I receive the expected: array(1) { [-1]=> string(2) "-1" } Actual result: -------------- On our 64-bit Linux servers, I get an incorrect index: array(1) { [4294967295]=> string(2) "-1" } ------------------------------------------------------------------------ -- Edit this bug report at http://bugs.php.net/?id=34879&edit=1

« previous php.bugs (#87180) next »