Repository navigation
Conversation
Fix php#22895 The return value of array_set_zval_key() was ignored, so when the key is not a legal array offset, e.g. MultipleIterator::key() returning an array, it threw and took no reference. The unconditional zval_ptr_dtor() then dropped the iterator's only reference to the borrowed value and the following Z_TRY_ADDREF_P() read freed memory. Let array_set_zval_key() own its reference the way spl_iterator_to_array_apply() does, and stop iterating on failure.
| try { | ||
| $client->__soapCall('audit', [new SoapVar($iterator, SOAP_ENC_ARRAY)]); | ||
| } catch (TypeError $e) { | ||
| echo $e->getMessage(), PHP_EOL; |
There was a problem hiding this comment.
| echo $e->getMessage(), PHP_EOL; | |
| echo $e::class, ': ', $e->getMessage(), PHP_EOL; |
|
This misses one case: a key that inserts fine but raises a throwing diagnostic. With a set_error_handler(function ($errno, $errstr) { throw new Exception($errstr); });
function gen() { yield 1.5 => new stdClass(); yield 2 => new stdClass(); }
$client = new SoapClient(null, ['location' => 'test://', 'uri' => 'urn:test']);
$client->test(new SoapVar(gen(), SOAP_ENC_ARRAY)); |
If this is caused by this function not behaving correctly then this should be fixed instead to return FAILURE when an exception is triggered. |
sure ! |
| case IS_STRING: | ||
| result = zend_symtable_update(ht, Z_STR_P(key), value); | ||
| break; | ||
| case IS_NULL: |
There was a problem hiding this comment.
This probably needs the same fix during up-merging due to null as array key deprecation.
Fix #22895
The return value of array_set_zval_key() was ignored, so when the key is not a legal array offset, e.g. MultipleIterator::key() returning an array, it threw and took no reference. The unconditional zval_ptr_dtor() then dropped the iterator's only reference to the borrowed value and the following Z_TRY_ADDREF_P() read freed memory.
Let array_set_zval_key() own its reference the way spl_iterator_to_array_apply() does, and stop iterating on failure.