Category
stdlib · php-src-strict · refs #1492
Problem
array_slice() mishandles negative $offset and negative $length when $preserve_keys is true (or when length is negative on packed lists). Zend returns the tail/middle segment; this compiler returns the wrong elements or an empty array.
| Call |
Zend |
This compiler VM |
array_slice([0=>'a',1=>'b',2=>'c',3=>'d'], -2, 2, true) |
array (2=>'c', 3=>'d') |
array (0=>'a', 1=>'b') |
array_slice(['a','b','c','d','e'], 1, -2) |
array (0=>'b', 1=>'c') |
array () |
php-src reference
Repro
Saved repro: test/repro/maintainer_gap_array_slice_negative_offset.php
./script/docker-exec.sh -- bash -lc 'source script/php-env.sh && php bin/vm.php test/repro/maintainer_gap_array_slice_negative_offset.php'
php test/repro/maintainer_gap_array_slice_negative_offset.php
Implementation hints (PHP-in-PHP)
- Likely bug in
lib/VM/HashTable.php — sliceCopyPreserveKeys() / normalizeSpliceRange() (negative length path sets $removeLen to 0 incorrectly for slice, or preserve-keys path ignores normalized offset)
ext/standard/array_slice.php delegates to HashTable::sliceCopy() — fix shared VM helper, not C runtime
- Mirror fix in
lib/JIT/ArrayBuiltinHelper.php buildSliceArray() if JIT path duplicates logic
Scope
lib/VM/HashTable.php — sliceCopy(), sliceCopyPreserveKeys(), normalizeSpliceRange()
ext/standard/array_slice.php
- Optional JIT:
lib/JIT/ArrayBuiltinHelper.php
Done when
Verification
./script/docker-exec.sh -- bash -lc 'source script/php-env.sh && php bin/vm.php test/repro/maintainer_gap_array_slice_negative_offset.php'
Related
Category
stdlib· php-src-strict · refs #1492Problem
array_slice()mishandles negative$offsetand negative$lengthwhen$preserve_keysis true (or when length is negative on packed lists). Zend returns the tail/middle segment; this compiler returns the wrong elements or an empty array.array_slice([0=>'a',1=>'b',2=>'c',3=>'d'], -2, 2, true)array (2=>'c', 3=>'d')array (0=>'a', 1=>'b')array_slice(['a','b','c','d','e'], 1, -2)array (0=>'b', 1=>'c')array ()php-src reference
ext/standard/array.c—PHP_FUNCTION(array_slice),php_array_slice()Repro
Saved repro:
test/repro/maintainer_gap_array_slice_negative_offset.php./script/docker-exec.sh -- bash -lc 'source script/php-env.sh && php bin/vm.php test/repro/maintainer_gap_array_slice_negative_offset.php' php test/repro/maintainer_gap_array_slice_negative_offset.phpImplementation hints (PHP-in-PHP)
lib/VM/HashTable.php—sliceCopyPreserveKeys()/normalizeSpliceRange()(negative length path sets$removeLento 0 incorrectly for slice, or preserve-keys path ignores normalized offset)ext/standard/array_slice.phpdelegates toHashTable::sliceCopy()— fix shared VM helper, not C runtimelib/JIT/ArrayBuiltinHelper.phpbuildSliceArray()if JIT path duplicates logicScope
lib/VM/HashTable.php—sliceCopy(),sliceCopyPreserveKeys(),normalizeSpliceRange()ext/standard/array_slice.phplib/JIT/ArrayBuiltinHelper.phpDone when
test/compliance/cases/stdlib/Verification
./script/docker-exec.sh -- bash -lc 'source script/php-env.sh && php bin/vm.php test/repro/maintainer_gap_array_slice_negative_offset.php'Related