Skip to content

Stdlib: array_slice() negative offset/length — wrong slice with preserve_keys (ext/standard/array.c) #10229

Description

@PurHur

Category

stdlib · php-src-strict · refs #1492

Problem

array_slice() mishandles negative $offset and negative $length when $preserve_keys is true (or when length is negative on packed lists). Zend returns the tail/middle segment; this compiler returns the wrong elements or an empty array.

Call Zend This compiler VM
array_slice([0=>'a',1=>'b',2=>'c',3=>'d'], -2, 2, true) array (2=>'c', 3=>'d') array (0=>'a', 1=>'b')
array_slice(['a','b','c','d','e'], 1, -2) array (0=>'b', 1=>'c') array ()

php-src reference

Repro

Saved repro: test/repro/maintainer_gap_array_slice_negative_offset.php

./script/docker-exec.sh -- bash -lc 'source script/php-env.sh && php bin/vm.php test/repro/maintainer_gap_array_slice_negative_offset.php'
php test/repro/maintainer_gap_array_slice_negative_offset.php

Implementation hints (PHP-in-PHP)

  • Likely bug in lib/VM/HashTable.php — sliceCopyPreserveKeys() / normalizeSpliceRange() (negative length path sets $removeLen to 0 incorrectly for slice, or preserve-keys path ignores normalized offset)
  • ext/standard/array_slice.php delegates to HashTable::sliceCopy() — fix shared VM helper, not C runtime
  • Mirror fix in lib/JIT/ArrayBuiltinHelper.php buildSliceArray() if JIT path duplicates logic

Scope

  • lib/VM/HashTable.php — sliceCopy(), sliceCopyPreserveKeys(), normalizeSpliceRange()
  • ext/standard/array_slice.php
  • Optional JIT: lib/JIT/ArrayBuiltinHelper.php

Done when

  • Negative offset + preserve_keys repro matches Zend
  • Negative length repro matches Zend
  • Positive offset/length regressions unchanged
  • Compliance guard committed under test/compliance/cases/stdlib/

Verification

./script/docker-exec.sh -- bash -lc 'source script/php-env.sh && php bin/vm.php test/repro/maintainer_gap_array_slice_negative_offset.php'

Related

Activity

  1. added
    enhancementNew feature or request
    phase-4:stdlibPhase 4 – stdlib for web apps
    area:vmVirtual machine
    implementation-readySpec complete: repro, php-src ref, done-when — safe for workers to claim
    on Jun 20, 2026
  2. PurHur commented on Jun 21, 2026

    @PurHur
    OwnerAuthor

    claim: cursor-agent-lane-c — starting this run (VM HashTable sliceCopy fix in lib/VM; not ext/standard builtin body despite stdlib label)

  3. PurHur commented on Jun 21, 2026

    @PurHur
    OwnerAuthor

    claim: cursor-agent-lane-c — continuing in-flight branch agent/issue-10229-array-slice-negative

  4. PurHur commented on Jun 21, 2026

    @PurHur
    OwnerAuthor

    Merged via #10513.

    Fix: HashTable::sliceCopy() uses normalizeSpliceRange() for negative offset/length; compile-time folding/mapping for hoisted UnaryMinus call args (php-cfg dead temps + embedded literals between producers).

    Verification: issue repro + array_slice_negative_length.phpt green on VM; unit guards in HashTableSpliceTest and InlineCallArgProducerSlotTest.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    area:vmVirtual machineenhancementNew feature or requestimplementation-readySpec complete: repro, php-src ref, done-when — safe for workers to claimphase-4:stdlibPhase 4 – stdlib for web appsstdlib

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions