Skip to content

Stdlib: str_replace/str_ireplace non-string array subject throws LogicException — Zend coerces (ext/standard/string.c) #27165

Description

@PurHur

Category

Stdlib · php-src-strict · string replace array subject · pillar 4

Problem

str_replace / str_ireplace accept array|string $subject. When $subject is an array of mixed scalars, Zend string-casts each element and replaces. VM/JIT throw LogicException: str_replace() array subject values must be strings in this compiler build (same for str_ireplace).

Verified 2026-08-03 at e0e5e10c9 (Docker Zend 8.2.32):

Repro Zend 8.2.32 VM / JIT
str_replace('1', 'X', [12, '13']) ['X2', 'X3'] LogicException: str_replace() array subject values must be strings…
str_ireplace('a', 'X', ['a', 12, 'A']) ['X', '12', 'X'] LogicException: str_ireplace() array subject values must be strings…

Peer of the preg_* non-string array-subject gap (same “must be strings in this compiler build” pattern).

php-src reference

PHP implementation target

  • ext/standard/ string replace helpers + VM/JIT lowering — coerce array subject values to string like Zend; delete LogicException guard
  • PHP-in-PHP; no new runtime/*.c

Repro

./script/docker-exec.sh -- bash -lc 'cat > /tmp/str_replace_mixed.php << "PHP"
<?php
var_export(str_replace("1", "X", [12, "13"]));
echo "\n";
var_export(str_ireplace("a", "X", ["a", 12, "A"]));
echo "\n";
PHP
php /tmp/str_replace_mixed.php
php bin/vm.php /tmp/str_replace_mixed.php
php bin/jit.php /tmp/str_replace_mixed.php'

Done when

  • VM + JIT match Zend for both calls
  • No LogicException for int array subject values
  • Compliance / test/repro/ guard; php-src-strict

Activity

  1. added
    bugSomething isn't working
    phase-4:stdlibPhase 4 – stdlib for web apps
    area:vmVirtual machine
    implementation-readySpec complete: repro, php-src ref, done-when — safe for workers to claim
    on Aug 3, 2026
  2. PurHur commented on Aug 3, 2026

    @PurHur
    OwnerAuthor

    Sibling filings (same maintainer run @ e0e5e10c9): #27163 (JIT Closure $this builtins), #27164 (preg_* non-string array subject — same LogicException pattern).

  3. PurHur commented on Aug 8, 2026

    @PurHur
    OwnerAuthor

    claim: PHP Compiler STD Lib Advanced — batch (issues #27165, #27716, #27827)

    Sequential PRs under ext/standard string/highlight:

    1. Stdlib: str_replace/str_ireplace non-string array subject throws LogicException — Zend coerces (ext/standard/string.c) #27165 str_replace/str_ireplace array-subject coercion (this PR)
    2. Regression: strcspn("",) with NUL in haystack returns full length on PROFILE=8.2 — Zend stops at NUL (ext/standard/string.c) #27716 strcspn NUL/empty-mask PROFILE=8.2 vs 8.4
    3. Regression: highlight_string/highlight_file HTML wire — Zend <code><span> + &nbsp; (re-#25419, ext/standard/basic_functions.c) #27827 highlight_string/file HTML wire (<code> + &nbsp;)

    PHP-in-PHP; php-src-strict; VM+JIT.

  4. PurHur commented on Aug 8, 2026

    @PurHur
    OwnerAuthor

    Merged #28951

    Verification (Docker php-compiler:22.04-dev):

    • Zend / bin/vm.php / bin/jit.php on test/repro/issue_27165_str_replace_array_value_coerce.php — identical var_export (X2/X3, X/12/X)
    • Existing string-only array subject repro still green VM+JIT
    • StrReplaceRuntimeShrinkTest OK (3)

    Next in batch: #27716 (strcspn PROFILE=8.2 NUL / empty characters).

  5. PurHur commented on Aug 8, 2026

    @PurHur
    OwnerAuthor

    Batch status: #27165/#27716 merged; #27827 closed already-fixed; replacement #28202/#28230 merged via #28959.

  6. added a commit that references this issue on Aug 8, 2026
    754ec3e
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    area:vmVirtual machinebugSomething isn't workingimplementation-readySpec complete: repro, php-src ref, done-when — safe for workers to claimphase-4:stdlibPhase 4 – stdlib for web appsstdlib

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions