Skip to content

Language: #[\SensitiveParameter] attribute — redact parameters in traces (PHP 8.2, Zend parity) #3351

Description

@PurHur

Category

language

Problem

The #[\SensitiveParameter] attribute (PHP 8.2) is not parsed or honored. Zend redacts marked parameters in stack traces, var_dump, and debug_backtrace output.

./script/docker-exec.sh -- bash -lc 'source script/php-env.sh && php bin/vm.php -r "
function f(#[\\SensitiveParameter] string \$secret) { throw new Exception(); }
try { f(\"hunter2\"); } catch (Exception \$e) { echo \$e->getTraceAsString(); }
"'
# Trace still shows hunter2 (or compile error if attribute unsupported)

php-src reference

  • Zend/zend_attributes.c — SensitiveParameter attribute class registration
  • Zend/zend_builtin_functions.c — backtrace / var_dump redaction
  • ext/standard/var.c — debug_zval_dump redaction paths

Repro

<?php
function login(#[\SensitiveParameter] string $password): void {
    throw new RuntimeException('fail');
}
try {
    login('hunter2');
} catch (Throwable $e) {
    echo $e->getTraceAsString();
}
./script/docker-exec.sh -- bash -lc 'source script/php-env.sh && php bin/vm.php repro.php'
php repro.php

Zend PHP: trace shows [Sensitive Parameter] instead of hunter2.

This compiler: attribute ignored or parse error; secret visible in trace.

Scope (this repo)

Area Path Notes
Parser php-cfg / nikic parser Preserve SensitiveParameter on Param nodes
Compiler lib/Compiler.php Store flag on Func / arg metadata
VM lib/VM.php, debug_backtrace lowering Redact in trace frames
Stdlib ext/standard/debug_backtrace paths Align with Zend
Tests test/compliance/cases/language/sensitive_parameter*.phpt

Done when

  • #[\SensitiveParameter] on parameters compiles
  • Exception::getTraceAsString() and debug_backtrace() redact marked args
  • Compliance PHPT matches Zend output shape

Verification

./script/docker-exec.sh -- bash -lc 'source script/php-env.sh && vendor/bin/phpunit --filter sensitive_parameter'
./script/ci-fast.sh --filter sensitive_parameter

Links

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    area:compilerCompiler / CFG / JITarea:vmVirtual machineenhancementNew feature or requestimplementation-readySpec complete: repro, php-src ref, done-when — safe for workers to claimphase-2:languagePhase 2 – language features

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions