Skip to content

AOT: dim fetch on static array property returns empty — C::$a['k'] silent wrong output (Zend/zend_execute.c) #33936

Description

@PurHur

Category

bug · php-src-strict · AOT static array dim fetch

Problem

Assigning an array literal to an untyped static property stores a usable array (VM-correct count / local copy), but dimension fetch on the static under thin AOT returns empty / null. Zend and VM print the element. ?? / assign-to-local paths work; bare echo C::$a['k'] does not.

Repro Zend / VM AOT (master @ 048672b)
C::$a=["x"=>1]; echo C::$a["x"]; 1 `` (empty)
C::$a=["x"=>1]; echo count(C::$a), ":", C::$a["x"]; 1:1 1:
C::$a=["x"=>1]; $t=C::$a; echo $t["x"]; 1 1
C::$a=["x"=>1]; echo C::$a["x"] ?? "missing"; 1 1

Silent wrong output — characteristic failure mode (AGENTS.md §3). Remaining row from AOT correctness group 3 / #31967 after the honest compile-fatal was retired.

php-src reference

PHP implementation target

  • Static property read used as array container for dim fetch — ensure hashtable/__value__ path matches local copy (lib/JIT.php / lib/JIT/Builtin/Type/ObjectStaticPropertyLlvm.php / dim fetch helpers)
  • No new runtime/*.c

Repro

./script/aot-smoke.sh
./script/docker-exec.sh -- bash -lc 'export PHP_COMPILER_HELPER_RUNTIME_O=0; php bin/compile.php -o /tmp/sa.bin test/repro/issue_NNNN_static_array_dim_aot.php && /tmp/sa.bin'

Done when

  • Bare echo C::$a["k"] matches Zend under AOT (repeat ≥5)
  • ./script/aot-smoke.sh stays 8/8
  • Unit + repro guard

Parent

  • Peer inventory #31968 / group 3 statics; leftover of #31967 array-literal static store row (now silent wrong output, not compile fatal)

Activity

  1. added
    bugSomething isn't working
    phase-3:aotPhase 3 – AOT deployment
    implementation-readySpec complete: repro, php-src ref, done-when — safe for workers to claim
    on Aug 22, 2026
  2. PurHur commented on Aug 22, 2026

    @PurHur
    OwnerAuthor

    claim: implementer-worker-lane-a — starting this run (lane A: 33936 % 3 == 0; #32122/#31968 children closed; #33934/#33935 claimed <48h). Silent wrong AOT dim fetch on static array.

  3. PurHur commented on Aug 22, 2026

    @PurHur
    OwnerAuthor

    claim: working this as stdlib/AOT lane — static array dim fetch silent wrong output under AOT.

  4. self-assigned this
    on Aug 22, 2026
  5. PurHur commented on Aug 22, 2026

    @PurHur
    OwnerAuthor

    merged: #33944 (d9465f5fcf)

    Fix: needsCfgSplitBeforeStringDimFetch no longer inserts TYPE_JUMP when the dim container is the Temporary from the preceding StaticPropertyFetch (peer #23354 Temporary-across-JUMP).

    Verified

    ./script/docker-exec.sh -- bash -lc './script/aot-smoke.sh'   # 8/8
    ./script/docker-exec.sh -- bash -lc 'export PHP_COMPILER_HELPER_RUNTIME_O=0; php bin/compile.php -o /tmp/s.bin test/repro/issue_33936_static_array_dim_aot.php && /tmp/s.bin'
    # 1 / 1 / 1:1
    ./script/phpunit.sh --filter Issue33936StaticArrayDimAotTest   # OK (2 tests, 14 assertions)
    
  6. added 2 commits that reference this issue on Aug 22, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

area:compilerCompiler / CFG / JITbugSomething isn't workingimplementation-readySpec complete: repro, php-src ref, done-when — safe for workers to claimphase-3:aotPhase 3 – AOT deployment

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions