Skip to content

AOT: Element::getElementsByTagName()->item() returns wrong node / includes self for '*' — lastTagQuery never set (ext/dom/element.c) #34780

Description

@PurHur

Category

bug · AOT DOM live NodeList

Problem

Thin-AOT DOMElement::getElementsByTagName() boxes a NodeList with the right length but never sets JitDomGetElementsByTagNameUserScript::$lastTagQuery / $liveItemTagQuery (unlike DOMDocument::getElementsByTagName). DOMNodeList::item(0) then falls through to pinned-root firstChild, so $root->getElementsByTagName('b')->item(0) returns a. After a prior Document query that left lastTagQuery='*', Element * lists also include the element itself (Zend is descendants-only).

Repro Zend 8.2+ AOT (master)
$root->getElementsByTagName('b')->item(0)->nodeName alone b a
$root->getElementsByTagName('*') names a,b,c root,a,b,c (after Document * poisoned tag)
replaceChild($n, $root->getElementsByTagName('b')->item(0)) replaces b replaces a

php-src reference

PHP implementation target

  • ext/dom/JitDomGetElementsByTagNameUserScript::tryInvokeFromElement — set $lastTagQuery / $liveItemTagQuery + from-element flag (peer Document tryInvoke)
  • ext/dom/JitDomLiveElementsByTagWalk / JitDomNodeListItemUserScript — when from-element, start walk at firstChild (exclude self)

Repro

./script/docker-exec.sh -- bash -lc 'php bin/compile.php -o /tmp/gebtn test/repro/issue_dom_element_getelements_item_aot.php && /tmp/gebtn'

Done when

  • Element getElementsByTagName('b')->item(0) is b without a prior Document query
  • Element getElementsByTagName('*') is descendants-only (a,b,c)
  • ./script/aot-smoke.sh stays 8/8
  • Unit test covers Element vs Document item()

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugSomething isn't workingimplementation-readySpec complete: repro, php-src ref, done-when — safe for workers to claim

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions