Skip to content

Stdlib: hash_equals() enum case operand must TypeError (ext/standard/hash.c) #5760

Description

@PurHur

Summary

hash_equals() must reject enum case objects with TypeError on both operands (Zend Z_PARAM_STR). This compiler coerces backed enum cases to backing strings and returns true, breaking timing-safe compare semantics.

php-src reference

  • ext/standard/hash.c — PHP_FUNCTION(hash_equals) (Z_PARAM_STR for $known_string and $user_string)

Repro

test/repro-maintainer/hash_equals_enum_operand.php:

enum E: string { case A = 'x'; }
var_export(hash_equals(E::A, 'x'));
Runtime Output
Zend PHP 8.3 TypeError: hash_equals(): Argument #1 ($known_string) must be of type string, E given
php bin/vm.php (this repo) true

Expected fix (PHP-in-PHP)

Notes

Not covered by #5524 alone (umbrella string builtins); hash_equals is security-sensitive and currently has only scalar repros (#2179).

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    area:vmVirtual machineenhancementNew feature or requestimplementation-readySpec complete: repro, php-src ref, done-when — safe for workers to claimphase-4:stdlibPhase 4 – stdlib for web apps

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions