Skip to content

Commit b86c624

Browse files
committed
Fix type inference
This fixes oss-fuzz #47777
1 parent 98e1291 commit b86c624

File tree

2 files changed

+24
-3
lines changed

2 files changed

+24
-3
lines changed

Zend/Optimizer/zend_inference.c

Lines changed: 6 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -3231,17 +3231,20 @@ static zend_always_inline int _zend_update_type_info(
32313231
key_type |= MAY_BE_ARRAY_PACKED;
32323232
}
32333233
if (t1 & MAY_BE_ARRAY) {
3234-
key_type |= MAY_BE_HASH_ONLY(t1) ? MAY_BE_ARRAY_NUMERIC_HASH : MAY_BE_ARRAY_KEY_LONG;
3234+
key_type |= (MAY_BE_HASH_ONLY(t1) || (t1 & (MAY_BE_UNDEF|MAY_BE_NULL|MAY_BE_FALSE))) ?
3235+
MAY_BE_ARRAY_NUMERIC_HASH : MAY_BE_ARRAY_KEY_LONG;
32353236
}
32363237
} else {
32373238
if (t2 & (MAY_BE_LONG|MAY_BE_FALSE|MAY_BE_TRUE|MAY_BE_RESOURCE|MAY_BE_DOUBLE)) {
3238-
key_type |= MAY_BE_HASH_ONLY(t1) ? MAY_BE_ARRAY_NUMERIC_HASH : MAY_BE_ARRAY_KEY_LONG;
3239+
key_type |= (MAY_BE_HASH_ONLY(t1) || (t1 & (MAY_BE_UNDEF|MAY_BE_NULL|MAY_BE_FALSE))) ?
3240+
MAY_BE_ARRAY_NUMERIC_HASH : MAY_BE_ARRAY_KEY_LONG;
32393241
}
32403242
if (t2 & MAY_BE_STRING) {
32413243
key_type |= MAY_BE_ARRAY_KEY_STRING;
32423244
if (opline->op2_type != IS_CONST) {
32433245
// FIXME: numeric string
3244-
key_type |= MAY_BE_HASH_ONLY(t1) ? MAY_BE_ARRAY_NUMERIC_HASH : MAY_BE_ARRAY_KEY_LONG;
3246+
key_type |= (MAY_BE_HASH_ONLY(t1) || (t1 & (MAY_BE_UNDEF|MAY_BE_NULL|MAY_BE_FALSE))) ?
3247+
MAY_BE_ARRAY_NUMERIC_HASH : MAY_BE_ARRAY_KEY_LONG;
32453248
}
32463249
}
32473250
if (t2 & (MAY_BE_UNDEF | MAY_BE_NULL)) {
Lines changed: 18 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,18 @@
1+
--TEST--
2+
Type inference 009: FRTCH_DIM_W
3+
--INI--
4+
opcache.enable=1
5+
opcache.enable_cli=1
6+
opcache.optimization_level=-1
7+
--FILE--
8+
<?php
9+
function y() {
10+
for(;;) {
11+
$arr[y][]=y;
12+
$arr=[''=>y];
13+
}
14+
}
15+
?>
16+
DONE
17+
--EXPECT--
18+
DONE

0 commit comments

Comments
 (0)