Fix negative SimpleXML offsets aliasing the first element - #215
Closed
iliaal wants to merge 6 commits into
Closed
Conversation
* PHP-8.2: Fix hMailServer URL in Windows CI (php#23055)
* PHP-8.3: Fix hMailServer URL in Windows CI (php#23055)
The id must be reset to NULL before calling code that can invoke userland code, as the id remains visible after release due to a stale pointer. Closes phpGH-23046.
iliaal
force-pushed
the
fix/sxe-negative-offset
branch
from
August 5, 2026 13:27
061844c to
b8b2e9b
Compare
sxe_get_element_by_offset scanned with nodendx <= offset, so a negative offset skipped the loop and returned the node it started from. Reads and isset() reported the first element, and a write overwrote it. Negative offsets now miss, and writing to one warns like an out-of-range positive offset instead of creating a node. Closes phpGH-23068
iliaal
force-pushed
the
fix/sxe-negative-offset
branch
from
August 5, 2026 13:28
b8b2e9b to
7bdf744
Compare
Owner
Author
|
Promoted upstream as php#23068. Extended there so a negative-offset write warns and creates nothing, instead of silently appending. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
sxe_get_element_by_offset treated negative offsets as a hit on the starting node because the scan loop never runs when offset < 0. Return NULL so reads miss and writes do not mutate item[0].