-
Notifications
You must be signed in to change notification settings - Fork 8k
Fix GH-20262: array_unique() SORT_REGULAR fails to deduplicate with mixed strings #20273
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
base: master
Are you sure you want to change the base?
Conversation
4102fe6 to
f60a45f
Compare
…h mixed strings array_unique() with SORT_REGULAR was failing to remove duplicate numeric strings when mixed with alphanumeric strings due to non-transitive comparison issues in the sort-based algorithm. Implemented hash-bucketing optimization for SORT_REGULAR that preserves full type coercion semantics while improving performance from O(n²) to O(n). Closes phpGH-20262
f60a45f to
c4fc6a9
Compare
| ZEND_HASH_FOREACH_KEY_VAL(Z_ARRVAL_P(array), num_key, str_key, val) { | ||
| /* Dereference if this is a reference */ | ||
| zval *deref_val = val; | ||
| ZVAL_DEREF(deref_val); |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
nit: might be relevant to add test case for it wdyt ?
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Thanks. This was added after a failed test in the circle jerk, I mean one of the CI checks. There's some other things I felt needed some TLC. Still passing all tests at the moment, but really trying to harden this up.
ext/standard/array.c
Outdated
| } else if (Z_TYPE_P(deref_val) == IS_OBJECT) { | ||
| /* Hash objects by class name */ | ||
| zend_class_entry *ce = Z_OBJCE_P(deref_val); | ||
| hash = zend_string_hash_val(ce->name); |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
How will this interact with inheritance?
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
I didn't note any issues with inheritance, but I ultimately found what I feel is a much more conservative approach that's still both performant and correct -- at least in regards to the original bug that was reported.
- Eliminate Hash-DoS and integer overflow vulnerabilities - Add exception handling to prevent memory leaks - Implement type-specific optimizations (hash/sort/bucket) - Dynamic bucket sizing for memory efficiency - Fix resource handling
The Bug
array_unique()withSORT_REGULARwas failing to remove duplicate numeric strings when mixed with alphanumeric strings:Root Cause
Non-transitive comparisons in
SORT_REGULAR(where'5' == 5and5 != '5abc'but'5' < '5abc') broke the sort-based algorithm's assumption that sorting would group duplicates adjacently.Solution
Implemented type-optimized hybrid approach for
SORT_REGULAR:Three-tier algorithm selection:
Key features:
SORT_REGULARtype coercion semantics (1 == '1' == true)Security Hardening
Performance
Improved performance across all data types compared to PHP 8.4.13 while fixing correctness issues.
Backward Compatibility
Tests Added
gh20262.phpt- Minimal regression test for the bugarray_unique_variation_sort_regular.phpt- Comprehensive SORT_REGULAR behavior coverage (16 scenarios)Closes #20262