Skip to content

Fix object reference key collision in msgpack_var_add - #192

Open
LaurinKerkloh wants to merge 1 commit into
msgpack:masterfrom
LaurinKerkloh:fix-var-hash-collision
Open

LaurinKerkloh wants to merge 1 commit into
msgpack:masterfrom
LaurinKerkloh:fix-var-hash-collision

Conversation

@LaurinKerkloh

@LaurinKerkloh LaurinKerkloh commented Oct 5, 2026 •

Copy link
Copy Markdown

Objects were keyed by a mix of class entry pointer and handle, which is not unique: two objects of different classes could share a key, so one was packed as a back-reference to the other.

Key objects by their zend_object address in a separate key space from arrays, and hold a reference to each packed object until packing ends so its address cannot be reused (as ext/standard/var.c does).

Fixes #191

Objects were keyed by a mix of class entry pointer and handle, which
is not unique: two objects of different classes could share a key,
so one was packed as a back-reference to the other.

Key objects by their zend_object address in a separate key space
from arrays, and hold a reference to each packed object until
packing ends so its address cannot be reused (as ext/standard/var.c
does).
@LaurinKerkloh
LaurinKerkloh force-pushed the fix-var-hash-collision branch from 745e454 to d8eba36 Compare October 5, 2026 07:59
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Object reference table key collision: an object is packed as a back-reference to a different object

1 participant