Description
Problem:
Svace reports a potential SIGN_EXTENSION issue in SplFixedArray::__serialize() in ext/spl/spl_fixedarray.c. The warning concerns the conversion of num_properties from uint32_t to zend_long in the expression intern->array.size + num_properties, which may cause different evaluation results on 32-bit and 64-bit platforms.
However, num_properties is obtained from HashTable::nNumOfElements, and the maximum hash table size is limited by HT_MAX_SIZE (0x02000000 on 32-bit platforms and 0x40000000 on 64-bit platforms). The hash table implementation checks these limits when allocating and growing tables. If the number of elements cannot exceed the table capacity, num_properties remains below INT32_MAX on 32-bit platforms, preventing the sign-bit issue described by the warning. On 64-bit platforms, all uint32_t values are representable in int64_t.
Request:
Please confirm whether this warning can be classified as a false positive based on the HashTable size constraints and integer conversion rules. If nNumOfElements can exceed INT32_MAX on any supported 32-bit configuration, please clarify the conditions under which this can occur and whether additional validation is required.
PHP Version
Operating System
Ubuntu 24.04
Description
Problem:
Svace reports a potential SIGN_EXTENSION issue in SplFixedArray::__serialize() in ext/spl/spl_fixedarray.c. The warning concerns the conversion of num_properties from uint32_t to zend_long in the expression intern->array.size + num_properties, which may cause different evaluation results on 32-bit and 64-bit platforms.
However, num_properties is obtained from HashTable::nNumOfElements, and the maximum hash table size is limited by HT_MAX_SIZE (0x02000000 on 32-bit platforms and 0x40000000 on 64-bit platforms). The hash table implementation checks these limits when allocating and growing tables. If the number of elements cannot exceed the table capacity, num_properties remains below INT32_MAX on 32-bit platforms, preventing the sign-bit issue described by the warning. On 64-bit platforms, all uint32_t values are representable in int64_t.
Request:
Please confirm whether this warning can be classified as a false positive based on the HashTable size constraints and integer conversion rules. If nNumOfElements can exceed INT32_MAX on any supported 32-bit configuration, please clarify the conditions under which this can occur and whether additional validation is required.
PHP Version
Operating System
Ubuntu 24.04