Skip to content

Potential SIGN_EXTENSION in SplFixedArray::__serialize() #24211

Description

@Ti-Mis

Description

Problem:
Svace reports a potential SIGN_EXTENSION issue in SplFixedArray::__serialize() in ext/spl/spl_fixedarray.c. The warning concerns the conversion of num_properties from uint32_t to zend_long in the expression intern->array.size + num_properties, which may cause different evaluation results on 32-bit and 64-bit platforms.

However, num_properties is obtained from HashTable::nNumOfElements, and the maximum hash table size is limited by HT_MAX_SIZE (0x02000000 on 32-bit platforms and 0x40000000 on 64-bit platforms). The hash table implementation checks these limits when allocating and growing tables. If the number of elements cannot exceed the table capacity, num_properties remains below INT32_MAX on 32-bit platforms, preventing the sign-bit issue described by the warning. On 64-bit platforms, all uint32_t values are representable in int64_t.

Request:
Please confirm whether this warning can be classified as a false positive based on the HashTable size constraints and integer conversion rules. If nNumOfElements can exceed INT32_MAX on any supported 32-bit configuration, please clarify the conditions under which this can occur and whether additional validation is required.

PHP Version

PHP 8.3.31 (cli)

Operating System

Ubuntu 24.04

Activity

  1. ndossche commented on Oct 9, 2026

    @ndossche
    Member

    False positive for the reason described: num_properties remains below INT32_MAX

  2. ndossche commented on Oct 9, 2026

    @ndossche
    Member

    @Ti-Mis which analysis tool are you using?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions