I'm actually quite surprised at the initial response by the PHP Core to this vulnerability. At very least I would have thought a sensible approach would be to fail securely - so if supplied with a bad hash you return false, not true!
Returning the input unmodified is not failure, but success. That's how you check that a password is valid without having a specialized API.
<strike>crypt is the hashing function, not the password checking function</strike>
So returning the original hash for a valid password is the success case.