Bug #69702 [Com]: Handle pool integer overflow
| From: | info at daniel-marschall dot de | Date: | Mon, 25 May 2015 14:54:22 +0000 |
| Subject: | Bug #69702 [Com]: Handle pool integer overflow | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-192881@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=69702&edit=1
ID: 69702
Comment by: info at daniel-marschall dot de
Reported by: info at daniel-marschall dot de
Summary: Handle pool integer overflow
Status: Closed
Type: Bug
Package: *General Issues
Operating System: Linux 3.2.0-4-amd64 #1 SMP Debia
PHP Version: 5.4.41
Assigned To: nikic
Block user comment: N
Private report: N
New Comment:
Ok, thanks for this information.
But why does a 64bit build of PHP have a 32 bit handle address space?
Previous Comments:
------------------------------------------------------------------------
[2015-05-24 22:56:31] nikic@php.net
The GMP issue is fixed in PHP 5.6 as a side-effect of no longer using resources: Unlike resource IDs
object handles get reused. This will not be fixed in earlier versions.
For the general issue of resource id overflow see also bug #67845 and FR #47396.
------------------------------------------------------------------------
[2015-05-24 22:21:32] info at daniel-marschall dot de
Description:
------------
Given is following CLI script, which will do a "for" loop for BigIntegers (gmp). I iterate
$i from 0 to 999999999999999999 .
I see 4 problems:
1) There is no possibility to increase a GMP number without re-creating it using gmp_add() .
2) On a 64-bit OS, the max handle pool is still an unsigned 32 bit int (see below)???
3) The handle pool counter does not reset when variables are freed, therefore an integer overflow
happens.
4) there is no possibility to free a gmp resource. I assume that it is done automatically, since
there is no gmp_free().
Test script:
---------------
#!/usr/bin/php
<?php
$max = gmp_init("999999999999999999");
$i = gmp_init(0);
while ((gmp_cmp($i, $max) == -1)) {
$i = gmp_add($i, 1);
}
Expected result:
----------------
Since $i is re-assigned (and the old instance of the gmp-object is freed therefore), there should be
neither a memory overflow, nor anything else failing.
Actual result:
--------------
[after a very long waiting time, of course!]
PHP Warning: gmp_cmp(): -2147483648 is not a valid GMP integer resource in .../phpbug.php on line 7
PHP Stack trace:
PHP 1. {main}() .../phpbug.php:0
PHP 2. gmp_cmp() .../phpbug.php:7
Warning: gmp_cmp(): -2147483648 is not a valid GMP integer resource in .../phpbug.php on line 7
Call Stack:
0.0001 226000 1. {main}() .../phpbug.php:0
4309.1840 227048 2. gmp_cmp() .../phpbug.php:7
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=69702&edit=1