Bug #72536 [Opn->Wfx]: gmp_random_bits / gmp_random abort reached
| From: | nikic@php.net | Date: | Sun, 03 Jul 2016 11:13:16 +0000 |
| Subject: | Bug #72536 [Opn->Wfx]: gmp_random_bits / gmp_random abort reached | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-202017@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=72536&edit=1
ID: 72536
Updated by: nikic@php.net
Reported by: fernando at null-life dot com
Summary: gmp_random_bits / gmp_random abort reached
-Status: Open
+Status: Wont fix
Type: Bug
Package: GNU MP related
Operating System: Windows
PHP Version: 7.0.8
Block user comment: N
Private report: N
New Comment:
Due to compatibility issues with other libraries that link against libgmp, we can no longer replace
the GMP default allocator with our own infallible allocator. As such, OOM aborts in GMP will not be
fixed.
Previous Comments:
------------------------------------------------------------------------
[2016-07-03 06:47:03] fernando at null-life dot com
Description:
------------
void *
__gmp_default_reallocate (void *oldptr, size_t old_size, size_t new_size)
{
void *ret;
#ifdef DEBUG
size_t req_size = new_size;
if (old_size != 0)
{
mp_ptr p = oldptr;
if (p[-1] != (0xdeadbeef << 31) + 0xdeafdeed)
{
fprintf (stderr, "gmp: (realloc) data clobbered before allocation block\n");
abort ();
}
if (old_size % BYTES_PER_MP_LIMB == 0)
if (p[old_size / BYTES_PER_MP_LIMB] != ~((0xdeadbeef << 31) + 0xdeafdeed))
{
fprintf (stderr, "gmp: (realloc) data clobbered after allocation block\n");
abort ();
}
oldptr = p - 1;
}
new_size += 2 * BYTES_PER_MP_LIMB;
#endif
ret = realloc (oldptr, new_size);
if (ret == 0)
{
#if defined _MSC_VER && defined _WIN64
fprintf (stderr, "GNU MP: Cannot reallocate memory (old_size=%llu
new_size=%llu)\n", old_size, new_size);
#else
fprintf (stderr, "GNU MP: Cannot reallocate memory (old_size=%lu new_size=%lu)\n",
old_size, new_size);
#endif
abort ();
}
This abort inside __gmp_default_reallocate is reached with the attached test scripts. Maybe a check
can be implemented inside php-gmp extension to prevent it. Tested on 64 bits Windows.
Test script:
---------------
<?php
$v1=-4500000000;
echo gmp_random($v1);
<?php
$v1=PHP_INT_MAX;
gmp_random_bits($v1);
Expected result:
----------------
No crash
Actual result:
--------------
php.exe crashes
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=72536&edit=1