Req #63510 [Asn]: Integer overflow with chr should be able to be detected

From: Date: Sun, 28 Aug 2016 21:22:17 +0000
Subject: Req #63510 [Asn]: Integer overflow with chr should be able to be detected
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-203637@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=63510&edit=1 ID: 63510 Updated by: yohgaki@php.net Reported by: idokan at gmail dot com Summary: Integer overflow with chr should be able to be detected Status: Assigned Type: Feature/Change Request Package: Strings related PHP Version: 5.4.8 Assigned To: yohgaki Block user comment: N Private report: N New Comment: BTW, we'll have mb_chr()/mb_ord() from PHP 7.2 commit 087dcd9381c33057901dbe1ef89847d6fa87316d Merge: 4a3188f 15e32fd Author: Yasuo Ohgaki <yohgaki@php.net> Date: Wed Aug 10 09:47:27 2016 +0900 pull-request/1100 Request #65081 mb_chr() and mb_ord() Previous Comments: ------------------------------------------------------------------------ [2016-08-28 21:20:25] yohgaki@php.net Should we close this bug? I'm fine with documentation change. chr() may have strict option that detects overflow, also. string chr(long $code [, bool $strict=FALSE]) ------------------------------------------------------------------------ [2016-07-01 20:07:19] cmb@php.net Automatic comment from SVN on behalf of cmb Revision: http://svn.php.net/viewvc/?view=revision&amp;revision=339537 Log: Address #63510: Integer overflow with chr ------------------------------------------------------------------------ [2016-07-01 19:49:28] cmb@php.net It seems to be appropriate to point out why this ticket had been changed to feature request. :) > Not to $value & 255 it. Actually, the integer is simply cast to char and used as the first and only byte of the returned string[1]. Of course, this behavior is questionable, but changing it would cause a BC break, so it can't be done in a minor version or even a patch release without a very good reason. Simply stating "you must report an error like XYZ" is not a very good reason, in my opinion. I'd rather fix the docs and maybe change the behavior in the next major version. [1] <https://github.com/php/php-src/blob/php-7.0.8/ext/standard/string.c#L2793> ------------------------------------------------------------------------ [2012-11-14 15:36:32] idokan at gmail dot com Huh ?! ASCII is 0..127 chars, if they are out of range and also from extended ASCII (128..255), then you must report an error like with normal implementation such as Ruby, Python, Pascal, Perl (with strict bytes) etc... Not to $value & 255 it. ------------------------------------------------------------------------ [2012-11-14 15:28:28] laruence@php.net I think this check could be done in user script self. the document said: chr convert *ascii* code .. so... ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=63510 -- Edit this bug report at https://bugs.php.net/bug.php?id=63510&edit=1

« previous php.bugs (#203637) next »