Bug #71201 [Com]: round() segfault on 64-bit builds

From: Date: Sat, 01 Oct 2016 16:33:52 +0000
Subject: Bug #71201 [Com]: round() segfault on 64-bit builds
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-204390@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=71201&edit=1 ID: 71201 Comment by: spam2 at rhsoft dot net Reported by: andrew at jmpesp dot org Summary: round() segfault on 64-bit builds Status: Closed Type: Bug Package: Scripting Engine problem Operating System: Linux PHP Version: Irrelevant Assigned To: ab Block user comment: N Private report: N New Comment: when building with -O3 and Profile-Guided Optimization (make prof-gen; <run-php-code>; make prof-clean; make prof-use" this crash comes back add -fwrapv to CCFLAGS and nothing else changed and it's fixed https://gcc.gnu.org/bugzilla/show_bug.cgi?id=63358#c1 _______________________________ in fact it happens only with profile-guided-optimization, otherwise the flags below without -fwrapv don't have this crash - final php7 compiler-flags for documentation purpose - '-m64 -O3 -g0 -fopenmp -mfpmath=sse -pipe -fomit-frame-pointer -finline-functions -fexceptions -fstack-protector-strong --param=ssp-buffer-size=8 -D_FORTIFY_SOURCE=2 -Wstack-protector -Wformat -Werror=format-security -fira-loop-pressure -fivopts -fmerge-all-constants -fstrict-aliasing -ftree-loop-distribution -ftree-loop-if-convert -ftree-loop-ivcanon -ftree-slp-vectorize -ftree-vectorize -funroll-loops -fwrapv -minline-all-stringops -fno-align-labels -fno-gcse -fno-math-errno -Wno-pointer-sign -Wno-stack-protector' Previous Comments: ------------------------------------------------------------------------ [2016-02-11 16:54:08] hui at pizda dot eba php хуйня ебаная ------------------------------------------------------------------------ [2015-12-23 17:35:59] ab@php.net Fixed in 0d822f6df946764f3f0348b82efae2e1eaa83aa0. Ttahnks. ------------------------------------------------------------------------ [2015-12-23 16:50:46] ab@php.net Ups, i meant abs(), not pow() is the issue. Thanks. ------------------------------------------------------------------------ [2015-12-23 16:49:33] jpauli@php.net Opening to public, this is not security related ------------------------------------------------------------------------ [2015-12-23 16:44:11] ab@php.net The Linux pow() function seems to be sensitive to the overflowed values. Please check the patch below (against 7.0) diff --git a/ext/standard/math.c b/ext/standard/math.c index 6059f3d..e79817e 100644 --- a/ext/standard/math.c +++ b/ext/standard/math.c @@ -390,7 +390,11 @@ PHP_FUNCTION(round) } if (ZEND_NUM_ARGS() >= 2) { - places = (int) precision; + if (precision >= 0) { + places = precision > INT_MAX ? INT_MAX : (int)precision; + } else { + places = precision <= INT_MIN ? INT_MIN+1 : (int)precision; + } } convert_scalar_to_number_ex(value); Thanks ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=71201 -- Edit this bug report at https://bugs.php.net/bug.php?id=71201&edit=1

« previous php.bugs (#204390) next »