Bug #63174 [Asn->Opn]: Magic negative number generated by rand

From: Date: Tue, 24 Oct 2017 06:03:56 +0000
Subject: Bug #63174 [Asn->Opn]: Magic negative number generated by rand
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-211970@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=63174&edit=1

 ID:                 63174
 Updated by:         kalle@php.net
 Reported by:        ub dot x7b8 at gmail dot com
 Summary:            Magic negative number generated by rand
-Status:             Assigned
+Status:             Open
 Type:               Bug
 Package:            *Math Functions
 Operating System:   32bit
 PHP Version:        Irrelevant
-Assigned To:        bishop
+Assigned To:        
 Block user comment: N
 Private report:     N



Previous Comments:
------------------------------------------------------------------------
[2015-08-15 10:23:49] cmb@php.net

Related To: Bug #60543

------------------------------------------------------------------------
[2015-07-15 22:49:49] cmb@php.net

> This problem only manifests when there's overflow on 32-bit
> platforms.

ACK. However, on 64bit platforms there's a closely related problem
if $max-$min > PHP_INT_MAX, in which case rand() unevenly
distributes, e.g. running

    <?php
    for ($i = 0; $i < 1000000; $i++) {
            if (rand(PHP_INT_MIN, PHP_INT_MAX) > 0) {
                    echo "Never\n";
                    break;
            }
    }
    ?>
    
never prints "Never". The problem is in RAND_RANGE() where only
the offset is calculated as double, instead of the whole
expression (see the attached patch "rand-range-double"). This
change would also fix the behavior on 32bit architectures.

However, changing the results of (mt_)rand() for $max-$min >
PHP_INT_MAX and with regard to inexact double to integer
conversion on 64bit architectures would be a BC break, so I'm not
sure whether we should apply that for PHP 5. IMHO, changing PHP 7
in this regard would be acceptable even though it's in feature
freeze.

Anyway, I would suggest to better document the behavior for non
default ranges.

------------------------------------------------------------------------
[2015-07-15 22:32:49] cmb@php.net

The following patch has been added/updated:

Patch Name: rand-range-double
Revision:   1436999569
URL:        https://bugs.php.net/patch-display.php?bug=63174&patch=rand-range-double&revision=1436999569

------------------------------------------------------------------------
[2015-07-13 20:06:48] bishop@php.net

https://github.com/php/php-src/pull/1416

------------------------------------------------------------------------
[2015-07-09 16:12:04] bishop@php.net

Duplicated by #70003.

------------------------------------------------------------------------


The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at

    https://bugs.php.net/bug.php?id=63174


--
Edit this bug report at https://bugs.php.net/bug.php?id=63174&edit=1


Thread (11 messages)

« previous php.bugs (#211970) next »