Bug #79358 [Opn]: JIT miscompile in composer

From: Date: Mon, 09 Mar 2020 11:39:16 +0000
Subject: Bug #79358 [Opn]: JIT miscompile in composer
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-225974@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=79358&edit=1 ID: 79358 Updated by: nikic@php.net Reported by: nikic@php.net Summary: JIT miscompile in composer Status: Open Type: Bug Package: opcache PHP Version: master-Git-2020-03-09 (Git) Block user comment: N Private report: N New Comment: Slightly better reduction: <?php function test(int $x) { return ($x > 0xdead && unimportant()) || ($x < 0xbeef && unimportant()); } var_dump(test(0xcccc)); We see #7.T2 [bool] RANGE[0..1] = IS_SMALLER #6.CV0($x) [long] RANGE[-9223372036854775808..9223372036854775807] int(48879) #8.T1 [bool] RANGE[0..1] = JMPZ_EX #7.T2 [bool] RANGE[0..1] BB7 BB5: follow lines=[8-9] and .L17: mov 0x50(%r14), %rax cmp $0xbeef, %rax setl %al movzx %al, %eax lea 0x2(%rax), %eax mov %eax, 0x78(%r14) jge .L31 where 0x78 is T2. We should be either writing directly to T1 at 0x68, or copying from T2 to T1. Previous Comments: ------------------------------------------------------------------------ [2020-03-09 10:52:22] nikic@php.net Description: ------------ The attached reduction is miscompiled, resulting in incorrect dependency resolution in composer. Test script: --------------- <?php function test($x, $y) { return ($x && $y && unimportant()) || ($x < 0 && unimportant()); } var_dump(test(1, [])); Expected result: ---------------- bool(false) Actual result: -------------- UNKNOWN:0 ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=79358&edit=1

« previous php.bugs (#225974) next »