Bug #79358 [Opn]: JIT miscompile in composer
| From: | nikic@php.net | Date: | Mon, 09 Mar 2020 11:39:16 +0000 |
| Subject: | Bug #79358 [Opn]: JIT miscompile in composer | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-225974@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=79358&edit=1
ID: 79358
Updated by: nikic@php.net
Reported by: nikic@php.net
Summary: JIT miscompile in composer
Status: Open
Type: Bug
Package: opcache
PHP Version: master-Git-2020-03-09 (Git)
Block user comment: N
Private report: N
New Comment:
Slightly better reduction:
<?php
function test(int $x)
{
return ($x > 0xdead && unimportant()) ||
($x < 0xbeef && unimportant());
}
var_dump(test(0xcccc));
We see
#7.T2 [bool] RANGE[0..1] = IS_SMALLER #6.CV0($x) [long]
RANGE[-9223372036854775808..9223372036854775807] int(48879)
#8.T1 [bool] RANGE[0..1] = JMPZ_EX #7.T2 [bool] RANGE[0..1] BB7
BB5: follow lines=[8-9]
and
.L17:
mov 0x50(%r14), %rax
cmp $0xbeef, %rax
setl %al
movzx %al, %eax
lea 0x2(%rax), %eax
mov %eax, 0x78(%r14)
jge .L31
where 0x78 is T2. We should be either writing directly to T1 at 0x68, or copying from T2 to T1.
Previous Comments:
------------------------------------------------------------------------
[2020-03-09 10:52:22] nikic@php.net
Description:
------------
The attached reduction is miscompiled, resulting in incorrect dependency resolution in composer.
Test script:
---------------
<?php
function test($x, $y)
{
return ($x && $y && unimportant()) ||
($x < 0 && unimportant());
}
var_dump(test(1, []));
Expected result:
----------------
bool(false)
Actual result:
--------------
UNKNOWN:0
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=79358&edit=1