Bug #80861 [Com]: erronous array key overflow in 2D array (only with JIT)
| From: | danack@php.net | Date: | Sun, 14 Mar 2021 13:18:00 +0000 |
| Subject: | Bug #80861 [Com]: erronous array key overflow in 2D array (only with JIT) | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-232704@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=80861&edit=1
ID: 80861
Comment by: danack@php.net
Reported by: tbali0524 at gmail dot com
Summary: erronous array key overflow in 2D array (only with
JIT)
Status: Open
Type: Bug
Package: JIT
Operating System: Windows 10 (x86_64)
PHP Version: 8.0.3
Block user comment: N
Private report: N
New Comment:
Someone should change this site to say that although short repro cases are better, longer ones are
fine also...
<?php
/*
Below code is excerpt from my implementation of D. Knuth's DLX algorithm for exact cover
solver, run from CLI
- without JIT, the code runs fine (with the code excerpt in this bug report, the output is nothing.)
- with JIT, it fails with tons of warnings like
PHP Warning: Undefined array key 1235698926592 in C:\Coding\v\jit_bug.php on line 95
- but array keys are confirmed to be within bounds, possible overflow in JIT?
- error is not present if the 2D array is much smaller
- PHP versions tested: v8.0.3, v8.0.2 (installed via XAMPP)
- OS: Windows 10 (x86_64)
- Invoke: php jit_bug.php > out.txt 2>&1
- PHP.ini settings:
opcache.enable=1
opcache.enable_cli=1
opcache.jit_buffer_size=128M
opcache.jit=tracing
*/
// note: when this is commented out, the code runs fine!
declare(strict_types=1);
// --------------------------------------------------------------------
class Node
{
public $column = null;
public $left = null;
public $right = null;
public $up = null;
public $down = null;
public static function joinLR(Node $a, Node $b): void
{
$a->right = $b;
$b->left = $a;
}
public static function joinDU(Node $a, Node $b): void
{
$a->up = $b;
$b->down = $a;
}
}
// --------------------------------------------------------------------
class Column extends Node
{
public function __construct()
{
$this->column = $this;
$this->up = $this;
$this->down = $this;
}
}
// --------------------------------------------------------------------
class Matrix
{
public $head = null;
public function __construct()
{
$this->head = new Node();
Node::joinLR($this->head, $this->head);
}
// $from is array[][] of bool
public static function fromArray(array $from): Matrix
{
$m = new Matrix();
$rowCount = count($from);
if ($rowCount == 0) {
return $m;
}
$columnCount = count($from[0]);
if ($columnCount == 0) {
return $m;
}
// we generate 2D double linked circular list of nodes from the input 2D bool array
// might be not relevant for the bug
$c = new Column();
Node::joinLR($m->head, $c);
for ($j = 1; $j < $columnCount; $j++) {
$nextCol = new Column();
Node::joinLR($c, $nextCol);
$c = $c->right;
}
Node::joinLR($c, $m->head);
$c = $m->head->right;
error_log("These are the array bounds: $rowCount * $columnCount");
for ($j = 0; $j < $columnCount; $j++) {
$prev = $c;
for ($i = 0; $i < $rowCount; $i++) {
// next line generates the warnings despite $i and $j is within bounds
if ($from[$i][$j]) {
$node = new Node();
$node->column = $c;
Node::joinDU($node, $prev);
Node::joinLR($node, $node);
$prev = $node;
// ... code to generate $m excluded
}
}
Node::joinDU($c, $prev);
$c = $c->right;
}
return $m;
}
}
// --------------------------------------------------------------------
// simple driver code - fills up a 2D bool matrix and calls the static matrix constructing function
above
for ($y = 0; $y < 100; $y++) {
for ($x = 0; $x < 177; $x++) {
$a[$y][$x] = true;
}
}
$m = Matrix::fromArray($a);
Previous Comments:
------------------------------------------------------------------------
[2021-03-14 08:47:57] tbali0524 at gmail dot com
Description:
------------
Below code is excerpt from my implementation of D. Knuth's DLX algorithm for exact cover
solver, run from CLI
- without JIT, the code runs fine (with the code excerpt in this bug report, the output is nothing.)
- with JIT, it fails with tons of warnings like
PHP Warning: Undefined array key 1235698926592 in C:\Coding\v\jit_bug.php on line 95
- but array keys are confirmed to be within bounds, possible overflow in JIT?
- error is not present if the 2D array is much smaller
- PHP versions tested: v8.0.3, v8.0.2 (installed via XAMPP)
- OS: Windows 10 (x86_64)
- Invoke: php jit_bug.php > out.txt 2>&1
- PHP.ini settings:
opcache.enable=1
opcache.enable_cli=1
opcache.jit_buffer_size=128M
opcache.jit=tracing
Test script:
---------------
link to test script (to be tun CLI only, so rename after download)
https://www.aviationfanatic.com/tmp/jit_bug.php.txt
Expected result:
----------------
with the code excerpt in this bug report, the output is nothing.
Actual result:
--------------
with JIT, it fails with tons of warnings like
PHP Warning: Undefined array key 1235698926592 in C:\Coding\v\jit_bug.php on line 92
- but array keys are confirmed to be within bounds
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=80861&edit=1