Bug #81070 [Opn->Csd]: Integer underflow in memory limit comparison

From: Date: Mon, 31 May 2021 13:25:20 +0000
Subject: Bug #81070 [Opn->Csd]: Integer underflow in memory limit comparison
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-234112@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=81070&edit=1

 ID:                 81070
 Updated by:         git@php.net
 Reported by:        pvandommelen at gmail dot com
 Summary:            Integer underflow in memory limit comparison
-Status:             Open
+Status:             Closed
 Type:               Bug
 Package:            Scripting Engine problem
 PHP Version:        7.3.28
 Block user comment: N
 Private report:     N

 New Comment:

Automatic comment on behalf of pvandommelen (author) and nikic (committer)
Revision: https://github.com/php/php-src/commit/1b3b5c94e52d10eb7a3f69b486a51b3f4d214d4f
Log: Fixed bug #81070


Previous Comments:
------------------------------------------------------------------------
[2021-05-24 09:40:27] pvandommelen at gmail dot com

The following pull request has been associated:

Patch Name: Fix #81070: Integer underflow when memory limit is exceeded
On GitHub:  https://github.com/php/php-src/pull/7040
Patch:      https://github.com/php/php-src/pull/7040.patch

------------------------------------------------------------------------
[2021-05-22 10:53:32] pvandommelen at gmail dot com

Browser autofilled the title an old bug report

------------------------------------------------------------------------
[2021-05-22 10:46:04] pvandommelen at gmail dot com

Description:
------------
When more memory is allocated, the currently allocated memory is compared to the limit. There is
currently an integer underflow problem when the limit is lower than the currently allocated memory.
This can occur when the memory limit is changed dynamically through
set_ini("memory_limit", ..).

This was introduced in 7.2.23 and also exists in 7.3.10 and all versions of 7.4 and 8.0.
https://github.com/php/php-src/commit/16d35eb643bf974554e5264021ee10fc969e2053

The code sample illustrates the problem. Allocation after the memory limit is reduced should throw
an error. 

The old behaviour can probably be reintroduced by also verifying that the memory limit is higher
than the currently allocated memory.

Test script:
---------------
https://3v4l.org/egq60

```
<?php
echo sprintf("\n%.1fMB", memory_get_usage(true) / 1024 / 1024);

// allocate a large byte string of around 5 MB
$a = str_repeat("0", 5 * 1024 * 1024);
echo sprintf("\n%.1fMB", memory_get_usage(true) / 1024 / 1024);

// setting the memory limit lower than the current is accepted
ini_set("memory_limit", "3M");
echo sprintf("\n%.1fMB", memory_get_usage(true) / 1024 / 1024);

// further allocation beyond the limit
$b = str_repeat("0", 5 * 1024 * 1024);
echo sprintf("\n%.1fMB", memory_get_usage(true) / 1024 / 1024);
```



------------------------------------------------------------------------



--
Edit this bug report at https://bugs.php.net/bug.php?id=81070&edit=1


Thread (4 messages)

« previous php.bugs (#234112) next »