Bug #81226 [Asn->Csd]: Integer overflow behavior is different with JIT enabled

From: Date: Wed, 21 Jul 2021 16:29:40 +0000
Subject: Bug #81226 [Asn->Csd]: Integer overflow behavior is different with JIT enabled
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-235248@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=81226&edit=1 ID: 81226 Updated by: git@php.net Reported by: smokey101stair at gmail dot com Summary: Integer overflow behavior is different with JIT enabled -Status: Assigned +Status: Closed Type: Bug Package: JIT Operating System: Ubuntu 20.04 PHP Version: 8.0.8 Assigned To: dmitry Block user comment: N Private report: N New Comment: Automatic comment on behalf of dstogov Revision: https://github.com/php/php-src/commit/053c56f52e094bcf57958e0d4e71c0c4e3f9a2b2 Log: Fixed bug #81226 (Integer overflow behavior is different with JIT enabled) Previous Comments: ------------------------------------------------------------------------ [2021-07-20 19:02:57] smokey101stair at gmail dot com Is there anything blocking the back-porting of these 2 commits? ------------------------------------------------------------------------ [2021-07-12 13:15:52] hao dot sun at arm dot com I can reproduce this bug in my local environment even with functional JIT. I noticed that this bug doesn't occur in JIT/x86 on master branch. After bisect, I guess the root cause is that the following patches in master branch are not merged to PHP-8.0.*. https://github.com/php/php-src/commit/5e05c70ee727815805697a90b39f4d82cd4b4d3d#diff-c0fa9f6cbf84b02388699bafb28a11d7f69780bbf2b0e1bceea4cb99763c1328 https://github.com/php/php-src/commit/186a5277aa237b1f98cd0a74f43c535b8958f85b# ------------------------------------------------------------------------ [2021-07-07 00:02:12] smokey101stair at gmail dot com Perhaps you will have better luck reproducing when it is extracted into a function, which also reproduces the issue for me <?php // 65-bit hexadecimal number $hex = '10000000000000041'; function getNumericReference(string $hex) { $characterReferenceCode = 0; for ($j = 0, $len = strlen($hex); $j < $len; ++$j) { $characterReferenceCode *= 16; $characterReferenceCode += ord($hex[$j]) - 0x0030; } return $characterReferenceCode; } for ($i = 0; $i < 20000; ++$i) { assert(getNumericReference($hex) > 0x10FFFF); } ------------------------------------------------------------------------ [2021-07-06 13:54:06] smokey101stair at gmail dot com Are you able to reproduce if you increase the iterations from 200 to 20000? If not, I'll have to recheck it when I get home. Is there any other info I can provide to help debug this? ------------------------------------------------------------------------ [2021-07-06 12:59:39] nikic@php.net This one doesn't reproduce for me. ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=81226 -- Edit this bug report at https://bugs.php.net/bug.php?id=81226&edit=1

« previous php.bugs (#235248) next »