Re: Sec Bug #81702 [Opn->Fbk]: JIT unit tests no longer show "Uncaught ArithmeticError: Bit shift by negative"
| From: | Rainer Jung | Date: | Sun, 19 Dec 2021 21:50:49 +0000 |
| Subject: | Re: Sec Bug #81702 [Opn->Fbk]: JIT unit tests no longer show "Uncaught ArithmeticError: Bit shift by negative" | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-238496@lists.php.net to get a copy of this message | ||
It seems the test execution now triggers a segmentation fault, which is converted by run-tests.php to a test FAIL without indicating the segmentation fault. The segmentation fault in ext/opcache/tests/jit/bool_not_002.phpt and ext/opcache/tests/jit/shift_right_004.phpt happen in the loop when j==5, so exactly when the shift count becomes negative.
So in effect instead of "Uncaught ArithmeticError: Bit shift by negative" we now get a segmentation fault, but only on RHEL 6 (maybe due to an old gcc compiler version 4.4.5?).
I checked the settings which are used by run-tests.php and the segfault is tiggered by the combination:
-d opcache.jit_hot_loop=1
-d opcache.jit_hot_return=1
-d opcache.jit_hot_func=1
-d opcache.jit_hot_side_exit=1
The first three alone are OK, but when using "opcache.jit_hot_side_exit=1" I get a crash in combination with each of "opcache.jit_hot_loop=1" and "opcache.jit_hot_func=1". Since run-tests.php has not changes at least between 8.0.13 and 8.0.14 resp. 8.0.0 and 8.0.1, it seems the implications of these switches have changed.
If I try to break the arithmentic expressions, that contains the negative right shift into parts, the segfault disappears and the ArithmeticException gets thrown.
Best regards,
Rainer