Re: Bug #1910: eval causes core dump with math functions that retun NaN
| From: | Chad Cunningham | Date: | Wed, 28 Jul 1999 21:35:07 +0000 |
| Subject: | Re: Bug #1910: eval causes core dump with math functions that retun NaN | ||
| References: | 1 2 | Groups: | php.dev |
| Request: | Send a blank email to php-dev+get-9292@lists.php.net to get a copy of this message | ||
Well, I had initially made too many assumptions about what the problem was, but
I've ended up finding two seperate things causing the core dumps. The first
problem was that in my simple test script I made to isolate the problem, I
forgot the closing ; at the end of the eval string. This causes a core dump on
Solaris, although on Linux is gives the proper parse error. Second, calling
numberformat on a string that was evaluated to be NaN causes a core dump.
Granted, this is a strange thing to do, but it seems as if it should return an
error rather than dump core. And on Linux, it does just return an error. Here
are example scripts of each problem and debugging data:
<?
eval("\$one = sin(-1)");
echo $one;
?>
Error Log:
[Wed Jul 28 17:20:35 1999] [notice] child pid 13254 exit signal Segmentation
Fault (11)
dbx:
In add vars
signal SEGV (no mapping at the fault address) in strlen at 0xef5a4614
0xef5a4614: strlen+0x0080: ld [%o1], %o2
-----------
<?
$one = sqrt(-50); // or $one = "NaN";
$out = number_format($one,12);
echo $out;
?>
Error Log:
Script: '/opt/web/htdocs/test.php'
---------------------------------------
math.c(641) : Block 0x00120270 status:
Beginning: Overrun (magic=0x0000119D, expected=0x7312F8DC)
End: Unknown
---------------------------------------
Script: '/opt/web/htdocs/test.php'
---------------------------------------
zend_hash.c(746) : Block 0x00120038 status:
Beginning: Overrun (magic=0x732E7068, expected=0x7312F8DC)
End: Unknown
---------------------------------------
[Wed Jul 28 17:24:54 1999] [notice] child pid 13289 exit signal Segmentation
Fault (11)
dbx:
In add vars
signal BUS (invalid address alignment) in _get_zval_ptr_ptr at 0xef3042c0
0xef3042c0: _get_zval_ptr_ptr+0x003c: ld [%o1 + 0xc], %o0
Andrey Zmievski wrote:
> ccunning@math.ohio-state.edu wrote:
> > From: ccunning@math.ohio-state.edu
> > Operating system: Solaris 2.6
> > PHP version: 4.0b1
> > PHP Bug Type: Reproduceable crash
> > Bug description: eval causes core dump with math functions that retun NaN
> >
> > Doing something like eval("\$one = log(-1)"); on Solaris causes a core
> dump. Doing the log(-1) outside of eval returns NaN. Any function that can
> return NaN or Infinity with the right argument seems to do this when executed
> inside an eval. Doing the eval on RedHat 6 with php4 works fine, and PHP3 on
> Solaris handles it fine. Here is the dbx output as well as some stuff that
> showed up in the error log.
>
> I believe this should be fixed in the latest CVS. Zeev?
>
> -Andrey
> * If it ain't broken, it doesn't have enough features yet. *
>
> --
> PHP Development Mailing List <http://www.php.net/>
> To unsubscribe, e-mail: php-dev-unsubscribe@lists.php.net
> For additional commands, e-mail: php-dev-help@lists.php.net
> To contact the list administrators, e-mail: php-list-admin@lists.php.net