Re: Bug #1910: eval causes core dump with math functions that retun NaN

From: Date: Wed, 28 Jul 1999 23:33:04 +0000
Subject: Re: Bug #1910: eval causes core dump with math functions that retun NaN
References: 1 2  Groups: php.dev 
Request: Send a blank email to php-dev+get-9296@lists.php.net to get a copy of this message
Assuming these are open problems, can you please submit bug reports to ensure these don't escape my memory before we release Beta 2? Thanks, Zeev At 23:35 28/07/99 , Chad Cunningham wrote:
Well, I had initially made too many assumptions about what the problem was, but I've ended up finding two seperate things causing the core dumps. The first problem was that in my simple test script I made to isolate the problem, I forgot the closing ; at the end of the eval string. This causes a core dump on Solaris, although on Linux is gives the proper parse error. Second, calling numberformat on a string that was evaluated to be NaN causes a core dump. Granted, this is a strange thing to do, but it seems as if it should return an error rather than dump core. And on Linux, it does just return an error. Here are example scripts of each problem and debugging data: <? eval("\$one = sin(-1)"); echo $one; ?> Error Log: [Wed Jul 28 17:20:35 1999] [notice] child pid 13254 exit signal Segmentation Fault (11) dbx: In add vars signal SEGV (no mapping at the fault address) in strlen at 0xef5a4614
0xef5a4614: strlen+0x0080:      ld      [%o1], %o2
----------- <? $one = sqrt(-50); // or $one = "NaN"; $out = number_format($one,12); echo $out; ?> Error Log: Script: '/opt/web/htdocs/test.php' --------------------------------------- math.c(641) : Block 0x00120270 status:
Beginning:      Overrun (magic=0x0000119D, expected=0x7312F8DC)
      End:      Unknown
--------------------------------------- Script: '/opt/web/htdocs/test.php' --------------------------------------- zend_hash.c(746) : Block 0x00120038 status:
Beginning:      Overrun (magic=0x732E7068, expected=0x7312F8DC)
      End:      Unknown
--------------------------------------- [Wed Jul 28 17:24:54 1999] [notice] child pid 13289 exit signal Segmentation Fault (11) dbx: In add vars signal BUS (invalid address alignment) in _get_zval_ptr_ptr at 0xef3042c0
0xef3042c0: _get_zval_ptr_ptr+0x003c:   ld      [%o1 + 0xc], %o0
Andrey Zmievski wrote: ccunning@math.ohio-state.edu wrote:
From:             ccunning@math.ohio-state.edu
Operating system: Solaris 2.6
PHP version:      4.0b1
PHP Bug Type:     Reproduceable crash
Bug description:  eval causes core dump with math functions that 
retun NaN
Doing something like eval("\$one = log(-1)"); on Solaris causes a core
dump. Doing the log(-1) outside of eval returns NaN. Any function that can return NaN or Infinity with the right argument seems to do this when executed inside an eval. Doing the eval on RedHat 6 with php4 works fine, and PHP3 on Solaris handles it fine. Here is the dbx output as well as some stuff that showed up in the error log. I believe this should be fixed in the latest CVS. Zeev? -Andrey * If it ain't broken, it doesn't have enough features yet. * -- PHP Development Mailing List <http://www.php.net/> To unsubscribe, e-mail: php-dev-unsubscribe@lists.php.net For additional commands, e-mail: php-dev-help@lists.php.net To contact the list administrators, e-mail: php-list-admin@lists.php.net -- PHP Development Mailing List <http://www.php.net/> To unsubscribe, e-mail: php-dev-unsubscribe@lists.php.net For additional commands, e-mail: php-dev-help@lists.php.net To contact the list administrators, e-mail: php-list-admin@lists.php.net
-- Zeev Suraski <zeev@zend.com> http://www.zend.com/ For a PGP public key, finger bourbon@netvision.net.il

« previous php.dev (#9296) next »