Edit report at https://bugs.php.net/bug.php?id=71197&edit=1
ID: 71197
Updated by: [email protected]
Reported by: [email protected]
Summary: 2 more segfaults in PHP's range() function
Status: Assigned
Type: Bug
Package: Reproducible crash
Operating System: Mac OS X Yosemite
PHP Version: 7.0.1
Assigned To: tpunt
Block user comment: N
Private report: N
New Comment:
PR: https://github.com/php/php-src/pull/1690
Previous Comments:
------------------------------------------------------------------------
[2015-12-22 15:58:07] [email protected]
Description:
------------
The segfaults are caused by precision loss of large longs being converted to doubles when the `step` parameter is a double. The for loops continue infinitely since the `step` being added/subtracted upon each iteration is too small to be represented accurately as a double.
The attached patch adds another condition to each of the for loops by ensuring that the number of iterations in the loop are less than the size of the range (`__calc_size`). This prevents both loops from continuing until segfaulting, however doesn't give an accurate result (due to `__calc_size` being incorrect because of aforementioned precision loss).
Test script:
---------------
var_dump(count(range(PHP_INT_MIN, PHP_INT_MIN + 513, .01)));
var_dump(count(range(PHP_INT_MIN + 513, PHP_INT_MIN, .01)));
Expected result:
----------------
// A completely correct output would be:
int(51400)
int(51400)
Actual result:
--------------
Segmentation fault: 11
Segmentation fault: 11
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=71197&edit=1
lmpx.com only provides a reader for public news (NNTP) servers. It is not
affiliated with the servers or forums shown here and is not responsible for
the content of articles, which is written by their respective authors.