From e704e1e8c25ff726e7c890cce20fb932210737b7 Mon Sep 17 00:00:00 2001 From: Remi Collet Date: Mon, 13 Nov 2017 09:55:10 +0100 Subject: [PATCH 1/2] Fixed bug #75514 mt_rand returns value outside [$min,$max]+ on 32-bit --- ext/standard/mt_rand.c | 4 ++-- ext/standard/tests/math/bug75514.phpt | 12 ++++++++++++ 2 files changed, 14 insertions(+), 2 deletions(-) create mode 100644 ext/standard/tests/math/bug75514.phpt diff --git a/ext/standard/mt_rand.c b/ext/standard/mt_rand.c index 0e2fe5143a2..0a76ab82828 100644 --- a/ext/standard/mt_rand.c +++ b/ext/standard/mt_rand.c @@ -260,7 +260,7 @@ PHPAPI zend_long php_mt_rand_range(zend_long min, zend_long max) * rand() allows min > max, mt_rand does not */ PHPAPI zend_long php_mt_rand_common(zend_long min, zend_long max) { - zend_long n; + uint32_t n; if (BG(mt_rand_mode) == MT_RAND_MT19937) { return php_mt_rand_range(min, max); @@ -268,7 +268,7 @@ PHPAPI zend_long php_mt_rand_common(zend_long min, zend_long max) /* Legacy mode deliberately not inside php_mt_rand_range() * to prevent other functions being affected */ - n = (zend_long)php_mt_rand() >> 1; + n = php_mt_rand() >> 1; RAND_RANGE_BADSCALING(n, min, max, PHP_MT_RAND_MAX); return n; diff --git a/ext/standard/tests/math/bug75514.phpt b/ext/standard/tests/math/bug75514.phpt new file mode 100644 index 00000000000..af97b6d0e17 --- /dev/null +++ b/ext/standard/tests/math/bug75514.phpt @@ -0,0 +1,12 @@ +--TEST-- +Bug #75514 mt_rand returns value outside [$min,$max] +--FILE-- + +===Done=== +--EXPECT-- +int(448865905) +int(592) +===Done=== From 3dbe8dd16fb018dccf1ae7fc8c34cd73354698d9 Mon Sep 17 00:00:00 2001 From: Remi Collet Date: Mon, 13 Nov 2017 10:22:32 +0100 Subject: [PATCH 2/2] NEWS --- NEWS | 2 ++ 1 file changed, 2 insertions(+) diff --git a/NEWS b/NEWS index 8b592a410e9..bb811386356 100644 --- a/NEWS +++ b/NEWS @@ -8,6 +8,8 @@ PHP NEWS - Standard: . Fixed bug #75511 (fread not free unused buffer). (Laruence) + . Fixed bug #75514 (mt_rand returns value outside [$min,$max]+ on 32-bit) + (Remi) 23 Nov 2017, PHP 7.1.12