php.net |  support |  documentation |  report a bug |  advanced search |  search howto |  statistics |  random bug |  login
Bug #3353 mt_getrandmax() and getrandmax() off by one
Submitted: 2000-01-29 20:47 UTC Modified: 2000-05-22 14:39 UTC
From: leon at leonatkinson dot com Assigned:
Status: Closed Package: Misbehaving function
PHP Version: 4.0 Beta 3 OS: Linux and Windows
Private report: No CVE-ID: None
 [2000-01-29 20:47 UTC] leon at leonatkinson dot com
OK, so I'm kind of abusing the random functions, but here's what I found.  I think the problem is with the bit of code that implements the ranges, and since it's the same for both rand and mt_rand  It seems like getrandmax() and mt_getrandmax() are off by one, at least as far as using ranges is concerned.  And the result seems to be that the sign bit gets flipped.  Here's some code that demonstrates:

srand(100000);
print(rand(0, getrandmax()) . "<BR>\n");

That returns -862632574

Likewise..

mt_srand(100000);
print(mt_rand(0, mt_getrandmax()) . "<BR>\n");

returns -863778341

Both mt_getrandmax() and getrandmax() return 2147483647, so I tried this:

mt_srand(100000);
print(mt_rand(0, 2147483646) . "<BR>\n");

and I got 863778340

Hmm...very suspicious.  This is on a Slackware box running on a Pentium, BTW.

The only range-check I see is that the first number is less than the second number.  But I feel certain that it should be checking that the difference isn't bigger than rand max.  It probably also shouldn't accept range values that don't fit into the local machine's integers, which I'm guessing is usually rand max.





Patches

Pull Requests

History

AllCommentsChangesGit/SVN commitsRelated reports
 [2000-05-22 14:39 UTC] hholzgra at cvs dot php dot net
range checking added and integer overflow fixed
in PHP3 code, PHP4 will follow as soon as 4.0.0
release is through
 
PHP Copyright © 2001-2026 The PHP Group
All rights reserved.
Last updated: Sat Oct 10 09:00:01 2026 UTC