php.net |  support |  documentation |  report a bug |  advanced search |  search howto |  statistics |  random bug |  login
Bug #6340 ord() function causes php to crash
Submitted: 2000-08-24 18:40 UTC Modified: 2000-08-24 19:46 UTC
From: aaron at meta dot lo-res dot org Assigned:
Status: Closed Package: Reproducible Crash
PHP Version: 4.0.1pl2 OS: FreeBSD 3.3 - stable
Private report: No CVE-ID: None
 [2000-08-24 18:40 UTC] aaron at meta dot lo-res dot org
type in :

<? 
  $str = "foobar";
  $val = ord($str[0]);
  echo "val = $val  <hr>";

?>

-> the apache process serving the page crashes

Patches

Pull Requests

History

AllCommentsChangesGit/SVN commitsRelated reports
 [2000-08-24 19:04 UTC] aaron at meta dot lo-res dot org
correction: 

the following code caused PHP to crash (for obvious reasons):

<?
$str = "foobar";
$hash = ord($str[0]);

/* .. rest of has value computation code ... */
?>


Well, I guess PHP could say something like: "dont use the variable name "hash" please... use your imagination to find another one :) "



 [2000-08-24 19:36 UTC] aaron at meta dot lo-res dot org
Sorry, again a correction:

the problem was NOT the ord() function, but rather that PHP will not cope with large integers (even below 2^31).
Maybe the problem was the modulo operator and large numbers.
I will reprint my original source here:


function hash($str) {
// $p = 4294967291;        /* largest prime <= 2^32 */
// $p = 2147483647;        /* largest prime <= 2^31 */
// $p = 1073741789;        /* largest prime <= 2^30 */
// $p = 268435399;        /* largest prime <= 2^28 */
   $p = 33554393 ;        /* largest prime <= 2^25 */
// $p = 65521;            /* largest prime <= sqrt(2^32) */
  $BASE = 256;            /* largest char */

  if ($str == -1) {
    return -1;
  }

  $len = strlen($str);
  $hash = ord($str[0]);

  for ($i = 1; $i < $len; $i++) {
    debug("i = $i");
    $hash = (($hash * 32) + ord($str[$i])) % $p;
    debug("hash = $hash");
  }
  return $hash;
}

----
you can see from the values for $p some kind of boundary where the arithmetic ops wont work anymore. 
The debug() function basically echos the given string parameter. so nothing special about that.

Unfortunately I cannot change the name of the PR anymore but still please keep me informed what I can do to work with large numbers.

thanks,
aaron.




 [2000-08-24 19:46 UTC] aaron at meta dot lo-res dot org
my mistake ... arghhh
sorry
(25 bits + 8 bit > 32 bit boundary)
Still, would be nice to have a "error: overflow message" :)

 
PHP Copyright © 2001-2026 The PHP Group
All rights reserved.
Last updated: Sun Oct 11 08:00:01 2026 UTC