| 
 | 1 | +--TEST--  | 
 | 2 | +GH-16262 Stack buffer overflow in ext/bcmath/libbcmath/src/div.c:459  | 
 | 3 | +--EXTENSIONS--  | 
 | 4 | +bcmath  | 
 | 5 | +--INI--  | 
 | 6 | +bcmath.scale=0  | 
 | 7 | +--FILE--  | 
 | 8 | +<?php  | 
 | 9 | +$scales = [  | 
 | 10 | +    null,  | 
 | 11 | +    0,  | 
 | 12 | +    1,  | 
 | 13 | +    2,  | 
 | 14 | +    3,  | 
 | 15 | +    4,  | 
 | 16 | +    5,  | 
 | 17 | +];  | 
 | 18 | +foreach ($scales as $scale) {  | 
 | 19 | +    echo '========== scale: ', $scale ?? 'null', " ==========\n";  | 
 | 20 | +    echo "1 / 1000:\n";  | 
 | 21 | +    var_dump(  | 
 | 22 | +        bcdiv('1', '1000', $scale),  | 
 | 23 | +        (new BcMath\Number('1'))->div('1000', $scale),  | 
 | 24 | +    );  | 
 | 25 | +    echo "1 / 2000:\n";  | 
 | 26 | +    var_dump(  | 
 | 27 | +        bcdiv('1', '2000', $scale),  | 
 | 28 | +        (new BcMath\Number('1'))->div('2000', $scale),  | 
 | 29 | +    );  | 
 | 30 | +    echo "\n";  | 
 | 31 | +}  | 
 | 32 | +?>  | 
 | 33 | +--EXPECT--  | 
 | 34 | +========== scale: null ==========  | 
 | 35 | +1 / 1000:  | 
 | 36 | +string(1) "0"  | 
 | 37 | +object(BcMath\Number)#2 (2) {  | 
 | 38 | +  ["value"]=>  | 
 | 39 | +  string(5) "0.001"  | 
 | 40 | +  ["scale"]=>  | 
 | 41 | +  int(3)  | 
 | 42 | +}  | 
 | 43 | +1 / 2000:  | 
 | 44 | +string(1) "0"  | 
 | 45 | +object(BcMath\Number)#1 (2) {  | 
 | 46 | +  ["value"]=>  | 
 | 47 | +  string(6) "0.0005"  | 
 | 48 | +  ["scale"]=>  | 
 | 49 | +  int(4)  | 
 | 50 | +}  | 
 | 51 | + | 
 | 52 | +========== scale: 0 ==========  | 
 | 53 | +1 / 1000:  | 
 | 54 | +string(1) "0"  | 
 | 55 | +object(BcMath\Number)#2 (2) {  | 
 | 56 | +  ["value"]=>  | 
 | 57 | +  string(1) "0"  | 
 | 58 | +  ["scale"]=>  | 
 | 59 | +  int(0)  | 
 | 60 | +}  | 
 | 61 | +1 / 2000:  | 
 | 62 | +string(1) "0"  | 
 | 63 | +object(BcMath\Number)#1 (2) {  | 
 | 64 | +  ["value"]=>  | 
 | 65 | +  string(1) "0"  | 
 | 66 | +  ["scale"]=>  | 
 | 67 | +  int(0)  | 
 | 68 | +}  | 
 | 69 | + | 
 | 70 | +========== scale: 1 ==========  | 
 | 71 | +1 / 1000:  | 
 | 72 | +string(3) "0.0"  | 
 | 73 | +object(BcMath\Number)#2 (2) {  | 
 | 74 | +  ["value"]=>  | 
 | 75 | +  string(3) "0.0"  | 
 | 76 | +  ["scale"]=>  | 
 | 77 | +  int(1)  | 
 | 78 | +}  | 
 | 79 | +1 / 2000:  | 
 | 80 | +string(3) "0.0"  | 
 | 81 | +object(BcMath\Number)#1 (2) {  | 
 | 82 | +  ["value"]=>  | 
 | 83 | +  string(3) "0.0"  | 
 | 84 | +  ["scale"]=>  | 
 | 85 | +  int(1)  | 
 | 86 | +}  | 
 | 87 | + | 
 | 88 | +========== scale: 2 ==========  | 
 | 89 | +1 / 1000:  | 
 | 90 | +string(4) "0.00"  | 
 | 91 | +object(BcMath\Number)#2 (2) {  | 
 | 92 | +  ["value"]=>  | 
 | 93 | +  string(4) "0.00"  | 
 | 94 | +  ["scale"]=>  | 
 | 95 | +  int(2)  | 
 | 96 | +}  | 
 | 97 | +1 / 2000:  | 
 | 98 | +string(4) "0.00"  | 
 | 99 | +object(BcMath\Number)#1 (2) {  | 
 | 100 | +  ["value"]=>  | 
 | 101 | +  string(4) "0.00"  | 
 | 102 | +  ["scale"]=>  | 
 | 103 | +  int(2)  | 
 | 104 | +}  | 
 | 105 | + | 
 | 106 | +========== scale: 3 ==========  | 
 | 107 | +1 / 1000:  | 
 | 108 | +string(5) "0.001"  | 
 | 109 | +object(BcMath\Number)#2 (2) {  | 
 | 110 | +  ["value"]=>  | 
 | 111 | +  string(5) "0.001"  | 
 | 112 | +  ["scale"]=>  | 
 | 113 | +  int(3)  | 
 | 114 | +}  | 
 | 115 | +1 / 2000:  | 
 | 116 | +string(5) "0.000"  | 
 | 117 | +object(BcMath\Number)#1 (2) {  | 
 | 118 | +  ["value"]=>  | 
 | 119 | +  string(5) "0.000"  | 
 | 120 | +  ["scale"]=>  | 
 | 121 | +  int(3)  | 
 | 122 | +}  | 
 | 123 | + | 
 | 124 | +========== scale: 4 ==========  | 
 | 125 | +1 / 1000:  | 
 | 126 | +string(6) "0.0010"  | 
 | 127 | +object(BcMath\Number)#2 (2) {  | 
 | 128 | +  ["value"]=>  | 
 | 129 | +  string(6) "0.0010"  | 
 | 130 | +  ["scale"]=>  | 
 | 131 | +  int(4)  | 
 | 132 | +}  | 
 | 133 | +1 / 2000:  | 
 | 134 | +string(6) "0.0005"  | 
 | 135 | +object(BcMath\Number)#1 (2) {  | 
 | 136 | +  ["value"]=>  | 
 | 137 | +  string(6) "0.0005"  | 
 | 138 | +  ["scale"]=>  | 
 | 139 | +  int(4)  | 
 | 140 | +}  | 
 | 141 | + | 
 | 142 | +========== scale: 5 ==========  | 
 | 143 | +1 / 1000:  | 
 | 144 | +string(7) "0.00100"  | 
 | 145 | +object(BcMath\Number)#2 (2) {  | 
 | 146 | +  ["value"]=>  | 
 | 147 | +  string(7) "0.00100"  | 
 | 148 | +  ["scale"]=>  | 
 | 149 | +  int(5)  | 
 | 150 | +}  | 
 | 151 | +1 / 2000:  | 
 | 152 | +string(7) "0.00050"  | 
 | 153 | +object(BcMath\Number)#1 (2) {  | 
 | 154 | +  ["value"]=>  | 
 | 155 | +  string(7) "0.00050"  | 
 | 156 | +  ["scale"]=>  | 
 | 157 | +  int(5)  | 
 | 158 | +}  | 
0 commit comments