Bug #45735 [Com]: preg_match fails with Segmentation Fault on capturing subpattern

From: Date: Thu, 06 Mar 2014 15:55:22 +0000
Subject: Bug #45735 [Com]: preg_match fails with Segmentation Fault on capturing subpattern
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-184584@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=45735&edit=1

 ID:                 45735
 Comment by:         php at mandark dot fr
 Reported by:        johnston dot joshua at gmail dot com
 Summary:            preg_match fails with Segmentation Fault on
                     capturing subpattern
 Status:             Not a bug
 Type:               Bug
 Package:            PCRE related
 Operating System:   *
 PHP Version:        5.2CVS, 5.3CVS, 6CVS (2008-08-06)
 Block user comment: N
 Private report:     N

 New Comment:

If it makes sense, you may use ungreedy quantifiers, they will inverse the order of backtracking,
fixing your problem in the only case a short match is found (else, it will backtrack to the whole
document, hitting your stack space another time).

You may also take a look at possessive quantifiers and atomic grouping, they are ways to prevent
backtracking, make sure to understand them before using them, but they are safer that just using
ungreedy quantifiers to reduce backtracking volume.


Previous Comments:
------------------------------------------------------------------------
[2013-04-13 00:23:49] rasmus@php.net

The problem here is that there is no way to detect run-away regular expressions 
here without huge performance and memory penalties. Yes, we could build PCRE in a 
way that it wouldn't segfault and we could crank up the default backtrack limit 
to something huge, but it would slow every regex call down by a lot. If PCRE 
provided a way to handle this in a more graceful manner without the performance 
hit we would of course use it.

------------------------------------------------------------------------
[2013-04-12 18:51:07] johnston dot joshua at gmail dot com

I agree that something needs to be done about this bug on the php side that 
doesn't involve custom compiling pcre.

In my case way back in '08, I found that the solution was misuse of capturing 
subpatterns. I was using () for grouping even though I did not need to match 
subpatterns. In reality I should have been using (:?) which solved my issue.

------------------------------------------------------------------------
[2013-04-12 18:40:49] josh dot adell at gmail dot com

Just hit this bug today as well. It would be nice if PHP handled this more 
gracefully by triggering an error or warning instead of segfaulting.

------------------------------------------------------------------------
[2013-04-11 16:35:34] michael at writhem dot com

why is this status not a bug?

------------------------------------------------------------------------
[2011-12-23 13:09:46] vojtech dot kurka at gmail dot com

We have hit this bug today on 5.3.8, just sending 70KB variable as an input to preg_match_all().

Please fix this, it took us quite a lot of time to find the root cause. This should never cause a
segfault. If the preg_match_all() function would throw a standard PHP error/warning, we would find
the problem immeadiately. Debugging such problems is just a waste of time, this bugreport is more
than 3 years old.

------------------------------------------------------------------------


The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at

    https://bugs.php.net/bug.php?id=45735


-- 
Edit this bug report at https://bugs.php.net/bug.php?id=45735&edit=1


Thread (18 messages)

« previous php.bugs (#184584) next »