Bug #69149 [Opn]: The PCRE extension crashes seeminglessly due to memory leaks or double free

From: Date: Sat, 28 Feb 2015 23:49:37 +0000
Subject: Bug #69149 [Opn]: The PCRE extension crashes seeminglessly due to memory leaks or double free
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-191012@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=69149&edit=1

 ID:                 69149
 User updated by:    gregory at luni dot fr
 Reported by:        gregory at luni dot fr
 Summary:            The PCRE extension crashes seeminglessly due to
                     memory leaks or double free
 Status:             Open
 Type:               Bug
 Package:            *Regular Expressions
 Operating System:   OSX, Linux
 PHP Version:        master-Git-2015-02-28 (Git)
 Block user comment: N
 Private report:     N

 New Comment:

Added backtrace :

(gdb) backtrace
#0  0x00007fff9b897286 in __pthread_kill () from /usr/lib/system/libsystem_kernel.dylib
#1  0x00007fff9631942f in pthread_kill () from /usr/lib/system/libsystem_pthread.dylib
#2  0x00007fff8d8d3b53 in abort () from /usr/lib/system/libsystem_c.dylib
#3  0x00007fff8d89bc39 in __assert_rtn () from /usr/lib/system/libsystem_c.dylib
#4  0x000000010071c97c in zend_function_dtor (zv=0x7fff5fbfe058) at Zend/zend_opcode.c:122
#5  0x000000010074b680 in _zend_hash_del_el_ex (ht=0x101413a70, idx=1462, p=0x101854ac0, prev=0x0)
at Zend/zend_hash.c:845
#6  0x000000010074cb69 in _zend_hash_del_el (ht=0x101413a70, idx=1462, p=0x101854ac0) at
Zend/zend_hash.c:869
#7  0x000000010074d33c in zend_hash_reverse_apply (ht=0x101413a70, apply_func=0x1007151a0
<clean_non_persistent_function>) at Zend/zend_hash.c:1384
#8  0x0000000100714e59 in shutdown_executor () at Zend/zend_execute_API.c:345
#9  0x000000010073349e in zend_deactivate () at Zend/zend.c:890
#10 0x00000001006823d2 in php_request_shutdown (dummy=0x0) at main/main.c:1850
#11 0x00000001007fe1be in do_cli (argc=2, argv=0x101413760) at sapi/cli/php_cli.c:1156
#12 0x00000001007fc313 in main (argc=2, argv=0x101413760) at sapi/cli/php_cli.c:1355


Previous Comments:
------------------------------------------------------------------------
[2015-02-28 23:19:40] gregory at luni dot fr

Changed title

------------------------------------------------------------------------
[2015-02-28 23:18:01] gregory at luni dot fr

Description:
------------
There is an error on the PCRE extension and memory management, I can't determine exactly
what's happening, I have These 2 types of messages :

php7(42118,0x7fff7e1dd300) malloc: *** error for object 0x7f8022f02b28: incorrect checksum for freed
object - object was probably modified after being freed.
*** set a breakpoint in malloc_error_break to debug
Abort trap: 6

Assertion failed: (function->type == 1), function zend_function_dtor, file
/Users/gplanchat/CLionProjects/php-src/Zend/zend_opcode.c, line 122.
Abort trap: 6

This is the configure command I used on my mac :

./configure --prefix=$HOME/tmp/usr --with-config-file-path=$HOME/tmp/usr/etc --enable-mbstring
--enable-zip --enable-bcmath --enable-pcntl --enable-ftp --enable-exif --enable-calendar
--enable-sysvmsg --enable-sysvsem --enable-sysvshm --enable-wddx --with-curl --with-mcrypt
--with-iconv --with-gmp --with-gd --with-jpeg-dir=/usr/local/opt/jpeg/include/
--with-png-dir=/usr/local/opt/libpng/include/ --with-zlib-dir=/usr --with-freetype-dir=/usr
--with-t1lib=/usr --enable-gd-native-ttf --enable-gd-jis-conv --with-openssl
--with-pdo-mysql=mysqlnd --with-gettext=/usr/local/opt/gettext/ --with-zlib=/usr --with-bz2=/usr
--with-recode=/usr --with-mysqli=mysqlnd --enable-debug --enable-maintainer-mode

I'm using OSX 10.10 Yosemite, with the latest master
(34ff6bbb0df152694e648161b149d41270fccdcb).

Test script:
---------------
<?php

$buffer = 'public function test(){return true;}';

preg_match('/(?:public|protected|private|final|abstract|static)*?'
    . '\s+function\s+test\([^\)]*\)\s*(?:\{(?:[^{}]*|(?R))*\})/sm',
        $buffer, $matches);

var_dump($matches[0]);

Expected result:
----------------
string(36) "public function test(){return true;}"


Actual result:
--------------
Either :

php7(42118,0x7fff7e1dd300) malloc: *** error for object 0x7f8022f02b28: incorrect checksum for freed
object - object was probably modified after being freed.
*** set a breakpoint in malloc_error_break to debug
Abort trap: 6

Or either :

Assertion failed: (function->type == 1), function zend_function_dtor, file
/Users/gplanchat/CLionProjects/php-src/Zend/zend_opcode.c, line 122.
Abort trap: 6


------------------------------------------------------------------------



--
Edit this bug report at https://bugs.php.net/bug.php?id=69149&edit=1


Thread (10 messages)

« previous php.bugs (#191012) next »