Bug #53823 [Ver->Ana]: preg_replace: * qualifier on unicode replace garbles the string

From: Date: Fri, 05 Jun 2015 01:15:11 +0000
Subject: Bug #53823 [Ver->Ana]: preg_replace: * qualifier on unicode replace garbles the string
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-193128@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=53823&edit=1

 ID:                 53823
 Updated by:         cmb@php.net
 Reported by:        keith at chaos-realm dot net
 Summary:            preg_replace: * qualifier on unicode replace garbles
                     the string
-Status:             Verified
+Status:             Analyzed
 Type:               Bug
 Package:            PCRE related
-Operating System:   Linux
+Operating System:   *
-PHP Version:        5.3SVN-2011-01-23 (snap)
+PHP Version:        5.6.9
-Assigned To:        
+Assigned To:        cmb
 Block user comment: N
 Private report:     N

 New Comment:

Confirmed: <http://3v4l.org/ueAJv>.

> The correct behavior is that when u modifier is used, the
> function should always advance by code unit (1 UTF character).

Exactly. Thanks for analyzing the issue. :)


Previous Comments:
------------------------------------------------------------------------
[2014-12-16 11:35:09] nhahtdh at gmail dot com

This should be a duplicate to https://bugs.php.net/bug.php?id=66121, since the
underlying cause is the same.

After matching empty string at the beginning (index 0) and replace it with empty string, the
function will try to match at index 0 again but pass a flag to assert non-empty string match, which
it obviously fails. Then the function advance the offset by 1 data unit (1 byte in this case) and
hilarity ensues.

The correct behavior is that when u modifier is used, the function should always
advance by code unit (1 UTF character).

------------------------------------------------------------------------
[2012-02-25 09:54:52] robertbasic dot com at gmail dot com

Updated the test case showing that preg_filter and preg_replace_callback are affected, too.

------------------------------------------------------------------------
[2012-02-24 23:33:34] robertbasic dot com at gmail dot com

I tried my best on this one. Tested against the trunk:
svn info | grep Revision
Revision: 323476

I created a test file for this, will attach.

I ran the following with gdb:

$ gdb sapi/cgi/php-cgi

and then set a breakpoint

(gdb) break php_pcre.c:1318

finally ran the test script like:

(gdb) run run-tests.php ext/pcre/tests/bug53823.phpt

On https://gist.github.com/1904467 I c/p-ed some
output from gdb, but that might be incorrect as I'm fairly new to all this. Anyway, lines 12
and 22 in that gist caught my attention.

Also, I think the same issue exists for preg_filter, too.

------------------------------------------------------------------------
[2011-01-26 08:02:54] aharvey@php.net

Verified on 5.3 and trunk.

------------------------------------------------------------------------
[2011-01-23 18:10:44] tino dot didriksen at gmail dot com

...and then I forget to change the *. Let's try that again...

These work as expected:
echo preg_replace('/[^\pL\pM]+/iu', '', 'áéíóú');
echo preg_replace('/[^\pL\pM\pN]+/iu', '', 'áéíóú');

------------------------------------------------------------------------


The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at

    https://bugs.php.net/bug.php?id=53823


--
Edit this bug report at https://bugs.php.net/bug.php?id=53823&edit=1


Thread (12 messages)

« previous php.bugs (#193128) next »