Bug #69864 [Opn->Fbk]: Segfault in preg_replace_callback
| From: | cmb@php.net | Date: | Wed, 17 Jun 2015 17:53:34 +0000 |
| Subject: | Bug #69864 [Opn->Fbk]: Segfault in preg_replace_callback | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-193620@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=69864&edit=1
ID: 69864
Updated by: cmb@php.net
Reported by: james dot h dot cracknell at gmail dot com
Summary: Segfault in preg_replace_callback
-Status: Open
+Status: Feedback
Type: Bug
Package: PCRE related
Operating System: Windows Server 2008 R2
PHP Version: 7.0.0alpha1
-Assigned To:
+Assigned To: cmb
Block user comment: N
Private report: N
New Comment:
Thank you for this bug report. To properly diagnose the problem, we
need a short but complete example script to be able to reproduce
this bug ourselves.
A proper reproducing script starts with <?php and ends with ?>,
is max. 10-20 lines long and does not require any external
resources such as databases, etc. If the script requires a
database to demonstrate the issue, please make sure it creates
all necessary tables, stored procedures etc.
Please avoid embedding huge scripts into the report.
Previous Comments:
------------------------------------------------------------------------
[2015-06-17 16:42:17] james dot h dot cracknell at gmail dot com
Description:
------------
Note the following in the provided stack trace:
struct real_pcre * argument_re = 0x00000001
I believe what is occurring here is if you use
preg_replace_callback with a callback
making (very) extensive use of PCRE functions, the outer regular expression gets evicted from the
PCRE cache and freed before preg_replace_callback completes.
Looking at pcre_get_compiled_regex_cache, it looks as though no checks are performed to
prevent this from happening:
https://github.com/php/php-src/blob/php-7.0.0alpha1/ext/pcre/php_pcre.c#L446
Switching to an approach using preg_match_all with manual replacement obviously
sidesteps the issue.
Stack trace follows, less the subject string value:
php7!php_pcre_exec(struct real_pcre * argument_re = 0x00000001, struct pcre_extra * extra_data =
0x0d6074b8, char * subject = 0x0598fa10 "(snip)", int length = 0n1235, int start_offset =
0n997, int options = 0n8192, int * offsets = 0x052ac3f0, int offsetcount = 0n21)+0x149
[c:\php-sdk\php70dev\vc14\x86\php-7.0.0alpha1\ext\pcre\pcrelib\pcre_exec.c @ 6420]
php7!php_pcre_replace_impl(struct pcre_cache_entry * pce = 0x00ee58d8, struct _zend_string *
subject_str = 0x0598fa00, char * subject = 0x0598fa10 "(snip)", int subject_len = 0n1235,
struct _zval_struct * replace_val = 0x008143d0, int is_callable_replace = 0n1, int limit = 0n-1, int
* replace_count = 0x052ac534)+0x148
[c:\php-sdk\php70dev\vc14\x86\php-7.0.0alpha1\ext\pcre\php_pcre.c @ 1120]
php7!php_pcre_replace+0x33 [c:\php-sdk\php70dev\vc14\x86\php-7.0.0alpha1\ext\pcre\php_pcre.c @ 1026]
php7!php_replace_in_subject(struct _zval_struct * regex = 0x008143c0, struct _zval_struct * replace
= 0x008143d0, struct _zval_struct * subject = 0x008143e0, int limit = 0n-1, int is_callable_replace
= 0n1, int * replace_count = 0x052ac534)+0x258
[c:\php-sdk\php70dev\vc14\x86\php-7.0.0alpha1\ext\pcre\php_pcre.c @ 1353]
php7!preg_replace_impl(struct _zval_struct * return_value = 0x00814370, struct _zval_struct * regex
= 0x008143c0, struct _zval_struct * replace = 0x008143d0, struct _zval_struct * subject =
0x008143e0, int limit_val = 0n-1, int is_callable_replace = 0n1, int is_filter = 0n0)+0x264
[c:\php-sdk\php70dev\vc14\x86\php-7.0.0alpha1\ext\pcre\php_pcre.c @ 1411]
php7!zif_preg_replace_callback(struct _zend_execute_data * execute_data = <Value unavailable
error>, struct _zval_struct * return_value = 0x00814370)+0x173
[c:\php-sdk\php70dev\vc14\x86\php-7.0.0alpha1\ext\pcre\php_pcre.c @ 1494]
php7!ZEND_DO_FCALL_BY_NAME_SPEC_HANDLER+0x2e6e14
[c:\php-sdk\php70dev\vc14\x86\php-7.0.0alpha1\zend\zend_vm_execute.h @ 701]
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=69864&edit=1