Bug #69864 [Com]: Segfault in preg_replace_callback

From: Date: Wed, 17 Jun 2015 18:58:31 +0000
Subject: Bug #69864 [Com]: Segfault in preg_replace_callback
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-193626@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=69864&edit=1

 ID:                 69864
 Comment by:         james dot h dot cracknell at gmail dot com
 Reported by:        james dot h dot cracknell at gmail dot com
 Summary:            Segfault in preg_replace_callback
 Status:             Open
 Type:               Bug
 Package:            PCRE related
 Operating System:   Windows Server 2008 R2
 PHP Version:        7.0.0alpha1
 Block user comment: N
 Private report:     N

 New Comment:

Ah look, try again with echoed output:
http://3v4l.org/1cRNo


Previous Comments:
------------------------------------------------------------------------
[2015-06-17 18:54:34] james dot h dot cracknell at gmail dot com

At minimum Win x86 NTS still crashes at the most recent available snap (r7db113f@2015-06-17).

------------------------------------------------------------------------
[2015-06-17 18:34:27] cmb@php.net

Indeed, it does crash under 7.0.0alpha1 on Linux:
<http://3v4l.org/RY30H>. I can't reproduce the
problem on Windows,
though (neither x86 nor x64, neither NTS nor TS).

Anyhow, the problem seems to have been fixed (see php7@20150601
result).

------------------------------------------------------------------------
[2015-06-17 18:19:07] james dot h dot cracknell at gmail dot com

This will crash on Windows and Linux:

preg_replace_callback('/a/', function($m) {
  for($i = 0; $i < 10000; $i++)
    preg_replace('/foo'.$i.'bar/', 'baz',
'???foo'.$i.'bar???');
  return 'b';
}, 'aa');

------------------------------------------------------------------------
[2015-06-17 17:53:48] rasmus@php.net

Do you have a reproducing example? PCRE_CACHE_SIZE is 4096 elements. That sounds like more than
"very extensive use" that sounds like "insane use".

------------------------------------------------------------------------
[2015-06-17 17:53:33] cmb@php.net

Thank you for this bug report. To properly diagnose the problem, we
need a short but complete example script to be able to reproduce
this bug ourselves. 

A proper reproducing script starts with <?php and ends with ?>,
is max. 10-20 lines long and does not require any external 
resources such as databases, etc. If the script requires a 
database to demonstrate the issue, please make sure it creates 
all necessary tables, stored procedures etc.

Please avoid embedding huge scripts into the report.



------------------------------------------------------------------------


The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at

    https://bugs.php.net/bug.php?id=69864


--
Edit this bug report at https://bugs.php.net/bug.php?id=69864&edit=1


Thread (28 messages)

« previous php.bugs (#193626) next »