Bug #71537 [Opn->Fbk]: PCRE segfault from Opcache

From: Date: Fri, 05 Feb 2016 18:50:28 +0000
Subject: Bug #71537 [Opn->Fbk]: PCRE segfault from Opcache
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-199072@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=71537&edit=1 ID: 71537 Updated by: rasmus@php.net Reported by: max dot goldberg at gmail dot com Summary: PCRE segfault from Opcache -Status: Open +Status: Feedback Type: Bug Package: opcache Operating System: Debian/Centos PHP Version: 7.0.3 Block user comment: N Private report: N New Comment: The PHP version listed is 7.0.3, but the line numbers in your backtrace don't seem to match 7.0.3? Previous Comments: ------------------------------------------------------------------------ [2016-02-05 16:53:55] max dot goldberg at gmail dot com Description: ------------ In certain conditions, PHP 7 will segfault when preg_replace() is executed from the opcache. This has been happening since at least 7.0.0RC1 and up until php-src as of today. Turning the opcache off, or blacklisting just the calling script seems to make the problem go away. Turning opcache.jit on or off seems to have no bearing on the issue. opcache ini settings are all at their default otherwise. Despite my best efforts, I have not been able to reduce the code causing the segfault to single script. I'm available on efnet in #php.pecl or via email to work through it if need be. Actual result: -------------- (gdb) bt #0 0x00000000004f486f in php_pcre_replace_impl (pce=0x127f380, subject_str=0x7ffff21b2f00, subject=0x7ffff21b2f18 "/find-a-class/studio/:id(/:offset)/", subject_len=35, replace_val=0x7fffea14a7d8, is_callable_replace=0, limit=-1, replace_count=0x7fffffffa78c) at /usr/local/src/php-src/ext/pcre/php_pcre.c:1197 #1 0x00000000004f43f7 in php_pcre_replace (regex=0x7ffff2077fc0, subject_str=0x7ffff21b2f00, subject=0x7ffff21b2f18 "/find-a-class/studio/:id(/:offset)/", subject_len=35, replace_val=0x7fffea14a7d8, is_callable_replace=0, limit=-1, replace_count=0x7fffffffa78c) at /usr/local/src/php-src/ext/pcre/php_pcre.c:1055 #2 0x00000000004f5115 in php_replace_in_subject (regex=0x7ffff2016880, replace=0x7ffff2016890, subject=0x7ffff20168a0, limit=-1, is_callable_replace=0, replace_count=0x7fffffffa78c) at /usr/local/src/php-src/ext/pcre/php_pcre.c:1389 #3 0x00000000004f54e9 in preg_replace_impl (return_value=0x7ffff20167f0, regex=0x7ffff2016880, replace=0x7ffff2016890, subject=0x7ffff20168a0, limit_val=-1, is_callable_replace=0, is_filter=0) at /usr/local/src/php-src/ext/pcre/php_pcre.c:1469 #4 0x00000000004f5b4a in zif_preg_replace (execute_data=0x7ffff2016820, return_value=0x7ffff20167f0) at /usr/local/src/php-src/ext/pcre/php_pcre.c:1511 #5 0x00000000008e3595 in ZEND_DO_FCALL_BY_NAME_SPEC_HANDLER (execute_data=0x7ffff2016700) at /usr/local/src/php-src/Zend/zend_vm_execute.h:714 #6 0x00000000008e29a4 in execute_ex (ex=0x7ffff2015750) at /usr/local/src/php-src/Zend/zend_vm_execute.h:417 #7 0x00000000008707ba in zend_call_function (fci=0x7fffffffaae0, fci_cache=0x7fffffffaab0) at /usr/local/src/php-src/Zend/zend_execute_API.c:860 #8 0x00000000006ebdae in zif_call_user_func_array (execute_data=0x7ffff20156d0, return_value=0x7ffff20156b0) at /usr/local/src/php-src/ext/standard/basic_functions.c:4815 #9 0x00000000008e3595 in ZEND_DO_FCALL_BY_NAME_SPEC_HANDLER (execute_data=0x7ffff2015620) at /usr/local/src/php-src/Zend/zend_vm_execute.h:714 #10 0x00000000008e29a4 in execute_ex (ex=0x7ffff2015030) at /usr/local/src/php-src/Zend/zend_vm_execute.h:417 #11 0x00000000008e2ace in zend_execute (op_array=0x7ffff2001000, return_value=0x0) at /usr/local/src/php-src/Zend/zend_vm_execute.h:458 #12 0x0000000000887ce6 in zend_execute_scripts (type=8, retval=0x0, file_count=3) at /usr/local/src/php-src/Zend/zend.c:1427 #13 0x00000000007f8b3a in php_execute_script (primary_file=0x7fffffffcfd0) at /usr/local/src/php-src/main/main.c:2484 #14 0x0000000000958da7 in php_cli_server_dispatch_script (server=0x121cda0, client=0x13cff60) at /usr/local/src/php-src/sapi/cli/php_cli_server.c:1940 #15 0x000000000095954b in php_cli_server_dispatch (server=0x121cda0, client=0x13cff60) at /usr/local/src/php-src/sapi/cli/php_cli_server.c:2101 #16 0x0000000000959dc0 in php_cli_server_recv_event_read_request (server=0x121cda0, client=0x13cff60) at /usr/local/src/php-src/sapi/cli/php_cli_server.c:2315 #17 0x000000000095a132 in php_cli_server_do_event_for_each_fd_callback (_params=0x7fffffffd240, fd=9, event=1) at /usr/local/src/php-src/sapi/cli/php_cli_server.c:2400 #18 0x0000000000956421 in php_cli_server_poller_iter_on_active (poller=0x121cda8, opaque=0x7fffffffd240, callback=0x959f18 <php_cli_server_do_event_for_each_fd_callback>) at /usr/local/src/php-src/sapi/cli/php_cli_server.c:834 #19 0x000000000095a1a5 in php_cli_server_do_event_for_each_fd (server=0x121cda0, rhandler=0x959cc9 <php_cli_server_recv_event_read_request>, whandler=0x959de7 <php_cli_server_send_event>) at /usr/local/src/php-src/sapi/cli/php_cli_server.c:2418 #20 0x000000000095a209 in php_cli_server_do_event_loop (server=0x121cda0) at /usr/local/src/php-src/sapi/cli/php_cli_server.c:2428 #21 0x000000000095a543 in do_cli_server (argc=5, argv=0x1226b50) at /usr/local/src/php-src/sapi/cli/php_cli_server.c:2529 #22 0x0000000000950ce2 in main (argc=5, argv=0x1226b50) at /usr/local/src/php-src/sapi/cli/php_cli.c:1348 (gdb) info local extra = 0x7fffffffa540 extra_data = {flags = 50, study_data = 0x7ffff2077fc0, match_limit = 100, callout_data = 0x7fffffffa640, tables = 0x7fffffffa590 "\030/\033\362\377\177", match_limit_recursion = 100, mark = 0x7fffffffa528, executable_jit = 0x69f20e3ec0} exoptions = 8192 count = 1 offsets = 0x7fffffffa4d0 subpat_names = 0x0 num_subpats = 1 size_offsets = 3 new_len = 500990 alloc_len = 0 match_len = 32767 backref = 0 start_offset = 0 g_notempty = 0 replace_len = 681947597 replace = 0x7ffff2185b18 "" walkbuf = 0x0 walk = 0x7ffff2200001 <Address 0x7ffff2200001 out of bounds> match = 0x7ffff21b2f2d ":id(/:offset)/" piece = 0x7ffff21b2f18 "/find-a-class/studio/:id(/:offset)/" replace_end = 0x80001abe0ce5 <Address 0x80001abe0ce5 out of bounds> walk_last = 0 '\000' result_len = 0 mark = 0x0 result = 0x0 eval_result = 0x0 use_heap = 0 '\000' __PRETTY_FUNCTION__ = "php_pcre_replace_impl" (gdb) ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=71537&edit=1

« previous php.bugs (#199072) next »