Bug #71537 [Opn]: PCRE segfault from Opcache

From: Date: Sun, 07 Feb 2016 09:15:49 +0000
Subject: Bug #71537 [Opn]: PCRE segfault from Opcache
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-199085@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=71537&edit=1 ID: 71537 Updated by: laruence@php.net Reported by: max dot goldberg at gmail dot com Summary: PCRE segfault from Opcache Status: Open Type: Bug Package: opcache Operating System: Debian/Centos PHP Version: 7.0.3 Block user comment: N Private report: N New Comment: is that possible you could grant me a ssh access to the reproducible box? (via mail) thanks Previous Comments: ------------------------------------------------------------------------ [2016-02-06 15:28:07] max dot goldberg at gmail dot com As with the built-in server, the first hit, pre-opcache goes fine, and the segfault occurs on the second hit. Here's the valgrind result from the second hit, let me know if you need it run with specific options: ==30154== Conditional jump or move depends on uninitialised value(s) ==30154== at 0x4F4CD6: php_pcre_replace_impl (php_pcre.c:1197) ==30154== by 0x4F486B: php_pcre_replace (php_pcre.c:1070) ==30154== by 0x4F5641: php_replace_in_subject (php_pcre.c:1403) ==30154== by 0x4F5A15: preg_replace_impl (php_pcre.c:1483) ==30154== by 0x4F6076: zif_preg_replace (php_pcre.c:1525) ==30154== by 0x8EC7FC: ZEND_DO_FCALL_BY_NAME_SPEC_HANDLER (zend_vm_execute.h:714) ==30154== by 0x8EBC1E: execute_ex (zend_vm_execute.h:417) ==30154== by 0x87A0DC: zend_call_function (zend_execute_API.c:860) ==30154== by 0x6EA22E: zif_call_user_func_array (basic_functions.c:4811) ==30154== by 0x8EC7FC: ZEND_DO_FCALL_BY_NAME_SPEC_HANDLER (zend_vm_execute.h:714) ==30154== by 0x8EBC1E: execute_ex (zend_vm_execute.h:417) ==30154== by 0x8EBD48: zend_execute (zend_vm_execute.h:458) ==30154== ==30154== Conditional jump or move depends on uninitialised value(s) ==30154== at 0x4F4CE4: php_pcre_replace_impl (php_pcre.c:1197) ==30154== by 0x4F486B: php_pcre_replace (php_pcre.c:1070) ==30154== by 0x4F5641: php_replace_in_subject (php_pcre.c:1403) ==30154== by 0x4F5A15: preg_replace_impl (php_pcre.c:1483) ==30154== by 0x4F6076: zif_preg_replace (php_pcre.c:1525) ==30154== by 0x8EC7FC: ZEND_DO_FCALL_BY_NAME_SPEC_HANDLER (zend_vm_execute.h:714) ==30154== by 0x8EBC1E: execute_ex (zend_vm_execute.h:417) ==30154== by 0x87A0DC: zend_call_function (zend_execute_API.c:860) ==30154== by 0x6EA22E: zif_call_user_func_array (basic_functions.c:4811) ==30154== by 0x8EC7FC: ZEND_DO_FCALL_BY_NAME_SPEC_HANDLER (zend_vm_execute.h:714) ==30154== by 0x8EBC1E: execute_ex (zend_vm_execute.h:417) ==30154== by 0x8EBD48: zend_execute (zend_vm_execute.h:458) ==30154== ==30154== Conditional jump or move depends on uninitialised value(s) ==30154== at 0x4F4CEE: php_pcre_replace_impl (php_pcre.c:1198) ==30154== by 0x4F486B: php_pcre_replace (php_pcre.c:1070) ==30154== by 0x4F5641: php_replace_in_subject (php_pcre.c:1403) ==30154== by 0x4F5A15: preg_replace_impl (php_pcre.c:1483) ==30154== by 0x4F6076: zif_preg_replace (php_pcre.c:1525) ==30154== by 0x8EC7FC: ZEND_DO_FCALL_BY_NAME_SPEC_HANDLER (zend_vm_execute.h:714) ==30154== by 0x8EBC1E: execute_ex (zend_vm_execute.h:417) ==30154== by 0x87A0DC: zend_call_function (zend_execute_API.c:860) ==30154== by 0x6EA22E: zif_call_user_func_array (basic_functions.c:4811) ==30154== by 0x8EC7FC: ZEND_DO_FCALL_BY_NAME_SPEC_HANDLER (zend_vm_execute.h:714) ==30154== by 0x8EBC1E: execute_ex (zend_vm_execute.h:417) ==30154== by 0x8EBD48: zend_execute (zend_vm_execute.h:458) ==30154== Uninitialised value was created by a stack allocation ==30154== at 0x8688FD: zend_compile_method_call (zend_compile.c:3256) ==30154== ==30154== Conditional jump or move depends on uninitialised value(s) ==30154== at 0x4F43C8: preg_get_backref (php_pcre.c:979) ==30154== by 0x4F4D23: php_pcre_replace_impl (php_pcre.c:1203) ==30154== by 0x4F486B: php_pcre_replace (php_pcre.c:1070) ==30154== by 0x4F5641: php_replace_in_subject (php_pcre.c:1403) ==30154== by 0x4F5A15: preg_replace_impl (php_pcre.c:1483) ==30154== by 0x4F6076: zif_preg_replace (php_pcre.c:1525) ==30154== by 0x8EC7FC: ZEND_DO_FCALL_BY_NAME_SPEC_HANDLER (zend_vm_execute.h:714) ==30154== by 0x8EBC1E: execute_ex (zend_vm_execute.h:417) ==30154== by 0x87A0DC: zend_call_function (zend_execute_API.c:860) ==30154== by 0x6EA22E: zif_call_user_func_array (basic_functions.c:4811) ==30154== by 0x8EC7FC: ZEND_DO_FCALL_BY_NAME_SPEC_HANDLER (zend_vm_execute.h:714) ==30154== by 0x8EBC1E: execute_ex (zend_vm_execute.h:417) ==30154== Uninitialised value was created by a stack allocation ==30154== at 0x8688FD: zend_compile_method_call (zend_compile.c:3256) ==30154== ==30154== Conditional jump or move depends on uninitialised value(s) ==30154== at 0x4F43D9: preg_get_backref (php_pcre.c:982) ==30154== by 0x4F4D23: php_pcre_replace_impl (php_pcre.c:1203) ==30154== by 0x4F486B: php_pcre_replace (php_pcre.c:1070) ==30154== by 0x4F5641: php_replace_in_subject (php_pcre.c:1403) ==30154== by 0x4F5A15: preg_replace_impl (php_pcre.c:1483) ==30154== by 0x4F6076: zif_preg_replace (php_pcre.c:1525) ==30154== by 0x8EC7FC: ZEND_DO_FCALL_BY_NAME_SPEC_HANDLER (zend_vm_execute.h:714) ==30154== by 0x8EBC1E: execute_ex (zend_vm_execute.h:417) ==30154== by 0x87A0DC: zend_call_function (zend_execute_API.c:860) ==30154== by 0x6EA22E: zif_call_user_func_array (basic_functions.c:4811) ==30154== by 0x8EC7FC: ZEND_DO_FCALL_BY_NAME_SPEC_HANDLER (zend_vm_execute.h:714) ==30154== by 0x8EBC1E: execute_ex (zend_vm_execute.h:417) ==30154== Uninitialised value was created by a stack allocation ==30154== at 0x8688FD: zend_compile_method_call (zend_compile.c:3256) ==30154== ==30154== Conditional jump or move depends on uninitialised value(s) ==30154== at 0x4F43F9: preg_get_backref (php_pcre.c:988) ==30154== by 0x4F4D23: php_pcre_replace_impl (php_pcre.c:1203) ==30154== by 0x4F486B: php_pcre_replace (php_pcre.c:1070) ==30154== by 0x4F5641: php_replace_in_subject (php_pcre.c:1403) ==30154== by 0x4F5A15: preg_replace_impl (php_pcre.c:1483) ==30154== by 0x4F6076: zif_preg_replace (php_pcre.c:1525) ==30154== by 0x8EC7FC: ZEND_DO_FCALL_BY_NAME_SPEC_HANDLER (zend_vm_execute.h:714) ==30154== by 0x8EBC1E: execute_ex (zend_vm_execute.h:417) ==30154== by 0x87A0DC: zend_call_function (zend_execute_API.c:860) ==30154== by 0x6EA22E: zif_call_user_func_array (basic_functions.c:4811) ==30154== by 0x8EC7FC: ZEND_DO_FCALL_BY_NAME_SPEC_HANDLER (zend_vm_execute.h:714) ==30154== by 0x8EBC1E: execute_ex (zend_vm_execute.h:417) ==30154== Uninitialised value was created by a stack allocation ==30154== at 0x8688FD: zend_compile_method_call (zend_compile.c:3256) ==30154== ==30154== ==30154== Process terminating with default action of signal 11 (SIGSEGV) ==30154== Bad permissions for mapped region at address 0xB037000 ==30154== at 0x4F4CD1: php_pcre_replace_impl (php_pcre.c:1197) ==30154== by 0x4F486B: php_pcre_replace (php_pcre.c:1070) ==30154== by 0x4F5641: php_replace_in_subject (php_pcre.c:1403) ==30154== by 0x4F5A15: preg_replace_impl (php_pcre.c:1483) ==30154== by 0x4F6076: zif_preg_replace (php_pcre.c:1525) ==30154== by 0x8EC7FC: ZEND_DO_FCALL_BY_NAME_SPEC_HANDLER (zend_vm_execute.h:714) ==30154== by 0x8EBC1E: execute_ex (zend_vm_execute.h:417) ==30154== by 0x87A0DC: zend_call_function (zend_execute_API.c:860) ==30154== by 0x6EA22E: zif_call_user_func_array (basic_functions.c:4811) ==30154== by 0x8EC7FC: ZEND_DO_FCALL_BY_NAME_SPEC_HANDLER (zend_vm_execute.h:714) ==30154== by 0x8EBC1E: execute_ex (zend_vm_execute.h:417) ==30154== by 0x8EBD48: zend_execute (zend_vm_execute.h:458) ==30154== ==30154== HEAP SUMMARY: ==30154== in use at exit: 2,114,167 bytes in 19,195 blocks ==30154== total heap usage: 23,125 allocs, 3,930 frees, 3,644,424 bytes allocated ==30154== ==30154== LEAK SUMMARY: ==30154== definitely lost: 0 bytes in 0 blocks ==30154== indirectly lost: 0 bytes in 0 blocks ==30154== possibly lost: 1,464,606 bytes in 14,788 blocks ==30154== still reachable: 649,561 bytes in 4,407 blocks ==30154== suppressed: 0 bytes in 0 blocks ==30154== Rerun with --leak-check=full to see details of leaked memory ==30154== ==30154== For counts of detected and suppressed errors, rerun with: -v ==30154== ERROR SUMMARY: 11846 errors from 6 contexts (suppressed: 17 from 9) Segmentation fault ------------------------------------------------------------------------ [2016-02-06 15:20:47] laruence@php.net could you try with valgrind? ------------------------------------------------------------------------ [2016-02-05 19:14:35] max dot goldberg at gmail dot com From 7.0.3: #0 0x00000000004f4cd1 in php_pcre_replace_impl (pce=0x128b180, subject_str=0x7ffff21b3ea0, subject=0x7ffff21b3eb8 "/find-a-class/studio/:id(/:offset)/", subject_len=35, replace_val=0x7fffea1923d8, is_callable_replace=0, limit=-1, replace_count=0x7fffffffa78c) at /usr/local/src/php-7.0.3/ext/pcre/php_pcre.c:1197 #1 0x00000000004f486c in php_pcre_replace (regex=0x7ffff21e4aa0, subject_str=0x7ffff21b3ea0, subject=0x7ffff21b3eb8 "/find-a-class/studio/:id(/:offset)/", subject_len=35, replace_val=0x7fffea1923d8, is_callable_replace=0, limit=-1, replace_count=0x7fffffffa78c) at /usr/local/src/php-7.0.3/ext/pcre/php_pcre.c:1070 #2 0x00000000004f5642 in php_replace_in_subject (regex=0x7ffff2016880, replace=0x7ffff2016890, subject=0x7ffff20168a0, limit=-1, is_callable_replace=0, replace_count=0x7fffffffa78c) at /usr/local/src/php-7.0.3/ext/pcre/php_pcre.c:1403 #3 0x00000000004f5a16 in preg_replace_impl (return_value=0x7ffff20167f0, regex=0x7ffff2016880, replace=0x7ffff2016890, subject=0x7ffff20168a0, limit_val=-1, is_callable_replace=0, is_filter=0) at /usr/local/src/php-7.0.3/ext/pcre/php_pcre.c:1483 #4 0x00000000004f6077 in zif_preg_replace (execute_data=0x7ffff2016820, return_value=0x7ffff20167f0) at /usr/local/src/php-7.0.3/ext/pcre/php_pcre.c:1525 #5 0x00000000008ec7fd in ZEND_DO_FCALL_BY_NAME_SPEC_HANDLER (execute_data=0x7ffff2016700) at /usr/local/src/php-7.0.3/Zend/zend_vm_execute.h:714 #6 0x00000000008ebc1f in execute_ex (ex=0x7ffff2015750) at /usr/local/src/php-7.0.3/Zend/zend_vm_execute.h:417 #7 0x000000000087a0dd in zend_call_function (fci=0x7fffffffaae0, fci_cache=0x7fffffffaab0) at /usr/local/src/php-7.0.3/Zend/zend_execute_API.c:860 #8 0x00000000006ea22f in zif_call_user_func_array (execute_data=0x7ffff20156d0, return_value=0x7ffff20156b0) at /usr/local/src/php-7.0.3/ext/standard/basic_functions.c:4811 #9 0x00000000008ec7fd in ZEND_DO_FCALL_BY_NAME_SPEC_HANDLER (execute_data=0x7ffff2015620) at /usr/local/src/php-7.0.3/Zend/zend_vm_execute.h:714 #10 0x00000000008ebc1f in execute_ex (ex=0x7ffff2015030) at /usr/local/src/php-7.0.3/Zend/zend_vm_execute.h:417 #11 0x00000000008ebd49 in zend_execute (op_array=0x7ffff2001000, return_value=0x0) at /usr/local/src/php-7.0.3/Zend/zend_vm_execute.h:458 #12 0x0000000000891802 in zend_execute_scripts (type=8, retval=0x0, file_count=3) at /usr/local/src/php-7.0.3/Zend/zend.c:1427 #13 0x0000000000803086 in php_execute_script (primary_file=0x7fffffffcfd0) at /usr/local/src/php-7.0.3/main/main.c:2484 #14 0x00000000009606a0 in php_cli_server_dispatch_script (server=0x12207e0, client=0x13b9260) at /usr/local/src/php-7.0.3/sapi/cli/php_cli_server.c:1940 #15 0x0000000000960e44 in php_cli_server_dispatch (server=0x12207e0, client=0x13b9260) at /usr/local/src/php-7.0.3/sapi/cli/php_cli_server.c:2101 #16 0x00000000009616b9 in php_cli_server_recv_event_read_request (server=0x12207e0, client=0x13b9260) at /usr/local/src/php-7.0.3/sapi/cli/php_cli_server.c:2315 #17 0x00000000009619e1 in php_cli_server_do_event_for_each_fd_callback (_params=0x7fffffffd240, fd=8, event=1) at /usr/local/src/php-7.0.3/sapi/cli/php_cli_server.c:2395 #18 0x000000000095dd1a in php_cli_server_poller_iter_on_active (poller=0x12207e8, opaque=0x7fffffffd240, callback=0x961811 <php_cli_server_do_event_for_each_fd_callback>) at /usr/local/src/php-7.0.3/sapi/cli/php_cli_server.c:834 #19 0x0000000000961a9e in php_cli_server_do_event_for_each_fd (server=0x12207e0, rhandler=0x9615c2 <php_cli_server_recv_event_read_request>, whandler=0x9616e0 <php_cli_server_send_event>) at /usr/local/src/php-7.0.3/sapi/cli/php_cli_server.c:2418 #20 0x0000000000961b02 in php_cli_server_do_event_loop (server=0x12207e0) at /usr/local/src/php-7.0.3/sapi/cli/php_cli_server.c:2428 #21 0x0000000000961e3c in do_cli_server (argc=5, argv=0x122ab40) at /usr/local/src/php-7.0.3/sapi/cli/php_cli_server.c:2529 #22 0x00000000009585ee in main (argc=5, argv=0x122ab40) at /usr/local/src/php-7.0.3/sapi/cli/php_cli.c:1348 ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=71537 -- Edit this bug report at https://bugs.php.net/bug.php?id=71537&edit=1

« previous php.bugs (#199085) next »