Bug #71537 [Opn]: PCRE segfault from Opcache
| From: | max dot goldberg at gmail dot com | Date: | Sun, 07 Feb 2016 10:33:09 +0000 |
| Subject: | Bug #71537 [Opn]: PCRE segfault from Opcache | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-199088@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=71537&edit=1
ID: 71537
User updated by: max dot goldberg at gmail dot com
Reported by: max dot goldberg at gmail dot com
Summary: PCRE segfault from Opcache
Status: Open
Type: Bug
Package: opcache
Operating System: Debian/Centos
PHP Version: 7.0.3
Block user comment: N
Private report: N
New Comment:
Credentials sent!
Previous Comments:
------------------------------------------------------------------------
[2016-02-07 09:15:46] laruence@php.net
is that possible you could grant me a ssh access to the reproducible box? (via mail)
thanks
------------------------------------------------------------------------
[2016-02-06 15:28:07] max dot goldberg at gmail dot com
As with the built-in server, the first hit, pre-opcache goes fine, and the segfault occurs on the
second hit. Here's the valgrind result from the second hit, let me know if you need it run with
specific options:
==30154== Conditional jump or move depends on uninitialised value(s)
==30154== at 0x4F4CD6: php_pcre_replace_impl (php_pcre.c:1197)
==30154== by 0x4F486B: php_pcre_replace (php_pcre.c:1070)
==30154== by 0x4F5641: php_replace_in_subject (php_pcre.c:1403)
==30154== by 0x4F5A15: preg_replace_impl (php_pcre.c:1483)
==30154== by 0x4F6076: zif_preg_replace (php_pcre.c:1525)
==30154== by 0x8EC7FC: ZEND_DO_FCALL_BY_NAME_SPEC_HANDLER (zend_vm_execute.h:714)
==30154== by 0x8EBC1E: execute_ex (zend_vm_execute.h:417)
==30154== by 0x87A0DC: zend_call_function (zend_execute_API.c:860)
==30154== by 0x6EA22E: zif_call_user_func_array (basic_functions.c:4811)
==30154== by 0x8EC7FC: ZEND_DO_FCALL_BY_NAME_SPEC_HANDLER (zend_vm_execute.h:714)
==30154== by 0x8EBC1E: execute_ex (zend_vm_execute.h:417)
==30154== by 0x8EBD48: zend_execute (zend_vm_execute.h:458)
==30154==
==30154== Conditional jump or move depends on uninitialised value(s)
==30154== at 0x4F4CE4: php_pcre_replace_impl (php_pcre.c:1197)
==30154== by 0x4F486B: php_pcre_replace (php_pcre.c:1070)
==30154== by 0x4F5641: php_replace_in_subject (php_pcre.c:1403)
==30154== by 0x4F5A15: preg_replace_impl (php_pcre.c:1483)
==30154== by 0x4F6076: zif_preg_replace (php_pcre.c:1525)
==30154== by 0x8EC7FC: ZEND_DO_FCALL_BY_NAME_SPEC_HANDLER (zend_vm_execute.h:714)
==30154== by 0x8EBC1E: execute_ex (zend_vm_execute.h:417)
==30154== by 0x87A0DC: zend_call_function (zend_execute_API.c:860)
==30154== by 0x6EA22E: zif_call_user_func_array (basic_functions.c:4811)
==30154== by 0x8EC7FC: ZEND_DO_FCALL_BY_NAME_SPEC_HANDLER (zend_vm_execute.h:714)
==30154== by 0x8EBC1E: execute_ex (zend_vm_execute.h:417)
==30154== by 0x8EBD48: zend_execute (zend_vm_execute.h:458)
==30154==
==30154== Conditional jump or move depends on uninitialised value(s)
==30154== at 0x4F4CEE: php_pcre_replace_impl (php_pcre.c:1198)
==30154== by 0x4F486B: php_pcre_replace (php_pcre.c:1070)
==30154== by 0x4F5641: php_replace_in_subject (php_pcre.c:1403)
==30154== by 0x4F5A15: preg_replace_impl (php_pcre.c:1483)
==30154== by 0x4F6076: zif_preg_replace (php_pcre.c:1525)
==30154== by 0x8EC7FC: ZEND_DO_FCALL_BY_NAME_SPEC_HANDLER (zend_vm_execute.h:714)
==30154== by 0x8EBC1E: execute_ex (zend_vm_execute.h:417)
==30154== by 0x87A0DC: zend_call_function (zend_execute_API.c:860)
==30154== by 0x6EA22E: zif_call_user_func_array (basic_functions.c:4811)
==30154== by 0x8EC7FC: ZEND_DO_FCALL_BY_NAME_SPEC_HANDLER (zend_vm_execute.h:714)
==30154== by 0x8EBC1E: execute_ex (zend_vm_execute.h:417)
==30154== by 0x8EBD48: zend_execute (zend_vm_execute.h:458)
==30154== Uninitialised value was created by a stack allocation
==30154== at 0x8688FD: zend_compile_method_call (zend_compile.c:3256)
==30154==
==30154== Conditional jump or move depends on uninitialised value(s)
==30154== at 0x4F43C8: preg_get_backref (php_pcre.c:979)
==30154== by 0x4F4D23: php_pcre_replace_impl (php_pcre.c:1203)
==30154== by 0x4F486B: php_pcre_replace (php_pcre.c:1070)
==30154== by 0x4F5641: php_replace_in_subject (php_pcre.c:1403)
==30154== by 0x4F5A15: preg_replace_impl (php_pcre.c:1483)
==30154== by 0x4F6076: zif_preg_replace (php_pcre.c:1525)
==30154== by 0x8EC7FC: ZEND_DO_FCALL_BY_NAME_SPEC_HANDLER (zend_vm_execute.h:714)
==30154== by 0x8EBC1E: execute_ex (zend_vm_execute.h:417)
==30154== by 0x87A0DC: zend_call_function (zend_execute_API.c:860)
==30154== by 0x6EA22E: zif_call_user_func_array (basic_functions.c:4811)
==30154== by 0x8EC7FC: ZEND_DO_FCALL_BY_NAME_SPEC_HANDLER (zend_vm_execute.h:714)
==30154== by 0x8EBC1E: execute_ex (zend_vm_execute.h:417)
==30154== Uninitialised value was created by a stack allocation
==30154== at 0x8688FD: zend_compile_method_call (zend_compile.c:3256)
==30154==
==30154== Conditional jump or move depends on uninitialised value(s)
==30154== at 0x4F43D9: preg_get_backref (php_pcre.c:982)
==30154== by 0x4F4D23: php_pcre_replace_impl (php_pcre.c:1203)
==30154== by 0x4F486B: php_pcre_replace (php_pcre.c:1070)
==30154== by 0x4F5641: php_replace_in_subject (php_pcre.c:1403)
==30154== by 0x4F5A15: preg_replace_impl (php_pcre.c:1483)
==30154== by 0x4F6076: zif_preg_replace (php_pcre.c:1525)
==30154== by 0x8EC7FC: ZEND_DO_FCALL_BY_NAME_SPEC_HANDLER (zend_vm_execute.h:714)
==30154== by 0x8EBC1E: execute_ex (zend_vm_execute.h:417)
==30154== by 0x87A0DC: zend_call_function (zend_execute_API.c:860)
==30154== by 0x6EA22E: zif_call_user_func_array (basic_functions.c:4811)
==30154== by 0x8EC7FC: ZEND_DO_FCALL_BY_NAME_SPEC_HANDLER (zend_vm_execute.h:714)
==30154== by 0x8EBC1E: execute_ex (zend_vm_execute.h:417)
==30154== Uninitialised value was created by a stack allocation
==30154== at 0x8688FD: zend_compile_method_call (zend_compile.c:3256)
==30154==
==30154== Conditional jump or move depends on uninitialised value(s)
==30154== at 0x4F43F9: preg_get_backref (php_pcre.c:988)
==30154== by 0x4F4D23: php_pcre_replace_impl (php_pcre.c:1203)
==30154== by 0x4F486B: php_pcre_replace (php_pcre.c:1070)
==30154== by 0x4F5641: php_replace_in_subject (php_pcre.c:1403)
==30154== by 0x4F5A15: preg_replace_impl (php_pcre.c:1483)
==30154== by 0x4F6076: zif_preg_replace (php_pcre.c:1525)
==30154== by 0x8EC7FC: ZEND_DO_FCALL_BY_NAME_SPEC_HANDLER (zend_vm_execute.h:714)
==30154== by 0x8EBC1E: execute_ex (zend_vm_execute.h:417)
==30154== by 0x87A0DC: zend_call_function (zend_execute_API.c:860)
==30154== by 0x6EA22E: zif_call_user_func_array (basic_functions.c:4811)
==30154== by 0x8EC7FC: ZEND_DO_FCALL_BY_NAME_SPEC_HANDLER (zend_vm_execute.h:714)
==30154== by 0x8EBC1E: execute_ex (zend_vm_execute.h:417)
==30154== Uninitialised value was created by a stack allocation
==30154== at 0x8688FD: zend_compile_method_call (zend_compile.c:3256)
==30154==
==30154==
==30154== Process terminating with default action of signal 11 (SIGSEGV)
==30154== Bad permissions for mapped region at address 0xB037000
==30154== at 0x4F4CD1: php_pcre_replace_impl (php_pcre.c:1197)
==30154== by 0x4F486B: php_pcre_replace (php_pcre.c:1070)
==30154== by 0x4F5641: php_replace_in_subject (php_pcre.c:1403)
==30154== by 0x4F5A15: preg_replace_impl (php_pcre.c:1483)
==30154== by 0x4F6076: zif_preg_replace (php_pcre.c:1525)
==30154== by 0x8EC7FC: ZEND_DO_FCALL_BY_NAME_SPEC_HANDLER (zend_vm_execute.h:714)
==30154== by 0x8EBC1E: execute_ex (zend_vm_execute.h:417)
==30154== by 0x87A0DC: zend_call_function (zend_execute_API.c:860)
==30154== by 0x6EA22E: zif_call_user_func_array (basic_functions.c:4811)
==30154== by 0x8EC7FC: ZEND_DO_FCALL_BY_NAME_SPEC_HANDLER (zend_vm_execute.h:714)
==30154== by 0x8EBC1E: execute_ex (zend_vm_execute.h:417)
==30154== by 0x8EBD48: zend_execute (zend_vm_execute.h:458)
==30154==
==30154== HEAP SUMMARY:
==30154== in use at exit: 2,114,167 bytes in 19,195 blocks
==30154== total heap usage: 23,125 allocs, 3,930 frees, 3,644,424 bytes allocated
==30154==
==30154== LEAK SUMMARY:
==30154== definitely lost: 0 bytes in 0 blocks
==30154== indirectly lost: 0 bytes in 0 blocks
==30154== possibly lost: 1,464,606 bytes in 14,788 blocks
==30154== still reachable: 649,561 bytes in 4,407 blocks
==30154== suppressed: 0 bytes in 0 blocks
==30154== Rerun with --leak-check=full to see details of leaked memory
==30154==
==30154== For counts of detected and suppressed errors, rerun with: -v
==30154== ERROR SUMMARY: 11846 errors from 6 contexts (suppressed: 17 from 9)
Segmentation fault
------------------------------------------------------------------------
[2016-02-06 15:20:47] laruence@php.net
could you try with valgrind?
------------------------------------------------------------------------
[2016-02-05 19:14:35] max dot goldberg at gmail dot com
From 7.0.3:
#0 0x00000000004f4cd1 in php_pcre_replace_impl (pce=0x128b180, subject_str=0x7ffff21b3ea0,
subject=0x7ffff21b3eb8 "/find-a-class/studio/:id(/:offset)/", subject_len=35,
replace_val=0x7fffea1923d8, is_callable_replace=0, limit=-1, replace_count=0x7fffffffa78c) at
/usr/local/src/php-7.0.3/ext/pcre/php_pcre.c:1197
#1 0x00000000004f486c in php_pcre_replace (regex=0x7ffff21e4aa0, subject_str=0x7ffff21b3ea0,
subject=0x7ffff21b3eb8 "/find-a-class/studio/:id(/:offset)/", subject_len=35,
replace_val=0x7fffea1923d8, is_callable_replace=0, limit=-1, replace_count=0x7fffffffa78c) at
/usr/local/src/php-7.0.3/ext/pcre/php_pcre.c:1070
#2 0x00000000004f5642 in php_replace_in_subject (regex=0x7ffff2016880, replace=0x7ffff2016890,
subject=0x7ffff20168a0, limit=-1, is_callable_replace=0,
replace_count=0x7fffffffa78c) at /usr/local/src/php-7.0.3/ext/pcre/php_pcre.c:1403
#3 0x00000000004f5a16 in preg_replace_impl (return_value=0x7ffff20167f0, regex=0x7ffff2016880,
replace=0x7ffff2016890, subject=0x7ffff20168a0, limit_val=-1,
is_callable_replace=0, is_filter=0) at /usr/local/src/php-7.0.3/ext/pcre/php_pcre.c:1483
#4 0x00000000004f6077 in zif_preg_replace (execute_data=0x7ffff2016820,
return_value=0x7ffff20167f0) at /usr/local/src/php-7.0.3/ext/pcre/php_pcre.c:1525
#5 0x00000000008ec7fd in ZEND_DO_FCALL_BY_NAME_SPEC_HANDLER (execute_data=0x7ffff2016700) at
/usr/local/src/php-7.0.3/Zend/zend_vm_execute.h:714
#6 0x00000000008ebc1f in execute_ex (ex=0x7ffff2015750) at
/usr/local/src/php-7.0.3/Zend/zend_vm_execute.h:417
#7 0x000000000087a0dd in zend_call_function (fci=0x7fffffffaae0, fci_cache=0x7fffffffaab0) at
/usr/local/src/php-7.0.3/Zend/zend_execute_API.c:860
#8 0x00000000006ea22f in zif_call_user_func_array (execute_data=0x7ffff20156d0,
return_value=0x7ffff20156b0) at /usr/local/src/php-7.0.3/ext/standard/basic_functions.c:4811
#9 0x00000000008ec7fd in ZEND_DO_FCALL_BY_NAME_SPEC_HANDLER (execute_data=0x7ffff2015620) at
/usr/local/src/php-7.0.3/Zend/zend_vm_execute.h:714
#10 0x00000000008ebc1f in execute_ex (ex=0x7ffff2015030) at
/usr/local/src/php-7.0.3/Zend/zend_vm_execute.h:417
#11 0x00000000008ebd49 in zend_execute (op_array=0x7ffff2001000, return_value=0x0) at
/usr/local/src/php-7.0.3/Zend/zend_vm_execute.h:458
#12 0x0000000000891802 in zend_execute_scripts (type=8, retval=0x0, file_count=3) at
/usr/local/src/php-7.0.3/Zend/zend.c:1427
#13 0x0000000000803086 in php_execute_script (primary_file=0x7fffffffcfd0) at
/usr/local/src/php-7.0.3/main/main.c:2484
#14 0x00000000009606a0 in php_cli_server_dispatch_script (server=0x12207e0, client=0x13b9260) at
/usr/local/src/php-7.0.3/sapi/cli/php_cli_server.c:1940
#15 0x0000000000960e44 in php_cli_server_dispatch (server=0x12207e0, client=0x13b9260) at
/usr/local/src/php-7.0.3/sapi/cli/php_cli_server.c:2101
#16 0x00000000009616b9 in php_cli_server_recv_event_read_request (server=0x12207e0,
client=0x13b9260) at /usr/local/src/php-7.0.3/sapi/cli/php_cli_server.c:2315
#17 0x00000000009619e1 in php_cli_server_do_event_for_each_fd_callback (_params=0x7fffffffd240,
fd=8, event=1) at /usr/local/src/php-7.0.3/sapi/cli/php_cli_server.c:2395
#18 0x000000000095dd1a in php_cli_server_poller_iter_on_active (poller=0x12207e8,
opaque=0x7fffffffd240, callback=0x961811 <php_cli_server_do_event_for_each_fd_callback>)
at /usr/local/src/php-7.0.3/sapi/cli/php_cli_server.c:834
#19 0x0000000000961a9e in php_cli_server_do_event_for_each_fd (server=0x12207e0, rhandler=0x9615c2
<php_cli_server_recv_event_read_request>,
whandler=0x9616e0 <php_cli_server_send_event>) at
/usr/local/src/php-7.0.3/sapi/cli/php_cli_server.c:2418
#20 0x0000000000961b02 in php_cli_server_do_event_loop (server=0x12207e0) at
/usr/local/src/php-7.0.3/sapi/cli/php_cli_server.c:2428
#21 0x0000000000961e3c in do_cli_server (argc=5, argv=0x122ab40) at
/usr/local/src/php-7.0.3/sapi/cli/php_cli_server.c:2529
#22 0x00000000009585ee in main (argc=5, argv=0x122ab40) at
/usr/local/src/php-7.0.3/sapi/cli/php_cli.c:1348
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=71537
--
Edit this bug report at https://bugs.php.net/bug.php?id=71537&edit=1