Bug #71537 [Opn->Csd]: PCRE segfault from Opcache

From: Date: Sun, 07 Feb 2016 15:39:17 +0000
Subject: Bug #71537 [Opn->Csd]: PCRE segfault from Opcache
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-199093@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=71537&edit=1 ID: 71537 Updated by: laruence@php.net Reported by: max dot goldberg at gmail dot com Summary: PCRE segfault from Opcache -Status: Open +Status: Closed Type: Bug Package: opcache Operating System: Debian/Centos PHP Version: 7.0.3 -Assigned To: +Assigned To: laruence Block user comment: N Private report: N New Comment: The fix for this bug has been committed. Snapshots of the sources are packaged every three hours; this change will be in the next snapshot. You can grab the snapshot at http://snaps.php.net/. For Windows: http://windows.php.net/snapshots/ Thank you for the report, and for helping us make PHP better. Previous Comments: ------------------------------------------------------------------------ [2016-02-07 15:20:59] laruence@php.net thanks max, it has been fixed, your help is appreciated.. anyway, your local php-src has been patched. so, you might need clean it :< thanks ------------------------------------------------------------------------ [2016-02-07 15:19:50] laruence@php.net Automatic comment on behalf of laruence@gmail.com Revision: http://git.php.net/?p=php-src.git;a=commit;h=336e39f2b194e1425dc363abd18554f60c80bed1 Log: Fixed bug #71537 (PCRE segfault from Opcache) ------------------------------------------------------------------------ [2016-02-07 10:33:07] max dot goldberg at gmail dot com Credentials sent! ------------------------------------------------------------------------ [2016-02-07 09:15:46] laruence@php.net is that possible you could grant me a ssh access to the reproducible box? (via mail) thanks ------------------------------------------------------------------------ [2016-02-06 15:28:07] max dot goldberg at gmail dot com As with the built-in server, the first hit, pre-opcache goes fine, and the segfault occurs on the second hit. Here's the valgrind result from the second hit, let me know if you need it run with specific options: ==30154== Conditional jump or move depends on uninitialised value(s) ==30154== at 0x4F4CD6: php_pcre_replace_impl (php_pcre.c:1197) ==30154== by 0x4F486B: php_pcre_replace (php_pcre.c:1070) ==30154== by 0x4F5641: php_replace_in_subject (php_pcre.c:1403) ==30154== by 0x4F5A15: preg_replace_impl (php_pcre.c:1483) ==30154== by 0x4F6076: zif_preg_replace (php_pcre.c:1525) ==30154== by 0x8EC7FC: ZEND_DO_FCALL_BY_NAME_SPEC_HANDLER (zend_vm_execute.h:714) ==30154== by 0x8EBC1E: execute_ex (zend_vm_execute.h:417) ==30154== by 0x87A0DC: zend_call_function (zend_execute_API.c:860) ==30154== by 0x6EA22E: zif_call_user_func_array (basic_functions.c:4811) ==30154== by 0x8EC7FC: ZEND_DO_FCALL_BY_NAME_SPEC_HANDLER (zend_vm_execute.h:714) ==30154== by 0x8EBC1E: execute_ex (zend_vm_execute.h:417) ==30154== by 0x8EBD48: zend_execute (zend_vm_execute.h:458) ==30154== ==30154== Conditional jump or move depends on uninitialised value(s) ==30154== at 0x4F4CE4: php_pcre_replace_impl (php_pcre.c:1197) ==30154== by 0x4F486B: php_pcre_replace (php_pcre.c:1070) ==30154== by 0x4F5641: php_replace_in_subject (php_pcre.c:1403) ==30154== by 0x4F5A15: preg_replace_impl (php_pcre.c:1483) ==30154== by 0x4F6076: zif_preg_replace (php_pcre.c:1525) ==30154== by 0x8EC7FC: ZEND_DO_FCALL_BY_NAME_SPEC_HANDLER (zend_vm_execute.h:714) ==30154== by 0x8EBC1E: execute_ex (zend_vm_execute.h:417) ==30154== by 0x87A0DC: zend_call_function (zend_execute_API.c:860) ==30154== by 0x6EA22E: zif_call_user_func_array (basic_functions.c:4811) ==30154== by 0x8EC7FC: ZEND_DO_FCALL_BY_NAME_SPEC_HANDLER (zend_vm_execute.h:714) ==30154== by 0x8EBC1E: execute_ex (zend_vm_execute.h:417) ==30154== by 0x8EBD48: zend_execute (zend_vm_execute.h:458) ==30154== ==30154== Conditional jump or move depends on uninitialised value(s) ==30154== at 0x4F4CEE: php_pcre_replace_impl (php_pcre.c:1198) ==30154== by 0x4F486B: php_pcre_replace (php_pcre.c:1070) ==30154== by 0x4F5641: php_replace_in_subject (php_pcre.c:1403) ==30154== by 0x4F5A15: preg_replace_impl (php_pcre.c:1483) ==30154== by 0x4F6076: zif_preg_replace (php_pcre.c:1525) ==30154== by 0x8EC7FC: ZEND_DO_FCALL_BY_NAME_SPEC_HANDLER (zend_vm_execute.h:714) ==30154== by 0x8EBC1E: execute_ex (zend_vm_execute.h:417) ==30154== by 0x87A0DC: zend_call_function (zend_execute_API.c:860) ==30154== by 0x6EA22E: zif_call_user_func_array (basic_functions.c:4811) ==30154== by 0x8EC7FC: ZEND_DO_FCALL_BY_NAME_SPEC_HANDLER (zend_vm_execute.h:714) ==30154== by 0x8EBC1E: execute_ex (zend_vm_execute.h:417) ==30154== by 0x8EBD48: zend_execute (zend_vm_execute.h:458) ==30154== Uninitialised value was created by a stack allocation ==30154== at 0x8688FD: zend_compile_method_call (zend_compile.c:3256) ==30154== ==30154== Conditional jump or move depends on uninitialised value(s) ==30154== at 0x4F43C8: preg_get_backref (php_pcre.c:979) ==30154== by 0x4F4D23: php_pcre_replace_impl (php_pcre.c:1203) ==30154== by 0x4F486B: php_pcre_replace (php_pcre.c:1070) ==30154== by 0x4F5641: php_replace_in_subject (php_pcre.c:1403) ==30154== by 0x4F5A15: preg_replace_impl (php_pcre.c:1483) ==30154== by 0x4F6076: zif_preg_replace (php_pcre.c:1525) ==30154== by 0x8EC7FC: ZEND_DO_FCALL_BY_NAME_SPEC_HANDLER (zend_vm_execute.h:714) ==30154== by 0x8EBC1E: execute_ex (zend_vm_execute.h:417) ==30154== by 0x87A0DC: zend_call_function (zend_execute_API.c:860) ==30154== by 0x6EA22E: zif_call_user_func_array (basic_functions.c:4811) ==30154== by 0x8EC7FC: ZEND_DO_FCALL_BY_NAME_SPEC_HANDLER (zend_vm_execute.h:714) ==30154== by 0x8EBC1E: execute_ex (zend_vm_execute.h:417) ==30154== Uninitialised value was created by a stack allocation ==30154== at 0x8688FD: zend_compile_method_call (zend_compile.c:3256) ==30154== ==30154== Conditional jump or move depends on uninitialised value(s) ==30154== at 0x4F43D9: preg_get_backref (php_pcre.c:982) ==30154== by 0x4F4D23: php_pcre_replace_impl (php_pcre.c:1203) ==30154== by 0x4F486B: php_pcre_replace (php_pcre.c:1070) ==30154== by 0x4F5641: php_replace_in_subject (php_pcre.c:1403) ==30154== by 0x4F5A15: preg_replace_impl (php_pcre.c:1483) ==30154== by 0x4F6076: zif_preg_replace (php_pcre.c:1525) ==30154== by 0x8EC7FC: ZEND_DO_FCALL_BY_NAME_SPEC_HANDLER (zend_vm_execute.h:714) ==30154== by 0x8EBC1E: execute_ex (zend_vm_execute.h:417) ==30154== by 0x87A0DC: zend_call_function (zend_execute_API.c:860) ==30154== by 0x6EA22E: zif_call_user_func_array (basic_functions.c:4811) ==30154== by 0x8EC7FC: ZEND_DO_FCALL_BY_NAME_SPEC_HANDLER (zend_vm_execute.h:714) ==30154== by 0x8EBC1E: execute_ex (zend_vm_execute.h:417) ==30154== Uninitialised value was created by a stack allocation ==30154== at 0x8688FD: zend_compile_method_call (zend_compile.c:3256) ==30154== ==30154== Conditional jump or move depends on uninitialised value(s) ==30154== at 0x4F43F9: preg_get_backref (php_pcre.c:988) ==30154== by 0x4F4D23: php_pcre_replace_impl (php_pcre.c:1203) ==30154== by 0x4F486B: php_pcre_replace (php_pcre.c:1070) ==30154== by 0x4F5641: php_replace_in_subject (php_pcre.c:1403) ==30154== by 0x4F5A15: preg_replace_impl (php_pcre.c:1483) ==30154== by 0x4F6076: zif_preg_replace (php_pcre.c:1525) ==30154== by 0x8EC7FC: ZEND_DO_FCALL_BY_NAME_SPEC_HANDLER (zend_vm_execute.h:714) ==30154== by 0x8EBC1E: execute_ex (zend_vm_execute.h:417) ==30154== by 0x87A0DC: zend_call_function (zend_execute_API.c:860) ==30154== by 0x6EA22E: zif_call_user_func_array (basic_functions.c:4811) ==30154== by 0x8EC7FC: ZEND_DO_FCALL_BY_NAME_SPEC_HANDLER (zend_vm_execute.h:714) ==30154== by 0x8EBC1E: execute_ex (zend_vm_execute.h:417) ==30154== Uninitialised value was created by a stack allocation ==30154== at 0x8688FD: zend_compile_method_call (zend_compile.c:3256) ==30154== ==30154== ==30154== Process terminating with default action of signal 11 (SIGSEGV) ==30154== Bad permissions for mapped region at address 0xB037000 ==30154== at 0x4F4CD1: php_pcre_replace_impl (php_pcre.c:1197) ==30154== by 0x4F486B: php_pcre_replace (php_pcre.c:1070) ==30154== by 0x4F5641: php_replace_in_subject (php_pcre.c:1403) ==30154== by 0x4F5A15: preg_replace_impl (php_pcre.c:1483) ==30154== by 0x4F6076: zif_preg_replace (php_pcre.c:1525) ==30154== by 0x8EC7FC: ZEND_DO_FCALL_BY_NAME_SPEC_HANDLER (zend_vm_execute.h:714) ==30154== by 0x8EBC1E: execute_ex (zend_vm_execute.h:417) ==30154== by 0x87A0DC: zend_call_function (zend_execute_API.c:860) ==30154== by 0x6EA22E: zif_call_user_func_array (basic_functions.c:4811) ==30154== by 0x8EC7FC: ZEND_DO_FCALL_BY_NAME_SPEC_HANDLER (zend_vm_execute.h:714) ==30154== by 0x8EBC1E: execute_ex (zend_vm_execute.h:417) ==30154== by 0x8EBD48: zend_execute (zend_vm_execute.h:458) ==30154== ==30154== HEAP SUMMARY: ==30154== in use at exit: 2,114,167 bytes in 19,195 blocks ==30154== total heap usage: 23,125 allocs, 3,930 frees, 3,644,424 bytes allocated ==30154== ==30154== LEAK SUMMARY: ==30154== definitely lost: 0 bytes in 0 blocks ==30154== indirectly lost: 0 bytes in 0 blocks ==30154== possibly lost: 1,464,606 bytes in 14,788 blocks ==30154== still reachable: 649,561 bytes in 4,407 blocks ==30154== suppressed: 0 bytes in 0 blocks ==30154== Rerun with --leak-check=full to see details of leaked memory ==30154== ==30154== For counts of detected and suppressed errors, rerun with: -v ==30154== ERROR SUMMARY: 11846 errors from 6 contexts (suppressed: 17 from 9) Segmentation fault ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=71537 -- Edit this bug report at https://bugs.php.net/bug.php?id=71537&edit=1

« previous php.bugs (#199093) next »