Bug #71537 [Opn->Csd]: PCRE segfault from Opcache
| From: | laruence@php.net | Date: | Sun, 07 Feb 2016 15:39:17 +0000 |
| Subject: | Bug #71537 [Opn->Csd]: PCRE segfault from Opcache | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-199093@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=71537&edit=1
ID: 71537
Updated by: laruence@php.net
Reported by: max dot goldberg at gmail dot com
Summary: PCRE segfault from Opcache
-Status: Open
+Status: Closed
Type: Bug
Package: opcache
Operating System: Debian/Centos
PHP Version: 7.0.3
-Assigned To:
+Assigned To: laruence
Block user comment: N
Private report: N
New Comment:
The fix for this bug has been committed.
Snapshots of the sources are packaged every three hours; this change
will be in the next snapshot. You can grab the snapshot at
http://snaps.php.net/.
For Windows:
http://windows.php.net/snapshots/
Thank you for the report, and for helping us make PHP better.
Previous Comments:
------------------------------------------------------------------------
[2016-02-07 15:20:59] laruence@php.net
thanks max, it has been fixed, your help is appreciated..
anyway, your local php-src has been patched. so, you might need clean it :<
thanks
------------------------------------------------------------------------
[2016-02-07 15:19:50] laruence@php.net
Automatic comment on behalf of laruence@gmail.com
Revision: http://git.php.net/?p=php-src.git;a=commit;h=336e39f2b194e1425dc363abd18554f60c80bed1
Log: Fixed bug #71537 (PCRE segfault from Opcache)
------------------------------------------------------------------------
[2016-02-07 10:33:07] max dot goldberg at gmail dot com
Credentials sent!
------------------------------------------------------------------------
[2016-02-07 09:15:46] laruence@php.net
is that possible you could grant me a ssh access to the reproducible box? (via mail)
thanks
------------------------------------------------------------------------
[2016-02-06 15:28:07] max dot goldberg at gmail dot com
As with the built-in server, the first hit, pre-opcache goes fine, and the segfault occurs on the
second hit. Here's the valgrind result from the second hit, let me know if you need it run with
specific options:
==30154== Conditional jump or move depends on uninitialised value(s)
==30154== at 0x4F4CD6: php_pcre_replace_impl (php_pcre.c:1197)
==30154== by 0x4F486B: php_pcre_replace (php_pcre.c:1070)
==30154== by 0x4F5641: php_replace_in_subject (php_pcre.c:1403)
==30154== by 0x4F5A15: preg_replace_impl (php_pcre.c:1483)
==30154== by 0x4F6076: zif_preg_replace (php_pcre.c:1525)
==30154== by 0x8EC7FC: ZEND_DO_FCALL_BY_NAME_SPEC_HANDLER (zend_vm_execute.h:714)
==30154== by 0x8EBC1E: execute_ex (zend_vm_execute.h:417)
==30154== by 0x87A0DC: zend_call_function (zend_execute_API.c:860)
==30154== by 0x6EA22E: zif_call_user_func_array (basic_functions.c:4811)
==30154== by 0x8EC7FC: ZEND_DO_FCALL_BY_NAME_SPEC_HANDLER (zend_vm_execute.h:714)
==30154== by 0x8EBC1E: execute_ex (zend_vm_execute.h:417)
==30154== by 0x8EBD48: zend_execute (zend_vm_execute.h:458)
==30154==
==30154== Conditional jump or move depends on uninitialised value(s)
==30154== at 0x4F4CE4: php_pcre_replace_impl (php_pcre.c:1197)
==30154== by 0x4F486B: php_pcre_replace (php_pcre.c:1070)
==30154== by 0x4F5641: php_replace_in_subject (php_pcre.c:1403)
==30154== by 0x4F5A15: preg_replace_impl (php_pcre.c:1483)
==30154== by 0x4F6076: zif_preg_replace (php_pcre.c:1525)
==30154== by 0x8EC7FC: ZEND_DO_FCALL_BY_NAME_SPEC_HANDLER (zend_vm_execute.h:714)
==30154== by 0x8EBC1E: execute_ex (zend_vm_execute.h:417)
==30154== by 0x87A0DC: zend_call_function (zend_execute_API.c:860)
==30154== by 0x6EA22E: zif_call_user_func_array (basic_functions.c:4811)
==30154== by 0x8EC7FC: ZEND_DO_FCALL_BY_NAME_SPEC_HANDLER (zend_vm_execute.h:714)
==30154== by 0x8EBC1E: execute_ex (zend_vm_execute.h:417)
==30154== by 0x8EBD48: zend_execute (zend_vm_execute.h:458)
==30154==
==30154== Conditional jump or move depends on uninitialised value(s)
==30154== at 0x4F4CEE: php_pcre_replace_impl (php_pcre.c:1198)
==30154== by 0x4F486B: php_pcre_replace (php_pcre.c:1070)
==30154== by 0x4F5641: php_replace_in_subject (php_pcre.c:1403)
==30154== by 0x4F5A15: preg_replace_impl (php_pcre.c:1483)
==30154== by 0x4F6076: zif_preg_replace (php_pcre.c:1525)
==30154== by 0x8EC7FC: ZEND_DO_FCALL_BY_NAME_SPEC_HANDLER (zend_vm_execute.h:714)
==30154== by 0x8EBC1E: execute_ex (zend_vm_execute.h:417)
==30154== by 0x87A0DC: zend_call_function (zend_execute_API.c:860)
==30154== by 0x6EA22E: zif_call_user_func_array (basic_functions.c:4811)
==30154== by 0x8EC7FC: ZEND_DO_FCALL_BY_NAME_SPEC_HANDLER (zend_vm_execute.h:714)
==30154== by 0x8EBC1E: execute_ex (zend_vm_execute.h:417)
==30154== by 0x8EBD48: zend_execute (zend_vm_execute.h:458)
==30154== Uninitialised value was created by a stack allocation
==30154== at 0x8688FD: zend_compile_method_call (zend_compile.c:3256)
==30154==
==30154== Conditional jump or move depends on uninitialised value(s)
==30154== at 0x4F43C8: preg_get_backref (php_pcre.c:979)
==30154== by 0x4F4D23: php_pcre_replace_impl (php_pcre.c:1203)
==30154== by 0x4F486B: php_pcre_replace (php_pcre.c:1070)
==30154== by 0x4F5641: php_replace_in_subject (php_pcre.c:1403)
==30154== by 0x4F5A15: preg_replace_impl (php_pcre.c:1483)
==30154== by 0x4F6076: zif_preg_replace (php_pcre.c:1525)
==30154== by 0x8EC7FC: ZEND_DO_FCALL_BY_NAME_SPEC_HANDLER (zend_vm_execute.h:714)
==30154== by 0x8EBC1E: execute_ex (zend_vm_execute.h:417)
==30154== by 0x87A0DC: zend_call_function (zend_execute_API.c:860)
==30154== by 0x6EA22E: zif_call_user_func_array (basic_functions.c:4811)
==30154== by 0x8EC7FC: ZEND_DO_FCALL_BY_NAME_SPEC_HANDLER (zend_vm_execute.h:714)
==30154== by 0x8EBC1E: execute_ex (zend_vm_execute.h:417)
==30154== Uninitialised value was created by a stack allocation
==30154== at 0x8688FD: zend_compile_method_call (zend_compile.c:3256)
==30154==
==30154== Conditional jump or move depends on uninitialised value(s)
==30154== at 0x4F43D9: preg_get_backref (php_pcre.c:982)
==30154== by 0x4F4D23: php_pcre_replace_impl (php_pcre.c:1203)
==30154== by 0x4F486B: php_pcre_replace (php_pcre.c:1070)
==30154== by 0x4F5641: php_replace_in_subject (php_pcre.c:1403)
==30154== by 0x4F5A15: preg_replace_impl (php_pcre.c:1483)
==30154== by 0x4F6076: zif_preg_replace (php_pcre.c:1525)
==30154== by 0x8EC7FC: ZEND_DO_FCALL_BY_NAME_SPEC_HANDLER (zend_vm_execute.h:714)
==30154== by 0x8EBC1E: execute_ex (zend_vm_execute.h:417)
==30154== by 0x87A0DC: zend_call_function (zend_execute_API.c:860)
==30154== by 0x6EA22E: zif_call_user_func_array (basic_functions.c:4811)
==30154== by 0x8EC7FC: ZEND_DO_FCALL_BY_NAME_SPEC_HANDLER (zend_vm_execute.h:714)
==30154== by 0x8EBC1E: execute_ex (zend_vm_execute.h:417)
==30154== Uninitialised value was created by a stack allocation
==30154== at 0x8688FD: zend_compile_method_call (zend_compile.c:3256)
==30154==
==30154== Conditional jump or move depends on uninitialised value(s)
==30154== at 0x4F43F9: preg_get_backref (php_pcre.c:988)
==30154== by 0x4F4D23: php_pcre_replace_impl (php_pcre.c:1203)
==30154== by 0x4F486B: php_pcre_replace (php_pcre.c:1070)
==30154== by 0x4F5641: php_replace_in_subject (php_pcre.c:1403)
==30154== by 0x4F5A15: preg_replace_impl (php_pcre.c:1483)
==30154== by 0x4F6076: zif_preg_replace (php_pcre.c:1525)
==30154== by 0x8EC7FC: ZEND_DO_FCALL_BY_NAME_SPEC_HANDLER (zend_vm_execute.h:714)
==30154== by 0x8EBC1E: execute_ex (zend_vm_execute.h:417)
==30154== by 0x87A0DC: zend_call_function (zend_execute_API.c:860)
==30154== by 0x6EA22E: zif_call_user_func_array (basic_functions.c:4811)
==30154== by 0x8EC7FC: ZEND_DO_FCALL_BY_NAME_SPEC_HANDLER (zend_vm_execute.h:714)
==30154== by 0x8EBC1E: execute_ex (zend_vm_execute.h:417)
==30154== Uninitialised value was created by a stack allocation
==30154== at 0x8688FD: zend_compile_method_call (zend_compile.c:3256)
==30154==
==30154==
==30154== Process terminating with default action of signal 11 (SIGSEGV)
==30154== Bad permissions for mapped region at address 0xB037000
==30154== at 0x4F4CD1: php_pcre_replace_impl (php_pcre.c:1197)
==30154== by 0x4F486B: php_pcre_replace (php_pcre.c:1070)
==30154== by 0x4F5641: php_replace_in_subject (php_pcre.c:1403)
==30154== by 0x4F5A15: preg_replace_impl (php_pcre.c:1483)
==30154== by 0x4F6076: zif_preg_replace (php_pcre.c:1525)
==30154== by 0x8EC7FC: ZEND_DO_FCALL_BY_NAME_SPEC_HANDLER (zend_vm_execute.h:714)
==30154== by 0x8EBC1E: execute_ex (zend_vm_execute.h:417)
==30154== by 0x87A0DC: zend_call_function (zend_execute_API.c:860)
==30154== by 0x6EA22E: zif_call_user_func_array (basic_functions.c:4811)
==30154== by 0x8EC7FC: ZEND_DO_FCALL_BY_NAME_SPEC_HANDLER (zend_vm_execute.h:714)
==30154== by 0x8EBC1E: execute_ex (zend_vm_execute.h:417)
==30154== by 0x8EBD48: zend_execute (zend_vm_execute.h:458)
==30154==
==30154== HEAP SUMMARY:
==30154== in use at exit: 2,114,167 bytes in 19,195 blocks
==30154== total heap usage: 23,125 allocs, 3,930 frees, 3,644,424 bytes allocated
==30154==
==30154== LEAK SUMMARY:
==30154== definitely lost: 0 bytes in 0 blocks
==30154== indirectly lost: 0 bytes in 0 blocks
==30154== possibly lost: 1,464,606 bytes in 14,788 blocks
==30154== still reachable: 649,561 bytes in 4,407 blocks
==30154== suppressed: 0 bytes in 0 blocks
==30154== Rerun with --leak-check=full to see details of leaked memory
==30154==
==30154== For counts of detected and suppressed errors, rerun with: -v
==30154== ERROR SUMMARY: 11846 errors from 6 contexts (suppressed: 17 from 9)
Segmentation fault
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=71537
--
Edit this bug report at https://bugs.php.net/bug.php?id=71537&edit=1