Edit report at https://bugs.php.net/bug.php?id=71659&edit=1
ID: 71659
Comment by: nish dot aravamudan at canonical dot com
Reported by: nish dot aravamudan at canonical dot com
Summary: segmentation fault in pcre running twig tests
Status: Open
Type: Bug
Package: Reproducible crash
Operating System: Ubuntu 16.04
PHP Version: 7.0.3
Block user comment: N
Private report: N
New Comment:
I was probably overconfident in my ability to understand the PHP code :)
But now I think the correct fix is:
Index: gitwd/ext/pcre/php_pcre.c
===================================================================
--- gitwd.orig/ext/pcre/php_pcre.c
+++ gitwd/ext/pcre/php_pcre.c
@@ -1848,6 +1848,10 @@ PHPAPI void php_pcre_split_impl(pcre_cac
RETURN_FALSE;
}
}
+#ifdef PCRE_EXTRA_MARK
+ extra_bump->mark = NULL;
+ extra_bump->flags &= ~PCRE_EXTRA_MARK;
+#endif
count = pcre_exec(re_bump, extra_bump, subject,
subject_len, start_offset,
exoptions, offsets, size_offsets);
Previous Comments:
------------------------------------------------------------------------
[2016-03-08 23:00:40] nish dot aravamudan at canonical dot com
If I understand this right, that should rather be:
+ extra->mark = NULL;
------------------------------------------------------------------------
[2016-03-08 22:48:35] nish dot aravamudan at canonical dot com
I'm going to test a new version of PHP7.0 that has a small adjustment to php_
--- php7.0-7.0.3.orig/ext/pcre/php_pcre.c
+++ php7.0-7.0.3/ext/pcre/php_pcre.c
@@ -1761,6 +1761,7 @@ PHPAPI void php_pcre_split_impl(pcre_cac
extra->match_limit = (unsigned long)PCRE_G(backtrack_limit);
extra->match_limit_recursion = (unsigned long)PCRE_G(recursion_limit);
#ifdef PCRE_EXTRA_MARK
+ extra->mark = &mark;
extra->flags &= ~PCRE_EXTRA_MARK;
#endif
Commit https://github.com/php/php-src/commit/376ab3b7873ca04142185d8c08dbb4c4be152474
(and presumably others based upon the current state of the code) modified the other functions to
avoid ->mark corruption. I don't know why this only shows up with JIT, but perhaps the
->mark value is not clobbered except if JIT is used.
------------------------------------------------------------------------
[2016-03-02 21:22:39] inefedor at gmail dot com
Probably when phpunit runs tests in different process, it uses another php binary or another set of
php.ini settings.
------------------------------------------------------------------------
[2016-03-02 16:45:14] nish dot aravamudan at canonical dot com
https://bugs.exim.org/show_bug.cgi?id=1803
filed.
However, two updates from my testing last night.
1) The twig testsuite is run using phpunit. phpunit has a parameter --process-isolation. When the
tests are run with that parameter, the tests pass (even with pcre.jit left on). This, I think,
points to a PHP bug, but I'm not sure.
2) When I tried to just run the failing twig tests on their own (split_utf8.test and
length_utf8.test are the two input files), I could not recreate the segmentation fault. This again,
it feels like, points to a fault somewhere in the php logic due to some corrupt state, perhaps?
------------------------------------------------------------------------
[2016-02-28 08:38:43] pajoye@php.net
One of the JIT bugs in pcre. It should be reported upstream.
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=71659
--
Edit this bug report at https://bugs.php.net/bug.php?id=71659&edit=1