Edit report at https://bugs.php.net/bug.php?id=71937&edit=1
ID: 71937
Comment by: aayaresko at gmail dot com
Reported by: aayaresko at gmail dot com
Summary: Php regular expression error with a large pattern
Status: Open
Type: Bug
Package: *Regular Expressions
Operating System: Linux debian 3.16.0-4-amd64 #1 S
PHP Version: 7.0.5
Block user comment: N
Private report: N
New Comment:
php7 is updated to latest repository version but it still results in sigfault when executing a
script that contains a regex.
root@debian:~# gdb php-cgi7.0
GNU gdb (Debian 7.7.1+dfsg-5) 7.7.1
Copyright (C) 2014 Free Software Foundation, Inc.
License GPLv3+: GNU GPL version 3 or later <http://gnu.org/licenses/gpl.html>
This is free software: you are free to change and redistribute it.
There is NO WARRANTY, to the extent permitted by law. Type "show copying"
and "show warranty" for details.
This GDB was configured as "x86_64-linux-gnu".
Type "show configuration" for configuration details.
For bug reporting instructions, please see:
<http://www.gnu.org/software/gdb/bugs/>.
Find the GDB manual and other documentation resources online at:
<http://www.gnu.org/software/gdb/documentation/>.
For help, type "help".
Type "apropos word" to search for commands related to "word"...
Reading symbols from php-cgi7.0...(no debugging symbols found)...done.
(gdb) run /var/www/demo/script.php
Starting program: /usr/bin/php-cgi7.0 /var/www/demo/script.php
[Thread debugging using libthread_db enabled]
Using host libthread_db library "/lib/x86_64-linux-gnu/libthread_db.so.1".
*** Error in `/usr/bin/php-cgi7.0': free(): invalid pointer: 0x00007ffff7f51564 ***
Program received signal SIGABRT, Aborted.
0x00007ffff5899067 in __GI_raise (sig=sig@entry=6) at ../nptl/sysdeps/unix/sysv/linux/raise.c:56
56 ../nptl/sysdeps/unix/sysv/linux/raise.c: No such file or directory.
(gdb) bt
#0 0x00007ffff5899067 in __GI_raise (sig=sig@entry=6) at ../nptl/sysdeps/unix/sysv/linux/raise.c:56
#1 0x00007ffff589a448 in __GI_abort () at abort.c:89
#2 0x00007ffff58d71b4 in __libc_message (do_abort=do_abort@entry=1, fmt=fmt@entry=0x7ffff59cc530
"*** Error in `%s': %s: 0x%s ***\n") at ../sysdeps/posix/libc_fatal.c:175
#3 0x00007ffff58dc98e in malloc_printerr (action=1, str=0x7ffff59c8646 "free(): invalid
pointer", ptr=<optimized out>) at malloc.c:4996
#4 0x00007ffff58dd696 in _int_free (av=<optimized out>, p=<optimized out>, have_lock=0)
at malloc.c:3840
#5 0x00007ffff6f1e3f5 in ?? () from /lib/x86_64-linux-gnu/libpcre.so.3
#6 0x00007ffff6f438ef in ?? () from /lib/x86_64-linux-gnu/libpcre.so.3
#7 0x00007ffff6f464a5 in pcre_study () from /lib/x86_64-linux-gnu/libpcre.so.3
#8 0x00000000004af33a in pcre_get_compiled_regex_cache ()
#9 0x00000000004b35fd in ?? ()
#10 0x000000000071f54a in dtrace_execute_internal ()
#11 0x00000000007b4190 in ?? ()
#12 0x000000000076f71b in execute_ex ()
#13 0x000000000071f3d8 in dtrace_execute_ex ()
#14 0x00000000007c39f7 in zend_execute ()
#15 0x000000000072f863 in zend_execute_scripts ()
#16 0x00000000006d0350 in php_execute_script ()
#17 0x000000000046fc22 in main ()
Previous Comments:
------------------------------------------------------------------------
[2016-04-24 17:16:57] aayareslp at gmail dot com
Thanks for the reply!
It looks like you're right but setting 'unlimited' for 'stack size' and
enormous '100000000000' for 'pcre.recursion_limit' still results in sigfault
when script executes.
root@debian:/# ulimit -a|grep stack
stack size (kbytes, -s) unlimited
root@debian:/# cat /etc/php/7.0/cgi/php.ini |grep recursion_limit
pcre.recursion_limit=100000000000
root@debian:/#gdb /usr/bin/php-cgi
(gdb) run /script.php
Starting program: /usr/bin/php-cgi /script.php
[Thread debugging using libthread_db enabled]
Using host libthread_db library "/lib/x86_64-linux-gnu/libthread_db.so.1".
*** Error in `/usr/bin/php-cgi': free(): invalid pointer: 0x00002aaaaaad2564 ***
Program received signal SIGABRT, Aborted.
0x00002aaaaced0067 in __GI_raise (sig=sig@entry=6) at ../nptl/sysdeps/unix/sysv/linux/raise.c:56
56 ../nptl/sysdeps/unix/sysv/linux/raise.c: No such file or directory.
(gdb) bt
#0 0x00002aaaaced0067 in __GI_raise (sig=sig@entry=6) at ../nptl/sysdeps/unix/sysv/linux/raise.c:56
#1 0x00002aaaaced1448 in __GI_abort () at abort.c:89
#2 0x00002aaaacf0e1b4 in __libc_message (do_abort=do_abort@entry=1, fmt=fmt@entry=0x2aaaad003530
"*** Error in `%s': %s: 0x%s ***\n") at ../sysdeps/posix/libc_fatal.c:175
#3 0x00002aaaacf1398e in malloc_printerr (action=1, str=0x2aaaacfff646 "free(): invalid
pointer", ptr=<optimized out>) at malloc.c:4996
#4 0x00002aaaacf14696 in _int_free (av=<optimized out>, p=<optimized out>, have_lock=0)
at malloc.c:3840
#5 0x00002aaaab96c3f5 in ?? () from /lib/x86_64-linux-gnu/libpcre.so.3
#6 0x00002aaaab9918ef in ?? () from /lib/x86_64-linux-gnu/libpcre.so.3
#7 0x00002aaaab9944a5 in pcre_study () from /lib/x86_64-linux-gnu/libpcre.so.3
#8 0x00000000004af0ca in pcre_get_compiled_regex_cache ()
#9 0x00000000004b0696 in ?? ()
#10 0x000000000071eb7a in dtrace_execute_internal ()
#11 0x00000000007b3370 in ?? ()
#12 0x000000000076e8ab in execute_ex ()
#13 0x000000000071ea08 in dtrace_execute_ex ()
#14 0x00000000007c27f7 in zend_execute ()
#15 0x000000000072ee83 in zend_execute_scripts ()
#16 0x00000000006cfb20 in php_execute_script ()
#17 0x000000000046fa12 in main ()
------------------------------------------------------------------------
[2016-04-24 16:18:43] pajoye@php.net
For php processes. This pattern looks like it will cause issue with the stack depending on the match
and/or recursion level.
For example for apache (the apache config is the same for linux)/windows:
http://stackoverflow.com/questions/5058845/how-do-i-increase-the-stack-size-for-apache-running-under-windows-7
or see
http://stackoverflow.com/questions/7535994/how-do-i-find-the-maximum-stack-size
------------------------------------------------------------------------
[2016-04-24 10:41:45] aayaresko at gmail dot com
Thanks for the reply!
You mean gdb-stack?
I'm sorry but could you please give me some hint on how to do that?
------------------------------------------------------------------------
[2016-04-24 09:48:57] pajoye@php.net
I would suggest to increase the stack as it is most likely exhausted.
------------------------------------------------------------------------
[2016-04-24 08:39:05] aayareslp at gmail dot com
And here one more backtrace from virtualbox guest:
#0 0x00007f4d76333067 in __GI_raise (sig=sig@entry=6) at ../nptl/sysdeps/unix/sysv/linux/raise.c:56
56 ../nptl/sysdeps/unix/sysv/linux/raise.c: No such file or directory.
(gdb) bt
#0 0x00007f4d76333067 in __GI_raise (sig=sig@entry=6) at ../nptl/sysdeps/unix/sysv/linux/raise.c:56
#1 0x00007f4d76334448 in __GI_abort () at abort.c:89
#2 0x00007f4d763711b4 in __libc_message (do_abort=do_abort@entry=1, fmt=fmt@entry=0x7f4d76466530
"*** Error in `%s': %s: 0x%s ***\n") at ../sysdeps/posix/libc_fatal.c:175
#3 0x00007f4d7637698e in malloc_printerr (action=1, str=0x7f4d76462646 "free(): invalid
pointer", ptr=<optimized out>) at malloc.c:4996
#4 0x00007f4d76377696 in _int_free (av=<optimized out>, p=<optimized out>, have_lock=0)
at malloc.c:3840
#5 0x00007f4d779b83f5 in ?? () from /lib/x86_64-linux-gnu/libpcre.so.3
#6 0x00007f4d779dd8ef in ?? () from /lib/x86_64-linux-gnu/libpcre.so.3
#7 0x00007f4d779e04a5 in pcre_study () from /lib/x86_64-linux-gnu/libpcre.so.3
#8 0x00000000004af0ca in pcre_get_compiled_regex_cache ()
#9 0x00000000004b0696 in ?? ()
#10 0x000000000071eb7a in dtrace_execute_internal ()
#11 0x00000000007b3370 in ?? ()
#12 0x000000000076e8ab in execute_ex ()
#13 0x000000000071ea08 in dtrace_execute_ex ()
#14 0x00000000007c27f7 in zend_execute ()
#15 0x000000000072ee83 in zend_execute_scripts ()
#16 0x00000000006cfb20 in php_execute_script ()
#17 0x000000000046fa12 in main ()
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=71937
--
Edit this bug report at https://bugs.php.net/bug.php?id=71937&edit=1