Bug #71937 [Com]: Php regular expression error with a large pattern

From: Date: Wed, 29 Jun 2016 08:36:23 +0000
Subject: Bug #71937 [Com]: Php regular expression error with a large pattern
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-201899@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=71937&edit=1

 ID:                 71937
 Comment by:         esteban dot marin at bithost dot ch
 Reported by:        aayaresko at gmail dot com
 Summary:            Php regular expression error with a large pattern
 Status:             Open
 Type:               Bug
 Package:            *Regular Expressions
 Operating System:   Linux debian 3.16.0-4-amd64 #1 S
 PHP Version:        7.0.5
 Block user comment: N
 Private report:     N

 New Comment:

we could track down the problem to the version of the pcre extension.

on the system where the issue occurs, we have PCRE Library Version 8.35 2014-04-04
on the system where it works, we have PCRE Library Version 8.38 2015-11-23

So updating the PCRE Library Version by updating the PHP version should fix the problem. However on
our system with Debian + PHP7.0.7 the PCRE Library Version should already be 8.38, but actually is
8.35, so it might not have been included in the debian package.

See also 

https://bugs.php.net/bug.php?id=71659
https://github.com/gplessis/dotdeb-php/issues/124
https://bugs.exim.org/show_bug.cgi?id=1803

A quick-fix if you cannot update: set the following php.ini setting:

pcre.jit = 0


Previous Comments:
------------------------------------------------------------------------
[2016-06-29 07:51:52] esteban dot marin at bithost dot ch

we also have the same issue with a different php software (TYPO3) which only occurs on a specific
hosting system with Debian 8.5+PHP 7.0.8, but does not occur on other systems (Ubuntu14+PHP7.0.6,
Mac OS X 10.11.4+PHP7.0.0, Mac OS X 10.11.4+PHP7.0.8), so it seems to depend on the
configuration/hosting environment:


Core: Error handler (BE): PHP Warning: preg_replace_callback(): Internal pcre_fullinfo() error -4 in
typo3_src-7.6.9/typo3/sysext/core/Classes/Http/Uri.php line 735

An explanation was found here:
http://last-horse.nenicirene.net/viewtopic.php?t=398&sid=8fc16478210b8bc1fcd1c1821de2ae92
PCRE_ERROR_BADMAGIC (-4) 

PCRE stores a 4-byte "magic number" at the start of the compiled code, 
to catch the case when it is passed a junk pointer and to detect when a 
pattern that was compiled in an environment of one endianness is run in 
an environment with the other endianness. This is the error that PCRE 
gives when the magic number is not present.


In typo3_src-7.6.9/typo3/sysext/core/Classes/Http/Uri.php line 735 the following function call is
made:


$a = preg_replace_callback(
            '/(?:[^' . 'a-zA-Z0-9_\-\.~' .
'!\$&\'\(\)\*\+,;=' . '%:@\/\?]+|%(?![A-Fa-f0-9]{2}))/',
            function ($matches) {
                return rawurlencode($matches[0]);
            },
            $value
        );

------------------------------------------------------------------------
[2016-06-29 07:36:19] esteban dot marin at bithost dot ch

hey, we are also experiencing this problem with Debian 8.5+PHP7.0.7-1~dotdeb+8.1.
please also note that others are having the same issue too:
https://github.com/monkeysuffrage/advanced_html_dom/issues/2

------------------------------------------------------------------------
[2016-05-11 05:49:12] aayaresko at gmail dot com

php7 is updated to latest repository version but it still results in sigfault when executing a
script that contains a regex.

root@debian:~# gdb php-cgi7.0
GNU gdb (Debian 7.7.1+dfsg-5) 7.7.1
Copyright (C) 2014 Free Software Foundation, Inc.
License GPLv3+: GNU GPL version 3 or later <http://gnu.org/licenses/gpl.html>
This is free software: you are free to change and redistribute it.
There is NO WARRANTY, to the extent permitted by law.  Type "show copying"
and "show warranty" for details.
This GDB was configured as "x86_64-linux-gnu".
Type "show configuration" for configuration details.
For bug reporting instructions, please see:
<http://www.gnu.org/software/gdb/bugs/>.
Find the GDB manual and other documentation resources online at:
<http://www.gnu.org/software/gdb/documentation/>.
For help, type "help".
Type "apropos word" to search for commands related to "word"...
Reading symbols from php-cgi7.0...(no debugging symbols found)...done.
(gdb) run /var/www/demo/script.php 
Starting program: /usr/bin/php-cgi7.0 /var/www/demo/script.php
[Thread debugging using libthread_db enabled]
Using host libthread_db library "/lib/x86_64-linux-gnu/libthread_db.so.1".
*** Error in `/usr/bin/php-cgi7.0': free(): invalid pointer: 0x00007ffff7f51564 ***

Program received signal SIGABRT, Aborted.
0x00007ffff5899067 in __GI_raise (sig=sig@entry=6) at ../nptl/sysdeps/unix/sysv/linux/raise.c:56
56	../nptl/sysdeps/unix/sysv/linux/raise.c: No such file or directory.
(gdb) bt
#0  0x00007ffff5899067 in __GI_raise (sig=sig@entry=6) at ../nptl/sysdeps/unix/sysv/linux/raise.c:56
#1  0x00007ffff589a448 in __GI_abort () at abort.c:89
#2  0x00007ffff58d71b4 in __libc_message (do_abort=do_abort@entry=1, fmt=fmt@entry=0x7ffff59cc530
"*** Error in `%s': %s: 0x%s ***\n") at ../sysdeps/posix/libc_fatal.c:175
#3  0x00007ffff58dc98e in malloc_printerr (action=1, str=0x7ffff59c8646 "free(): invalid
pointer", ptr=<optimized out>) at malloc.c:4996
#4  0x00007ffff58dd696 in _int_free (av=<optimized out>, p=<optimized out>, have_lock=0)
at malloc.c:3840
#5  0x00007ffff6f1e3f5 in ?? () from /lib/x86_64-linux-gnu/libpcre.so.3
#6  0x00007ffff6f438ef in ?? () from /lib/x86_64-linux-gnu/libpcre.so.3
#7  0x00007ffff6f464a5 in pcre_study () from /lib/x86_64-linux-gnu/libpcre.so.3
#8  0x00000000004af33a in pcre_get_compiled_regex_cache ()
#9  0x00000000004b35fd in ?? ()
#10 0x000000000071f54a in dtrace_execute_internal ()
#11 0x00000000007b4190 in ?? ()
#12 0x000000000076f71b in execute_ex ()
#13 0x000000000071f3d8 in dtrace_execute_ex ()
#14 0x00000000007c39f7 in zend_execute ()
#15 0x000000000072f863 in zend_execute_scripts ()
#16 0x00000000006d0350 in php_execute_script ()
#17 0x000000000046fc22 in main ()

------------------------------------------------------------------------
[2016-04-24 17:16:57] aayareslp at gmail dot com

Thanks for the reply!
It looks like you're right but setting 'unlimited' for 'stack size'  and
enormous '100000000000' for 'pcre.recursion_limit' still results in sigfault
when script executes.

root@debian:/# ulimit -a|grep stack
stack size              (kbytes, -s) unlimited

root@debian:/# cat /etc/php/7.0/cgi/php.ini |grep recursion_limit
pcre.recursion_limit=100000000000

root@debian:/#gdb /usr/bin/php-cgi
(gdb) run /script.php
Starting program: /usr/bin/php-cgi /script.php
[Thread debugging using libthread_db enabled]
Using host libthread_db library "/lib/x86_64-linux-gnu/libthread_db.so.1".
*** Error in `/usr/bin/php-cgi': free(): invalid pointer: 0x00002aaaaaad2564 ***

Program received signal SIGABRT, Aborted.
0x00002aaaaced0067 in __GI_raise (sig=sig@entry=6) at ../nptl/sysdeps/unix/sysv/linux/raise.c:56
56	../nptl/sysdeps/unix/sysv/linux/raise.c: No such file or directory.
(gdb) bt
#0  0x00002aaaaced0067 in __GI_raise (sig=sig@entry=6) at ../nptl/sysdeps/unix/sysv/linux/raise.c:56
#1  0x00002aaaaced1448 in __GI_abort () at abort.c:89
#2  0x00002aaaacf0e1b4 in __libc_message (do_abort=do_abort@entry=1, fmt=fmt@entry=0x2aaaad003530
"*** Error in `%s': %s: 0x%s ***\n") at ../sysdeps/posix/libc_fatal.c:175
#3  0x00002aaaacf1398e in malloc_printerr (action=1, str=0x2aaaacfff646 "free(): invalid
pointer", ptr=<optimized out>) at malloc.c:4996
#4  0x00002aaaacf14696 in _int_free (av=<optimized out>, p=<optimized out>, have_lock=0)
at malloc.c:3840
#5  0x00002aaaab96c3f5 in ?? () from /lib/x86_64-linux-gnu/libpcre.so.3
#6  0x00002aaaab9918ef in ?? () from /lib/x86_64-linux-gnu/libpcre.so.3
#7  0x00002aaaab9944a5 in pcre_study () from /lib/x86_64-linux-gnu/libpcre.so.3
#8  0x00000000004af0ca in pcre_get_compiled_regex_cache ()
#9  0x00000000004b0696 in ?? ()
#10 0x000000000071eb7a in dtrace_execute_internal ()
#11 0x00000000007b3370 in ?? ()
#12 0x000000000076e8ab in execute_ex ()
#13 0x000000000071ea08 in dtrace_execute_ex ()
#14 0x00000000007c27f7 in zend_execute ()
#15 0x000000000072ee83 in zend_execute_scripts ()
#16 0x00000000006cfb20 in php_execute_script ()
#17 0x000000000046fa12 in main ()

------------------------------------------------------------------------
[2016-04-24 16:18:43] pajoye@php.net

For php processes. This pattern looks like it will cause issue with the stack depending on the match
and/or recursion level.

For example for apache (the apache config is the same for linux)/windows:

http://stackoverflow.com/questions/5058845/how-do-i-increase-the-stack-size-for-apache-running-under-windows-7

or see
http://stackoverflow.com/questions/7535994/how-do-i-find-the-maximum-stack-size

------------------------------------------------------------------------


The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at

    https://bugs.php.net/bug.php?id=71937


--
Edit this bug report at https://bugs.php.net/bug.php?id=71937&edit=1


Thread (23 messages)

« previous php.bugs (#201899) next »