Edit report at https://bugs.php.net/bug.php?id=71982&edit=1
ID: 71982
Updated by: cmb@php.net
Reported by: s dot chernomor at gmail dot com
Summary: Segmentation fault
-Status: Feedback
+Status: Open
Type: Bug
Package: PCRE related
Operating System: centos7
PHP Version: 7.0.5
-Assigned To: cmb
+Assigned To:
Block user comment: N
Private report: N
New Comment:
> pcre-8.32-15.el7_2.1.x86_64
Hm, PCRE 8.32 has been released 2012-11-30. I don't know which
fixed have been applied to -15.el7_2.1, but those fixes may not
have been sufficient.
Previous Comments:
------------------------------------------------------------------------
[2016-08-22 08:10:34] s dot chernomorets at gmail dot com
Max stack size = 10240000
------------------------------------------------------------------------
[2016-08-22 08:03:43] s dot chernomorets at gmail dot com
httpd-2.4.6-40.el7.centos.4.x86_64
pcre-8.32-15.el7_2.1.x86_64
php-7.0.10
# gdb /usr/sbin/httpd /tmp/core.31035
GNU gdb (GDB) Red Hat Enterprise Linux 7.6.1-80.el7
Copyright (C) 2013 Free Software Foundation, Inc.
License GPLv3+: GNU GPL version 3 or later <http://gnu.org/licenses/gpl.html>
This is free software: you are free to change and redistribute it.
There is NO WARRANTY, to the extent permitted by law. Type "show copying"
and "show warranty" for details.
This GDB was configured as "x86_64-redhat-linux-gnu".
For bug reporting instructions, please see:
<http://www.gnu.org/software/gdb/bugs/>...
Reading symbols from /usr/sbin/httpd...Reading symbols from
/usr/lib/debug/usr/sbin/httpd.debug...done.
done.
[New LWP 31035]
[Thread debugging using libthread_db enabled]
Using host libthread_db library "/lib64/libthread_db.so.1".
Core was generated by `/usr/sbin/httpd -DFOREGROUND'.
Program terminated with signal 11, Segmentation fault.
#0 0x00007f02e0d53f23 in sljit_remove_free_block (free_block=0x7f02d178ad38,
free_block=0x7f02d178ad38) at sljit/sljitExecAllocator.c:165
165 free_block->next->prev = free_block->prev;
(gdb)
(gdb)
(gdb)
(gdb) where
#0 0x00007f02e0d53f23 in sljit_remove_free_block (free_block=0x7f02d178ad38,
free_block=0x7f02d178ad38) at sljit/sljitExecAllocator.c:165
#1 sljit_free_exec (ptr=0x7f02d178ab10) at sljit/sljitExecAllocator.c:273
#2 0x00007f02e0d70eba in sljit_free_code (code=<optimized out>) at sljit/sljitLir.c:397
#3 _pcre_jit_free (executable_funcs=0x7f02e1dcff50) at pcre_jit_compile.c:8419
#4 0x00007f02e0d72a1c in pcre_free_study (extra=0x7f02e205e9b0) at pcre_study.c:1557
#5 0x00007f02da9ecfc3 in php_free_pcre_cache (data=<optimized out>) at
/usr/src/debug/php-7.0.10/ext/pcre/php_pcre.c:113
#6 0x00007f02dad312e1 in zend_hash_destroy (ht=0x7f02db655720 <pcre_globals>) at
/usr/src/debug/php-7.0.10/Zend/zend_hash.c:1284
#7 0x00007f02da9ecf49 in zm_globals_dtor_pcre (pcre_globals=<optimized out>) at
/usr/src/debug/php-7.0.10/ext/pcre/php_pcre.c:136
#8 0x00007f02dad274a9 in module_destructor (module=module@entry=0x7f02e1cfae30) at
/usr/src/debug/php-7.0.10/Zend/zend_API.c:2516
#9 0x00007f02dad1fffc in module_destructor_zval (zv=<optimized out>) at
/usr/src/debug/php-7.0.10/Zend/zend.c:615
#10 0x00007f02dad31e08 in _zend_hash_del_el_ex (prev=<optimized out>, p=<optimized out>,
idx=<optimized out>, ht=<optimized out>)
at /usr/src/debug/php-7.0.10/Zend/zend_hash.c:1026
#11 _zend_hash_del_el (p=0x7f02e1d15c00, idx=4, ht=0x7f02db65c440 <module_registry>) at
/usr/src/debug/php-7.0.10/Zend/zend_hash.c:1050
#12 zend_hash_graceful_reverse_destroy (ht=ht@entry=0x7f02db65c440 <module_registry>) at
/usr/src/debug/php-7.0.10/Zend/zend_hash.c:1502
#13 0x00007f02dad258cc in zend_destroy_modules () at /usr/src/debug/php-7.0.10/Zend/zend_API.c:1984
#14 0x00007f02dad20f65 in zend_shutdown () at /usr/src/debug/php-7.0.10/Zend/zend.c:840
#15 0x00007f02dacc5a6b in php_module_shutdown () at /usr/src/debug/php-7.0.10/main/main.c:2362
#16 0x00007f02dacc5b29 in php_module_shutdown_wrapper (sapi_globals=<optimized out>) at
/usr/src/debug/php-7.0.10/main/main.c:2330
#17 0x00007f02dada7681 in php_apache_child_shutdown (tmp=<optimized out>) at
/usr/src/debug/php-7.0.10/sapi/apache2handler/sapi_apache2.c:399
#18 0x00007f02dfeaa1ae in apr_pool_destroy () from /lib64/libapr-1.so.0
#19 0x00007f02dcc1223c in clean_child_exit (code=code@entry=0) at prefork.c:221
#20 0x00007f02dcc126e7 in child_main (child_num_arg=child_num_arg@entry=17) at prefork.c:728
#21 0x00007f02dcc12a55 in make_child (s=0x7f02e1b40320, slot=slot@entry=17) at prefork.c:810
#22 0x00007f02dcc12ab6 in startup_children (number_to_start=83) at prefork.c:828
#23 0x00007f02dcc137c0 in prefork_run (_pconf=<optimized out>, plog=0x7f02e1b44358,
s=0x7f02e1b40320) at prefork.c:986
#24 0x00007f02e11d75be in ap_run_mpm (pconf=pconf@entry=0x7f02e1b17138, plog=0x7f02e1b44358,
s=0x7f02e1b40320) at mpm_common.c:96
#25 0x00007f02e11d0b46 in main (argc=2, argv=0x7ffcd95b0788) at main.c:777
------------------------------------------------------------------------
[2016-08-21 10:28:11] cmb@php.net
> PCRE Library Version => 8.38 2015-11-23
Thanks. That version should be fine.
I assume that the segfault caused by sljit_remove_free_block ()
occurred due to the JIT stack being too small. That has been
corrected as of PHP 7.0.6[1], so please try with a a newer version
and pcre.jit=1.
[1] <https://github.com/php/php-src/commit/e23a4122>
------------------------------------------------------------------------
[2016-08-20 17:50:24] s dot chernomorets at gmail dot com
pcre
PCRE (Perl Compatible Regular Expressions) Support => enabled
PCRE Library Version => 8.38 2015-11-23
PCRE JIT Support => enabled
Directive => Local Value => Master Value
pcre.backtrack_limit => 1000000 => 1000000
pcre.jit => 0 => 0
pcre.recursion_limit => 100000 => 100000
pcre-8.32-15.el7.x86_64
------------------------------------------------------------------------
[2016-08-20 13:26:56] cmb@php.net
What's your PCRE_VERSION?
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=71982
--
Edit this bug report at https://bugs.php.net/bug.php?id=71982&edit=1