Bug #71647 [Com]: Recursive (?R) regexp crashes PHP7.0-FPM
| From: | adaur dot underground at gmail dot com | Date: | Sun, 28 Aug 2016 09:41:49 +0000 |
| Subject: | Bug #71647 [Com]: Recursive (?R) regexp crashes PHP7.0-FPM | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-203626@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=71647&edit=1
ID: 71647
Comment by: adaur dot underground at gmail dot com
Reported by: adaur dot underground at gmail dot com
Summary: Recursive (?R) regexp crashes PHP7.0-FPM
Status: No Feedback
Type: Bug
Package: PCRE related
Operating System: Debian 8
PHP Version: 7.0.3
Assigned To: cmb
Block user comment: N
Private report: N
New Comment:
Hello,
Sorry for the delay.
Disabling the jit options does the trick. Indeed, my version of PHP7 was bundled with PRCE 8.35.
I'll ask the package's maintainer to update it.
Previous Comments:
------------------------------------------------------------------------
[2016-08-28 04:22:31] php-bugs at lists dot php dot net
No feedback was provided. The bug is being suspended because
we assume that you are no longer experiencing the problem.
If this is not the case and you are able to provide the
information that was requested earlier, please do so and
change the status of the bug back to "Re-Opened". Thank you.
------------------------------------------------------------------------
[2016-08-20 10:36:22] cmb@php.net
This issue may be caused by pcre.jit=1. Please try with
pcre.jit=0. Also check PCRE_VERSION; 8.35 is known to cause some
issues regarding the JIT. Try with 8.38.
------------------------------------------------------------------------
[2016-02-22 22:57:41] adaur dot underground at gmail dot com
Thank you for your answer.
As you may have guessed, this is a regexp used to parse BBCode in a forum script. Every time the
parser is called, the page crashes, hence any input seems to trigger the bug.
I have tried with a simple dot (.), crashes too.
------------------------------------------------------------------------
[2016-02-22 22:36:37] nikic@php.net
Can you please also provide the input you're matching against?
------------------------------------------------------------------------
[2016-02-22 22:34:48] adaur dot underground at gmail dot com
This is the regex that causes the crash (it's long, but you can skip to the end):
're_bbcode' => '% # re_bbcode Rev:20110220_1200
# First, match opening tag of syntax: "[TAGNAME (= ("\')ATTRIBUTE("\')
)]";
\[ # Match opening bracket of outermost opening TAGNAME tag.
(?>(%taglist%)\s*+) # $1:
(?> # Atomically group remainder of opening tag.
(?: # Optional attribute.
(=)\s*+ # $2: = Optional attribute\'s equals sign delimiter, ws.
(?: # Group for 1-line attribute value alternatives.
\'([^\'\r\n\\\\]*+(?:\\\\.[^\'\r\n\\\\]*+)*+)\' # Either $3: == single
quoted,
| "([^"\r\n\\\\]*+(?:\\\\.[^"\r\n\\\\]*+)*+)" # or $4: == double
quoted,
| ( [^[\]\r\n]*+ # or $5: == un-or-any-quoted. "normal*" ==
non-"[]"
(?: # Begin "(special normal*)*"
"Unrolling-the-loop" construct.
\[[^[\]\r\n]*+\] # Allow matching [square brackets] 1 level deep.
"special".
[^[\]\r\n]*+ # More "normal*" any non-"[]", non-newline
characters.
)*+ # End "(special normal*)*" "Unrolling-the-loop"
construct.
) # End $5: Un-or-any-quoted attribute value.
) # End group of attribute values alternatives.
\s*+ # Optional whitespace following quoted values.
)? # End optional attribute group.
\] # Match closing bracket of outermost opening TAGNAME tag.
) # End atomic group with opening tag remainder.
# Second, match the contents of the tag.
( # $6: Non-trimmed contents of TAGNAME tag.
(?> # Atomic group for contents alternatives.
[^\[]++ # Option 1: Match non-tag chars (starting with non-"[").
(?: # Begin "(special normal*)*"
"Unrolling-the-loop" construct.
(?!\[/?+\1[\]=\s])\[ # "special" = "[" if not start of [TAGNAME*] or
[/TAGNAME].
[^\[]*+ # More "normal*".
)*+ # Zero or more "special normal*"s allowed for option 1.
| (?: # or Option 2: Match non-tag chars (starting with "[").
(?!\[/?+\1[\]=\s])\[ # "special" = "[" if not start of [TAGNAME*] or
[/TAGNAME].
[^\[]*+ # More "normal*".
)++ # One or more "special normal*"s required for option 2.
| (?R) # Or option 3: recursively match nested [TAGNAME]..[/TAGNAME].
)*+ # One of these three options as many times as necessary.
) # End $6: Non-trimmed contents of TAGNAME tag.
# Finally, match the closing tag.
\[/\1\s*+\] # Match outermost closing [/ TAGNAME ]
%ix',
If I remove the following line, it works:
| (?R) # Or option 3: recursively match nested
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=71647
--
Edit this bug report at https://bugs.php.net/bug.php?id=71647&edit=1