Bug #71647 [Com]: Recursive (?R) regexp crashes PHP7.0-FPM

From: Date: Sun, 28 Aug 2016 09:41:49 +0000
Subject: Bug #71647 [Com]: Recursive (?R) regexp crashes PHP7.0-FPM
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-203626@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=71647&edit=1 ID: 71647 Comment by: adaur dot underground at gmail dot com Reported by: adaur dot underground at gmail dot com Summary: Recursive (?R) regexp crashes PHP7.0-FPM Status: No Feedback Type: Bug Package: PCRE related Operating System: Debian 8 PHP Version: 7.0.3 Assigned To: cmb Block user comment: N Private report: N New Comment: Hello, Sorry for the delay. Disabling the jit options does the trick. Indeed, my version of PHP7 was bundled with PRCE 8.35. I'll ask the package's maintainer to update it. Previous Comments: ------------------------------------------------------------------------ [2016-08-28 04:22:31] php-bugs at lists dot php dot net No feedback was provided. The bug is being suspended because we assume that you are no longer experiencing the problem. If this is not the case and you are able to provide the information that was requested earlier, please do so and change the status of the bug back to "Re-Opened". Thank you. ------------------------------------------------------------------------ [2016-08-20 10:36:22] cmb@php.net This issue may be caused by pcre.jit=1. Please try with pcre.jit=0. Also check PCRE_VERSION; 8.35 is known to cause some issues regarding the JIT. Try with 8.38. ------------------------------------------------------------------------ [2016-02-22 22:57:41] adaur dot underground at gmail dot com Thank you for your answer. As you may have guessed, this is a regexp used to parse BBCode in a forum script. Every time the parser is called, the page crashes, hence any input seems to trigger the bug. I have tried with a simple dot (.), crashes too. ------------------------------------------------------------------------ [2016-02-22 22:36:37] nikic@php.net Can you please also provide the input you're matching against? ------------------------------------------------------------------------ [2016-02-22 22:34:48] adaur dot underground at gmail dot com This is the regex that causes the crash (it's long, but you can skip to the end): 're_bbcode' => '% # re_bbcode Rev:20110220_1200 # First, match opening tag of syntax: "[TAGNAME (= ("\')ATTRIBUTE("\') )]"; \[ # Match opening bracket of outermost opening TAGNAME tag. (?>(%taglist%)\s*+) # $1: (?> # Atomically group remainder of opening tag. (?: # Optional attribute. (=)\s*+ # $2: = Optional attribute\'s equals sign delimiter, ws. (?: # Group for 1-line attribute value alternatives. \'([^\'\r\n\\\\]*+(?:\\\\.[^\'\r\n\\\\]*+)*+)\' # Either $3: == single quoted, | "([^"\r\n\\\\]*+(?:\\\\.[^"\r\n\\\\]*+)*+)" # or $4: == double quoted, | ( [^[\]\r\n]*+ # or $5: == un-or-any-quoted. "normal*" == non-"[]" (?: # Begin "(special normal*)*" "Unrolling-the-loop" construct. \[[^[\]\r\n]*+\] # Allow matching [square brackets] 1 level deep. "special". [^[\]\r\n]*+ # More "normal*" any non-"[]", non-newline characters. )*+ # End "(special normal*)*" "Unrolling-the-loop" construct. ) # End $5: Un-or-any-quoted attribute value. ) # End group of attribute values alternatives. \s*+ # Optional whitespace following quoted values. )? # End optional attribute group. \] # Match closing bracket of outermost opening TAGNAME tag. ) # End atomic group with opening tag remainder. # Second, match the contents of the tag. ( # $6: Non-trimmed contents of TAGNAME tag. (?> # Atomic group for contents alternatives. [^\[]++ # Option 1: Match non-tag chars (starting with non-"["). (?: # Begin "(special normal*)*" "Unrolling-the-loop" construct. (?!\[/?+\1[\]=\s])\[ # "special" = "[" if not start of [TAGNAME*] or [/TAGNAME]. [^\[]*+ # More "normal*". )*+ # Zero or more "special normal*"s allowed for option 1. | (?: # or Option 2: Match non-tag chars (starting with "["). (?!\[/?+\1[\]=\s])\[ # "special" = "[" if not start of [TAGNAME*] or [/TAGNAME]. [^\[]*+ # More "normal*". )++ # One or more "special normal*"s required for option 2. | (?R) # Or option 3: recursively match nested [TAGNAME]..[/TAGNAME]. )*+ # One of these three options as many times as necessary. ) # End $6: Non-trimmed contents of TAGNAME tag. # Finally, match the closing tag. \[/\1\s*+\] # Match outermost closing [/ TAGNAME ] %ix', If I remove the following line, it works: | (?R) # Or option 3: recursively match nested ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=71647 -- Edit this bug report at https://bugs.php.net/bug.php?id=71647&edit=1

« previous php.bugs (#203626) next »