Bug #72281 [Opn]: PaX MPROTECT breaks php
| From: | cmb@php.net | Date: | Wed, 09 Nov 2016 20:32:29 +0000 |
| Subject: | Bug #72281 [Opn]: PaX MPROTECT breaks php | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-205268@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=72281&edit=1
ID: 72281
Updated by: cmb@php.net
Reported by: tk at giga dot or dot at
Summary: PaX MPROTECT breaks php
Status: Open
Type: Bug
-Package: Compile Failure
+Package: PCRE related
Operating System: NetBSD
PHP Version: 7.0.7
Block user comment: N
Private report: N
New Comment:
As I understand it, the compilation succeeds, but the problem is PCRE's
JIT support, so I'm changing the "package affected".
> Since JIT and MPROTECT are at odds with each other, I suggest running
> "paxctl +m" on the binary, [â¦]
But what if PCRE is built as shared library? Would that also work in
this case?
Furthermore, according to Gentoo's Hardened/PaX Quickstart[1] it appears
that marking is not without issues. Perhaps we should simply document
the issue instead of trying to fix it?
[1] <https://wiki.gentoo.org/wiki/Hardened/PaX_Quickstart#Marking_for_PaX>
Previous Comments:
------------------------------------------------------------------------
[2016-11-09 15:10:17] ab@php.net
Related To: Bug #73114
------------------------------------------------------------------------
[2016-05-28 08:11:44] tk at giga dot or dot at
Description:
------------
When compiling php-7.0.7 on NetBSD-7.99.29/amd64, the compilation fails because php dumps core.
The problem is that NetBSD on that release has PaX MPROTECT turned on by default (see http://netbsd.gw.com/cgi-bin/man-cgi?security++NetBSD-current),
i.e. it does not allow mapping pages both writable and executable. However, this is needed by php.
The backtrace of the core dump has:
#1 0x00000000004d0d87 in _pcre_jit_exec ()
#2 0x00000000004a53f1 in php_pcre_exec ()
Since JIT and MPROTECT are at odds with each other, I suggest running "paxctl +m" on the
binary, which (on NetBSD, see http://netbsd.gw.com/cgi-bin/man-cgi?paxctl++NetBSD-current)
removes the MPROTECT restrictions for the php binary.
A workaround patch is attached.
It can not be used as is, since paxctl on *BSD and paxctl on Linux have different syntax.
I hope that someone can extend this to also work on Linux.
The patch is an example, but is tested and works on NetBSD.
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=72281&edit=1