Bug #74623 [Ver->Csd]: Infinite loop in type inference when using HTMLPurifier

From: Date: Fri, 23 Jun 2017 15:35:03 +0000
Subject: Bug #74623 [Ver->Csd]: Infinite loop in type inference when using HTMLPurifier
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-209653@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=74623&edit=1

 ID:                 74623
 Updated by:         nikic@php.net
 Reported by:        lkebin at gmail dot com
 Summary:            Infinite loop in type inference when using
                     HTMLPurifier
-Status:             Verified
+Status:             Closed
 Type:               Bug
 Package:            opcache
 Operating System:   CentOS 6.9
 PHP Version:        7.1.5
 Block user comment: N
 Private report:     N

 New Comment:

Automatic comment on behalf of nikita.ppv@gmail.com
Revision: http://git.php.net/?p=php-src.git;a=commit;h=5b5a92b8b6d96b8fbd8557645801ae99310cab2b
Log: Fixed bug #74623


Previous Comments:
------------------------------------------------------------------------
[2017-06-07 22:45:43] phpbugs at ackermann dot ca

Wrong test code posted before. This one should do it.

<?php

function crash($arr) {
    $current_item = false;

    foreach($arr as $item) {
        if($item->name === 'string') {
            $current_item = $item;
        } else {
            $current_item->a[] = '';
        }
    }

}

------------------------------------------------------------------------
[2017-06-07 22:39:36] phpbugs at ackermann dot ca

Hello,

just run into this bug. The boil down version is a file with the following content. Opening or
including the file results in 100% CPU load.

<?php

function crash($arr) {
    $current_item = false;

    foreach($arr as $item) {
        $current_item = $item;
        $current_item->a[] = '';
    }

}

------------------------------------------------------------------------
[2017-06-03 01:38:34] Xiphin at qq dot com

https://gist.github.com/lkebin/e25594cfd493e984054686a7cd2ec4b8
You can fix it by follow:
line 14727: change "$current_li = false;" to "$current_li = null;"
line 14748: change "if ($current_li === false) {" to "if ($current_li === null)
{"

------------------------------------------------------------------------
[2017-06-03 01:02:09] ezyang@php.net

Xiphin reports that the following patch to HTML Purifier solves the problem. Maybe this will help
diagnose the opcode problem: https://github.com/ezyang/htmlpurifier/pull/137

------------------------------------------------------------------------
[2017-05-22 03:08:51] lkebin at gmail dot com

Run the script should be 

./sapi/cli/php -c ./php.ini-development ~/HTMLPurifier.standalone.php

------------------------------------------------------------------------


The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at

    https://bugs.php.net/bug.php?id=74623


--
Edit this bug report at https://bugs.php.net/bug.php?id=74623&edit=1


Thread (8 messages)

« previous php.bugs (#209653) next »