Bug #76270 [Opn->Csd]: regex-related functions crash instead of triggering memory-limit error
| From: | nikic@php.net | Date: | Fri, 27 Jul 2018 20:52:33 +0000 |
| Subject: | Bug #76270 [Opn->Csd]: regex-related functions crash instead of triggering memory-limit error | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-216508@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=76270&edit=1
ID: 76270
Updated by: nikic@php.net
Reported by: teo8976 at gmail dot com
Summary: regex-related functions crash instead of triggering
memory-limit error
-Status: Open
+Status: Closed
Type: Bug
Package: Reproducible crash
PHP Version: 5.6.35
-Assigned To:
+Assigned To: nikic
Block user comment: N
Private report: N
New Comment:
This was mostly fixed in PHP 7, which enables PCRE JIT by default. In PHP 7.3 the issue is fully
fixed with the update to PCRE2 (in particular including the rewrite of the non-JIT matcher to be
non-recursive in version 10.30.)
Previous Comments:
------------------------------------------------------------------------
[2018-04-25 17:02:23] teo8976 at gmail dot com
Description:
------------
When memory usage exceeds the memory limit during the execution of regular-expression related
functions (such as preg_replace, preg_replace_callback, etc), instead of triggering the error that
you would normally get when exceeding the memory limit, php execution is simply abruptly aborted (it
crashes?) and produces empty output, regardless of whether you have display_errors set to true
and/or have set an error handler.
Test script:
---------------
// PSEUDOCODE
ini_set('memory_limit', $some_low_limit);
$s="a huge string (not big enough to exceed the memory limit itself";
preg_replace_callback(
"/some_complex_regex_with_a_lot_of_matches/",
function($match) { return whatever; },
$s
);
Expected result:
----------------
Should trigger the memory-limit error in the same way as when you exceed the memory limit without
regular expressions.
With display_errors set to true, you should see an error message
Actual result:
--------------
crashes and produces a f*****g blank page, even if display_errors is set to true, and you have no
way of debugging what the f**k is going on. Took me ages to narrow it down to regular expressions.
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=76270&edit=1