Bug #77193 [Opn]: Infinite loop in preg_replace_callback

From: Date: Sun, 25 Nov 2018 19:21:55 +0000
Subject: Bug #77193 [Opn]: Infinite loop in preg_replace_callback
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-218131@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=77193&edit=1 ID: 77193 User updated by: mlocati at gmail dot com Reported by: mlocati at gmail dot com Summary: Infinite loop in preg_replace_callback Status: Open Type: Bug Package: PCRE related PHP Version: 7.3.0RC6 Block user comment: N Private report: N New Comment: I tried both with pcre.jit=0 and with pcre.jit=1 in php.ini. The infinite loop also occurs when I remove the "return" instruction from "return (string) \URL::to($c);", and always returning an empty string, that is: $text = preg_replace_callback( '/{CCM:CID_([0-9]+)}/i', function ($matches) { $cID = $matches[1]; if ($cID > 0) { $c = Page::getByID($cID, 'ACTIVE'); if ($c->isActive()) { (string) \URL::to($c); } } return ''; }, $text ); Previous Comments: ------------------------------------------------------------------------ [2018-11-25 12:37:21] cmb@php.net Does this happen regardless of the value of pcre.jit? Also, does this happen if you actually return an empty string from the callback instead of the implicit NULL? ------------------------------------------------------------------------ [2018-11-23 13:55:58] mlocati at gmail dot com Description: ------------ While testing the develop branch of concrete5 for PHP 7.3 compatibility, I've seen that the code at https://github.com/concrete5/concrete5/blob/27bcd1b36ef35f21b0df32bfd7e57d2ecf347d65/concrete/src/Editor/LinkAbstractor.php#L97-L109 loops forever. Here's a copy of the code: $text = preg_replace_callback( '/{CCM:CID_([0-9]+)}/i', function ($matches) { $cID = $matches[1]; if ($cID > 0) { $c = Page::getByID($cID, 'ACTIVE'); if ($c->isActive()) { return (string) \URL::to($c); } } }, $text ); If I comment the "return (string) \URL::to($c);" line, everything works fine, but with that line the closure is called an infinite number of times. I tried hard but I really can't replicate this issue in a simpler test case. I tested it both on Windows (PHP 7.3.0RC6 32bit TS) and on the php:7.3.0RC5-cli-stretch docker image (sorry, no RC6 available yet). To replicate the problem in the same environment as mine, you can run the php:7.3.0RC5-cli-stretch docker image ("docker run --rm -it php:7.3.0RC5-cli-stretch bash") and call these shell commands: # Update the APT repository & install required packages apt update && apt install -y mysql-server git unzip # Setup MySQL/MariaDB service mysql start mysql -e "CREATE USER 'travis'@'localhost' IDENTIFIED BY ''; GRANT ALL PRIVILEGES ON * . * TO 'travis'@'localhost'; FLUSH PRIVILEGES;" # Build and enable GD and PDO_MYSQL curl https://raw.githubusercontent.com/mlocati/docker-php-extension-installer/master/install-php-extensions -o /usr/local/bin/install-php-extensions chmod +x /usr/local/bin/install-php-extensions install-php-extensions gd pdo_mysql # Install Composer php -r "copy('https://getcomposer.org/installer', 'composer-setup.php');" php -r "if (hash_file('sha384', 'composer-setup.php') === '93b54496392c062774670ac18b134c3b3a95e5a5e5c8f1a9f115f203b75bf9a129d5daa8ba6a13e2cc8a1da0806388a8') { echo 'Installer verified'; } else { echo 'Installer corrupt'; unlink('composer-setup.php'); } echo PHP_EOL;" php composer-setup.php php -r "unlink('composer-setup.php');" chmod a+x composer.phar mv composer.phar /usr/local/bin/composer # Clone repository git clone --depth=1 https://github.com/concrete5/concrete5.git cd concrete5 # Patch required for making the tests work sed -i -e 's/localhost/127.0.0.1/g' tests/config/database.php # Install composer dependencies composer install # Execute the test composer test -- --filter=ContentPageTranslateTest::testFrom The test will last forever (well, actually until PHP goes out of memory). On previous PHP versions everything works fine. ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=77193&edit=1

« previous php.bugs (#218131) next »