Bug #78630 [Com]: PHP 7.3 preg_match(): JIT compilation failed: no more memory (need pcre.jit=0)

From: Date: Fri, 04 Oct 2019 07:49:09 +0000
Subject: Bug #78630 [Com]: PHP 7.3 preg_match(): JIT compilation failed: no more memory (need pcre.jit=0)
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-223050@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=78630&edit=1

 ID:                 78630
 Comment by:         build+suse at de-korte dot org
 Reported by:        ilya at ilya dot pp dot ua
 Summary:            PHP 7.3 preg_match(): JIT compilation failed: no
                     more memory (need pcre.jit=0)
 Status:             Open
 Type:               Bug
 Package:            PCRE related
 Operating System:   openSUSE Tumbleweed
 PHP Version:        7.3.10
 Block user comment: N
 Private report:     N

 New Comment:

I'm running php-7.3.10 on openSUSE Tumbleweed too and see no problems with 'pcre.jit =
1' and phpMyAdmin. I too use the mpm_event and have an identical memory_limit (128M) for PHP as
the reporter. I do run php-fpm through mod_proxy_fcgi though and not through mod_fcgid +
php-fastcgi.

I think it is safe to assume that the problems the OP is seeing, is not going to be solved by
upgrading to 7.4.0RC3.


Previous Comments:
------------------------------------------------------------------------
[2019-10-03 21:33:06] nikic@php.net

Thanks for the information. As the PCRE2 build uses --enable-jit-sealloc (which sets
SLJIT_PROT_EXECUTABLE_ALLOCATOR) and the PHP build uses the system PCRE2 build, this means that
preg_* should end up using the ProtExec allocator, which is W^X compatible.

So the problem here might be the other way around, and the use of the ProtExec allocator is what
causes the issue. Looking at recent pcre-dev posts, I saw the discussion in https://bugs.exim.org/show_bug.cgi?id=2445,
which looks potentially relevant.

------------------------------------------------------------------------
[2019-10-03 21:15:29] ilya at ilya dot pp dot ua

wget https://www.php.net/distributions/php-7.4.0RC3.tar.xz
... 404 Not a found
Give me please, correct link to dowload 7.4.0RC3

------------------------------------------------------------------------
[2019-10-03 20:56:49] ilya at ilya dot pp dot ua

> Do you know how opensuse builds pcre2? Do they use the bundled PHP library, or do they build a
> separate pcre2 library and link PHP against it? I'm assuming it's the latter.

See, please, pcre2 project: https://build.opensuse.org/package/show/devel:libraries:c_c++/pcre2
(click on pcre2.spec file)
And see, please, php7 project: https://build.opensuse.org/package/show/devel:languages:php/php7

> Do you know if there is any security mechanism (such as SELinux) that might prevent the
> allocation of writable executable memory?

Judging by my installed packages, the system contains libapparmor and libselinux.
But whether they are actually used and how I do not know.

> If such a mechanism exists and is enabled by default, is pcre2 being compiled with
> -DSLJIT_PROT_EXECUTABLE_ALLOCATOR=1, as is necessary to avoid W+X mmaps?

https://build.opensuse.org/package/view_file/devel:libraries:c_c++/pcre2/pcre2.spec?expand=1
%configure \
%ifarch %{ix86} x86_64 %{arm} ppc ppc64 ppc64le mips sparc
	    --enable-jit \
        --enable-jit-sealloc \
%endif

Most probably not.
But you can always look at the current build log to be sure of this.
https://build.opensuse.org/build/devel:libraries:c_c++/openSUSE_Factory/x86_64/pcre2/_log

> Finally, do you know whether the first preg_* call already fails, or are there any preg_* calls
> that succeed before the first failure?

Not all. In my code, preg_match () is called once to check my email and it always causes an error.

------------------------------------------------------------------------
[2019-10-03 20:28:51] ilya at ilya dot pp dot ua

> @nikic's two referenced commits are only for PHP 7.4.0rc3. @ilya, can you test with that
> version?

Problematically, openSUSE has many patches, and simply updating the source code will fail.
I asked the maintainer to build 7.4.0RC3, if he has time for this I will test.

> @ilya: It would be helpful to also provide an strace of the process, which should also show the
> mmap failure.

This is also problematic, I never used strace.
Can you give detailed instructions on how to do it?

------------------------------------------------------------------------
[2019-10-03 20:17:31] nikic@php.net

Do you know how opensuse builds pcre2? Do they use the bundled PHP library, or do they build a
separate pcre2 library and link PHP against it? I'm assuming it's the latter.

Do you know if there is any security mechanism (such as SELinux) that might prevent the allocation
of writable executable memory?

If such a mechanism exists and is enabled by default, is pcre2 being compiled with
-DSLJIT_PROT_EXECUTABLE_ALLOCATOR=1, as is necessary to avoid W+X mmaps?

Finally, do you know whether the first preg_* call already fails, or are there any preg_* calls that
succeed before the first failure?

------------------------------------------------------------------------


The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at

    https://bugs.php.net/bug.php?id=78630


--
Edit this bug report at https://bugs.php.net/bug.php?id=78630&edit=1


Thread (34 messages)

« previous php.bugs (#223050) next »