Bug #78927 [Com]: Crash in pcre2_code_free_8, zend_hash_destroy

From: Date: Mon, 09 Dec 2019 23:47:36 +0000
Subject: Bug #78927 [Com]: Crash in pcre2_code_free_8, zend_hash_destroy
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-224179@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=78927&edit=1

 ID:                 78927
 Comment by:         xnoreq at gmail dot com
 Reported by:        xnoreq at gmail dot com
 Summary:            Crash in pcre2_code_free_8, zend_hash_destroy
 Status:             Open
 Type:               Bug
 Package:            Reproducible crash
 Operating System:   Linux 5.3.11
 PHP Version:        7.4.0
 Block user comment: N
 Private report:     N

 New Comment:

Here's a simple test-case to reproduce the issue:

$ php -f test.php

test.php:
<?php
function regex() {
        preg_match('/(foo)(bar)(baz)/', 'foobarbaz', $matches,
PREG_OFFSET_CAPTURE);
}

regex();

$pid = pcntl_fork();
if ($pid == -1) {
        die('error.');
}
else if ($pid) {
        echo 'parent... ';
        pcntl_wait($pid);
        echo 'wait done';
}
else {
        echo 'child.';
}
?>


Previous Comments:
------------------------------------------------------------------------
[2019-12-09 23:39:41] xnoreq at gmail dot com

I was using 7.3.12 before.

You can find the build files and patches here:
https://git.archlinux.org/svntogit/packages.git/tree/repos/extra-x86_64?h=packages/php

There's no --enable-sealloc option.

------------------------------------------------------------------------
[2019-12-09 21:16:23] nikic@php.net

Thanks, the trace makes much more sense with this being a cli executable.

fork() in most cases shouldn't matter, but here there might be a possible interference with the
JIT mapped memory used by PCRE.

Which Linux distro are you using and do you know how they build their PCRE binaries? If they are
using --enable-sealloc, then this may indeed be incompatible with fork().

Which PHP version did you use before the upgrade? PHP 7.3 or something older?

------------------------------------------------------------------------
[2019-12-09 20:59:13] xnoreq at gmail dot com

This is tiny tiny rss's update script (update_daemon2.php) which is a cli executable.
That's why the process name is also php (and not php-cgi or php-fpm).

It forks off do to multiple updates in parallel and I guess that leads to the invalid frees.

------------------------------------------------------------------------
[2019-12-09 08:52:21] nikic@php.net

Based on code inspection alone, I don't see what the issue could be.

------------------------------------------------------------------------
[2019-12-09 08:44:23] nikic@php.net

It looks to me like for some reason the per-request PCRE cache gets shut down, even though FPM
shouldn't be using it.

------------------------------------------------------------------------


The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at

    https://bugs.php.net/bug.php?id=78927


--
Edit this bug report at https://bugs.php.net/bug.php?id=78927&edit=1


Thread (11 messages)

« previous php.bugs (#224179) next »