#25754 [Opn->Csd]: preg_replace() and preg_replace_callback() crash with long matches
| From: | nlopess@php.net | Date: | Sun, 22 Feb 2004 20:19:17 +0000 |
| Subject: | #25754 [Opn->Csd]: preg_replace() and preg_replace_callback() crash with long matches | ||
| References: | 1 | Groups: | php.doc |
| Request: | Send a blank email to phpdoc+get-969359150@lists.php.net to get a copy of this message | ||
ID: 25754
Updated by: nlopess@php.net
Reported By: ilya at lebedev dot net
-Status: Open
+Status: Closed
Bug Type: Documentation problem
Operating System: Win32
PHP Version: 4CVS-2003-10-04 (stable)
New Comment:
This bug has been fixed in the documentation's XML sources. Since the
online and downloadable versions of the documentation need some time
to get updated, we would like to ask you to be a bit patient.
Thank you for the report, and for helping us make our documentation
better.
Previous Comments:
------------------------------------------------------------------------
[2003-10-28 18:16:55] coldrain at workingonit dot org
It seems the bug I reported (http://bugs.php.net/bug.php?id=26020) is a
duplicate of this one. In this (now bogus) bug report there is more
info on a similar, yet different case.
It should be noted that the maximum amount of data between pairs of
tags in this PCRE case is not a constant as it differs between
platforms, even with the same installed PHP versions. On a Debian box,
I was able to process about 11650 bytes between to matching div tags.
------------------------------------------------------------------------
[2003-10-04 22:04:17] sniper@php.net
From http://www.pcre.org/pcre.txt, LIMITATIONS:
"The maximum length of a subject string is the largest
positive number that an integer variable can hold. However,
PCRE uses recursion to handle subpatterns and indefinite
repetition. This means that the available stack space may
limit the size of a subject string that can be processed by
certain patterns."
This propably should be mentioned in our manual pages too.
(On Linux, the example script worked fine with 9344 chars between the
tags, but 9345 crashed)
------------------------------------------------------------------------
[2003-10-04 19:56:54] ilya at lebedev dot net
Description:
------------
Regular expression from the J.Friedl's "Mastering regular expressions"
book that matches pair html tags:
#<tag([^>]*)>(((?!</?tag(?:[^>]*)>).)*)</tag>#si
When between <tag> and </tag> are more then 2100 bytes (symbols),
Apache crashes.
Same happens without "s" modifier, if string has no "newline" codes.
Reproduce code:
---------------
===
preg_replace("#<tag([^>]*)>(((?!</?tag(?:[^>]*)>).)*)</tag>#si","","<tag>
2200 symbols</tag>");
===
or
===
function callback (&$m) { return "";};
preg_replace_callback
("#<tag([^>]*)>(((?!</?tag(?:[^>]*)>).)*)</tag>#si","callback","<tag>
2200 symbols </tag>");
===
Expected result:
----------------
Match blocks bigger then 2100 symbols long.
Actual result:
--------------
With more then 2100 sybmols between tags Apache crashes.
------------------------------------------------------------------------
--
Edit this bug report at http://bugs.php.net/?id=25754&edit=1