Re: Possible Parse Bomb
| From: | Zak Greant | Date: | Sat, 09 Dec 2000 12:32:54 +0000 |
| Subject: | Re: Possible Parse Bomb | ||
| References: | 1 2 | Groups: | php.qa |
| Request: | Send a blank email to php-qa+get-1772@lists.php.net to get a copy of this message | ||
Hello Derick,
That would be great! :)
I am just running:
% ab hostname.com/path/test.php -n 1000000 > ~/ab_test &
The test script is basically what Mark is using. I was initially using a
more complex script, but the test looked like it would take about 38 hours
to complete.... eeek!
Here is my initial run:
Document Length: 1 bytes
Concurrency Level: 1
Time taken for tests: 7.609 seconds
Complete requests: 1000
Failed requests: 0
Total transferred: 174000 bytes
HTML transferred: 1000 bytes
Requests per second: 131.42
Transfer rate: 22.87 kb/s received
Connnection Times (ms)
min avg max
Connect: 0 0 2
Processing: 5 5 5
Total: 5 5 7
Everything looks good... I should have the results for the -n 1000000 run in
about 2 hours
--zak
----- Original Message -----
From: "Derick Rethans" <d.rethans@jdimedia.nl>
To: "Zak Greant" <zak@nucleus.com>; <php-qa@lists.php.net>
Sent: Saturday, December 09, 2000 5:10 AM
Subject: Re: [PHP-QA] Possible Parse Bomb
> Hello Zak,
>
> I'd be happy to donate some time for running tests on my machines here.
> So, if someone does have the test scripts, I'll run them. (Dont have
> time to make the test scritps by myself now...
>
> Derick
>
> Zak Greant wrote:
> >
> > Hello All,
> >
> > Zeev recently highlighted possible problems with PHP failing to parse
> > requests properly. I would like for us to attempt to recreate this
problem.
> > Does anyone have any suggestions on good ways to perform these tests?
> >
> > Mark J. Hershenson proposed using ab to do the tests -- this sounds like
a
> > good idea to me - at least for the initial purpose of attempting to
verify
> > if the problem exists.
> >
> > Based on Mark's suggestions, I have a few ideas:
> >
> > Create a nice clean custom log ( + format) to track the results of the
> > tests. This will make it easier for us to parse the data.
> >
> > In the interests of time, we should probably start with the simplest set
of
> > tests. Run a simple test many times and see if we get anything that
looks
> > like a parse bomb. If we don't get any results this way, perhaps move
to a
> > more complex text that calls a wide range of functions.
> >
> > As soon as we can recreate the problem, then move to trying to capture
what
> > is actually going on. I don't know if there is any way to easily
capture
> > the pages output by ab - I am guessing that there is not. If not, and we
can
> > recreate the problem, then we should look at writing a script that
requests
> > a file, compares the length of the content served to the expected length
and
> > captures any odd results.
> >
> > Thoughts, comments?
> >
> > Zak
> >
> > --
> > PHP Quality Assurance Mailing List
> > <http://www.php.net/>
> > To unsubscribe, e-mail: php-qa-unsubscribe@lists.php.net
> > For additional commands, e-mail: php-qa-help@lists.php.net
> > To contact the list administrators, e-mail: php-list-admin@lists.php.net
>
> --
> Derick Rethans
>
> ---------------------------------------------------------------------
> PHP: Scripting the Web - www.php.net - derick@php.net
> ---------------------------------------------------------------------
> JDI Media Solutions - www.jdimedia.nl - d.rethans@jdimedia.nl
> H.v. Tussenbroekstraat 1 - 6952 BL Dieren - The Netherlands
> ---------------------------------------------------------------------