#45327 [Opn->Asn]: [PATCH] memory leak if offsetGet throws exception (PHP_5_2 branch only!)

From: Date: Sat, 06 Sep 2008 00:50:58 +0000
Subject: #45327 [Opn->Asn]: [PATCH] memory leak if offsetGet throws exception (PHP_5_2 branch only!)
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-128716@lists.php.net to get a copy of this message
ID: 45327 Updated by: jani@php.net Reported By: cellog@php.net -Status: Open +Status: Assigned Bug Type: Scripting Engine problem Operating System: linux 64bit PHP Version: 5.2CVS-2008-06-21 Assigned To: dmitry Previous Comments: ------------------------------------------------------------------------ [2008-09-02 16:14:32] cellog@php.net yes, to reproduce, cp ext/phar from PHP_5_3 into PHP_5_2 and run the test I described ------------------------------------------------------------------------ [2008-09-02 13:44:20] dmitry@php.net ext/phar is not a part of PHP_5_2 branch, and I don't see any leaks in PHP_5_3. Do you still have this leak? Could you provide a script that causes leak on PHP_5_2 (without ext/phar) or PHP_5_3 (with phar). ------------------------------------------------------------------------ [2008-06-21 17:36:19] cellog@php.net Description: ------------ ext/phar's test phar_offset_get_error.phpt fails with leaked memory in zend_execute_API.c:1023, which is where retval is allocated. It turns out that if offsetGet() throws an exception, zend_std_read_dimension() does not free the return zval, and it leaks. This only affects PHP 5.2. The patch to fix is at http://pear.php.net/~greg/fix_leak.patch.txt and is pasted below Reproduce code: --------------- Index: Zend/zend_object_handlers.c =================================================================== RCS file: /repository/ZendEngine2/zend_object_handlers.c,v retrieving revision 1.135.2.6.2.28 diff -u -r1.135.2.6.2.28 zend_object_handlers.c --- Zend/zend_object_handlers.c 21 Feb 2008 13:55:22 -0000 1.135.2.6.2.28 +++ Zend/zend_object_handlers.c 21 Jun 2008 17:33:18 -0000 @@ -469,6 +469,10 @@ return 0; } + if (EG(exception)) { + zval_ptr_dtor(&retval); + return 0; + } /* Undo PZVAL_LOCK() */ retval->refcount--; ------------------------------------------------------------------------ -- Edit this bug report at http://bugs.php.net/?id=45327&edit=1

« previous php.bugs (#128716) next »