#18800 [Opn]: PHP crashes on cleaning up COM objects

From: Date: Fri, 09 Aug 2002 11:38:19 +0000
Subject: #18800 [Opn]: PHP crashes on cleaning up COM objects
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-16380@lists.php.net to get a copy of this message
ID: 18800 User updated by: mlorenz@novadys.de Reported By: mlorenz@novadys.de Status: Open Bug Type: COM related Operating System: Windows2000 Professional PHP Version: 4.2.2 New Comment: It seems that the line $myC->B = $myB is responsible for the crash, because it does not crash when I put // in front of the line. Previous Comments: ------------------------------------------------------------------------ [2002-08-08 05:45:18] mlorenz@novadys.de It seems that php has a problem cleaning up COM object references. I wrote a litte COM server and the following script that demonstrates the problem. <?php $myA = new COM("PHPTest.A.1") or die("Cannot create A"); $myB = $myA->GetB(); // myA creates a B object and returns a pointer to it. // It does not store the pointer itself. $myA->Release(); $myC = new COM("PHPTest.C.1") or die("Cannot create C"); $myC->B = $myB; // myC stores the pointer to the B object and AddRefs it. // It releases the pointer on destruction. $myC->Release(); $myB->Release(); ?> After executing the script PHP crashes on cleanup. I did a little debugging and found the following. There is a function php_COM_release in ext/com/COM.c that is called on every ...->Release call. During execution of the script all objects are deleted as expected. A look at the watch window shows me a structure called 'obj' that contains a field named 'resourceindex' the values are 1 for the A object 3 for the C object 2 for the B object After destroying these objects the COM server is going down as expected because there are no more living objects. When PHP is cleaning up, it crashes in the same function trying to realease an object with the 'resourceindex' 4. Here is the call stack: php_COM_release(comval_ * 0x00dbd1f8, void * * * 0x00da2ad0) line 231 + 17 bytes php_COM_destruct(comval_ * 0x00dbd1f8, void * * * 0x00da2ad0) line 363 + 13 bytes php_comval_destructor(_zend_rsrc_list_entry * 0x00dbd3b0, void * * * 0x00da2ad0) line 373 + 15 bytes list_entry_destructor(void * 0x00dbd3b0) line 177 + 16 bytes zend_hash_apply_deleter(_hashtable * 0x00da8a34, bucket * 0x00dbd340) line 596 + 15 bytes zend_hash_graceful_reverse_destroy(_hashtable * 0x00da8a34) line 662 + 13 bytes zend_destroy_rsrc_list(_hashtable * 0x00da8a34, void * * * 0x00da2ad0) line 233 + 9 bytes shutdown_executor(void * * * 0x00da2ad0) line 196 + 30 bytes zend_deactivate(void * * * 0x00da2ad0) line 596 + 9 bytes php_request_shutdown(void * 0x00000000) line 787 + 9 bytes main(int 0x00000002, char * * 0x00da25d0) line 827 + 8 bytes mainCRTStartup() line 338 + 17 bytes KERNEL32! 77e87d08() The line where the crash happens is: hr = C_DISPATCH_VT(obj)->Release(C_DISPATCH(obj)); Best regards Michael ------------------------------------------------------------------------ -- Edit this bug report at http://bugs.php.net/?id=18800&edit=1

« previous php.bugs (#16380) next »