#18800 [Opn->Csd]: PHP crashes on cleaning up COM objects

From: Date: Mon, 12 Aug 2002 15:05:06 +0000
Subject: #18800 [Opn->Csd]: PHP crashes on cleaning up COM objects
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-16545@lists.php.net to get a copy of this message
ID: 18800 Updated by: phanto@php.net Reported By: mlorenz@novadys.de -Status: Open +Status: Closed Bug Type: COM related Operating System: Windows2000 Professional PHP Version: 4.2.2 New Comment: thanks for your great work, but i'm sorry to have to inform you that this is fixed in cvs for quite a while now (since 31.5.2002), the fix came after 4.2.1 and didn't get into 4.2.2 as it was only a security update and didn't contain all the patches. try a cvs snapshot after this date and reopen this report if you still have problems. Previous Comments: ------------------------------------------------------------------------ [2002-08-12 10:18:19] mlorenz@novadys.de Maybe i have found the problem. I tracked down reference counts in the debugger. Because it is a little difficult with an out of process server, I turned my server into an inproc server. Please send me a mail if you want to have these sources too. I found the following problem in do_COM_propput: There is a VARIANT allocated with ALLOC_VARIANT(new_value); Some lines later it is filled with the Dispatch pointer to the A object with php_pval_to_variant(value, new_value, codepage TSRMLS_CC); As far as i have seen, this function does not AddRef the pointer. At the end of the function the VARIANT is cleared by FREE_VARIANT(new_value); This internally calls the COM API VariantFree that calls Release on the stored Dispatch pointer. Can you please verify this ? Best regards, Michael ------------------------------------------------------------------------ [2002-08-12 03:57:02] mlorenz@novadys.de I have simplified the script slightly for easier debugging but it still produces the same problem. 1. $myA = new COM("PHPTest.A.1") or die("Cannot create A"); 2. $myC = new COM("PHPTest.C.1") or die("Cannot create C"); 3. $myC->B = $myA; 4. $myA->Release(); 5. $myC->Release(); Now only three objects are created and the one that causes the crash has the resourceindex '3'. It is created in line 3. I found the following additional information: There is a function do_COM_propput in ext/com/COM.c static void do_COM_propput(pval *return_value, comval *obj, pval *arg_property, pval *value TSRMLS_DC) { ... hr = php_COM_invoke(obj, dispid, DISPATCH_PROPERTYPUT, &dispparams, NULL, &ErrString TSRMLS_CC); ... hr = php_COM_invoke(obj, dispid, DISPATCH_PROPERTYGET, &dispparams, var_result, &ErrString TSRMLS_CC); if (SUCCEEDED(hr)) { php_variant_to_pval(var_result, return_value, codepage TSRMLS_CC); } else { *return_value = *value; zval_copy_ctor(return_value); } ... } The object is created by php_variant_to_pval. I do not understand why PHP is making a PROPERTYGET on the object on a put request, because it is possible for some COM object to have write only properties that do not implement the get_... method. But that's another story. I will send the zipped COM example server sources to your e-mail. Best regards, Michael ------------------------------------------------------------------------ [2002-08-09 21:48:40] phanto@php.net wow, this is indeed an exemplary bugreport :) can you also tell me on which line in the php code the object with the resource index 4 is created ? or can you mail me your sample com server, this would save me a bit of work. implicit objects should only be created in two cases, either if they are a return value of a function or property or if you dereference a member (e.g. $obj->foo->bar(), then an unnamed object for foo will be created), but these should be released again immediately if the were not assigned to a phpspace variable. as i don't see any of the two cases i'm a bit confused and pondering where the 4th object instance comes from. harald ------------------------------------------------------------------------ [2002-08-09 08:03:06] mlorenz@novadys.de This problem did not occur in PHP 4.0.6 ------------------------------------------------------------------------ [2002-08-09 07:38:19] mlorenz@novadys.de It seems that the line $myC->B = $myB is responsible for the crash, because it does not crash when I put // in front of the line. ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at http://bugs.php.net/18800 -- Edit this bug report at http://bugs.php.net/?id=18800&edit=1

« previous php.bugs (#16545) next »