Bug #68358 [NEW]: memory leak with custom get_method/call_method object handlers

From: Date: Wed, 05 Nov 2014 23:18:15 +0000
Subject: Bug #68358 [NEW]: memory leak with custom get_method/call_method object handlers
Groups: php.bugs 
Request: Send a blank email to php-bugs+get-188474@lists.php.net to get a copy of this message
From:             stesie at brokenpipe dot de
Operating system: irrelevant
PHP version:      5.6.2
Package:          Scripting Engine problem
Bug Type:         Bug
Bug description:memory leak with custom get_method/call_method object handlers

Description:
------------
This is just a minimal example, demonstrating a memory leak I found
writing/debugging a php extension.

I have custom get_method/call_method handlers on a class exported by the
extension to allow dispatching arbitrary calls off php.

However every direct function call leaks a reference on the object
itself;
while a call using call_user_func does *not*.

I wrote a minimal php "hello" extension, which demonstrates the problem,
available at https://gist.github.com/stesie/40d9ab136bea473a16ac
It exports a Hello class, which returns this_ptr->refcount__gc on any
method call.

Each time I call $foo->blar() the refcount__gc is incremented once more
then decremented.  (i.e. leaks a ref to the object)

If I call_user_func([ $foo, 'blar']) however, which I would expect to
behave identical, there's no refcount__gc leak.


I have not digged further into Zend internals, let me know if that would
help.
... or if I'm completely off or doing it wrong :)


cheers
  ~stesie

Test script:
---------------
<?php
 
$foo = new Hello();
var_dump($foo);
 
echo "--- direct method call ---\n";
var_dump($foo->blar());
var_dump($foo->blar());
var_dump($foo->blar());
 
echo "--- call_user_func calls ---\n";
var_dump(call_user_func([ $foo, 'blar' ]));
var_dump(call_user_func([ $foo, 'blar' ]));
var_dump(call_user_func([ $foo, 'blar' ]));

Expected result:
----------------
successing direct method calls should not increment refcount__gc

Actual result:
--------------
object(Hello)#1 (0) {
}
--- direct method call ---
int(2)
int(3)
int(4)
--- call_user_func calls ---
int(6)
int(6)
int(6)
[Wed Nov  5 22:40:08 2014]  Script: 
'/tmp/40d9ab136bea473a16ac/foo.php'
/usr/local/src/php-5.6.2/Zend/zend_vm_execute.h(944) :  Freeing
0x7FFFF7FE2578 (32 bytes), script=/tmp/40d9ab136bea473a16ac/foo.php
=== Total 1 memory leaks detected ===
[Inferior 1 (process 1711) exited normally]


-- 
Edit bug report at https://bugs.php.net/bug.php?id=68358&edit=1
-- 
Try a snapshot (PHP 5.4):   https://bugs.php.net/fix.php?id=68358&r=trysnapshot54
Try a snapshot (PHP 5.5):   https://bugs.php.net/fix.php?id=68358&r=trysnapshot55
Try a snapshot (trunk):     https://bugs.php.net/fix.php?id=68358&r=trysnapshottrunk
Fixed in SVN:               https://bugs.php.net/fix.php?id=68358&r=fixed
Fixed in release:           https://bugs.php.net/fix.php?id=68358&r=alreadyfixed
Need backtrace:             https://bugs.php.net/fix.php?id=68358&r=needtrace
Need Reproduce Script:      https://bugs.php.net/fix.php?id=68358&r=needscript
Try newer version:          https://bugs.php.net/fix.php?id=68358&r=oldversion
Not developer issue:        https://bugs.php.net/fix.php?id=68358&r=support
Expected behavior:          https://bugs.php.net/fix.php?id=68358&r=notwrong
Not enough info:            https://bugs.php.net/fix.php?id=68358&r=notenoughinfo
Submitted twice:            https://bugs.php.net/fix.php?id=68358&r=submittedtwice
register_globals:           https://bugs.php.net/fix.php?id=68358&r=globals
PHP 4 support discontinued: https://bugs.php.net/fix.php?id=68358&r=php4
Daylight Savings:           https://bugs.php.net/fix.php?id=68358&r=dst
IIS Stability:              https://bugs.php.net/fix.php?id=68358&r=isapi
Install GNU Sed:            https://bugs.php.net/fix.php?id=68358&r=gnused
Floating point limitations: https://bugs.php.net/fix.php?id=68358&r=float
No Zend Extensions:         https://bugs.php.net/fix.php?id=68358&r=nozend
MySQL Configuration Error:  https://bugs.php.net/fix.php?id=68358&r=mysqlcfg



Thread (2 messages)

« previous php.bugs (#188474) next »