Bug #69212 [NEW]: Leaking VIA_HANDLER func when exception thrown in __call/... arg passing
| From: | nikic@php.net | Date: | Tue, 10 Mar 2015 13:56:08 +0000 |
| Subject: | Bug #69212 [NEW]: Leaking VIA_HANDLER func when exception thrown in __call/... arg passing | ||
| Groups: | php.bugs | ||
| Request: | Send a blank email to php-bugs+get-191286@lists.php.net to get a copy of this message | ||
From: nikic
Operating system:
PHP version: 5.5.22
Package: Scripting Engine problem
Bug Type: Bug
Bug description:Leaking VIA_HANDLER func when exception thrown in __call/... arg passing
Description:
------------
Script:
<?php
class Test {
public static function __callStatic($method, $args) {}
}
function do_throw() { throw new Exception; }
try {
Test::foo(do_throw());
} catch (Exception $e) {
echo $e, "\n";
}
Output (valgrind):
exception 'Exception' in /home/nikic/php-5.6/t004.php:7
Stack trace:
#0 /home/nikic/php-5.6/t004.php(10): do_throw()
#1 {main}
==3036==
==3036== HEAP SUMMARY:
==3036== in use at exit: 76 bytes in 2 blocks
==3036== total heap usage: 14,602 allocs, 14,600 frees, 3,148,477
bytes allocated
==3036==
==3036== 76 (72 direct, 4 indirect) bytes in 1 blocks are definitely
lost in loss record 2 of 2
==3036== at 0x4C2AB80: malloc (in
/usr/lib/valgrind/vgpreload_memcheck-amd64-linux.so)
==3036== by 0x7D7983: _emalloc (zend_alloc.c:2427)
==3036== by 0x84668E: zend_get_user_callstatic_function
(zend_object_handlers.c:1137)
==3036== by 0x846A2A: zend_std_get_static_method
(zend_object_handlers.c:1192)
==3036== by 0x857699:
ZEND_INIT_STATIC_METHOD_CALL_SPEC_CONST_CONST_HANDLER
(zend_vm_execute.h:3596)
==3036== by 0x84FCB6: execute_ex (zend_vm_execute.h:363)
==3036== by 0x84FD3F: zend_execute (zend_vm_execute.h:388)
==3036== by 0x810E00: zend_execute_scripts (zend.c:1327)
==3036== by 0x779E7A: php_execute_script (main.c:2525)
==3036== by 0x8BFAB4: do_cli (php_cli.c:994)
==3036== by 0x8C0DE2: main (php_cli.c:1378)
We don't three the ZEND_ACC_CALL_VIA_HANDLER temp function. Applies to
__call, __callStatic and probably Closure __invoke.
Reproducible in PHP 5.5, PHP 5.6 and PHP 7.
--
Edit bug report at https://bugs.php.net/bug.php?id=69212&edit=1
--
Try a snapshot (PHP 5.4): https://bugs.php.net/fix.php?id=69212&r=trysnapshot54
Try a snapshot (PHP 5.5): https://bugs.php.net/fix.php?id=69212&r=trysnapshot55
Try a snapshot (trunk): https://bugs.php.net/fix.php?id=69212&r=trysnapshottrunk
Fixed in SVN: https://bugs.php.net/fix.php?id=69212&r=fixed
Fixed in release: https://bugs.php.net/fix.php?id=69212&r=alreadyfixed
Need backtrace: https://bugs.php.net/fix.php?id=69212&r=needtrace
Need Reproduce Script: https://bugs.php.net/fix.php?id=69212&r=needscript
Try newer version: https://bugs.php.net/fix.php?id=69212&r=oldversion
Not developer issue: https://bugs.php.net/fix.php?id=69212&r=support
Expected behavior: https://bugs.php.net/fix.php?id=69212&r=notwrong
Not enough info: https://bugs.php.net/fix.php?id=69212&r=notenoughinfo
Submitted twice: https://bugs.php.net/fix.php?id=69212&r=submittedtwice
register_globals: https://bugs.php.net/fix.php?id=69212&r=globals
PHP 4 support discontinued: https://bugs.php.net/fix.php?id=69212&r=php4
Daylight Savings: https://bugs.php.net/fix.php?id=69212&r=dst
IIS Stability: https://bugs.php.net/fix.php?id=69212&r=isapi
Install GNU Sed: https://bugs.php.net/fix.php?id=69212&r=gnused
Floating point limitations: https://bugs.php.net/fix.php?id=69212&r=float
No Zend Extensions: https://bugs.php.net/fix.php?id=69212&r=nozend
MySQL Configuration Error: https://bugs.php.net/fix.php?id=69212&r=mysqlcfg