Bug #71778 [Opn->Nab]: zend_std_get_method() inconsistently increments the method_name refcount

From: Date: Thu, 10 Mar 2016 23:21:46 +0000
Subject: Bug #71778 [Opn->Nab]: zend_std_get_method() inconsistently increments the method_name refcount
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-199745@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=71778&edit=1 ID: 71778 Updated by: aharvey@php.net Reported by: aharvey@php.net Summary: zend_std_get_method() inconsistently increments the method_name refcount -Status: Open +Status: Not a bug Type: Bug Package: Scripting Engine problem Operating System: Irrelevant PHP Version: 7.0Git-2016-03-10 (Git) Block user comment: N Private report: N New Comment: Not a bug, per PR discussion with Nikita. Previous Comments: ------------------------------------------------------------------------ [2016-03-10 22:26:10] aharvey@php.net Description: ------------ I'll file a PR for this shortly. zend_std_get_method() doesn't increment the refcount on the given method_name zend_string (which is good) _except_ when the method is resolved via __call (which is bad). This is due to https://github.com/php/php-src/blob/741bfe3932de28c20f401cc7e0447fffb2bea7d6/Zend/zend_object_handlers.c#L1065-L1069, which calls zend_string_copy() in normal operation. This makes it very easy to leak the string, since a possible pattern might be: method_name = zend_string_init(name, name_len); func = Z_OBJ_HT_P(obj)->get_method(&Z_OBJ_P(obj), method_name, NULL); zend_string_release(method_name); For non-__call classes, method_name is freed at this point. For __call classes, not so much. Obviously another option here is to use zend_string_free(), but I think it'd be considerably better if we just didn't ever increment the refcount. ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=71778&edit=1

« previous php.bugs (#199745) next »