Bug #71778 [Opn->Nab]: zend_std_get_method() inconsistently increments the method_name refcount
| From: | aharvey@php.net | Date: | Thu, 10 Mar 2016 23:21:46 +0000 |
| Subject: | Bug #71778 [Opn->Nab]: zend_std_get_method() inconsistently increments the method_name refcount | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-199745@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=71778&edit=1
ID: 71778
Updated by: aharvey@php.net
Reported by: aharvey@php.net
Summary: zend_std_get_method() inconsistently increments the
method_name refcount
-Status: Open
+Status: Not a bug
Type: Bug
Package: Scripting Engine problem
Operating System: Irrelevant
PHP Version: 7.0Git-2016-03-10 (Git)
Block user comment: N
Private report: N
New Comment:
Not a bug, per PR discussion with Nikita.
Previous Comments:
------------------------------------------------------------------------
[2016-03-10 22:26:10] aharvey@php.net
Description:
------------
I'll file a PR for this shortly.
zend_std_get_method() doesn't increment the refcount on the given method_name zend_string
(which is good) _except_ when the method is resolved via __call (which is bad). This is due to https://github.com/php/php-src/blob/741bfe3932de28c20f401cc7e0447fffb2bea7d6/Zend/zend_object_handlers.c#L1065-L1069,
which calls zend_string_copy() in normal operation.
This makes it very easy to leak the string, since a possible pattern might be:
method_name = zend_string_init(name, name_len);
func = Z_OBJ_HT_P(obj)->get_method(&Z_OBJ_P(obj), method_name, NULL);
zend_string_release(method_name);
For non-__call classes, method_name is freed at this point. For __call classes, not so much.
Obviously another option here is to use zend_string_free(), but I think it'd be considerably
better if we just didn't ever increment the refcount.
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=71778&edit=1