Bug #73960 [Csd]: Leak with instance method calling static method with referenced return

From: Date: Mon, 20 Mar 2017 17:09:46 +0000
Subject: Bug #73960 [Csd]: Leak with instance method calling static method with referenced return
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-207964@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=73960&edit=1 ID: 73960 User updated by: highmind63 at gmail dot com Reported by: highmind63 at gmail dot com Summary: Leak with instance method calling static method with referenced return Status: Closed Type: Bug Package: Class/Object related Operating System: Windows 10 and Ubuntu 14.04 PHP Version: 7.0.15 Block user comment: N Private report: N New Comment: Is this going to be backported to 7.0.x? Previous Comments: ------------------------------------------------------------------------ [2017-03-10 17:23:32] nikic@php.net Automatic comment on behalf of nikita.ppv@gmail.com Revision: http://git.php.net/?p=php-src.git;a=commit;h=29ee3e3c49bd3b32219f45ea4d4f1263c3021150 Log: Fixed bug #73960 ------------------------------------------------------------------------ [2017-01-22 11:07:07] krakjoe@php.net Nikita can you turn that into a PR with test case please, so we can get CI and some attention. ------------------------------------------------------------------------ [2017-01-21 14:18:16] nikic@php.net Even simpler repro: $array = array('one'); $array = $ref =& $array; The problem is that in zend_assign_to_variable() in the case where LHS and RHS point to the same value we currently do not destroy the RHS if it is a VAR. Proposed patch: diff --git a/Zend/zend_execute.h b/Zend/zend_execute.h index 554ad28..5f0caf6 100644 --- a/Zend/zend_execute.h +++ b/Zend/zend_execute.h @@ -81,6 +81,10 @@ static zend_always_inline zval* zend_assign_to_variable(zval *variable_ptr, zval return variable_ptr; } if (ZEND_CONST_COND(value_type & (IS_VAR|IS_CV), 1) && variable_ptr == value) { + if (value_type == IS_VAR && ref) { + ZEND_ASSERT(GC_REFCOUNT(ref) > 1); + --GC_REFCOUNT(ref); + } return variable_ptr; } garbage = Z_COUNTED_P(variable_ptr); ------------------------------------------------------------------------ [2017-01-21 13:03:14] nikic@php.net Reduced testcase: function &leaked(array &$array = null) { $array = array('one'); return $array; } $array = leaked($array); ------------------------------------------------------------------------ [2017-01-21 12:50:19] cmb@php.net > This apparently affects 7.0.x but not 7.1.x Running the supplied test script on --enable-debug builds shows memory leaks for PHP-7.1 and master as well. ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=73960 -- Edit this bug report at https://bugs.php.net/bug.php?id=73960&edit=1

« previous php.bugs (#207964) next »