Edit report at https://bugs.php.net/bug.php?id=77922&edit=1
ID: 77922
Updated by: nikic@php.net
Reported by: enumag at gmail dot com
Summary: Double release of doc comment on inherited shadow
property
-Status: Analyzed
+Status: Closed
Type: Bug
Package: Unknown/Other Function
Operating System: Ubuntu
PHP Version: 7.3.4
Block user comment: N
Private report: N
New Comment:
Automatic comment on behalf of nikita.ppv@gmail.com
Revision: http://git.php.net/?p=php-src.git;a=commit;h=be7e819068985859f92e4af21e49b4f647dd0467
Log: Fixed bug #77922
Previous Comments:
------------------------------------------------------------------------
[2019-08-16 21:50:00] nikic@php.net
@enumag: Thanks for providing the reproducer!
I think that part of your problem is already fixed in the upcoming release, at least most of the
valgrind warnings that I could reproduce on earlier versions no longer do on current 7.3 HEAD. Quite
likely one of the recent GC fixes applied to your case.
However, there is still a double-free happening during shutdown. I was able to reduce it to the
following embarrassingly simple reproducer:
<?php
class A {
/** Foo */
private $prop;
}
class B extends A {
}
class C extends B {
}
The issue is that we free the doc comment either if the property was declared on the class, or it is
a SHADOW property, because those get copied. However, this does not consider the case where a SHADOW
property is inherited, in which case no copy occurs.
This is fixed in 7.4 already because the SHADOW property concept was removed.
------------------------------------------------------------------------
[2019-08-16 13:46:58] enumag at gmail dot com
@nikic Sent you an email to nikic@php.net with an archive to reproduce the segfault.
------------------------------------------------------------------------
[2019-08-13 10:00:20] nikic@php.net
@enumag: That would be useful, yes.
------------------------------------------------------------------------
[2019-08-13 09:28:09] enumag at gmail dot com
For the original issue, would it help if we provide a repository where the issue can be reproduced
every time?
------------------------------------------------------------------------
[2019-08-13 08:45:00] nikic@php.net
A valgrind trace would be pretty useful. It's pretty likely that this is unrelated to the
original issue here (pretty much any form of memory corruption is likely to end up crashing in the
allocator...)
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=77922
--
Edit this bug report at https://bugs.php.net/bug.php?id=77922&edit=1