Bug #78589 [Opn->Ana]: Memory leak with GC + __destruct()

From: Date: Mon, 23 Sep 2019 10:35:07 +0000
Subject: Bug #78589 [Opn->Ana]: Memory leak with GC + __destruct()
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-222890@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=78589&edit=1 ID: 78589 Updated by: nikic@php.net Reported by: nikic@php.net Summary: Memory leak with GC + __destruct() -Status: Open +Status: Analyzed Type: Bug Package: Scripting Engine problem PHP Version: 7.4Git-2019-09-23 (Git) Block user comment: N Private report: N New Comment: The problem seems to be that we set gc_protected=1 during the zval destruction phase. However, in this case the destruction of the object wants to add the inner array to the GC buffer. (It was previously removed as nested data of the __destruct object.) Previous Comments: ------------------------------------------------------------------------ [2019-09-23 10:20:38] nikic@php.net Description: ------------ This is reduced from an OSS-Fuzz testcase involving unserialize(), but turns out to be some kind of generic GC bug. It is related to the changes to __destruct() handling in 7.4. Test script: --------------- class Test { public function __destruct() {} } $test = new Test; $test->foo = [&$test->foo]; $ary = [&$ary, $test]; unset($ary, $test); gc_collect_cycles(); Actual result: -------------- [Mon Sep 23 12:17:48 2019] Script: '/home/nikic/php-src-fuzz/t009.php' Zend/zend_vm_execute.h(27609) : Freeing 0x00007f8220201940 (32 bytes), script=/home/nikic/php-src-fuzz/t009.php [Mon Sep 23 12:17:48 2019] Script: '/home/nikic/php-src-fuzz/t009.php' /home/nikic/php-src-fuzz/Zend/zend_hash.c(256) : Freeing 0x00007f82202588a0 (56 bytes), script=/home/nikic/php-src-fuzz/t009.php [Mon Sep 23 12:17:48 2019] Script: '/home/nikic/php-src-fuzz/t009.php' /home/nikic/php-src-fuzz/Zend/zend_hash.c(131) : Freeing 0x00007f822025c280 (264 bytes), script=/home/nikic/php-src-fuzz/t009.php === Total 3 memory leaks detected === ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=78589&edit=1

« previous php.bugs (#222890) next »