Bug #78589 [Opn->Ana]: Memory leak with GC + __destruct()
| From: | nikic@php.net | Date: | Mon, 23 Sep 2019 10:35:07 +0000 |
| Subject: | Bug #78589 [Opn->Ana]: Memory leak with GC + __destruct() | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-222890@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=78589&edit=1
ID: 78589
Updated by: nikic@php.net
Reported by: nikic@php.net
Summary: Memory leak with GC + __destruct()
-Status: Open
+Status: Analyzed
Type: Bug
Package: Scripting Engine problem
PHP Version: 7.4Git-2019-09-23 (Git)
Block user comment: N
Private report: N
New Comment:
The problem seems to be that we set gc_protected=1 during the zval destruction phase. However, in
this case the destruction of the object wants to add the inner array to the GC buffer. (It was
previously removed as nested data of the __destruct object.)
Previous Comments:
------------------------------------------------------------------------
[2019-09-23 10:20:38] nikic@php.net
Description:
------------
This is reduced from an OSS-Fuzz testcase involving unserialize(), but turns out to be some kind of
generic GC bug. It is related to the changes to __destruct() handling in 7.4.
Test script:
---------------
class Test {
public function __destruct() {}
}
$test = new Test;
$test->foo = [&$test->foo];
$ary = [&$ary, $test];
unset($ary, $test);
gc_collect_cycles();
Actual result:
--------------
[Mon Sep 23 12:17:48 2019] Script: '/home/nikic/php-src-fuzz/t009.php'
Zend/zend_vm_execute.h(27609) : Freeing 0x00007f8220201940 (32 bytes),
script=/home/nikic/php-src-fuzz/t009.php
[Mon Sep 23 12:17:48 2019] Script: '/home/nikic/php-src-fuzz/t009.php'
/home/nikic/php-src-fuzz/Zend/zend_hash.c(256) : Freeing 0x00007f82202588a0 (56 bytes),
script=/home/nikic/php-src-fuzz/t009.php
[Mon Sep 23 12:17:48 2019] Script: '/home/nikic/php-src-fuzz/t009.php'
/home/nikic/php-src-fuzz/Zend/zend_hash.c(131) : Freeing 0x00007f822025c280 (264 bytes),
script=/home/nikic/php-src-fuzz/t009.php
=== Total 3 memory leaks detected ===
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=78589&edit=1