Bug #78589 [Ana->Csd]: Memory leak with GC + __destruct()

From: Date: Tue, 24 Sep 2019 10:19:22 +0000
Subject: Bug #78589 [Ana->Csd]: Memory leak with GC + __destruct()
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-222906@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=78589&edit=1 ID: 78589 Updated by: nikic@php.net Reported by: nikic@php.net Summary: Memory leak with GC + __destruct() -Status: Analyzed +Status: Closed Type: Bug Package: Scripting Engine problem PHP Version: 7.4Git-2019-09-23 (Git) Block user comment: N Private report: N New Comment: Automatic comment on behalf of nikita.ppv@gmail.com Revision: http://git.php.net/?p=php-src.git;a=commit;h=73115ef8730cc2466fdb039acb6b9463bc08808a Log: Fixed bug #78589 Previous Comments: ------------------------------------------------------------------------ [2019-09-23 10:35:07] nikic@php.net The problem seems to be that we set gc_protected=1 during the zval destruction phase. However, in this case the destruction of the object wants to add the inner array to the GC buffer. (It was previously removed as nested data of the __destruct object.) ------------------------------------------------------------------------ [2019-09-23 10:20:38] nikic@php.net Description: ------------ This is reduced from an OSS-Fuzz testcase involving unserialize(), but turns out to be some kind of generic GC bug. It is related to the changes to __destruct() handling in 7.4. Test script: --------------- class Test { public function __destruct() {} } $test = new Test; $test->foo = [&$test->foo]; $ary = [&$ary, $test]; unset($ary, $test); gc_collect_cycles(); Actual result: -------------- [Mon Sep 23 12:17:48 2019] Script: '/home/nikic/php-src-fuzz/t009.php' Zend/zend_vm_execute.h(27609) : Freeing 0x00007f8220201940 (32 bytes), script=/home/nikic/php-src-fuzz/t009.php [Mon Sep 23 12:17:48 2019] Script: '/home/nikic/php-src-fuzz/t009.php' /home/nikic/php-src-fuzz/Zend/zend_hash.c(256) : Freeing 0x00007f82202588a0 (56 bytes), script=/home/nikic/php-src-fuzz/t009.php [Mon Sep 23 12:17:48 2019] Script: '/home/nikic/php-src-fuzz/t009.php' /home/nikic/php-src-fuzz/Zend/zend_hash.c(131) : Freeing 0x00007f822025c280 (264 bytes), script=/home/nikic/php-src-fuzz/t009.php === Total 3 memory leaks detected === ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=78589&edit=1

« previous php.bugs (#222906) next »