Bug #65387 [Com]: Circular references in SPL iterators are not garbage collected

From: Date: Thu, 01 Oct 2020 15:14:32 +0000
Subject: Bug #65387 [Com]: Circular references in SPL iterators are not garbage collected
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-229315@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=65387&edit=1

 ID:                 65387
 Comment by:         php dot net at ss dot st dot tc
 Reported by:        bugs dot php dot net at ss dot chernousov dot net
 Summary:            Circular references in SPL iterators are not garbage
                     collected
 Status:             Closed
 Type:               Bug
 Package:            Scripting Engine problem
 Operating System:   Any
 PHP Version:        5.5.1
 Assigned To:        nikic
 Block user comment: N
 Private report:     N

 New Comment:

The bug author here.

Thank you for fixing the issue with SPL iterators. However, the original issue was about circular
references on callbacks in general, and not specifically about handling circular references in SPL
iterators. I see the bug title was changed on 2020-10-01, affecting its meaning quite much. Among
the 6 cases provided (https://gist.github.com/5lava/53aa2e53c7f8c658f045), only one of them had to
do with SPL iterators. I tested that case and I confirm it's fixed, but the 2nd one still
leaks, as it did 7 years ago.

I did not re-test cases 3-6 since then, they are rather specific and I don't know if
that's something that has to be addressed in the corresponding extensions or PHP core itself.

That does not, however, diminish the scale of the problem. For example, with curl:

// TEST 7: curl callback
$obj->a = curl_init('https://www.php.net/');
curl_setopt($obj->a, CURLOPT_HEADERFUNCTION, static function() use ($obj) {});

That leaks. Or with PDO/sqlite:

// TEST 8: PDO/sqlite callback
$db = new PDO('sqlite::memory:');
$db->sqliteCreateFunction('md5rev', static function() use ($obj) {}, 1);

That leaks, too. My point being: the bug (the reported one!) was NOT fixed.

@nikic I'd appreciate some input from you regarding this matter. Thank you.


Previous Comments:
------------------------------------------------------------------------
[2020-10-01 14:13:22] nikic@php.net

Automatic comment on behalf of nikita.ppv@gmail.com
Revision: http://git.php.net/?p=php-src.git;a=commit;h=afab9eb48c883766b7870f76f2e2b0a4bd575786
Log: Fix bug #65387

------------------------------------------------------------------------
[2020-09-24 09:09:09] mvorisek at mvorisek dot cz

@nikic why dual_it can not be GCed like any other object and is this something than can be fixed?

https://3v4l.org/AL2Hr the issue seems to be present even if
the callback is static but the (outer) Iterator is linked with any object

------------------------------------------------------------------------
[2020-09-23 20:08:19] nikic@php.net

Related To: Bug #80125

------------------------------------------------------------------------
[2016-03-26 23:40:58] nikic@php.net

Still leaks, even in PHP 7. dual_it doesn't implement GC handling.

------------------------------------------------------------------------
[2013-08-04 20:14:37] bugs dot php dot net at ss dot chernousov dot net

Description:
------------
GC fails to resolve the circular reference if object A retains a reference to a 
callback in object B and object B retains a reference to object A. Both objects 
leak.

Native PHP stuff like SPL iterators with callbacks and Stream callbacks are also 
vulnerable to this problem.

This does not apply to userland PHP objects (i.e. objects of classes that were 
defined in PHP scripts by a user).

I provided a test script with a number of tests, including SPL iterators with 
callbacks, Stream callbacks, as well as 3rd-party extensions like pecl-event, 
pecl-ev, pecl-libevent, pecl-eio.

Test script:
---------------
https://gist.github.com/5lava/53aa2e53c7f8c658f045

Expected result:
----------------
==== NULL ====
==== GC ====
Obj::__destruct
==== THE END ====

or

==== NULL ====
Obj::__destruct
==== GC ====
==== THE END ====


Actual result:
--------------
==== NULL ====
==== GC ====
==== THE END ====
Obj::__destruct



------------------------------------------------------------------------



--
Edit this bug report at https://bugs.php.net/bug.php?id=65387&edit=1


Thread (11 messages)

« previous php.bugs (#229315) next »