[php-src] Issue #11883: memory leak in `zend_type_release`

From: Date: Sat, 05 Aug 2023 17:22:47 +0000
Subject: [php-src] Issue #11883: memory leak in `zend_type_release`
Groups: php.bugs 
Request: Send a blank email to php-bugs+get-245108@lists.php.net to get a copy of this message
Issue: https://github.com/php/php-src/issues/11883 Author: ju1ius ### Description Hi, The [zend_type_release](https://github.com/php/php-src/blob/4f84b159b908921cc627ef81de0c6ae883e88a78/Zend/zend_opcode.c#L111) function never frees intersection type lists inside union type lists (i.e. Iterator|(Traversable&Countable), which leads to valgrind reporting memory leaks. The issue does not manifest itself with userland code because userland zend_types are arena-allocated, and does not show-up in most extensions because gen_stubs cannot generate proper DNF types. Here's the current code of the function, with added comments: ```c ZEND_API void zend_type_release(zend_type type, bool persistent) { if (ZEND_TYPE_HAS_LIST(type)) { zend_type *list_type, *sublist_type; ZEND_TYPE_LIST_FOREACH(ZEND_TYPE_LIST(type), list_type) { if (ZEND_TYPE_HAS_LIST(*list_type)) { ZEND_TYPE_LIST_FOREACH(ZEND_TYPE_LIST(*list_type), sublist_type) { if (ZEND_TYPE_HAS_NAME(*sublist_type)) { zend_string_release(ZEND_TYPE_NAME(*sublist_type)); } } ZEND_TYPE_LIST_FOREACH_END(); // -------------------- // The inner list should be freed here, but it is not... // -------------------- } else if (ZEND_TYPE_HAS_NAME(*list_type)) { zend_string_release(ZEND_TYPE_NAME(*list_type)); } } ZEND_TYPE_LIST_FOREACH_END(); if (!ZEND_TYPE_USES_ARENA(type)) { pefree(ZEND_TYPE_LIST(type), persistent); } } else if (ZEND_TYPE_HAS_NAME(type)) { zend_string_release(ZEND_TYPE_NAME(type)); } } ``` ### PHP Version PHP 8.3-dev ### Operating System _No response_

« previous php.bugs (#245108) next »