[php-src] PR #24201: Bug: Memory leak of the last response headers after a nested HTTP request
| From: | EdmondDantes | Date: | Thu, 08 Oct 2026 19:30:30 +0000 |
| Subject: | [php-src] PR #24201: Bug: Memory leak of the last response headers after a nested HTTP request | ||
| Groups: | php.git-pulls | ||
| Request: | Send a blank email to git-pulls+get-39267@lists.php.net to get a copy of this message | ||
Pull Request: https://github.com/php/php-src/pull/24201
Author: EdmondDantes
php_stream_url_wrap_http() releases BG(last_http_headers) before the
request and copies the new headers over it after the request. A request made from the notification
callback of a running one stores its own headers there in between, and the outer copy overwrote that
array without releasing it.
Reproduction (debug build, no extensions beyond pcntl and posix for the test server):
```php
$ctx = stream_context_create([], ['notification' => function ($code) use (&$nested,
$uri) {
if ($code === STREAM_NOTIFY_MIME_TYPE_IS && !$nested) {
$nested = true;
file_get_contents($uri);
}
}]);
file_get_contents($uri, false, $ctx);
```
Expected: no leak. Actual: === Total 4 memory leaks detected === (the nested
request's header array).
The fix releases the stored array before the copy. No behaviour change:
http_get_last_response_headers() already returned the outer request's headers.
Test: ext/standard/tests/http/http_response_header_nested_request.phpt (fails on
PHP-8.4 debug without the fix with the leak report, passes with it). The leak report comes from
debug builds; a release build reports the leak only under ASAN or valgrind.