Skip to content

Zend: gc_collect_white() frees data reachable from a resurrected object. - #24061

Closed
devnexen wants to merge 2 commits into
php:PHP-8.4from
devnexen:gh24050
Closed

devnexen wants to merge 2 commits into
php:PHP-8.4from
devnexen:gh24050

Conversation

@devnexen

@devnexen devnexen commented Oct 1, 2026

Copy link
Copy Markdown
Member

A properties table shared through a cast got no garbage slot, so nested data removal stopped at it before the destructor ran.

Fix #24050

A properties table shared through a cast got no garbage slot, so nested
data removal stopped at it before the destructor ran.

Fix php#24050
@devnexen
devnexen marked this pull request as ready for review October 1, 2026 22:22

@arnaud-lb arnaud-lb left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

gc_collect_white() adds all refcounted nodes to the GARBAGE buffer, but when a ht is reached as the return of get_gc we forget to do so, preventing it from ever being added to GARBAGE as it's already seen.

gc_remove_nested_data_from_buffer() follows only GARBAGE, so ht and anything reachable from it is left in GARBAGE.

The ht is then made reachable by the dtor, and everything left in GARBAGE is freed.

The fix looks good to me!

@devnexen devnexen closed this in 7b75d71 Oct 2, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

GC frees an object still held by a resurrected closure when (object) and use share an array

2 participants