Skip to content

Fix leak when the added previous exception is already in the chain - #24177

Closed
EdmondDantes wants to merge 2 commits into
php:PHP-8.4from
true-async:exception-previous-in-chain-leak
Closed

EdmondDantes wants to merge 2 commits into
php:PHP-8.4from
true-async:exception-previous-in-chain-leak

Conversation

@EdmondDantes

@EdmondDantes EdmondDantes commented Oct 7, 2026 •

Copy link
Copy Markdown
Contributor

zend_exception_set_previous() takes ownership of add_previous: every exit either releases it or stores it as previous. When the walk over the exception's previous chain reaches add_previous itself, the loop ends and the function returns without releasing it. Pure PHP reaches it from finally:

function f() {
    $e = new RuntimeException("x");
    try {
        throw $e;
    } finally {
        throw new LogicException("y", 0, $e);
    }
}
try { f(); } catch (Throwable $t) {}

A debug build reports Freeing ... (152 bytes), Total 1 memory leaks detected on PHP-8.4 and master. The fix releases add_previous after the loop, as the other discarding exit does.

Tests, one per caller that reaches the leak from PHP code:

  • Zend/tests/try/try_finally_previous_already_in_chain.phpt: an exception thrown in finally (ZEND_HANDLE_EXCEPTION), with the pending exception as the direct previous and one level deeper;
  • Zend/tests/exception_previous_already_in_chain_destructor.phpt: a destructor called during unwinding (zend_objects_destroy_object());
  • Zend/tests/generators/finally/yield_throw_previous_already_in_chain.phpt: finally of a generator destroyed during unwinding (zend_generator_dtor_storage());
  • Zend/tests/fibers/unfinished-fiber-with-throw-previous-already-in-chain.phpt: finally of a fiber destroyed during unwinding (zend_fiber_object_destroy());
  • Zend/tests/fibers/gc-destructor-throw-previous-already-in-chain.phpt: GC destructors run in a fiber (remember_prev_exception()).

zend_exception_set_previous() takes ownership of add_previous. When the walk
over exception's previous chain reaches add_previous, the function returns
without releasing it, e.g. for an exception thrown in finally whose previous
chain holds the pending exception.
…revious()

A destructor during unwinding, a GC destructor fiber, a generator destroyed during unwinding and a fiber destroyed during unwinding each reach the leak through their own call.
@Sjord

Sjord commented Oct 7, 2026

Copy link
Copy Markdown
Contributor

Looks good to me.

@ndossche ndossche left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks

@LamentXU123 LamentXU123 left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thank you.

LamentXU123 added a commit that referenced this pull request Oct 8, 2026
* PHP-8.6:
  Fix leak when the added previous exception is already in the chain (#24177)
t0ny4 pushed a commit to t0ny4/php-src that referenced this pull request Oct 8, 2026
* PHP-8.4:
  Fix leak when the added previous exception is already in the chain (php#24177)
t0ny4 pushed a commit to t0ny4/php-src that referenced this pull request Oct 8, 2026
* PHP-8.5:
  Fix leak when the added previous exception is already in the chain (php#24177)
arnaud-lb added a commit to frodeborli/php-src that referenced this pull request Oct 9, 2026
* up/master: (180 commits)
  Changed the test expected result of `pdo_mysql/bug76815_pdo_mysql_f to %d (php#13808)
  ext/standard: name the real parameter in the unpack() offset error (php#24215)
  ext/readline: Refactor CLI readline completion generators
  Fix phpGH-24081: User opcode DISPATCH runs on a stale frame in the TAILCALL VM
  ext/standard: Validate the bcrypt cost before reading it
  JIT: Avoid object type check if the object is known to be a type (php#24086)
  zend_alloc: move a small block shrunk to the size of the bin below
  Fix phpGH-23979: Nullsafe operator must not flush delayed oplines of an enclosing function
  ext/zip: Reject ZipArchive mutators during close() (php#24025)
  Fix OSS-Fuzz #568005340: FETCH_DIM_FUNC_ARG partial conversion
  Fix too wide type inference for ASSIGN_DIM_OP
  Fix type inference of ADD_ARRAY_UNPACK with integer keys
  Evaluate ZEND_SPACESHIP in SCCP
  Add range inference for SPACESHIP
  JIT: Optimize array checks in comparisons (php#24084)
  Fix leak when the added previous exception is already in the chain (php#24177)
  date: Add `php_date_time_duration_create()` in a new `time_duration.h` (php#24072)
  ext/zip: Fix use-after-free in the archive destructor path (php#23779)
  ext/standard: Optimize array_chunk() by filling packed chunks directly
  Fix phpGH-17626: JIT corrupts opline handler when blacklisting root trace
  ...
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants