Repository navigation
Fix leak when the added previous exception is already in the chain - #24177
Closed
EdmondDantes wants to merge 2 commits into
Closed
EdmondDantes wants to merge 2 commits into
EdmondDantes wants to merge 2 commits into
Conversation
zend_exception_set_previous() takes ownership of add_previous. When the walk over exception's previous chain reaches add_previous, the function returns without releasing it, e.g. for an exception thrown in finally whose previous chain holds the pending exception.
…revious() A destructor during unwinding, a GC destructor fiber, a generator destroyed during unwinding and a fiber destroyed during unwinding each reach the leak through their own call.
Contributor
|
Looks good to me. |
LamentXU123
added a commit
that referenced
this pull request
Oct 8, 2026
* PHP-8.6: Fix leak when the added previous exception is already in the chain (#24177)
t0ny4
pushed a commit
to t0ny4/php-src
that referenced
this pull request
Oct 8, 2026
* PHP-8.4: Fix leak when the added previous exception is already in the chain (php#24177)
t0ny4
pushed a commit
to t0ny4/php-src
that referenced
this pull request
Oct 8, 2026
* PHP-8.5: Fix leak when the added previous exception is already in the chain (php#24177)
arnaud-lb
added a commit
to frodeborli/php-src
that referenced
this pull request
Oct 9, 2026
* up/master: (180 commits) Changed the test expected result of `pdo_mysql/bug76815_pdo_mysql_f to %d (php#13808) ext/standard: name the real parameter in the unpack() offset error (php#24215) ext/readline: Refactor CLI readline completion generators Fix phpGH-24081: User opcode DISPATCH runs on a stale frame in the TAILCALL VM ext/standard: Validate the bcrypt cost before reading it JIT: Avoid object type check if the object is known to be a type (php#24086) zend_alloc: move a small block shrunk to the size of the bin below Fix phpGH-23979: Nullsafe operator must not flush delayed oplines of an enclosing function ext/zip: Reject ZipArchive mutators during close() (php#24025) Fix OSS-Fuzz #568005340: FETCH_DIM_FUNC_ARG partial conversion Fix too wide type inference for ASSIGN_DIM_OP Fix type inference of ADD_ARRAY_UNPACK with integer keys Evaluate ZEND_SPACESHIP in SCCP Add range inference for SPACESHIP JIT: Optimize array checks in comparisons (php#24084) Fix leak when the added previous exception is already in the chain (php#24177) date: Add `php_date_time_duration_create()` in a new `time_duration.h` (php#24072) ext/zip: Fix use-after-free in the archive destructor path (php#23779) ext/standard: Optimize array_chunk() by filling packed chunks directly Fix phpGH-17626: JIT corrupts opline handler when blacklisting root trace ...
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
zend_exception_set_previous()takes ownership ofadd_previous: every exit either releases it or stores it asprevious. When the walk over the exception'spreviouschain reachesadd_previousitself, the loop ends and the function returns without releasing it. Pure PHP reaches it fromfinally:A debug build reports
Freeing ... (152 bytes),Total 1 memory leaks detectedon PHP-8.4 and master. The fix releasesadd_previousafter the loop, as the other discarding exit does.Tests, one per caller that reaches the leak from PHP code:
Zend/tests/try/try_finally_previous_already_in_chain.phpt: an exception thrown infinally(ZEND_HANDLE_EXCEPTION), with the pending exception as the directpreviousand one level deeper;Zend/tests/exception_previous_already_in_chain_destructor.phpt: a destructor called during unwinding (zend_objects_destroy_object());Zend/tests/generators/finally/yield_throw_previous_already_in_chain.phpt:finallyof a generator destroyed during unwinding (zend_generator_dtor_storage());Zend/tests/fibers/unfinished-fiber-with-throw-previous-already-in-chain.phpt:finallyof a fiber destroyed during unwinding (zend_fiber_object_destroy());Zend/tests/fibers/gc-destructor-throw-previous-already-in-chain.phpt: GC destructors run in a fiber (remember_prev_exception()).