Skip to content

Fix session save-handler argv leak on recursive rejection - #106

Closed
iliaal wants to merge 1 commit into
PHP-8.4from
session-recursive-argv-leak
Closed

iliaal wants to merge 1 commit into
PHP-8.4from
session-recursive-argv-leak

Conversation

@iliaal

@iliaal iliaal commented Jun 21, 2026

Copy link
Copy Markdown
Owner

ps_call_handler() returns on the recursive-call rejection branch before the argv cleanup loop, leaking one ref per owned argument. A save handler that re-enters session machinery (for example session_destroy() from within write()) leaks the copied session id and data strings; valgrind under USE_ZEND_ALLOC=0 shows 64 bytes definitely lost per trip. Folding the handler call into an else branch runs the cleanup unconditionally.

ps_call_handler() returned on the recursive-call rejection branch before
reaching the argv cleanup loop, leaking one ref per owned argument. The
read/write/destroy/validate_sid/update_timestamp callers copy the session
id and data into argv and rely on ps_call_handler() to release them, so a
handler that re-enters session machinery (for example calling
session_destroy() from within a write handler) leaks those strings. Fold
the handler call into an else branch so the cleanup loop always runs.
@iliaal

iliaal commented Jun 21, 2026

Copy link
Copy Markdown
Owner Author

Submitted upstream as php#22382.

@iliaal iliaal closed this Jun 21, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant