Skip to content

Zend: release the trampoline when zend_call_function() bails early - #313

Closed
iliaal wants to merge 1 commit into
masterfrom
fix/call-function-trampoline-leak
Closed

iliaal wants to merge 1 commit into
masterfrom
fix/call-function-trampoline-leak

Conversation

@iliaal

@iliaal iliaal commented Sep 21, 2026

Copy link
Copy Markdown
Owner

Two early returns in zend_call_function() skip zend_release_fcall_info_cache(): the one taken when zend_deprecated_function() leaves an exception pending, and the one taken when zend_handle_undef_args() fails. The three sibling early returns in the same function already release it. Both leak the trampoline, so a #[\Deprecated] __call() whose deprecation is promoted to an exception, and a missing required argument on Closure::__invoke(), each leak 256 bytes per call and trip the EG(trampoline) assertion in shutdown_executor() on a debug build.

The test covers both sites independently: with either hunk reverted on its own it still fails.

Two early returns in zend_call_function() skip
zend_release_fcall_info_cache(): the one taken when zend_deprecated_function()
leaves an exception pending, and the one taken when zend_handle_undef_args()
fails. Both leak the trampoline, so a #[\Deprecated] __call() whose
deprecation is promoted to an exception, and a missing required argument on
Closure::__invoke(), each leak 256 bytes per call and trip the
EG(trampoline) assertion in shutdown_executor().
@iliaal

iliaal commented Sep 22, 2026

Copy link
Copy Markdown
Owner Author

Merged upstream as d19c413 (php#23831).

@iliaal iliaal closed this Sep 22, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant