Skip to content

[PDO] Report bound params/columns to GC and fix driver_params refcount - #302

Open
iliaal wants to merge 1 commit into
PHP-8.4from
fix/pdo-getgc-boundparams-84
Open

[PDO] Report bound params/columns to GC and fix driver_params refcount#302
iliaal wants to merge 1 commit into
PHP-8.4from
fix/pdo-getgc-boundparams-84

Conversation

@iliaal

@iliaal iliaal commented Aug 24, 2026

Copy link
Copy Markdown
Owner

PDOStatement::get_gc() never reported the bound_params and bound_columns hash tables, so cycles created through the bindParam()/bindColumn() driver_params argument were invisible to the collector and leaked permanently; both hashtables are now walked and their zvals added to the GC buffer like the sibling handlers do. A sibling audit found a related refcount bug that kept even correctly reported cycles uncollectable: since 5b8d0dc register_bound_param() ZVAL_COPYs driver_params while really_register_bound_param() addrefs it again, storing one zval with two references; the extra addref is removed and registration failure in register_bound_param() now releases the caller's reference. The new phpt fails on unpatched PHP-8.4 (destructors never run) and passes with the patch.

PDOStatement::get_gc() never reported the bound_params and bound_columns
hash tables, so cycles through bindParam()/bindColumn() arguments were
invisible to the collector and leaked permanently. Additionally, since
5b8d0dc register_bound_param() ZVAL_COPY'd driver_params while
really_register_bound_param() addref'd it again, storing one zval with
two references, which kept even correctly reported cycles uncollectable;
the extra addref is removed and the failure path now releases the caller's
reference. Sibling audit: free_obj destroys both hashtables and param_dtor
releases driver_params, other get_gc sites unaffected.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant