php / php/php-src

zend_types.h:1383: zend_gc_delref: Assertion `p->refcount > 0' failed upon memory exhaustion

Open
#23,586 1 comment 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Bug Category: Engine Status: Verified
Dominant language
C
Stars
40.4k
Forks
8.1k
Avg merge
2d 13h
Merged PRs (30d)
96

Description

Description

The following code:

<?php
class Node {
    public $parent = NULL;
    public $children = array();

    function __construct(?Node $parent=NULL) {
        if ($parent) {
            $parent->children[] = $this;
        }
        $this->children[] = $this;
    }

    function __destruct() {
        $this->children = NULL;
    }
}

define("MAX", 16);

for ($n = 0; $n < 20; $n++) {
    $top = new Node();
    for ($i=0 ; $i<MAX ; $i++) {
        $ci = new Node($top);
        for ($j=0 ; $j<MAX ; $j++) {
            $cj = new Node($ci);
            for ($k=0 ; $n ?? (0 >> $i) & $n ?? $n ?? 20 ?? MAX<MAX ; $k++) {
                $ck = new Node($cj);
            }
        }
    }
    echo "$n\n";
}
echo "ok\n";
?>

Resulted in this output:

0

Fatal error: Allowed memory size of 97517568 bytes exhausted at /home/user/software/php-debug-noasan/src/Zend/zend_gc.c:356 (tried to allocate 4096 bytes) in /tmp/bug.php on line 27
Stack trace:
#0 {main}
php: /home/user/software/php-debug-noasan/src/Zend/zend_types.h:1383: zend_gc_delref: Assertion `p->refcount > 0' failed.
Aborted (core dumped)

But I expected this output instead:

Fatal error: Allowed memory size of 97517568 bytes exhausted at /home/user/software/php-debug-noasan/src/Zend/zend_gc.c:356 (tried to allocate 4096 bytes) in /tmp/bug.php on line 27

This bug seems to be dependent on how much memory you give php, through grid searching I found these values of memory trigger the bug

93M, 94M, 127M, 128M, 159M, 160M, 193M-196M, 243M-248M, 287M-290M, 333M-338M, 383M-390M

Looks very similar to https://github.com/php/php-src/issues/16835 but unsure about same root cause

PHP Version
PHP 8.5.10 (cli) (built: Sep  5 2026 19:25:14) (NTS DEBUG)
Copyright (c) The PHP Group
Zend Engine v4.5.10, Copyright (c) Zend Technologies
    with Zend OPcache v8.5.10, Copyright (c), by Zend Technologies

34308a6666b2d489c509541ea9befea9e2b42348
Operating System

Ubuntu 24.04

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start by running the supplied PHP reproducer with the reported debug build and memory limits. Inspect Zend/zend_gc.c at line 356 and zend_types.h at line 1383, then compare the behavior with issue #16835. Done means memory exhaustion reports the fatal error without triggering the refcount assertion or aborting.

Written by the indexing model from the issue text.

Assessment

Tech stack
c, php
Domain
backend
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Active
Clarity
Mostly clear
Newbie friendliness
45/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.