Skip to content

AOT: fix intermittent free() on e08_spread (#24226) - #24269

Merged
PurHur merged 1 commit into
masterfrom
agent/issue-24226-aot-spread-heap
Jul 28, 2026
Merged

PurHur merged 1 commit into
masterfrom
agent/issue-24226-aot-spread-heap

Conversation

@PurHur

@PurHur PurHur commented Jul 28, 2026

Copy link
Copy Markdown
Owner

Summary

  • Persist __ref__ aggregate updates: insertValue results are now stored in __ref__init / __ref__addref / __ref__delref (previously a no-op, so refcounts never hit memory).
  • Fix __value__valueDelref to load the heap pointer for string/object/hashtable tags only, then clear the type (old codegen bitcast the payload storage as __ref__virtual*).
  • Make __value__writeHashtable retain like writeObject; drop redundant call-site addrefs.
  • @differential-repeat: 30 on e08_spread so any regress stays honest.

Closes #24226

Test plan

  • php bin/compile.php -o /tmp/e08 test/differential/cases/e08_spread.php && 50× run → 50/50 OK (was ~50% free(): invalid pointer)
  • script/differential-sweep.sh --aot --dir <e08-only> --repeat 30 → ok e08_spread.php (30/30 runs)
  • Local implode(",", $p) + hello still green under the new refcount path

TRY_FIRST

  • release-readiness --json: user_release_ready=yes (before change)
  • inventory doc drift only (not this change)

Note

Non-variadic function s($v){ implode(",", $v); } s($p) still segfaults early in this workspace — separate from the filed e08 spread/variadic path; not claimed fixed here.

Made with Cursor

__ref__init/addref/delref discarded insertValue results (never stored), and
valueDelref bitcast value-box payload storage as a ref header. Together with
writeHashtable not retaining the HT, by-value array args corrupted the heap
~43% of the time on e08_spread.

Co-authored-by: Cursor <cursoragent@cursor.com>
@PurHur
PurHur merged commit a71bd1f into master Jul 28, 2026
@PurHur
PurHur deleted the agent/issue-24226-aot-spread-heap branch July 28, 2026 13:40
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

AOT: e08_spread is flaky — fails ~43% of runs with free(): invalid pointer (heap corruption)

1 participant