Project

General

Profile

Actions

Bug #20718

closed

Objects created with Data_Make_Struct and the default free function are not freed

Added by jcalvert (Jonathan Calvert) about 2 months ago. Updated about 20 hours ago.

Status:
Closed
Assignee:
-
Target version:
-
ruby -v:
ruby 3.3.5 (2024-09-03 revision ef084cc8f4) [x86_64-linux]
[ruby-core:119091]

Description

I discovered a memory leak when using the FFI gem prior to version 1.16 and Ruby 3.3 and up.

During debugging I found that this earlier version of FFI uses Data_Make_Struct (https://github.com/ffi/ffi/blob/v1.15.5/ext/ffi_c/Pointer.c#L57) instead of TypedData_Make_Struct and it uses -1 as the free function, which is RUBY_DEFAULT_FREE

When the object goes to get garbage collected, it enters into rb_data_free and it is passed to the RTYPEDDATA_EMBEDDED_P macro even though it is not of RTypedData. Because of that, the conditional is evaluated to false and xfree is never called. This was discovered by using jemalloc leak detection.

I have attached a somewhat minimal replication of the issue. The fix would appear to check the type of the obj before casting it.


Files

pointer_bug.rb (418 Bytes) pointer_bug.rb replication using ffi gem jcalvert (Jonathan Calvert), 09/06/2024 09:40 PM
Gemfile.txt (104 Bytes) Gemfile.txt gemfile for convenience jcalvert (Jonathan Calvert), 09/06/2024 09:41 PM
Actions

Also available in: Atom PDF

Like0
Like0Like0Like1Like0