Skip to content

Return a stack block unchanged from objc_retain() - #427

Closed
ashalkhakov wants to merge 1 commit into
gnustep:masterfrom
ashalkhakov:fix/stack-block-retain
Closed

ashalkhakov wants to merge 1 commit into
gnustep:masterfrom
ashalkhakov:fix/stack-block-retain

Conversation

@ashalkhakov

Copy link
Copy Markdown

retain() copied any block to the heap and returned the copy, so objc_retain() on a stack block returned a different object. The code clang generates cannot rely on that: LLVM's ARC optimiser treats objc_retain() as returning its argument, and once the call is optimised nothing uses the result. The copy is never released, and neither is anything it captured.

It happens as soon as a function or method that captures a block parameter in another block is inlined into its caller, with optimisation on:

static void keep(void (^block)(void))
{
  kept = ^{ block(); };
}
...
keep(^{ use(object); });

ARC retains the parameter on entry. Here that makes a heap copy of the caller's stack block, which retains object. The matching release goes to the stack block, which the runtime ignores, so object is never deallocated. Completion handlers and dispatch_async() have exactly this shape. In a server built this way every connection object leaked, because its completion block was captured like this.

Apple's runtime returns a stack block unchanged from objc_retain(), and so does this one now. Moving a block to the heap is objc_retainBlock()'s job, and ARC already calls it wherever a block must outlive its frame. Heap blocks are still retained through Block_copy(), and an explicit -retain message is not affected: the block classes implement it themselves.

Test/StackBlockRetain_arc.m fails its final assertion in the optimised build without this change and passes with it; the rest of the suite passes either way.

🤖 Generated with Claude Code

retain() copied any block to the heap and returned the copy, so
objc_retain() on a stack block returned a different object. The code
clang generates cannot rely on that: LLVM's ARC optimiser treats
objc_retain() as returning its argument, and once the call is optimised
nothing uses the result. The copy is never released, and neither is
anything it captured.

It happens as soon as a function or method that captures a block
parameter in another block is inlined into its caller, with optimisation
on:

    static void keep(void (^block)(void))
    {
      kept = ^{ block(); };
    }
    ...
    keep(^{ use(object); });

ARC retains the parameter on entry. Here that makes a heap copy of the
caller's stack block, which retains object. The matching release goes to
the stack block, which the runtime ignores, so object is never
deallocated. Completion handlers and dispatch_async() have exactly this
shape. In a server built this way every connection object leaked,
because its completion block was captured like this.

Apple's runtime returns a stack block unchanged from objc_retain(), and
so does this one now. Moving a block to the heap is objc_retainBlock()'s
job, and ARC already calls it wherever a block must outlive its frame.
Heap blocks are still retained through Block_copy(), and an explicit
-retain message is not affected: the block classes implement it
themselves.

Test/StackBlockRetain_arc.m fails its final assertion in the optimised
build without this change and passes with it; the rest of the suite
passes either way.
@davidchisnall

Copy link
Copy Markdown
Member

Generated with Claude Code

This project does not accept code generated with LLMs.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Development

Successfully merging this pull request may close these issues.

2 participants