Minimal repro for godot-kotlin-jvm non-RefCounted binding leak

This commit is contained in:
stan220
2026-07-10 10:24:04 +03:00
commit 5243fb9dcd
12 changed files with 444 additions and 0 deletions
+7
View File
@@ -0,0 +1,7 @@
.godot/
ISSUE_DRAFT.md
.gradle/
.kotlin/
build/
/gradle/
jvm/
+40
View File
@@ -0,0 +1,40 @@
# godot-kotlin-jvm binding leak PoC
Minimal reproduction for a JVM-side binding leak in godot-kotlin-jvm 0.16.2
(present since the MemoryManager rework, still present on master): every
non-RefCounted `Object` freed at runtime leaves its entry in
`MemoryManager.ObjectDB` forever. For Objects the binding holds a strong
reference to the wrapper, so the JVM heap grows without bound while native
memory stays flat.
## Run
Requires a godot-kotlin-jvm 0.16.2-4.6.3 editor binary and a JDK 17+.
```bash
./gradlew build
godot --headless --import .
godot --headless --import . # run twice, first pass may bail early
godot --headless --path . res://main.tscn
```
Output on 0.16.2-4.6.3 (macOS, headless):
```
[POC] freed=20000 nativeObjects=1472 jvmObjectDB=20039
[POC] LEAK CONFIRMED: ~18567 zombie bindings in MemoryManager.ObjectDB
```
All 20000 freed nodes are still in the JVM ObjectDB. How the node is freed
does not matter: `free()` from Kotlin, `queueFree()`, or engine-side deletion
all leak.
## Root cause
`KotlinBindingManager::_instance_binding_free_callback` queues the dead object
via `MemoryManager::queue_dead_object(obj)`, which reads
`obj->get_instance_id()`. Godot calls instance-binding free callbacks at the
very end of `Object::~Object`, after `ObjectDB::remove_instance(this);
_instance_id = ObjectID();` (core/object/object.cpp, same order in every 4.x
release since 4.3). The id is always the null ObjectID by then, so the JVM is
told to remove `ObjectID(0)` instead of the real id and the real entry stays.
Binary file not shown.
+11
View File
@@ -0,0 +1,11 @@
distributionBase=GRADLE_USER_HOME
distributionPath=wrapper/dists
distributionUrl=https\://services.gradle.org/distributions/gradle-9.3.0-bin.zip
networkTimeout=10000
validateDistributionUrl=true
zipStoreBase=GRADLE_USER_HOME
zipStorePath=wrapper/dists
org.gradle.daemon=true
org.gradle.parallel=true
+24
View File
@@ -0,0 +1,24 @@
import godot.gradle.GodotLanguage
plugins {
id("com.utopia-rise.godot-kotlin-jvm") version "0.16.2-4.6.3"
}
repositories {
mavenCentral()
}
kotlin {
jvmToolchain(17)
}
godot {
languages.set(setOf(GodotLanguage.KOTLIN))
javaVersion.set(17)
godotProjectDirectory.set(file("."))
registrationFilesDirectory.set(file("gdj"))
}
tasks.named<Wrapper>("wrapper") {
jarFile = file("bin/gradle/gradle-wrapper.jar")
}
+22
View File
@@ -0,0 +1,22 @@
// THIS FILE IS GENERATED! DO NOT EDIT OR DELETE IT. EDIT OR DELETE THE ASSOCIATED SOURCE CODE FILE INSTEAD
// Note: You can however freely move this file inside your godot project if you want. Keep in mind however, that if you rename the originating source code file, this file will be deleted and regenerated as a new file instead of being updated! Other modifications to the source file however, will result in this file being updated.
registeredName = LeakPoc
fqName = LeakPoc
baseType = Node
supertypes = [
godot.api.Node,
godot.api.Object,
godot.core.KtObject,
godot.common.interop.NativeWrapper,
godot.common.interop.NativePointer
]
signals = [
]
properties = [
]
functions = [
_process
]
+12
View File
@@ -0,0 +1,12 @@
{
"custom_jvm_args": [],
"debug_address": "*",
"debug_port": 5005,
"disable_gc": false,
"jmx_port": -1,
"max_string_size": -1,
"use_debug": false,
"version": "2.0",
"vm_type": "auto",
"wait_for_debugger": false
}
Vendored Executable
+248
View File
@@ -0,0 +1,248 @@
#!/bin/sh
#
# Copyright © 2015 the original authors.
#
# Licensed under the Apache License, Version 2.0 (the "License");
# you may not use this file except in compliance with the License.
# You may obtain a copy of the License at
#
# https://www.apache.org/licenses/LICENSE-2.0
#
# Unless required by applicable law or agreed to in writing, software
# distributed under the License is distributed on an "AS IS" BASIS,
# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
# See the License for the specific language governing permissions and
# limitations under the License.
#
# SPDX-License-Identifier: Apache-2.0
#
##############################################################################
#
# Gradle start up script for POSIX generated by Gradle.
#
# Important for running:
#
# (1) You need a POSIX-compliant shell to run this script. If your /bin/sh is
# noncompliant, but you have some other compliant shell such as ksh or
# bash, then to run this script, type that shell name before the whole
# command line, like:
#
# ksh Gradle
#
# Busybox and similar reduced shells will NOT work, because this script
# requires all of these POSIX shell features:
# * functions;
# * expansions «$var», «${var}», «${var:-default}», «${var+SET}»,
# «${var#prefix}», «${var%suffix}», and «$( cmd )»;
# * compound commands having a testable exit status, especially «case»;
# * various built-in commands including «command», «set», and «ulimit».
#
# Important for patching:
#
# (2) This script targets any POSIX shell, so it avoids extensions provided
# by Bash, Ksh, etc; in particular arrays are avoided.
#
# The "traditional" practice of packing multiple parameters into a
# space-separated string is a well documented source of bugs and security
# problems, so this is (mostly) avoided, by progressively accumulating
# options in "$@", and eventually passing that to Java.
#
# Where the inherited environment variables (DEFAULT_JVM_OPTS, JAVA_OPTS,
# and GRADLE_OPTS) rely on word-splitting, this is performed explicitly;
# see the in-line comments for details.
#
# There are tweaks for specific operating systems such as AIX, CygWin,
# Darwin, MinGW, and NonStop.
#
# (3) This script is generated from the Groovy template
# https://github.com/gradle/gradle/blob/HEAD/platforms/jvm/plugins-application/src/main/resources/org/gradle/api/internal/plugins/unixStartScript.txt
# within the Gradle project.
#
# You can find Gradle at https://github.com/gradle/gradle/.
#
##############################################################################
# Attempt to set APP_HOME
# Resolve links: $0 may be a link
app_path=$0
# Need this for daisy-chained symlinks.
while
APP_HOME=${app_path%"${app_path##*/}"} # leaves a trailing /; empty if no leading path
[ -h "$app_path" ]
do
ls=$( ls -ld "$app_path" )
link=${ls#*' -> '}
case $link in #(
/*) app_path=$link ;; #(
*) app_path=$APP_HOME$link ;;
esac
done
# This is normally unused
# shellcheck disable=SC2034
APP_BASE_NAME=${0##*/}
# Discard cd standard output in case $CDPATH is set (https://github.com/gradle/gradle/issues/25036)
APP_HOME=$( cd -P "${APP_HOME:-./}" > /dev/null && printf '%s\n' "$PWD" ) || exit
# Use the maximum available, or set MAX_FD != -1 to use that value.
MAX_FD=maximum
warn () {
echo "$*"
} >&2
die () {
echo
echo "$*"
echo
exit 1
} >&2
# OS specific support (must be 'true' or 'false').
cygwin=false
msys=false
darwin=false
nonstop=false
case "$( uname )" in #(
CYGWIN* ) cygwin=true ;; #(
Darwin* ) darwin=true ;; #(
MSYS* | MINGW* ) msys=true ;; #(
NONSTOP* ) nonstop=true ;;
esac
# Determine the Java command to use to start the JVM.
if [ -n "$JAVA_HOME" ] ; then
if [ -x "$JAVA_HOME/jre/sh/java" ] ; then
# IBM's JDK on AIX uses strange locations for the executables
JAVACMD=$JAVA_HOME/jre/sh/java
else
JAVACMD=$JAVA_HOME/bin/java
fi
if [ ! -x "$JAVACMD" ] ; then
die "ERROR: JAVA_HOME is set to an invalid directory: $JAVA_HOME
Please set the JAVA_HOME variable in your environment to match the
location of your Java installation."
fi
else
JAVACMD=java
if ! command -v java >/dev/null 2>&1
then
die "ERROR: JAVA_HOME is not set and no 'java' command could be found in your PATH.
Please set the JAVA_HOME variable in your environment to match the
location of your Java installation."
fi
fi
# Increase the maximum file descriptors if we can.
if ! "$cygwin" && ! "$darwin" && ! "$nonstop" ; then
case $MAX_FD in #(
max*)
# In POSIX sh, ulimit -H is undefined. That's why the result is checked to see if it worked.
# shellcheck disable=SC2039,SC3045
MAX_FD=$( ulimit -H -n ) ||
warn "Could not query maximum file descriptor limit"
esac
case $MAX_FD in #(
'' | soft) :;; #(
*)
# In POSIX sh, ulimit -n is undefined. That's why the result is checked to see if it worked.
# shellcheck disable=SC2039,SC3045
ulimit -n "$MAX_FD" ||
warn "Could not set maximum file descriptor limit to $MAX_FD"
esac
fi
# Collect all arguments for the java command, stacking in reverse order:
# * args from the command line
# * the main class name
# * -classpath
# * -D...appname settings
# * --module-path (only if needed)
# * DEFAULT_JVM_OPTS, JAVA_OPTS, and GRADLE_OPTS environment variables.
# For Cygwin or MSYS, switch paths to Windows format before running java
if "$cygwin" || "$msys" ; then
APP_HOME=$( cygpath --path --mixed "$APP_HOME" )
JAVACMD=$( cygpath --unix "$JAVACMD" )
# Now convert the arguments - kludge to limit ourselves to /bin/sh
for arg do
if
case $arg in #(
-*) false ;; # don't mess with options #(
/?*) t=${arg#/} t=/${t%%/*} # looks like a POSIX filepath
[ -e "$t" ] ;; #(
*) false ;;
esac
then
arg=$( cygpath --path --ignore --mixed "$arg" )
fi
# Roll the args list around exactly as many times as the number of
# args, so each arg winds up back in the position where it started, but
# possibly modified.
#
# NB: a `for` loop captures its iteration list before it begins, so
# changing the positional parameters here affects neither the number of
# iterations, nor the values presented in `arg`.
shift # remove old arg
set -- "$@" "$arg" # push replacement arg
done
fi
# Add default JVM options here. You can also use JAVA_OPTS and GRADLE_OPTS to pass JVM options to this script.
DEFAULT_JVM_OPTS='"-Xmx64m" "-Xms64m"'
# Collect all arguments for the java command:
# * DEFAULT_JVM_OPTS, JAVA_OPTS, and optsEnvironmentVar are not allowed to contain shell fragments,
# and any embedded shellness will be escaped.
# * For example: A user cannot expect ${Hostname} to be expanded, as it is an environment variable and will be
# treated as '${Hostname}' itself on the command line.
set -- \
"-Dorg.gradle.appname=$APP_BASE_NAME" \
-jar "$APP_HOME/bin/gradle/gradle-wrapper.jar" \
"$@"
# Stop when "xargs" is not available.
if ! command -v xargs >/dev/null 2>&1
then
die "xargs is not available"
fi
# Use "xargs" to parse quoted args.
#
# With -n1 it outputs one arg per line, with the quotes and backslashes removed.
#
# In Bash we could simply go:
#
# readarray ARGS < <( xargs -n1 <<<"$var" ) &&
# set -- "${ARGS[@]}" "$@"
#
# but POSIX shell has neither arrays nor command substitution, so instead we
# post-process each arg (as a line of input to sed) to backslash-escape any
# character that might be a shell metacharacter, then use eval to reverse
# that process (while maintaining the separation between arguments), and wrap
# the whole thing up as a single "set" statement.
#
# This will of course break if any of these variables contains a newline or
# an unmatched quote.
#
eval "set -- $(
printf '%s\n' "$DEFAULT_JVM_OPTS $JAVA_OPTS $GRADLE_OPTS" |
xargs -n1 |
sed ' s~[^-[:alnum:]+,./:=@_]~\\&~g; ' |
tr '\n' ' '
)" '"$@"'
exec "$JAVACMD" "$@"
+6
View File
@@ -0,0 +1,6 @@
[gd_scene load_steps=2 format=3]
[ext_resource type="Script" path="res://gdj/LeakPoc.gdj" id="1"]
[node name="LeakPoc" type="Node"]
script = ExtResource("1")
+13
View File
@@ -0,0 +1,13 @@
; Engine configuration file.
config_version=5
[application]
config/name="gkj-binding-leak-poc"
run/main_scene="res://main.tscn"
config/features=PackedStringArray("4.6")
[rendering]
renderer/rendering_method="gl_compatibility"
+1
View File
@@ -0,0 +1 @@
rootProject.name = "gkj-binding-leak-poc"
+60
View File
@@ -0,0 +1,60 @@
import godot.annotation.RegisterClass
import godot.annotation.RegisterFunction
import godot.api.Node
import godot.api.Performance
/**
* Repro for the godot-kotlin-jvm 0.16.2 binding leak: every freed non-RefCounted
* Object keeps its entry in MemoryManager.ObjectDB forever. Spawns nodes for a few
* frames, frees them (both free() and queueFree()), waits so sync_memory has plenty
* of chances to run, then compares ObjectDB size with the native object count.
*/
@RegisterClass
class LeakPoc : Node() {
private var frame = 0
private var freedTotal = 0
@RegisterFunction
override fun _process(delta: Double) {
frame++
when {
frame <= SPAWN_FRAMES -> {
repeat(BATCH) {
Node().free()
val q = Node()
addChild(q)
q.queueFree()
}
freedTotal += BATCH * 2
}
frame == REPORT_FRAME -> {
report()
getTree()!!.quit()
}
}
}
private fun report() {
val dbSize = objectDbSize()
val nativeObjects = Performance.getMonitor(Performance.Monitor.OBJECT_COUNT).toInt()
println("[POC] freed=$freedTotal nativeObjects=$nativeObjects jvmObjectDB=$dbSize")
if (dbSize > nativeObjects + 100) {
println("[POC] LEAK CONFIRMED: ~${dbSize - nativeObjects} zombie bindings in MemoryManager.ObjectDB")
} else {
println("[POC] no leak detected")
}
}
private fun objectDbSize(): Int {
val clazz = Class.forName("godot.internal.memory.MemoryManager")
val instance = clazz.getDeclaredField("INSTANCE").get(null)
val field = clazz.getDeclaredField("ObjectDB").apply { isAccessible = true }
return (field.get(instance) as Map<*, *>).size
}
companion object {
private const val BATCH = 1000
private const val SPAWN_FRAMES = 10
private const val REPORT_FRAME = 60
}
}