cvs: php4 / php.ini-dist php.ini-optimized /ext/session session.c /main main.c network.c php_globals.h php_network.h php_variables.c rfc1867.c
/win32 php4dllts.dsp

From: Date: Tue, 05 Sep 2000 19:06:30 +0000
Subject: cvs: php4 / php.ini-dist php.ini-optimized /ext/session session.c /main main.c network.c php_globals.h php_network.h php_variables.c rfc1867.c
/win32 php4dllts.dsp
Groups: php.cvs 
Request: Send a blank email to php-cvs+get-1590@lists.php.net to get a copy of this message
zeev Tue Sep 5 12:06:30 2000 EDT Modified files: /php4 php.ini-dist php.ini-optimized /php4/ext/session session.c /php4/main main.c network.c php_globals.h php_network.h php_variables.c rfc1867.c /php4/win32 php4dllts.dsp Log: - Remove track_vars - it is now always on - Make the various $HTTP_*_VARS[] arrays be defined always, even if they're empty - Fix Win32 build and warnings Index: php4/php.ini-dist diff -u php4/php.ini-dist:1.46 php4/php.ini-dist:1.47 --- php4/php.ini-dist:1.46 Mon Sep 4 15:22:16 2000 +++ php4/php.ini-dist Tue Sep 5 12:06:28 2000 @@ -181,6 +181,7 @@ ;;;;;;;;;;;;;;;;; ; Data Handling ; ;;;;;;;;;;;;;;;;; +; Note - track_vars is ALWAYS enabled as of PHP 4.0.3 variables_order = "EGPCS" ; This directive describes the order in which PHP registers ; GET, POST, Cookie, Environment and Built-in variables (G, P, ; C, E & S respectively, often referred to as EGPCS or GPC). @@ -192,12 +193,14 @@ ; most sense when coupled with track_vars - in which case you can ; access all of the GPC variables through the $HTTP_*_VARS[], ; variables. + ; You should do your best to write your scripts so that they do + ; not require register_globals to be on; Using form variables + ; as globals can easily lead to possible security problems, if + ; the code is not very well thought of. register_argc_argv = On ; This directive tells PHP whether to declare the argv&argc ; variables (that would contain the GET information). If you ; don't use these variables, you should turn it off for ; increased performance -track_vars = On ; enable the $HTTP_*_VARS[] arrays, where * is one of - ; ENV, POST, GET, COOKIE or SERVER. gpc_order = "GPC" ; This directive is deprecated. Use variables_order instead. ; Magic quotes Index: php4/php.ini-optimized diff -u php4/php.ini-optimized:1.15 php4/php.ini-optimized:1.16 --- php4/php.ini-optimized:1.15 Mon Sep 4 15:22:16 2000 +++ php4/php.ini-optimized Tue Sep 5 12:06:28 2000 @@ -182,9 +182,8 @@ register_argc_argv = Off ; This directive tells PHP whether to declare the argv&argc ; variables (that would contain the GET information). If you ; don't use these variables, you should turn it off for - ; increased performance -track_vars = On ; enable the $HTTP_*_VARS[] arrays, where * is one of - ; ENV, POST, GET, COOKIE or SERVER. + ; increased performance (you should try not to use it anyway, + ; for less likelihood of security bugs in your code). gpc_order = "GPC" ; This directive is deprecated. Use variables_order instead. ; Magic quotes Index: php4/ext/session/session.c diff -u php4/ext/session/session.c:1.160 php4/ext/session/session.c:1.161 --- php4/ext/session/session.c:1.160 Tue Sep 5 11:41:46 2000 +++ php4/ext/session/session.c Tue Sep 5 12:06:29 2000 @@ -244,16 +244,14 @@ zval_copy_ctor(state_val_copy); state_val_copy->refcount = 0; - if (PG(register_globals) && PG(track_vars)) { + if (PG(register_globals)) { zend_set_hash_symbol(state_val_copy, name, namelen, 0, 2, PS(http_session_vars)->value.ht, &EG(symbol_table)); } else { if (PG(register_globals)) { zend_set_hash_symbol(state_val_copy, name, namelen, 0, 1, &EG(symbol_table)); } - if (PG(track_vars)) { - zend_set_hash_symbol(state_val_copy, name, namelen, 0, 1, PS(http_session_vars)->value.ht); - } + zend_set_hash_symbol(state_val_copy, name, namelen, 0, 1, PS(http_session_vars)->value.ht); } } @@ -261,7 +259,7 @@ { HashTable *ht = &EG(symbol_table); - if (!PG(register_globals) && PG(track_vars)) + if (!PG(register_globals)) ht = PS(http_session_vars)->value.ht; return zend_hash_find(ht, name, namelen + 1, (void **)state_var); @@ -523,8 +521,7 @@ { PLS_FETCH(); - if (PG(track_vars)) - php_session_track_init(); + php_session_track_init(); if (PS(serializer)->decode(val, vallen PSLS_CC) == FAILURE) { _php_session_destroy(PSLS_C); php_error(E_WARNING, "Failed to decode session object. Session has been destroyed."); @@ -844,8 +841,6 @@ char *p; int send_cookie = 1; int define_sid = 1; - zend_bool register_globals; - zend_bool track_vars; int module_number = PS(module_number); int nrand; int lensess; @@ -856,39 +851,13 @@ lensess = strlen(PS(session_name)); - register_globals = INI_BOOL("register_globals"); - track_vars = INI_BOOL("track_vars"); - - if (!register_globals && !track_vars) { - php_error(E_ERROR, "The session module will not work if you have disabled track_vars and register_globals. At least one of them must be enabled."); - return; - } - if (!track_vars && PS(use_cookies)) - php_error(E_NOTICE, "Because track_vars is disabled, the session module will not be able to determine whether the user has sent a cookie. SID will always be defined."); - - /* - * If our only resource is the global symbol_table, then check it. - * If track_vars are enabled, we prefer these, because they are more - * reliable, and we always know whether the user has accepted the - * cookie. - */ - - if (register_globals && - !track_vars && - !PS(id) && - zend_hash_find(&EG(symbol_table), PS(session_name), - lensess + 1, (void **) &ppid) == SUCCESS) { - PPID2SID; - send_cookie = 0; - } - /* - * Now check the track_vars. Cookies are preferred, because initially + * Cookies are preferred, because initially * cookie and get variables will be available. */ - if (!PS(id) && track_vars) { + if (!PS(id)) { if (zend_hash_find(&EG(symbol_table), "HTTP_COOKIE_VARS", sizeof("HTTP_COOKIE_VARS"), (void **) &data) == SUCCESS && (*data)->type == IS_ARRAY && @@ -1244,7 +1213,7 @@ } else { convert_to_string_ex(entry); - if (!PG(track_vars) || strcmp((*entry)->value.str.val, "HTTP_SESSION_VARS") != 0) + if (strcmp((*entry)->value.str.val, "HTTP_SESSION_VARS") != 0) PS_ADD_VARL((*entry)->value.str.val, (*entry)->value.str.len); } } Index: php4/main/main.c diff -u php4/main/main.c:1.311 php4/main/main.c:1.312 --- php4/main/main.c:1.311 Sat Sep 2 11:03:58 2000 +++ php4/main/main.c Tue Sep 5 12:06:29 2000 @@ -19,7 +19,7 @@ */ -/* $Id: main.c,v 1.311 2000/09/02 18:03:58 zeev Exp $ */ +/* $Id: main.c,v 1.312 2000/09/05 19:06:29 zeev Exp $ */ #include <stdio.h> @@ -225,7 +225,6 @@ STD_PHP_INI_BOOLEAN("short_open_tag", "1", PHP_INI_SYSTEM|PHP_INI_PERDIR, OnUpdateBool, short_tags, zend_compiler_globals, compiler_globals) STD_PHP_INI_BOOLEAN("sql.safe_mode", "0", PHP_INI_SYSTEM, OnUpdateBool, sql_safe_mode, php_core_globals, core_globals) STD_PHP_INI_BOOLEAN("track_errors", "0", PHP_INI_ALL, OnUpdateBool, track_errors, php_core_globals, core_globals) - STD_PHP_INI_BOOLEAN("track_vars", "1", PHP_INI_ALL, OnUpdateBool, track_vars, php_core_globals, core_globals) STD_PHP_INI_BOOLEAN("y2k_compliance", "0", PHP_INI_ALL, OnUpdateBool, y2k_compliance, php_core_globals, core_globals) STD_PHP_INI_ENTRY("arg_separator", "&", PHP_INI_ALL, OnUpdateStringUnempty, arg_separator, php_core_globals, core_globals) @@ -922,12 +921,10 @@ { zval *array_ptr=NULL; - if (PG(track_vars)) { - ALLOC_ZVAL(array_ptr); - array_init(array_ptr); - INIT_PZVAL(array_ptr); - PG(http_globals).server = array_ptr; - } + ALLOC_ZVAL(array_ptr); + array_init(array_ptr); + INIT_PZVAL(array_ptr); + PG(http_globals)[TRACK_VARS_SERVER] = array_ptr; /* Server variables */ if (sapi_module.register_server_variables) { @@ -954,8 +951,31 @@ char *p; unsigned char _gpc_flags[3] = {0,0,0}; zend_bool have_variables_order; + zval *dummy_track_vars_array; + zend_bool initialized_dummy_track_vars_array=0; + int i; + char *track_vars_names[] = { + "HTTP_POST_VARS", + "HTTP_GET_VARS", + "HTTP_COOKIE_VARS", + "HTTP_SERVER_VARS", + "HTTP_ENV_VARS", + "HTTP_POST_FILES", + NULL + }; + int track_vars_names_length[] = { + sizeof("HTTP_POST_VARS"), + sizeof("HTTP_GET_VARS"), + sizeof("HTTP_COOKIE_VARS"), + sizeof("HTTP_SERVER_VARS"), + sizeof("HTTP_ENV_VARS"), + sizeof("HTTP_POST_FILES") + }; + - PG(http_globals).post = PG(http_globals).get = PG(http_globals).cookie = PG(http_globals).server = PG(http_globals).environment = PG(http_globals).post_files = NULL; + for (i=0; i<6; i++) { + PG(http_globals)[i] = NULL; + } if (PG(variables_order)) { p = PG(variables_order); @@ -1008,25 +1028,18 @@ php_register_server_variables(ELS_C SLS_CC PLS_CC); } - if (PG(http_globals).post) { - zend_hash_update(&EG(symbol_table), "HTTP_POST_VARS", sizeof("HTTP_POST_VARS"), &PG(http_globals).post, sizeof(zval *), NULL); - } - if (PG(http_globals).get) { - zend_hash_update(&EG(symbol_table), "HTTP_GET_VARS", sizeof("HTTP_GET_VARS"), &PG(http_globals).get, sizeof(zval *), NULL); - } - if (PG(http_globals).cookie) { - zend_hash_update(&EG(symbol_table), "HTTP_COOKIE_VARS", sizeof("HTTP_COOKIE_VARS"), &PG(http_globals).cookie, sizeof(zval *), NULL); - } - if (PG(http_globals).server) { - zend_hash_update(&EG(symbol_table), "HTTP_SERVER_VARS", sizeof("HTTP_SERVER_VARS"), &PG(http_globals).server, sizeof(zval *), NULL); - } - if (PG(http_globals).environment) { - zend_hash_update(&EG(symbol_table), "HTTP_ENV_VARS", sizeof("HTTP_ENV_VARS"), &PG(http_globals).environment, sizeof(zval *), NULL); - } - if (PG(http_globals).post_files) { - zend_hash_update(&EG(symbol_table), "HTTP_POST_FILES", sizeof("HTTP_POST_FILES"), &PG(http_globals).post_files, sizeof(zval *),NULL); + for (i=0; i<6; i++) { + if (!PG(http_globals)[i] && !initialized_dummy_track_vars_array) { + ALLOC_ZVAL(dummy_track_vars_array); + array_init(dummy_track_vars_array); + INIT_PZVAL(dummy_track_vars_array); + initialized_dummy_track_vars_array = 1; + } else { + dummy_track_vars_array->refcount++; + PG(http_globals)[i] = dummy_track_vars_array; + } + zend_hash_update(&EG(symbol_table), track_vars_names[i], track_vars_names_length[i], &PG(http_globals)[i], sizeof(zval *), NULL); } - return SUCCESS; } @@ -1036,9 +1049,6 @@ pval *arr, *argc, *tmp; int count = 0; char *ss, *space; - - if (!PG(register_globals) && !PG(track_vars)) - return; ALLOC_ZVAL(arr); array_init(arr); @@ -1084,15 +1094,12 @@ zend_hash_add(&EG(symbol_table), "argc", sizeof("argc"), &argc, sizeof(zval *), NULL); } - if (PG(track_vars)) { - if (PG(register_globals)) { - arr->refcount++; - argc->refcount++; - } - zend_hash_update(track_vars_array->value.ht, "argv", sizeof("argv"), &arr, sizeof(pval *), NULL); - zend_hash_update(track_vars_array->value.ht, "argc", sizeof("argc"), &argc, sizeof(pval *), NULL); + if (PG(register_globals)) { + arr->refcount++; + argc->refcount++; } - + zend_hash_update(track_vars_array->value.ht, "argv", sizeof("argv"), &arr, sizeof(pval *), NULL); + zend_hash_update(track_vars_array->value.ht, "argc", sizeof("argc"), &argc, sizeof(pval *), NULL); } Index: php4/main/network.c diff -u php4/main/network.c:1.6 php4/main/network.c:1.7 --- php4/main/network.c:1.6 Tue Sep 5 10:37:44 2000 +++ php4/main/network.c Tue Sep 5 12:06:29 2000 @@ -15,7 +15,7 @@ | Authors: Stig Venaas <venaas@uninett.no> | +----------------------------------------------------------------------+ */ -/* $Id: network.c,v 1.6 2000/09/05 17:37:44 venaas Exp $ */ +/* $Id: network.c,v 1.7 2000/09/05 19:06:29 zeev Exp $ */ #include "php.h" @@ -37,8 +37,12 @@ #include <netinet/in.h> #include <netdb.h> #include <arpa/inet.h> +#else +int inet_aton(const char *, struct in_addr *); #endif +#include "php_network.h" + #ifdef PHP_WIN32 #undef AF_UNIX #endif @@ -150,7 +154,7 @@ * port, returns the created socket on success, else returns -1. * timeout gives timeout in seconds, 0 means blocking mode. */ -int php_hostconnect(char *host, int port, int socktype, int timeout) +int php_hostconnect(char *host, unsigned short port, int socktype, int timeout) { int s; struct sockaddr **sal, **psal; Index: php4/main/php_globals.h diff -u php4/main/php_globals.h:1.54 php4/main/php_globals.h:1.55 --- php4/main/php_globals.h:1.54 Mon Sep 4 12:07:50 2000 +++ php4/main/php_globals.h Tue Sep 5 12:06:29 2000 @@ -42,15 +42,14 @@ extern ZEND_API struct _php_core_globals core_globals; #endif -typedef struct _php_http_globals { - zval *post; - zval *get; - zval *cookie; - zval *server; - zval *environment; - zval *post_files; -} php_http_globals; +#define TRACK_VARS_POST 1 +#define TRACK_VARS_GET 2 +#define TRACK_VARS_COOKIE 3 +#define TRACK_VARS_SERVER 4 +#define TRACK_VARS_ENV 5 +#define TRACK_VARS_FILES 6 + struct _php_tick_function_entry; struct _php_core_globals { @@ -103,11 +102,10 @@ zend_llist tick_functions; - php_http_globals http_globals; + zval *http_globals[6]; zend_bool expose_php; - zend_bool track_vars; zend_bool register_globals; zend_bool register_argc_argv; Index: php4/main/php_network.h diff -u php4/main/php_network.h:1.3 php4/main/php_network.h:1.4 --- php4/main/php_network.h:1.3 Tue Sep 5 09:36:56 2000 +++ php4/main/php_network.h Tue Sep 5 12:06:29 2000 @@ -15,9 +15,14 @@ | Authors: Stig Venaas <venaas@uninett.no> | +----------------------------------------------------------------------+ */ -/* $Id: php_network.h,v 1.3 2000/09/05 16:36:56 venaas Exp $ */ +/* $Id: php_network.h,v 1.4 2000/09/05 19:06:29 zeev Exp $ */ -int php_hostconnect(char *host, int port, int socktype, int timeout); +#ifndef _PHP_NETWORK_H +#define _PHP_NETWORK_H + +int php_hostconnect(char *host, unsigned short port, int socktype, int timeout); + +#endif /* _PHP_NETWORK_H */ /* * Local variables: Index: php4/main/php_variables.c diff -u php4/main/php_variables.c:1.15 php4/main/php_variables.c:1.16 --- php4/main/php_variables.c:1.15 Mon Aug 21 02:50:53 2000 +++ php4/main/php_variables.c Tue Sep 5 12:06:29 2000 @@ -57,7 +57,7 @@ zend_bool free_index; HashTable *symtable1=NULL; HashTable *symtable2=NULL; - + if (PG(register_globals)) { symtable1 = EG(active_symbol_table); } @@ -69,7 +69,7 @@ } } if (!symtable1) { - /* we don't need track_vars, and we're not setting GPC globals either. */ + /* Nothing to do */ zval_dtor(val); return; } @@ -220,23 +220,19 @@ case PARSE_POST: case PARSE_GET: case PARSE_COOKIE: - if (PG(track_vars)) { - ALLOC_ZVAL(array_ptr); - array_init(array_ptr); - INIT_PZVAL(array_ptr); - switch (arg) { - case PARSE_POST: - PG(http_globals).post = array_ptr; - break; - case PARSE_GET: - PG(http_globals).get = array_ptr; - break; - case PARSE_COOKIE: - PG(http_globals).cookie = array_ptr; - break; - } - } else { - array_ptr=NULL; + ALLOC_ZVAL(array_ptr); + array_init(array_ptr); + INIT_PZVAL(array_ptr); + switch (arg) { + case PARSE_POST: + PG(http_globals)[TRACK_VARS_POST] = array_ptr; + break; + case PARSE_GET: + PG(http_globals)[TRACK_VARS_GET] = array_ptr; + break; + case PARSE_COOKIE: + PG(http_globals)[TRACK_VARS_COOKIE] = array_ptr; + break; } break; default: @@ -309,12 +305,10 @@ char **env, *p, *t; zval *array_ptr=NULL; - if (PG(track_vars)) { - ALLOC_ZVAL(array_ptr); - array_init(array_ptr); - INIT_PZVAL(array_ptr); - PG(http_globals).environment = array_ptr; - } + ALLOC_ZVAL(array_ptr); + array_init(array_ptr); + INIT_PZVAL(array_ptr); + PG(http_globals)[TRACK_VARS_ENV] = array_ptr; for (env = environ; env != NULL && *env != NULL; env++) { p = strchr(*env, '='); Index: php4/main/rfc1867.c diff -u php4/main/rfc1867.c:1.45 php4/main/rfc1867.c:1.46 --- php4/main/rfc1867.c:1.45 Mon Sep 4 15:26:01 2000 +++ php4/main/rfc1867.c Tue Sep 5 12:06:29 2000 @@ -15,7 +15,7 @@ | Authors: Rasmus Lerdorf <rasmus@php.net> | +----------------------------------------------------------------------+ */ -/* $Id: rfc1867.c,v 1.45 2000/09/04 22:26:01 zeev Exp $ */ +/* $Id: rfc1867.c,v 1.46 2000/09/05 19:06:29 zeev Exp $ */ #include <stdio.h> #include "php.h" @@ -102,12 +102,10 @@ zend_hash_init(&PG(rfc1867_protected_variables), 5, NULL, NULL, 0); - if (PG(track_vars)) { - ALLOC_ZVAL(http_post_files); - array_init(http_post_files); - INIT_PZVAL(http_post_files); - PG(http_globals).post_files = http_post_files; - } + ALLOC_ZVAL(http_post_files); + array_init(http_post_files); + INIT_PZVAL(http_post_files); + PG(http_globals)[TRACK_VARS_POST] = http_post_files; ptr = buf; rem = cnt; Index: php4/win32/php4dllts.dsp diff -u php4/win32/php4dllts.dsp:1.12 php4/win32/php4dllts.dsp:1.13 --- php4/win32/php4dllts.dsp:1.12 Sun Sep 3 12:43:09 2000 +++ php4/win32/php4dllts.dsp Tue Sep 5 12:06:29 2000 @@ -153,6 +153,10 @@ # End Source File # Begin Source File +SOURCE=..\main\network.c +# End Source File +# Begin Source File + SOURCE=..\main\php_content_types.c # End Source File # Begin Source File

« previous php.cvs (#1590) next »