cvs: php4 /main rfc1867.c

From: Date: Thu, 13 Dec 2001 18:12:59 +0000
Subject: cvs: php4 /main rfc1867.c
Groups: php.cvs 
Request: Send a blank email to php-cvs+get-8607@lists.php.net to get a copy of this message
sesser Thu Dec 13 13:12:59 2001 EDT Modified files: /php4/main rfc1867.c Log: fixed some minor bugs and reordered some code to fix array uploads. Index: php4/main/rfc1867.c diff -u php4/main/rfc1867.c:1.89 php4/main/rfc1867.c:1.90 --- php4/main/rfc1867.c:1.89 Tue Dec 11 10:31:05 2001 +++ php4/main/rfc1867.c Thu Dec 13 13:12:58 2001 @@ -16,7 +16,7 @@ | Jani Taskinen <sniper@php.net> | +----------------------------------------------------------------------+ */ -/* $Id: rfc1867.c,v 1.89 2001/12/11 15:31:05 sebastian Exp $ */ +/* $Id: rfc1867.c,v 1.90 2001/12/13 18:12:58 sesser Exp $ */ /* * This product includes software developed by the Apache Group @@ -549,15 +549,12 @@ int total_bytes=0, read_bytes=0; while((read_bytes = multipart_buffer_read(self, buf, sizeof(buf) TSRMLS_CC))) { + out = erealloc(out, total_bytes + read_bytes + 1); + memcpy(out + total_bytes, buf, read_bytes); total_bytes += read_bytes; - out = erealloc(out, total_bytes); - memcpy(out, buf, read_bytes); } - if (out) { - out = erealloc(out, total_bytes + 1); - out[total_bytes] = '\0'; - } + if (out) out[total_bytes] = '\0'; return out; } @@ -601,6 +598,10 @@ boundary_len = strlen(boundary); if (boundary[0] == '"' && boundary[boundary_len-1] == '"') { + if (boundary_len < 2) { /* otherwise a single " passes */ + sapi_module.sapi_error(E_WARNING, "Invalid boundary in multipart/form-data POST data"); + return; + } boundary++; boundary_len -= 2; boundary[boundary_len] = '\0'; @@ -740,21 +741,13 @@ zend_hash_add(SG(rfc1867_uploaded_files), temp_filename, strlen(temp_filename) + 1, &temp_filename, sizeof(char *), NULL); } - /* Initialize variables */ - add_protected_variable(param TSRMLS_CC); - - magic_quotes_gpc = PG(magic_quotes_gpc); - PG(magic_quotes_gpc) = 0; - safe_php_register_variable(param, temp_filename, NULL, 1 TSRMLS_CC); - /* is_arr_upload is true when name of file upload field * ends in [.*] * start_arr is set to point to 1st [ * end_arr points to last ] */ is_arr_upload = (start_arr = strchr(param,'[')) && - (end_arr = strrchr(param,']')) && - (end_arr = param+strlen(param)-1); + (param[strlen(param)-1] == ']'); if (is_arr_upload) { array_len = strlen(start_arr); @@ -764,12 +757,11 @@ array_index = estrndup(start_arr+1, array_len-2); } - /* Add $foo_name */ if (lbuf) { efree(lbuf); } - lbuf = (char *) emalloc(strlen(param) + array_len + MAX_SIZE_OF_INDEX + 1); + lbuf = (char *) emalloc(strlen(param) + MAX_SIZE_OF_INDEX + 1); if (is_arr_upload) { if (abuf) efree(abuf); @@ -778,6 +770,14 @@ } else { sprintf(lbuf, "%s_name", param); } + + /* Initialize variables */ + add_protected_variable(param TSRMLS_CC); + + magic_quotes_gpc = PG(magic_quotes_gpc); + PG(magic_quotes_gpc) = 0; + /* if param is of form xxx[.*] this will cut it to xxx */ + safe_php_register_variable(param, temp_filename, NULL, 1 TSRMLS_CC); s = strrchr(filename, '\\'); if (s && s > filename) {

« previous php.cvs (#8607) next »