Re: Bug #757 Updated: strpos is not binary save
| From: | Zeev Suraski | Date: | Fri, 18 Sep 1998 15:14:06 +0000 |
| Subject: | Re: Bug #757 Updated: strpos is not binary save | ||
| References: | 1 | Groups: | php.dev |
| Request: | Send a blank email to php-dev+get-1237@lists.php.net to get a copy of this message | ||
On Fri, 18 Sep 1998, Rasmus Lerdorf wrote:
> > strpos() as it is right now is not binary safe, and
> > that check is intentional, to protect the binary
> > unsafe implementation from receiving unexpected
> > arguments (and thus crash).
>
> That's not much of a check though. If the needle argument can crash it,
> then so can the haystack argument which is not checked. What we really
> need is a memstr() function. The strchr() should probably be changed to
> memchr().
The check is quite alright actually. The haystack argument can't crash
strstr() since it may be empty by definition, whereas the delimiter
argument must not be. If there's binary data in the haystack argument,
then anything past the first NULL would simply be silently ignored.
The function as it was is in working condition, binary unsafe, but safe
from crashes. Coding memstr() would make it binary safe, but I'm not sure
how necessary it is...
Zeev
--
-----------------------------------------------------
Zeev Suraski <zeev@php.net>
For a PGP public key, finger bourbon@netvision.net.il
--
PHP Development Mailing List http://www.php.net/
To unsubscribe send an empty message to php-dev-unsubscribe@lists.php.net
For help: php-dev-help@lists.php.net