Re: cvs: /php3 ChangeLog language-parser.y /php3/functions xml.c
| From: | thies at digicol dot de | Date: | Tue, 08 Feb 2000 08:37:29 +0000 |
| Subject: | Re: cvs: /php3 ChangeLog language-parser.y /php3/functions xml.c | ||
| References: | 1 | Groups: | php.dev |
| Request: | Send a blank email to php-dev+get-15297@lists.php.net to get a copy of this message | ||
well, eehm - almost. these a tiny buglet left - see attached
purify dump. hope it's an easy one!
tc
On Mon, Feb 07, 2000 at 11:48:09PM -0000, Zeev Suraski wrote:
> zeev Mon Feb 7 15:48:09 2000 EDT
>
> Modified files:
> /php3 ChangeLog language-parser.y
> /php3/functions xml.c
> Log:
> Unbelievable, language-parser.y actually gets a year 2000 commit!
> - Fix an historical bug in call_user_function()
> - Fix XML module interface with call_user_function() - if it returns FAILURE,
> you may not assume that the return_value is valid.
>
>
> Index: php3/ChangeLog
> diff -u php3/ChangeLog:1.819 php3/ChangeLog:1.820
> --- php3/ChangeLog:1.819 Sun Feb 6 07:16:17 2000
> +++ php3/ChangeLog Mon Feb 7 15:48:09 2000
> @@ -2,6 +2,10 @@
> |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
>
> ???, Version 3.0.15
> +- Fixed a bug in the XML module that could cause crashes (Zeev)
> +- Fixed a long historical bug in the API function call_user_function(),
> + that could cause crashes in functions that made use of it (e.g.,
> + XML module functions) (Zeev)
> - Fixed possible buffer-overflow in base64_decode(). (Thies)
> - Fixed possible buffer-overflow in setcookie(). (Thies)
> - Added ImageWbmp() for outputting WAP's Wireless Bitmaps (markonen)
> Index: php3/language-parser.y
> diff -u php3/language-parser.y:1.182 php3/language-parser.y:1.183
> --- php3/language-parser.y:1.182 Fri Dec 31 20:48:04 1999
> +++ php3/language-parser.y Mon Feb 7 15:48:09 2000
> @@ -31,7 +31,7 @@
> */
>
>
> -/* $Id: language-parser.y,v 1.182 2000/01/01 04:48:04 sas Exp $ */
> +/* $Id: language-parser.y,v 1.183 2000/02/07 23:48:09 zeev Exp $ */
>
>
> /*
> @@ -739,15 +739,26 @@
> int original_shutdown_requested=GLOBAL(shutdown_requested);
> int original_execute_flag = GLOBAL(ExecuteFlag);
> FunctionState original_function_state = GLOBAL(function_state);
> + pval p_function_name;
>
> + if (GLOBAL(shutdown_requested)==ABNORMAL_SHUTDOWN) {
> + return FAILURE;
> + }
> +
> /* save the location to go back to */
> return_offset.offset = tc_get_current_offset(&GLOBAL(token_cache_manager))-1;
>
> if (object) {
> function_table = object->value.ht;
> }
> - php3_str_tolower(function_name->value.str.val, function_name->value.str.len);
> - if (_php3_hash_find(function_table, function_name->value.str.val,
> function_name->value.str.len+1, (void **) &func)==FAILURE
> +
> + /* if phpparse() triggers shutdown, function_name would get erased, so it'd end up
> + * being freed twice. Avoid this.
> + */
> + p_function_name = *function_name;
> + pval_copy_constructor(&p_function_name);
> + php3_str_tolower(p_function_name.value.str.val, p_function_name.value.str.len);
> + if (_php3_hash_find(function_table, p_function_name.value.str.val,
> p_function_name.value.str.len+1, (void **) &func)==FAILURE
> || func->type != IS_USER_FUNCTION) {
> return FAILURE;
> }
> @@ -756,25 +767,27 @@
> GLOBAL(shutdown_requested) = 0;
> GLOBAL(function_state).loop_nest_level = GLOBAL(function_state).loop_change_level =
> GLOBAL(function_state).loop_change_type = 0;
> GLOBAL(function_state).returned = 0;
> + GLOBAL(function_state).function_name = p_function_name.value.str.val;
> GLOBAL(ExecuteFlag) = EXECUTE;
> GLOBAL(Execute) = SHOULD_EXECUTE;
>
> tc_set_token(&token_cache_manager, func->offset, IC_FUNCTION);
> if (object) {
> class_ptr.value.varptr.pvalue = object;
> - cs_functioncall_pre_variable_passing(function_name, &class_ptr, 0 _INLINE_TLS);
> + cs_functioncall_pre_variable_passing(&p_function_name, &class_ptr, 0 _INLINE_TLS);
> } else {
> - cs_functioncall_pre_variable_passing(function_name,NULL, 0 _INLINE_TLS);
> + cs_functioncall_pre_variable_passing(&p_function_name,NULL, 0 _INLINE_TLS);
> }
> for (i=0; i<param_count; i++) {
> _php3_hash_next_index_pointer_insert(GLOBAL(function_state).function_symbol_table,
> params[i]);
> }
> - cs_functioncall_post_variable_passing(function_name, NULL);
> + cs_functioncall_post_variable_passing(&p_function_name, NULL);
> phpparse();
> if (GLOBAL(shutdown_requested)) { /* we died during this function call */
> return FAILURE;
> }
> - cs_functioncall_end(retval,function_name,&return_offset,NULL,0);
> + cs_functioncall_end(retval,&p_function_name,&return_offset,NULL,0);
> + pval_destructor(&p_function_name);
> GLOBAL(function_state) = original_function_state;
> GLOBAL(ExecuteFlag) = original_execute_flag;
> GLOBAL(shutdown_requested) = original_shutdown_requested;
> Index: php3/functions/xml.c
> diff -u php3/functions/xml.c:1.32 php3/functions/xml.c:1.33
> --- php3/functions/xml.c:1.32 Fri Dec 31 20:31:17 1999
> +++ php3/functions/xml.c Mon Feb 7 15:48:09 2000
> @@ -27,7 +27,7 @@
> +----------------------------------------------------------------------+
> */
>
> -/* $Id: xml.c,v 1.32 2000/01/01 04:31:17 sas Exp $ */
> +/* $Id: xml.c,v 1.33 2000/02/07 23:48:09 zeev Exp $ */
> #define IS_EXT_MODULE
> #if COMPILE_DL
> # include "dl/phpdl.h"
> @@ -336,7 +336,7 @@
> Instead, we create a callback function. */
> function_table=php3i_get_function_table();
> if (call_user_function(function_table, NULL, func, retval, argc, argv) == FAILURE) {
> - php3tls_pval_destructor(retval);
> + /*php3tls_pval_destructor(retval);*/
> efree(retval);
> return NULL;
> }
>
>
>
> --
> PHP Development Mailing List <http://www.php.net/>
> To unsubscribe, e-mail: php-dev-unsubscribe@lists.php.net
> For additional commands, e-mail: php-dev-help@lists.php.net
> To contact the list administrators, e-mail: php-list-admin@lists.php.net
>
--
Thies C. Arntzen "One Big-Mac, Small Fries and a Coke!"
Digital Collections Phone +49 40 235350 Fax +49 40 23535180
Hammerbrookstr. 93 20097 Hamburg / Germany