cvs: ZendEngine2(PHP_5_2) / zend_builtin_functions.c

[email protected] ("Ilia Alshanetsky")
Newsgroups php.zend-engine.cvs
Message-ID <cvsiliaa1224440171@cvsserver>
iliaa		Sun Oct 19 18:16:11 2008 UTC

  Modified files:              (Branch: PHP_5_2)
    /ZendEngine2	zend_builtin_functions.c 
  Log:
  MFB: Fixed bug #46341 (Added missing validation checks into define() for
  class constants)
  
  
  
http://cvs.php.net/viewvc.cgi/ZendEngine2/zend_builtin_functions.c?r1=1.277.2.12.2.30&r2=1.277.2.12.2.31&diff_format=u
Index: ZendEngine2/zend_builtin_functions.c
diff -u ZendEngine2/zend_builtin_functions.c:1.277.2.12.2.30 ZendEngine2/zend_builtin_functions.c:1.277.2.12.2.31
--- ZendEngine2/zend_builtin_functions.c:1.277.2.12.2.30	Fri Aug 22 01:06:55 2008
+++ ZendEngine2/zend_builtin_functions.c	Sun Oct 19 18:16:11 2008
@@ -17,7 +17,7 @@
    +----------------------------------------------------------------------+
 */
 
-/* $Id: zend_builtin_functions.c,v 1.277.2.12.2.30 2008/08/22 01:06:55 felipe Exp $ */
+/* $Id: zend_builtin_functions.c,v 1.277.2.12.2.31 2008/10/19 18:16:11 iliaa Exp $ */
 
 #include "zend.h"
 #include "zend_API.h"
@@ -26,6 +26,7 @@
 #include "zend_ini.h"
 #include "zend_exceptions.h"
 #include "zend_extensions.h"
+#include <ctype.h>
 
 #undef ZEND_TEST_EXCEPTIONS
 
@@ -454,35 +455,58 @@
    Define a new constant */
 ZEND_FUNCTION(define)
 {
-	zval **var, **val, **non_cs, *val_free = NULL;
-	int case_sensitive;
+	char *name, *p;
+	int name_len;
+	zval *val;
+	zval *val_free = NULL;
+	zend_bool non_cs = 0;
+	int case_sensitive = CONST_CS;
 	zend_constant c;
 
-	switch (ZEND_NUM_ARGS()) {
-		case 2:
-			if (zend_get_parameters_ex(2, &var, &val)==FAILURE) {
-				RETURN_FALSE;
+	if (zend_parse_parameters(ZEND_NUM_ARGS() TSRMLS_CC, "sz|b", &name, &name_len, &val, &non_cs) == FAILURE) {
+		return;
+	}
+
+	/* check if class constant */
+	if ((p = memchr(name, ':', name_len))) {
+		char *s = name;
+		zend_class_entry **ce;
+
+		if (*(p + 1) != ':') { /* invalid constant specifier */
+			RETURN_FALSE;
+		} else if ((p + 2) >= (name + name_len)) { /* constant name length < 1 */
+			zend_error(E_WARNING, "Constants name cannot be empty");
+			RETURN_FALSE;
+		} else if (zend_lookup_class(s, (p - s), &ce TSRMLS_CC) != SUCCESS) { /* invalid class name */
+			zend_error(E_WARNING, "Class does not exists");
+			RETURN_FALSE;
+		} else { /* check of constant name contains invalid chars */
+			int ok = 1;
+			p += 2; /* move beyond :: to 1st char of constant's name */
+
+			if (!isalpha(*p) && *p != '_') {
+				ok = 0;
 			}
-			case_sensitive = CONST_CS;
-			break;
-		case 3:
-			if (zend_get_parameters_ex(3, &var, &val, &non_cs)==FAILURE) {
-				RETURN_FALSE;
+
+			while (ok && *++p) {
+				if (!isalnum(*p) && *p != '_') {
+					ok = 0;
+					break;
+				}
 			}
-			convert_to_long_ex(non_cs);
-			if (Z_LVAL_PP(non_cs)) {
-				case_sensitive = 0;
-			} else {
-				case_sensitive = CONST_CS;
+
+			if (!ok) {
+				RETURN_FALSE;
 			}
-			break;
-		default:
-			ZEND_WRONG_PARAM_COUNT();
-			break;
+		}
+	}
+
+	if(non_cs) {
+		case_sensitive = 0;
 	}
 
 repeat:
-	switch (Z_TYPE_PP(val)) {
+	switch (Z_TYPE_P(val)) {
 		case IS_LONG:
 		case IS_DOUBLE:
 		case IS_STRING:
@@ -492,13 +516,13 @@
 			break;
 		case IS_OBJECT:
 			if (!val_free) {
-				if (Z_OBJ_HT_PP(val)->get) {
-					val_free = *val = Z_OBJ_HT_PP(val)->get(*val TSRMLS_CC);
+				if (Z_OBJ_HT_P(val)->get) {
+					val_free = val = Z_OBJ_HT_P(val)->get(val TSRMLS_CC);
 					goto repeat;
-				} else if (Z_OBJ_HT_PP(val)->cast_object) {
+				} else if (Z_OBJ_HT_P(val)->cast_object) {
 					ALLOC_INIT_ZVAL(val_free);
-					if (Z_OBJ_HT_PP(val)->cast_object(*val, val_free, IS_STRING TSRMLS_CC) == SUCCESS) {
-						val = &val_free;
+					if (Z_OBJ_HT_P(val)->cast_object(val, val_free, IS_STRING TSRMLS_CC) == SUCCESS) {
+						val = val_free;
 						break;
 					}
 				}
@@ -511,16 +535,15 @@
 			}
 			RETURN_FALSE;
 	}
-	convert_to_string_ex(var);
 	
-	c.value = **val;
+	c.value = *val;
 	zval_copy_ctor(&c.value);
 	if (val_free) {
 		zval_ptr_dtor(&val_free);
 	}
 	c.flags = case_sensitive; /* non persistent */
-	c.name = zend_strndup(Z_STRVAL_PP(var), Z_STRLEN_PP(var));
-	c.name_len = Z_STRLEN_PP(var)+1;
+	c.name = zend_strndup(name, name_len);
+	c.name_len = name_len+1;
 	c.module_number = PHP_USER_CONSTANT;
 	if (zend_register_constant(&c TSRMLS_CC) == SUCCESS) {
 		RETURN_TRUE;
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.