diff options
| author | Xinchen Hui <laruence@php.net> | 2015-03-01 23:17:41 +0800 |
|---|---|---|
| committer | Xinchen Hui <laruence@php.net> | 2015-03-01 23:17:41 +0800 |
| commit | 672a396d4a961a10f7483727973777e444ff7022 (patch) | |
| tree | 2699f51bd37cc994b77cda8d301a23fa87bcc71d | |
| parent | aaaa90591289a98b2b40af216a50a46a5e379505 (diff) | |
| parent | caebb76131ffce8ef7d8086f4eff2726c93d329f (diff) | |
| download | php-git-672a396d4a961a10f7483727973777e444ff7022.tar.gz | |
Merge branch 'PHP-5.5' into PHP-5.6
Conflicts:
ext/standard/var_unserializer.c
| -rw-r--r-- | ext/standard/tests/serialize/bug69139.phpt | 10 | ||||
| -rw-r--r-- | ext/standard/var_unserializer.c | 68 | ||||
| -rw-r--r-- | ext/standard/var_unserializer.re | 3 |
3 files changed, 44 insertions, 37 deletions
diff --git a/ext/standard/tests/serialize/bug69139.phpt b/ext/standard/tests/serialize/bug69139.phpt new file mode 100644 index 0000000000..48127a2461 --- /dev/null +++ b/ext/standard/tests/serialize/bug69139.phpt @@ -0,0 +1,10 @@ +--TEST-- +Bug #69139 (Crash in gc_zval_possible_root on unserialize) +--FILE-- +<?php +$str = 'a:1126666:{i:0;r:1;i:-09610;r:1;i:-0;i:0;i:0;O:1:"A":2119X:i:0;i:0;i:0;i:0;i:0;O:1:"A":2116:{i:0;r:5;i:-096766610;r:1;i:-610;r:1;i:0;i:0;'; +@unserialize($str); +echo "Alive"; +?> +--EXPECT-- +Alive diff --git a/ext/standard/var_unserializer.c b/ext/standard/var_unserializer.c index 222e704211..26e532ac43 100644 --- a/ext/standard/var_unserializer.c +++ b/ext/standard/var_unserializer.c @@ -1,4 +1,4 @@ -/* Generated by re2c 0.13.7.5 */ +/* Generated by re2c 0.13.5 */ #line 1 "ext/standard/var_unserializer.re" /* +----------------------------------------------------------------------+ @@ -319,8 +319,7 @@ static inline int process_nested_data(UNSERIALIZE_PARAMETER, HashTable *ht, long if (!php_var_unserialize(&data, p, max, var_hash TSRMLS_CC)) { zval_dtor(key); FREE_ZVAL(key); - zval_dtor(data); - FREE_ZVAL(data); + zval_ptr_dtor(&data); return 0; } @@ -478,7 +477,7 @@ PHPAPI int php_var_unserialize(UNSERIALIZE_PARAMETER) -#line 482 "ext/standard/var_unserializer.c" +#line 481 "ext/standard/var_unserializer.c" { YYCTYPE yych; static const unsigned char yybm[] = { @@ -538,9 +537,9 @@ yy2: yych = *(YYMARKER = ++YYCURSOR); if (yych == ':') goto yy95; yy3: -#line 833 "ext/standard/var_unserializer.re" +#line 832 "ext/standard/var_unserializer.re" { return 0; } -#line 544 "ext/standard/var_unserializer.c" +#line 543 "ext/standard/var_unserializer.c" yy4: yych = *(YYMARKER = ++YYCURSOR); if (yych == ':') goto yy89; @@ -583,13 +582,13 @@ yy13: goto yy3; yy14: ++YYCURSOR; -#line 827 "ext/standard/var_unserializer.re" +#line 826 "ext/standard/var_unserializer.re" { /* this is the case where we have less data than planned */ php_error_docref(NULL TSRMLS_CC, E_NOTICE, "Unexpected end of serialized data"); return 0; /* not sure if it should be 0 or 1 here? */ } -#line 593 "ext/standard/var_unserializer.c" +#line 592 "ext/standard/var_unserializer.c" yy16: yych = *++YYCURSOR; goto yy3; @@ -615,12 +614,11 @@ yy20: if (yybm[0+yych] & 128) { goto yy20; } - if (yych <= '/') goto yy18; - if (yych >= ';') goto yy18; + if (yych != ':') goto yy18; yych = *++YYCURSOR; if (yych != '"') goto yy18; ++YYCURSOR; -#line 681 "ext/standard/var_unserializer.re" +#line 680 "ext/standard/var_unserializer.re" { size_t len, len2, len3, maxlen; long elements; @@ -766,7 +764,7 @@ yy20: return object_common2(UNSERIALIZE_PASSTHRU, elements); } -#line 770 "ext/standard/var_unserializer.c" +#line 768 "ext/standard/var_unserializer.c" yy25: yych = *++YYCURSOR; if (yych <= ',') { @@ -791,7 +789,7 @@ yy27: yych = *++YYCURSOR; if (yych != '"') goto yy18; ++YYCURSOR; -#line 673 "ext/standard/var_unserializer.re" +#line 672 "ext/standard/var_unserializer.re" { INIT_PZVAL(*rval); @@ -799,7 +797,7 @@ yy27: return object_common2(UNSERIALIZE_PASSTHRU, object_common1(UNSERIALIZE_PASSTHRU, ZEND_STANDARD_CLASS_DEF_PTR)); } -#line 803 "ext/standard/var_unserializer.c" +#line 801 "ext/standard/var_unserializer.c" yy32: yych = *++YYCURSOR; if (yych == '+') goto yy33; @@ -820,7 +818,7 @@ yy34: yych = *++YYCURSOR; if (yych != '{') goto yy18; ++YYCURSOR; -#line 653 "ext/standard/var_unserializer.re" +#line 652 "ext/standard/var_unserializer.re" { long elements = parse_iv(start + 2); /* use iv() not uiv() in order to check data range */ @@ -840,7 +838,7 @@ yy34: return finish_nested_data(UNSERIALIZE_PASSTHRU); } -#line 844 "ext/standard/var_unserializer.c" +#line 842 "ext/standard/var_unserializer.c" yy39: yych = *++YYCURSOR; if (yych == '+') goto yy40; @@ -861,7 +859,7 @@ yy41: yych = *++YYCURSOR; if (yych != '"') goto yy18; ++YYCURSOR; -#line 624 "ext/standard/var_unserializer.re" +#line 623 "ext/standard/var_unserializer.re" { size_t len, maxlen; char *str; @@ -890,7 +888,7 @@ yy41: ZVAL_STRINGL(*rval, str, len, 0); return 1; } -#line 894 "ext/standard/var_unserializer.c" +#line 892 "ext/standard/var_unserializer.c" yy46: yych = *++YYCURSOR; if (yych == '+') goto yy47; @@ -911,7 +909,7 @@ yy48: yych = *++YYCURSOR; if (yych != '"') goto yy18; ++YYCURSOR; -#line 596 "ext/standard/var_unserializer.re" +#line 595 "ext/standard/var_unserializer.re" { size_t len, maxlen; char *str; @@ -939,7 +937,7 @@ yy48: ZVAL_STRINGL(*rval, str, len, 1); return 1; } -#line 943 "ext/standard/var_unserializer.c" +#line 941 "ext/standard/var_unserializer.c" yy53: yych = *++YYCURSOR; if (yych <= '/') { @@ -1027,7 +1025,7 @@ yy61: } yy63: ++YYCURSOR; -#line 586 "ext/standard/var_unserializer.re" +#line 585 "ext/standard/var_unserializer.re" { #if SIZEOF_LONG == 4 use_double: @@ -1037,7 +1035,7 @@ use_double: ZVAL_DOUBLE(*rval, zend_strtod((const char *)start + 2, NULL)); return 1; } -#line 1041 "ext/standard/var_unserializer.c" +#line 1039 "ext/standard/var_unserializer.c" yy65: yych = *++YYCURSOR; if (yych <= ',') { @@ -1096,7 +1094,7 @@ yy73: yych = *++YYCURSOR; if (yych != ';') goto yy18; ++YYCURSOR; -#line 571 "ext/standard/var_unserializer.re" +#line 570 "ext/standard/var_unserializer.re" { *p = YYCURSOR; INIT_PZVAL(*rval); @@ -1111,7 +1109,7 @@ yy73: return 1; } -#line 1115 "ext/standard/var_unserializer.c" +#line 1113 "ext/standard/var_unserializer.c" yy76: yych = *++YYCURSOR; if (yych == 'N') goto yy73; @@ -1138,7 +1136,7 @@ yy79: if (yych <= '9') goto yy79; if (yych != ';') goto yy18; ++YYCURSOR; -#line 544 "ext/standard/var_unserializer.re" +#line 543 "ext/standard/var_unserializer.re" { #if SIZEOF_LONG == 4 int digits = YYCURSOR - start - 3; @@ -1165,7 +1163,7 @@ yy79: ZVAL_LONG(*rval, parse_iv(start + 2)); return 1; } -#line 1169 "ext/standard/var_unserializer.c" +#line 1167 "ext/standard/var_unserializer.c" yy83: yych = *++YYCURSOR; if (yych <= '/') goto yy18; @@ -1173,24 +1171,24 @@ yy83: yych = *++YYCURSOR; if (yych != ';') goto yy18; ++YYCURSOR; -#line 537 "ext/standard/var_unserializer.re" +#line 536 "ext/standard/var_unserializer.re" { *p = YYCURSOR; INIT_PZVAL(*rval); ZVAL_BOOL(*rval, parse_iv(start + 2)); return 1; } -#line 1184 "ext/standard/var_unserializer.c" +#line 1182 "ext/standard/var_unserializer.c" yy87: ++YYCURSOR; -#line 530 "ext/standard/var_unserializer.re" +#line 529 "ext/standard/var_unserializer.re" { *p = YYCURSOR; INIT_PZVAL(*rval); ZVAL_NULL(*rval); return 1; } -#line 1194 "ext/standard/var_unserializer.c" +#line 1192 "ext/standard/var_unserializer.c" yy89: yych = *++YYCURSOR; if (yych <= ',') { @@ -1213,7 +1211,7 @@ yy91: if (yych <= '9') goto yy91; if (yych != ';') goto yy18; ++YYCURSOR; -#line 507 "ext/standard/var_unserializer.re" +#line 506 "ext/standard/var_unserializer.re" { long id; @@ -1236,7 +1234,7 @@ yy91: return 1; } -#line 1240 "ext/standard/var_unserializer.c" +#line 1238 "ext/standard/var_unserializer.c" yy95: yych = *++YYCURSOR; if (yych <= ',') { @@ -1259,7 +1257,7 @@ yy97: if (yych <= '9') goto yy97; if (yych != ';') goto yy18; ++YYCURSOR; -#line 486 "ext/standard/var_unserializer.re" +#line 485 "ext/standard/var_unserializer.re" { long id; @@ -1280,9 +1278,9 @@ yy97: return 1; } -#line 1284 "ext/standard/var_unserializer.c" +#line 1282 "ext/standard/var_unserializer.c" } -#line 835 "ext/standard/var_unserializer.re" +#line 834 "ext/standard/var_unserializer.re" return 0; diff --git a/ext/standard/var_unserializer.re b/ext/standard/var_unserializer.re index 018c51355b..fe019fb93d 100644 --- a/ext/standard/var_unserializer.re +++ b/ext/standard/var_unserializer.re @@ -323,8 +323,7 @@ static inline int process_nested_data(UNSERIALIZE_PARAMETER, HashTable *ht, long if (!php_var_unserialize(&data, p, max, var_hash TSRMLS_CC)) { zval_dtor(key); FREE_ZVAL(key); - zval_dtor(data); - FREE_ZVAL(data); + zval_ptr_dtor(&data); return 0; } |
