tony2001 Wed Jul 26 08:06:59 2006 UTC Modified files: /php-src/ext/reflection php_reflection.c /php-src/ext/reflection/tests bug38217.phpt Log: fix bug #38217 (ReflectionClass::newInstanceArgs() tries to allocate too much memory) http://cvs.php.net/viewvc.cgi/php-src/ext/reflection/php_reflection.c?r1=1.246&r2=1.247&diff_format=u Index: php-src/ext/reflection/php_reflection.c diff -u php-src/ext/reflection/php_reflection.c:1.246 php-src/ext/reflection/php_reflection.c:1.247 --- php-src/ext/reflection/php_reflection.c:1.246 Tue Jul 25 12:36:29 2006 +++ php-src/ext/reflection/php_reflection.c Wed Jul 26 08:06:59 2006 @@ -20,7 +20,7 @@ +----------------------------------------------------------------------+ */ -/* $Id: php_reflection.c,v 1.246 2006/07/25 12:36:29 iliaa Exp $ */ +/* $Id: php_reflection.c,v 1.247 2006/07/26 08:06:59 tony2001 Exp $ */ #ifdef HAVE_CONFIG_H #include "config.h" @@ -3405,7 +3405,7 @@ zval *retval_ptr; reflection_object *intern; zend_class_entry *ce; - int argc; + int argc = 0; HashTable *args; @@ -3415,11 +3415,13 @@ if (zend_parse_parameters(ZEND_NUM_ARGS() TSRMLS_CC, "|h", &args) == FAILURE) { return; } - argc = args->nNumOfElements; + if (ZEND_NUM_ARGS() > 0) { + argc = args->nNumOfElements; + } /* Run the constructor if there is one */ if (ce->constructor) { - zval ***params; + zval ***params = NULL; zend_fcall_info fci; zend_fcall_info_cache fcc; @@ -3427,10 +3429,12 @@ zend_throw_exception_ex(reflection_exception_ptr, 0 TSRMLS_CC, "Access to non-public constructor of class %v", ce->name); return; } - - params = safe_emalloc(sizeof(zval **), argc, 0); - zend_hash_apply_with_argument(args, (apply_func_arg_t)_zval_array_to_c_array, ¶ms TSRMLS_CC); - params -= argc; + + if (argc) { + params = safe_emalloc(sizeof(zval **), argc, 0); + zend_hash_apply_with_argument(args, (apply_func_arg_t)_zval_array_to_c_array, ¶ms TSRMLS_CC); + params -= argc; + } object_init_ex(return_value, ce); @@ -3450,7 +3454,9 @@ fcc.object_pp = &return_value; if (zend_call_function(&fci, &fcc TSRMLS_CC) == FAILURE) { - efree(params); + if (params) { + efree(params); + } zval_ptr_dtor(&retval_ptr); zend_error(E_WARNING, "Invocation of %v's constructor failed", ce->name); RETURN_NULL(); @@ -3458,7 +3464,9 @@ if (retval_ptr) { zval_ptr_dtor(&retval_ptr); } - efree(params); + if (params) { + efree(params); + } } else if (!ZEND_NUM_ARGS()) { object_init_ex(return_value, ce); } else { @@ -4837,7 +4845,7 @@ php_info_print_table_start(); php_info_print_table_header(2, "Reflection", "enabled"); - php_info_print_table_row(2, "Version", "$Id: php_reflection.c,v 1.246 2006/07/25 12:36:29 iliaa Exp $"); + php_info_print_table_row(2, "Version", "$Id: php_reflection.c,v 1.247 2006/07/26 08:06:59 tony2001 Exp $"); php_info_print_table_end(); } /* }}} */ http://cvs.php.net/viewvc.cgi/php-src/ext/reflection/tests/bug38217.phpt?r1=1.1&r2=1.2&diff_format=u Index: php-src/ext/reflection/tests/bug38217.phpt diff -u /dev/null php-src/ext/reflection/tests/bug38217.phpt:1.2 --- /dev/null Wed Jul 26 08:06:59 2006 +++ php-src/ext/reflection/tests/bug38217.phpt Wed Jul 26 08:06:59 2006 @@ -0,0 +1,54 @@ +--TEST-- +#38217 (ReflectionClass::newInstanceArgs() tries to allocate too much memory) +--FILE-- +<?php + +class Object { + public function __construct() { + } +} + +$class= new ReflectionClass('Object'); +var_dump($class->newInstanceArgs()); + +class Object1 { + public function __construct($var) { + var_dump($var); + } +} + +$class= new ReflectionClass('Object1'); +var_dump($class->newInstanceArgs()); +var_dump($class->newInstanceArgs(array('test'))); + + +echo "Done\n"; +?> +--EXPECTF-- +object(Object)#%d (0) { +} + +Warning: Missing argument 1 for Object1::__construct() in %s on line %d + +Notice: Undefined variable: var in %s on line %d +NULL +object(Object1)#%d (0) { +} +string(4) "test" +object(Object1)#%d (0) { +} +Done +--UEXPECTF-- +object(Object)#%d (0) { +} + +Warning: Missing argument 1 for Object1::__construct() in %s on line %d + +Notice: Undefined variable: var in %s on line %d +NULL +object(Object1)#%d (0) { +} +unicode(4) "test" +object(Object1)#%d (0) { +} +Done
-- PHP CVS Mailing List (http://www.php.net/) To unsubscribe, visit: http://www.php.net/unsub.php