Merge branch 'PHP-7.2'

* PHP-7.2:
  Update NEWS
  Fixed bug #75573 (Segmentation fault in 7.1.12 and 7.0.26)
  Revert "ext/sodium: pwhash: do not warn on low parameters"

Conflicts:
	Zend/zend_object_handlers.c
This commit is contained in:
Xinchen Hui 2017-11-29 14:54:05 +08:00
commit 60c742979d
3 changed files with 92 additions and 43 deletions

64
Zend/tests/bug75573.phpt Normal file
View File

@ -0,0 +1,64 @@
--TEST--
Bug #75573 (Segmentation fault in 7.1.12 and 7.0.26)
--FILE--
<?php
class A
{
var $_stdObject;
function initialize($properties = FALSE) {
$this->_stdObject = $properties ? (object) $properties : new stdClass();
parent::initialize();
}
function &__get($property)
{
if (isset($this->_stdObject->{$property})) {
$retval =& $this->_stdObject->{$property};
return $retval;
} else {
return NULL;
}
}
function &__set($property, $value)
{
return $this->_stdObject->{$property} = $value;
}
function __isset($property_name)
{
return isset($this->_stdObject->{$property_name});
}
}
class B extends A
{
function initialize($properties = array())
{
parent::initialize($properties);
}
function &__get($property)
{
if (isset($this->settings) && isset($this->settings[$property])) {
$retval =& $this->settings[$property];
return $retval;
} else {
return parent::__get($property);
}
}
}
$b = new B();
$b->settings = [ "foo" => "bar", "name" => "abc" ];
var_dump($b->name);
var_dump($b->settings);
?>
--EXPECTF--
Warning: Creating default object from empty value in %sbug75573.php on line %d
Notice: Only variable references should be returned by reference in %sbug75573.php on line %d
string(3) "abc"
array(2) {
["foo"]=>
string(3) "bar"
["name"]=>
string(3) "abc"
}

View File

@ -660,13 +660,11 @@ zval *zend_std_read_property(zval *object, zval *member, int type, void **cache_
}
zval_ptr_dtor(&tmp_object);
goto exit;
} else {
if (Z_STRVAL_P(member)[0] == '\0' && Z_STRLEN_P(member) != 0) {
zval_ptr_dtor(&tmp_object);
zend_throw_error(NULL, "Cannot access property started with '\\0'");
retval = &EG(uninitialized_zval);
goto exit;
}
} else if (Z_STRVAL_P(member)[0] == '\0' && Z_STRLEN_P(member) != 0) {
zval_ptr_dtor(&tmp_object);
zend_throw_error(NULL, "Cannot access property started with '\\0'");
retval = &EG(uninitialized_zval);
goto exit;
}
}

View File

@ -233,19 +233,6 @@ ZEND_END_ARG_INFO()
# undef crypto_secretstream_xchacha20poly1305_ABYTES
#endif
#ifndef crypto_pwhash_OPSLIMIT_MIN
# define crypto_pwhash_OPSLIMIT_MIN crypto_pwhash_OPSLIMIT_INTERACTIVE
#endif
#ifndef crypto_pwhash_MEMLIMIT_MIN
# define crypto_pwhash_MEMLIMIT_MIN crypto_pwhash_MEMLIMIT_INTERACTIVE
#endif
#ifndef crypto_pwhash_scryptsalsa208sha256_OPSLIMIT_MIN
# define crypto_pwhash_scryptsalsa208sha256_OPSLIMIT_MIN crypto_pwhash_scryptsalsa208sha256_OPSLIMIT_INTERACTIVE
#endif
#ifndef crypto_pwhash_scryptsalsa208sha256_MEMLIMIT_MIN
# define crypto_pwhash_scryptsalsa208sha256_MEMLIMIT_MIN crypto_pwhash_scryptsalsa208sha256_MEMLIMIT_INTERACTIVE
#endif
const zend_function_entry sodium_functions[] = {
PHP_FE(sodium_crypto_aead_aes256gcm_is_available, AI_None)
#ifdef HAVE_AESGCM
@ -1852,12 +1839,12 @@ PHP_FUNCTION(sodium_crypto_pwhash)
zend_throw_exception(sodium_exception_ce, "salt should be SODIUM_CRYPTO_PWHASH_SALTBYTES bytes", 0);
return;
}
if (opslimit < crypto_pwhash_OPSLIMIT_MIN) {
zend_error(E_ERROR,
"number of operations for the password hashing function is too low");
if (opslimit < crypto_pwhash_OPSLIMIT_INTERACTIVE) {
zend_error(E_WARNING,
"number of operations for the password hashing function is low");
}
if (memlimit < crypto_pwhash_MEMLIMIT_MIN) {
zend_error(E_ERROR, "maximum memory for the password hashing function is too low");
if (memlimit < crypto_pwhash_MEMLIMIT_INTERACTIVE) {
zend_error(E_WARNING, "maximum memory for the password hashing function is low");
}
hash = zend_string_alloc((size_t) hash_len, 0);
ret = -1;
@ -1915,13 +1902,13 @@ PHP_FUNCTION(sodium_crypto_pwhash_str)
if (passwd_len <= 0) {
zend_error(E_WARNING, "empty password");
}
if (opslimit < crypto_pwhash_OPSLIMIT_MIN) {
zend_error(E_ERROR,
"number of operations for the password hashing function is too low");
if (opslimit < crypto_pwhash_OPSLIMIT_INTERACTIVE) {
zend_error(E_WARNING,
"number of operations for the password hashing function is low");
}
if (memlimit < crypto_pwhash_MEMLIMIT_MIN) {
zend_error(E_ERROR,
"maximum memory for the password hashing function is too low");
if (memlimit < crypto_pwhash_MEMLIMIT_INTERACTIVE) {
zend_error(E_WARNING,
"maximum memory for the password hashing function is low");
}
hash_str = zend_string_alloc(crypto_pwhash_STRBYTES - 1, 0);
if (crypto_pwhash_str
@ -2029,13 +2016,13 @@ PHP_FUNCTION(sodium_crypto_pwhash_scryptsalsa208sha256)
0);
return;
}
if (opslimit < crypto_pwhash_scryptsalsa208sha256_OPSLIMIT_INTERACTIVE) {
zend_error(E_ERROR,
"number of operations for the scrypt function is too low");
if (opslimit < crypto_pwhash_scryptsalsa208sha256_opslimit_interactive()) {
zend_error(E_WARNING,
"number of operations for the scrypt function is low");
}
if (memlimit < crypto_pwhash_scryptsalsa208sha256_MEMLIMIT_INTERACTIVE) {
zend_error(E_ERROR,
"maximum memory for the scrypt function is too low");
if (memlimit < crypto_pwhash_scryptsalsa208sha256_memlimit_interactive()) {
zend_error(E_WARNING,
"maximum memory for the scrypt function is low");
}
hash = zend_string_alloc((size_t) hash_len, 0);
if (crypto_pwhash_scryptsalsa208sha256
@ -2076,13 +2063,13 @@ PHP_FUNCTION(sodium_crypto_pwhash_scryptsalsa208sha256_str)
if (passwd_len <= 0) {
zend_error(E_WARNING, "empty password");
}
if (opslimit < crypto_pwhash_scryptsalsa208sha256_OPSLIMIT_INTERACTIVE) {
zend_error(E_ERROR,
"number of operations for the scrypt function is too low");
if (opslimit < crypto_pwhash_scryptsalsa208sha256_opslimit_interactive()) {
zend_error(E_WARNING,
"number of operations for the scrypt function is low");
}
if (memlimit < crypto_pwhash_scryptsalsa208sha256_MEMLIMIT_INTERACTIVE) {
zend_error(E_ERROR,
"maximum memory for the scrypt function is too low");
if (memlimit < crypto_pwhash_scryptsalsa208sha256_memlimit_interactive()) {
zend_error(E_WARNING,
"maximum memory for the scrypt function is low");
}
hash_str = zend_string_alloc
(crypto_pwhash_scryptsalsa208sha256_STRBYTES - 1, 0);