]> granicus.if.org Git - php/commitdiff
fix bug #38217 (ReflectionClass::newInstanceArgs() tries to allocate too much memory)
authorAntony Dovgal <tony2001@php.net>
Wed, 26 Jul 2006 08:06:59 +0000 (08:06 +0000)
committerAntony Dovgal <tony2001@php.net>
Wed, 26 Jul 2006 08:06:59 +0000 (08:06 +0000)
ext/reflection/php_reflection.c
ext/reflection/tests/bug38217.phpt [new file with mode: 0644]

index 3afd5275e6048acd11456b9a4b72c4f3de290f6b..084c82930ffed3e2dcda083049c0707d6dc5f5d5 100644 (file)
@@ -3405,7 +3405,7 @@ ZEND_METHOD(reflection_class, newInstanceArgs)
        zval *retval_ptr;
        reflection_object *intern;
        zend_class_entry *ce;
-       int argc;
+       int argc = 0;
        HashTable *args;
        
        
@@ -3415,11 +3415,13 @@ ZEND_METHOD(reflection_class, newInstanceArgs)
        if (zend_parse_parameters(ZEND_NUM_ARGS() TSRMLS_CC, "|h", &args) == FAILURE) {
                return;
        }
-       argc = args->nNumOfElements;
+       if (ZEND_NUM_ARGS() > 0) {
+               argc = args->nNumOfElements;
+       }
        
        /* Run the constructor if there is one */
        if (ce->constructor) {
-               zval ***params;
+               zval ***params = NULL;
                zend_fcall_info fci;
                zend_fcall_info_cache fcc;
 
@@ -3427,10 +3429,12 @@ ZEND_METHOD(reflection_class, newInstanceArgs)
                        zend_throw_exception_ex(reflection_exception_ptr, 0 TSRMLS_CC, "Access to non-public constructor of class %v", ce->name);
                        return;
                }
-
-               params = safe_emalloc(sizeof(zval **), argc, 0);
-               zend_hash_apply_with_argument(args, (apply_func_arg_t)_zval_array_to_c_array, &params TSRMLS_CC);       
-               params -= argc;
+               
+               if (argc) {
+                       params = safe_emalloc(sizeof(zval **), argc, 0);
+                       zend_hash_apply_with_argument(args, (apply_func_arg_t)_zval_array_to_c_array, &params TSRMLS_CC);       
+                       params -= argc;
+               }
 
                object_init_ex(return_value, ce);
 
@@ -3450,7 +3454,9 @@ ZEND_METHOD(reflection_class, newInstanceArgs)
                fcc.object_pp = &return_value;
 
                if (zend_call_function(&fci, &fcc TSRMLS_CC) == FAILURE) {
-                       efree(params);
+                       if (params) {
+                               efree(params);
+                       }
                        zval_ptr_dtor(&retval_ptr);
                        zend_error(E_WARNING, "Invocation of %v's constructor failed", ce->name);
                        RETURN_NULL();
@@ -3458,7 +3464,9 @@ ZEND_METHOD(reflection_class, newInstanceArgs)
                if (retval_ptr) {
                        zval_ptr_dtor(&retval_ptr);
                }
-               efree(params);
+               if (params) {
+                       efree(params);
+               }
        } else if (!ZEND_NUM_ARGS()) {
                object_init_ex(return_value, ce);
        } else {
diff --git a/ext/reflection/tests/bug38217.phpt b/ext/reflection/tests/bug38217.phpt
new file mode 100644 (file)
index 0000000..7a1e22b
--- /dev/null
@@ -0,0 +1,54 @@
+--TEST--
+#38217 (ReflectionClass::newInstanceArgs() tries to allocate too much memory)
+--FILE--
+<?php
+
+class Object {
+       public function __construct() {
+       }
+}
+
+$class= new ReflectionClass('Object');
+var_dump($class->newInstanceArgs());
+
+class Object1 {
+       public function __construct($var) {
+               var_dump($var);
+       }
+}
+
+$class= new ReflectionClass('Object1');
+var_dump($class->newInstanceArgs());
+var_dump($class->newInstanceArgs(array('test')));
+
+
+echo "Done\n";
+?>
+--EXPECTF--    
+object(Object)#%d (0) {
+}
+
+Warning: Missing argument 1 for Object1::__construct() in %s on line %d
+
+Notice: Undefined variable: var in %s on line %d
+NULL
+object(Object1)#%d (0) {
+}
+string(4) "test"
+object(Object1)#%d (0) {
+}
+Done
+--UEXPECTF--
+object(Object)#%d (0) {
+}
+
+Warning: Missing argument 1 for Object1::__construct() in %s on line %d
+
+Notice: Undefined variable: var in %s on line %d
+NULL
+object(Object1)#%d (0) {
+}
+unicode(4) "test"
+object(Object1)#%d (0) {
+}
+Done