Browse Source

Merge branch 'PHP-7.0' into PHP-7.1

* PHP-7.0:
  Fixed bug #75420 (Crash when modifing property name in __isset for BP_VAR_IS)

Conflicts:
	Zend/zend_object_handlers.c
PHP-7.1.12
Xinchen Hui 9 years ago
parent
commit
3c4c9a23bc
  1. 15
      Zend/tests/bug75420.phpt
  2. 7
      Zend/zend_object_handlers.c

15
Zend/tests/bug75420.phpt

@ -0,0 +1,15 @@
--TEST--
Bug #75420 (Crash when modifing property name in __isset for BP_VAR_IS)
--FILE--
<?php
class Test {
public function __isset($x) { $GLOBALS["name"] = 24; return true; }
public function __get($x) { var_dump($x); return 42; }
}
$obj = new Test;
$name = "foo";
var_dump($obj->$name ?? 12);
?>
--EXPECT--

7
Zend/zend_object_handlers.c

@ -577,6 +577,7 @@ zval *zend_std_read_property(zval *object, zval *member, int type, void **cache_
zval tmp_member;
zval *retval;
uint32_t property_offset;
uint32_t *guard = NULL;
zobj = Z_OBJ_P(object);
@ -612,7 +613,7 @@ zval *zend_std_read_property(zval *object, zval *member, int type, void **cache_
/* magic isset */
if ((type == BP_VAR_IS) && zobj->ce->__isset) {
zval tmp_object, tmp_result;
uint32_t *guard = zend_get_property_guard(zobj, Z_STR_P(member));
guard = zend_get_property_guard(zobj, Z_STR_P(member));
if (!((*guard) & IN_ISSET)) {
ZVAL_COPY(&tmp_object, object);
@ -636,7 +637,9 @@ zval *zend_std_read_property(zval *object, zval *member, int type, void **cache_
/* magic get */
if (zobj->ce->__get) {
uint32_t *guard = zend_get_property_guard(zobj, Z_STR_P(member));
if (guard == NULL) {
guard = zend_get_property_guard(zobj, Z_STR_P(member));
}
if (!((*guard) & IN_GET)) {
zval tmp_object;

Loading…
Cancel
Save