Browse Source

Merge branch 'PHP-7.0' into PHP-7.1

pull/2252/merge
Nikita Popov 9 years ago
parent
commit
d9fd44366d
  1. 3
      NEWS
  2. 10
      ext/dom/node.c
  3. 15
      ext/dom/tests/bug69373.phpt
  4. 2
      ext/libxml/libxml.c
  5. 1
      ext/libxml/php_libxml.h

3
NEWS

@ -11,6 +11,9 @@ PHP NEWS
. Fixed bug #74639 (implement clone for DatePeriod and DateInterval).
(andrewnester)
- DOM:
. Fixed bug #69373 (References to deleted XPath query results). (ttoohey)
- Intl:
. Fixed bug #73473 (Stack Buffer Overflow in msgfmt_parse_message). (libnex)

10
ext/dom/node.c

@ -337,6 +337,8 @@ int dom_node_node_value_write(dom_object *obj, zval *newval)
case XML_ATTRIBUTE_NODE:
if (nodep->children) {
node_list_unlink(nodep->children);
php_libxml_node_free_list((xmlNodePtr) nodep->children);
nodep->children = NULL;
}
case XML_TEXT_NODE:
case XML_COMMENT_NODE:
@ -854,6 +856,14 @@ int dom_node_text_content_write(dom_object *obj, zval *newval)
return FAILURE;
}
if (nodep->type == XML_ELEMENT_NODE || nodep->type == XML_ATTRIBUTE_NODE) {
if (nodep->children) {
node_list_unlink(nodep->children);
php_libxml_node_free_list((xmlNodePtr) nodep->children);
nodep->children = NULL;
}
}
str = zval_get_string(newval);
/* we have to use xmlNodeAddContent() to get the same behavior as with xmlNewText() */
xmlNodeSetContent(nodep, (xmlChar *) "");

15
ext/dom/tests/bug69373.phpt

@ -0,0 +1,15 @@
--TEST--
Bug #69373 References to deleted XPath query results
--FILE--
<?php
$doc = new DOMDocument();
for( $i=0; $i<20; $i++ ) {
$doc->loadXML("<parent><child /><child /></parent>");
$xpath = new DOMXpath($doc);
$all = $xpath->query('//*');
$doc->firstChild->nodeValue = '';
}
echo 'DONE', PHP_EOL;
?>
--EXPECT--
DONE

2
ext/libxml/libxml.c

@ -224,7 +224,7 @@ static void php_libxml_node_free(xmlNodePtr node)
}
}
static void php_libxml_node_free_list(xmlNodePtr node)
PHP_LIBXML_API void php_libxml_node_free_list(xmlNodePtr node)
{
xmlNodePtr curnode;

1
ext/libxml/php_libxml.h

@ -100,6 +100,7 @@ PHP_LIBXML_API int php_libxml_decrement_doc_ref(php_libxml_node_object *object);
PHP_LIBXML_API xmlNodePtr php_libxml_import_node(zval *object);
PHP_LIBXML_API zval *php_libxml_register_export(zend_class_entry *ce, php_libxml_export_node export_function);
/* When an explicit freeing of node and children is required */
PHP_LIBXML_API void php_libxml_node_free_list(xmlNodePtr node);
PHP_LIBXML_API void php_libxml_node_free_resource(xmlNodePtr node);
/* When object dtor is called as node may still be referenced */
PHP_LIBXML_API void php_libxml_node_decrement_resource(php_libxml_node_object *object);

Loading…
Cancel
Save