diff --git a/.github/scripts/windows/test_task.bat b/.github/scripts/windows/test_task.bat index 7c526be95c3d..6c49ebe40417 100644 --- a/.github/scripts/windows/test_task.bat +++ b/.github/scripts/windows/test_task.bat @@ -117,8 +117,9 @@ set PHP_BUILD_DIR=%PHP_BUILD_OBJ_DIR%\Release if "%THREAD_SAFE%" equ "1" set PHP_BUILD_DIR=%PHP_BUILD_DIR%_TS rem prepare for mail -curl -sLo hMailServer.exe https://www.hmailserver.com/download_file/?downloadid=271 -hMailServer.exe /verysilent +curl -sLo hMailServer.zip https://downloads.php.net/~windows/php-sdk/deps/vs18/x64/hmailserver-5.7.0-vs18-x64.zip +unzip -q hMailServer.zip -d hMailServer +hMailServer\bin\hMailServer.exe /verysilent cd %APPVEYOR_BUILD_FOLDER% %PHP_BUILD_DIR%\php.exe -dextension_dir=%PHP_BUILD_DIR% -dextension=com_dotnet .github\setup_hmailserver.php diff --git a/NEWS b/NEWS index 378643836c80..a9ca3fea246c 100644 --- a/NEWS +++ b/NEWS @@ -37,6 +37,15 @@ PHP NEWS . Fixed segfault in ReflectionMethod::createFromMethodName() on an uninstantiable subclass. (iliaal) +- Session: + . Fix corruption in mod_mm. (ndossche) + . Fixed bug GH-23043 (broken session id code can cause zend_mm_heap + corrupted). (ndossche) + +- SimpleXML: + . Fixed segfault when comparing uninitialized SimpleXMLElement + instances. (iliaal) + - Sockets: . Fixed various memory related issues in ext/sockets. (David Carlier) diff --git a/ext/session/mod_mm.c b/ext/session/mod_mm.c index b997a2bdcff5..75ee713e9f09 100644 --- a/ext/session/mod_mm.c +++ b/ext/session/mod_mm.c @@ -351,7 +351,7 @@ PS_READ_FUNC(mm) && ps_mm_key_exists(data, key) == FAILURE) { /* key points to PS(id), but cannot change here. */ if (key) { - efree(PS(id)); + zend_string_release_ex(PS(id), false); PS(id) = NULL; } PS(id) = PS(mod)->s_create_sid((void **)&data); diff --git a/ext/session/session.c b/ext/session/session.c index ba71d709a536..6380505ae951 100644 --- a/ext/session/session.c +++ b/ext/session/session.c @@ -443,6 +443,7 @@ static zend_result php_session_initialize(void) /* {{{ */ if (!PS(id) || !ZSTR_VAL(PS(id))[0]) { if (PS(id)) { zend_string_release_ex(PS(id), 0); + PS(id) = NULL; } PS(id) = PS(mod)->s_create_sid(&PS(mod_data)); if (!PS(id)) { @@ -460,6 +461,7 @@ static zend_result php_session_initialize(void) /* {{{ */ ) { if (PS(id)) { zend_string_release_ex(PS(id), 0); + PS(id) = NULL; } PS(id) = PS(mod)->s_create_sid(&PS(mod_data)); if (!PS(id)) { @@ -2440,6 +2442,7 @@ PHP_FUNCTION(session_regenerate_id) /* Try to generate non-existing ID */ while (limit-- && PS(mod)->s_validate_sid(&PS(mod_data), PS(id)) == SUCCESS) { zend_string_release_ex(PS(id), 0); + PS(id) = NULL; PS(id) = PS(mod)->s_create_sid(&PS(mod_data)); if (!PS(id)) { PS(mod)->s_close(&PS(mod_data)); diff --git a/ext/session/tests/user_session_module/gh23043.phpt b/ext/session/tests/user_session_module/gh23043.phpt new file mode 100644 index 000000000000..e3528884a79a --- /dev/null +++ b/ext/session/tests/user_session_module/gh23043.phpt @@ -0,0 +1,35 @@ +--TEST-- +GH-23043 (broken session id code can cause zend_mm_heap corrupted) +--EXTENSIONS-- +session +--CREDITS-- +lmaltsis +--FILE-- + +--EXPECTF-- +string(0) "" + +Warning: SessionHandler::write(): Session ID is too long or contains illegal characters. Only the A-Z, a-z, 0-9, "-", and "," characters are allowed in %s on line %d + +Warning: session_write_close(): Failed to write session data using user defined save handler. (session.save_path: , handler: a::write) in %s on line %d +string(0) "" + +Warning: SessionHandler::write(): Session ID is too long or contains illegal characters. Only the A-Z, a-z, 0-9, "-", and "," characters are allowed in Unknown on line 0 + +Warning: session_write_close(): Failed to write session data using user defined save handler. (session.save_path: , handler: a::write) in Unknown on line 0 diff --git a/ext/simplexml/simplexml.c b/ext/simplexml/simplexml.c index 8cf8e657e58f..b3266f813975 100644 --- a/ext/simplexml/simplexml.c +++ b/ext/simplexml/simplexml.c @@ -1229,6 +1229,12 @@ static int sxe_objects_compare(zval *object1, zval *object2) /* {{{ */ if (sxe1->node == NULL && sxe2->node == NULL) { /* Both nodes not set: Only support equality comparison between documents. */ + if (sxe1->document == NULL || sxe2->document == NULL) { + if (sxe1->document == sxe2->document) { + return 0; + } + return ZEND_UNCOMPARABLE; + } if (sxe1->document->ptr == sxe2->document->ptr) { return 0; } diff --git a/ext/simplexml/tests/bug_sxe_compare_uninitialized.phpt b/ext/simplexml/tests/bug_sxe_compare_uninitialized.phpt new file mode 100644 index 000000000000..742761eed6c0 --- /dev/null +++ b/ext/simplexml/tests/bug_sxe_compare_uninitialized.phpt @@ -0,0 +1,25 @@ +--TEST-- +Comparing uninitialized SimpleXMLElement instances must not segfault +--EXTENSIONS-- +simplexml +--FILE-- +'); +echo "uninit vs init: "; +var_dump($a == $c); +echo "done\n"; +?> +--EXPECT-- +equal: bool(true) +identical: bool(false) +uninit vs init: bool(false) +done diff --git a/ext/standard/tests/mail/bug80751.phpt b/ext/standard/tests/mail/bug80751.phpt index b6dc29e42f14..802bd542482d 100644 --- a/ext/standard/tests/mail/bug80751.phpt +++ b/ext/standard/tests/mail/bug80751.phpt @@ -48,7 +48,7 @@ foreach (['to' => $to, 'cc' => $cc, 'bcc' => $bcc] as $recipient => $mailAddress echo "Found the email. {$recipient} received.\n"; } - if ($mail->getHeader('Return-Path') === $from) { + if ($mail->getHeader('Return-Path') === "<{$from}>") { echo "Return-Path is as expected.\n"; }