php_variables.c 26 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590591592593594595596597598599600601602603604605606607608609610611612613614615616617618619620621622623624625626627628629630631632633634635636637638639640641642643644645646647648649650651652653654655656657658659660661662663664665666667668669670671672673674675676677678679680681682683684685686687688689690691692693694695696697698699700701702703704705706707708709710711712713714715716717718719720721722723724725726727728729730731732733734735736737738739740741742743744745746747748749750751752753754755756757758759760761762763764765766767768769770771772773774775776777778779780781782783784785786787788789790791792793794795796797798799800801802803804805806807808809810811812813814815816817818819820821822823824825826827828829830831832833834835836837838839840841842843844845846847848849850851852853854855856857858859860861862863864865866867868869870871872873874875876877878879880881882883884885886887888889890891892893894895896897898899900901902903904905906907908909910911912913914915916917918919920921922923924925926927928929930931932933934935936937938939940941942943944945946947948949950951952953954955
  1. /*
  2. +----------------------------------------------------------------------+
  3. | PHP Version 5 |
  4. +----------------------------------------------------------------------+
  5. | Copyright (c) 1997-2016 The PHP Group |
  6. +----------------------------------------------------------------------+
  7. | This source file is subject to version 3.01 of the PHP license, |
  8. | that is bundled with this package in the file LICENSE, and is |
  9. | available through the world-wide-web at the following url: |
  10. | http://www.php.net/license/3_01.txt |
  11. | If you did not receive a copy of the PHP license and are unable to |
  12. | obtain it through the world-wide-web, please send a note to |
  13. | license@php.net so we can mail you a copy immediately. |
  14. +----------------------------------------------------------------------+
  15. | Authors: Rasmus Lerdorf <rasmus@lerdorf.on.ca> |
  16. | Zeev Suraski <zeev@zend.com> |
  17. +----------------------------------------------------------------------+
  18. */
  19. /* $Id$ */
  20. #include <stdio.h>
  21. #include "php.h"
  22. #include "ext/standard/php_standard.h"
  23. #include "ext/standard/credits.h"
  24. #include "ext/standard/php_smart_str.h"
  25. #include "php_variables.h"
  26. #include "php_globals.h"
  27. #include "php_content_types.h"
  28. #include "SAPI.h"
  29. #include "zend_globals.h"
  30. #ifdef PHP_WIN32
  31. # include "win32/php_inttypes.h"
  32. #endif
  33. /* for systems that need to override reading of environment variables */
  34. void _php_import_environment_variables(zval *array_ptr TSRMLS_DC);
  35. PHPAPI void (*php_import_environment_variables)(zval *array_ptr TSRMLS_DC) = _php_import_environment_variables;
  36. PHPAPI void php_register_variable(char *var, char *strval, zval *track_vars_array TSRMLS_DC)
  37. {
  38. php_register_variable_safe(var, strval, strlen(strval), track_vars_array TSRMLS_CC);
  39. }
  40. /* binary-safe version */
  41. PHPAPI void php_register_variable_safe(char *var, char *strval, int str_len, zval *track_vars_array TSRMLS_DC)
  42. {
  43. zval new_entry;
  44. assert(strval != NULL);
  45. /* Prepare value */
  46. Z_STRLEN(new_entry) = str_len;
  47. Z_STRVAL(new_entry) = estrndup(strval, Z_STRLEN(new_entry));
  48. Z_TYPE(new_entry) = IS_STRING;
  49. php_register_variable_ex(var, &new_entry, track_vars_array TSRMLS_CC);
  50. }
  51. PHPAPI void php_register_variable_ex(char *var_name, zval *val, zval *track_vars_array TSRMLS_DC)
  52. {
  53. char *p = NULL;
  54. char *ip = NULL; /* index pointer */
  55. char *index;
  56. char *var, *var_orig;
  57. int var_len, index_len;
  58. zval *gpc_element, **gpc_element_p;
  59. zend_bool is_array = 0;
  60. HashTable *symtable1 = NULL;
  61. ALLOCA_FLAG(use_heap)
  62. assert(var_name != NULL);
  63. if (track_vars_array) {
  64. symtable1 = Z_ARRVAL_P(track_vars_array);
  65. }
  66. if (!symtable1) {
  67. /* Nothing to do */
  68. zval_dtor(val);
  69. return;
  70. }
  71. /* ignore leading spaces in the variable name */
  72. while (*var_name && *var_name==' ') {
  73. var_name++;
  74. }
  75. /*
  76. * Prepare variable name
  77. */
  78. var_len = strlen(var_name);
  79. var = var_orig = do_alloca(var_len + 1, use_heap);
  80. memcpy(var_orig, var_name, var_len + 1);
  81. /* ensure that we don't have spaces or dots in the variable name (not binary safe) */
  82. for (p = var; *p; p++) {
  83. if (*p == ' ' || *p == '.') {
  84. *p='_';
  85. } else if (*p == '[') {
  86. is_array = 1;
  87. ip = p;
  88. *p = 0;
  89. break;
  90. }
  91. }
  92. var_len = p - var;
  93. if (var_len==0) { /* empty variable name, or variable name with a space in it */
  94. zval_dtor(val);
  95. free_alloca(var_orig, use_heap);
  96. return;
  97. }
  98. /* GLOBALS hijack attempt, reject parameter */
  99. if (symtable1 == EG(active_symbol_table) &&
  100. var_len == sizeof("GLOBALS")-1 &&
  101. !memcmp(var, "GLOBALS", sizeof("GLOBALS")-1)) {
  102. zval_dtor(val);
  103. free_alloca(var_orig, use_heap);
  104. return;
  105. }
  106. index = var;
  107. index_len = var_len;
  108. if (is_array) {
  109. int nest_level = 0;
  110. while (1) {
  111. char *index_s;
  112. int new_idx_len = 0;
  113. if(++nest_level > PG(max_input_nesting_level)) {
  114. HashTable *ht;
  115. /* too many levels of nesting */
  116. if (track_vars_array) {
  117. ht = Z_ARRVAL_P(track_vars_array);
  118. zend_symtable_del(ht, var, var_len + 1);
  119. }
  120. zval_dtor(val);
  121. /* do not output the error message to the screen,
  122. this helps us to to avoid "information disclosure" */
  123. if (!PG(display_errors)) {
  124. php_error_docref(NULL TSRMLS_CC, E_WARNING, "Input variable nesting level exceeded %ld. To increase the limit change max_input_nesting_level in php.ini.", PG(max_input_nesting_level));
  125. }
  126. free_alloca(var_orig, use_heap);
  127. return;
  128. }
  129. ip++;
  130. index_s = ip;
  131. if (isspace(*ip)) {
  132. ip++;
  133. }
  134. if (*ip==']') {
  135. index_s = NULL;
  136. } else {
  137. ip = strchr(ip, ']');
  138. if (!ip) {
  139. /* PHP variables cannot contain '[' in their names, so we replace the character with a '_' */
  140. *(index_s - 1) = '_';
  141. index_len = 0;
  142. if (index) {
  143. index_len = strlen(index);
  144. }
  145. goto plain_var;
  146. return;
  147. }
  148. *ip = 0;
  149. new_idx_len = strlen(index_s);
  150. }
  151. if (!index) {
  152. MAKE_STD_ZVAL(gpc_element);
  153. array_init(gpc_element);
  154. if (zend_hash_next_index_insert(symtable1, &gpc_element, sizeof(zval *), (void **) &gpc_element_p) == FAILURE) {
  155. zval_ptr_dtor(&gpc_element);
  156. zval_dtor(val);
  157. free_alloca(var_orig, use_heap);
  158. return;
  159. }
  160. } else {
  161. if (zend_symtable_find(symtable1, index, index_len + 1, (void **) &gpc_element_p) == FAILURE
  162. || Z_TYPE_PP(gpc_element_p) != IS_ARRAY) {
  163. MAKE_STD_ZVAL(gpc_element);
  164. array_init(gpc_element);
  165. zend_symtable_update(symtable1, index, index_len + 1, &gpc_element, sizeof(zval *), (void **) &gpc_element_p);
  166. }
  167. }
  168. symtable1 = Z_ARRVAL_PP(gpc_element_p);
  169. /* ip pointed to the '[' character, now obtain the key */
  170. index = index_s;
  171. index_len = new_idx_len;
  172. ip++;
  173. if (*ip == '[') {
  174. is_array = 1;
  175. *ip = 0;
  176. } else {
  177. goto plain_var;
  178. }
  179. }
  180. } else {
  181. plain_var:
  182. MAKE_STD_ZVAL(gpc_element);
  183. gpc_element->value = val->value;
  184. Z_TYPE_P(gpc_element) = Z_TYPE_P(val);
  185. if (!index) {
  186. if (zend_hash_next_index_insert(symtable1, &gpc_element, sizeof(zval *), (void **) &gpc_element_p) == FAILURE) {
  187. zval_ptr_dtor(&gpc_element);
  188. }
  189. } else {
  190. /*
  191. * According to rfc2965, more specific paths are listed above the less specific ones.
  192. * If we encounter a duplicate cookie name, we should skip it, since it is not possible
  193. * to have the same (plain text) cookie name for the same path and we should not overwrite
  194. * more specific cookies with the less specific ones.
  195. */
  196. if (PG(http_globals)[TRACK_VARS_COOKIE] &&
  197. symtable1 == Z_ARRVAL_P(PG(http_globals)[TRACK_VARS_COOKIE]) &&
  198. zend_symtable_exists(symtable1, index, index_len + 1)) {
  199. zval_ptr_dtor(&gpc_element);
  200. } else {
  201. zend_symtable_update(symtable1, index, index_len + 1, &gpc_element, sizeof(zval *), (void **) &gpc_element_p);
  202. }
  203. }
  204. }
  205. free_alloca(var_orig, use_heap);
  206. }
  207. typedef struct post_var_data {
  208. smart_str str;
  209. char *ptr;
  210. char *end;
  211. uint64_t cnt;
  212. /* Bytes in ptr that have already been scanned for '&' */
  213. size_t already_scanned;
  214. } post_var_data_t;
  215. static zend_bool add_post_var(zval *arr, post_var_data_t *var, zend_bool eof TSRMLS_DC)
  216. {
  217. char *start, *ksep, *vsep, *val;
  218. size_t klen, vlen;
  219. /* FIXME: string-size_t */
  220. unsigned int new_vlen;
  221. if (var->ptr >= var->end) {
  222. return 0;
  223. }
  224. start = var->ptr + var->already_scanned;
  225. vsep = memchr(start, '&', var->end - start);
  226. if (!vsep) {
  227. if (!eof) {
  228. var->already_scanned = var->end - var->ptr;
  229. return 0;
  230. } else {
  231. vsep = var->end;
  232. }
  233. }
  234. ksep = memchr(var->ptr, '=', vsep - var->ptr);
  235. if (ksep) {
  236. *ksep = '\0';
  237. /* "foo=bar&" or "foo=&" */
  238. klen = ksep - var->ptr;
  239. vlen = vsep - ++ksep;
  240. } else {
  241. ksep = "";
  242. /* "foo&" */
  243. klen = vsep - var->ptr;
  244. vlen = 0;
  245. }
  246. php_url_decode(var->ptr, klen);
  247. val = estrndup(ksep, vlen);
  248. if (vlen) {
  249. vlen = php_url_decode(val, vlen);
  250. }
  251. if (sapi_module.input_filter(PARSE_POST, var->ptr, &val, vlen, &new_vlen TSRMLS_CC)) {
  252. php_register_variable_safe(var->ptr, val, new_vlen, arr TSRMLS_CC);
  253. }
  254. efree(val);
  255. var->ptr = vsep + (vsep != var->end);
  256. var->already_scanned = 0;
  257. return 1;
  258. }
  259. static inline int add_post_vars(zval *arr, post_var_data_t *vars, zend_bool eof TSRMLS_DC)
  260. {
  261. uint64_t max_vars = PG(max_input_vars);
  262. vars->ptr = vars->str.c;
  263. vars->end = vars->str.c + vars->str.len;
  264. while (add_post_var(arr, vars, eof TSRMLS_CC)) {
  265. if (++vars->cnt > max_vars) {
  266. php_error_docref(NULL TSRMLS_CC, E_WARNING,
  267. "Input variables exceeded %" PRIu64 ". "
  268. "To increase the limit change max_input_vars in php.ini.",
  269. max_vars);
  270. return FAILURE;
  271. }
  272. }
  273. if (!eof && vars->str.c != vars->ptr) {
  274. memmove(vars->str.c, vars->ptr, vars->str.len = vars->end - vars->ptr);
  275. }
  276. return SUCCESS;
  277. }
  278. #ifdef PHP_WIN32
  279. #define SAPI_POST_HANDLER_BUFSIZ 16384
  280. #else
  281. # define SAPI_POST_HANDLER_BUFSIZ BUFSIZ
  282. #endif
  283. SAPI_API SAPI_POST_HANDLER_FUNC(php_std_post_handler)
  284. {
  285. zval *arr = (zval *) arg;
  286. php_stream *s = SG(request_info).request_body;
  287. post_var_data_t post_data;
  288. if (s && SUCCESS == php_stream_rewind(s)) {
  289. memset(&post_data, 0, sizeof(post_data));
  290. while (!php_stream_eof(s)) {
  291. char buf[SAPI_POST_HANDLER_BUFSIZ] = {0};
  292. size_t len = php_stream_read(s, buf, SAPI_POST_HANDLER_BUFSIZ);
  293. if (len && len != (size_t) -1) {
  294. smart_str_appendl(&post_data.str, buf, len);
  295. if (SUCCESS != add_post_vars(arr, &post_data, 0 TSRMLS_CC)) {
  296. if (post_data.str.c) {
  297. efree(post_data.str.c);
  298. }
  299. return;
  300. }
  301. }
  302. if (len != SAPI_POST_HANDLER_BUFSIZ){
  303. break;
  304. }
  305. }
  306. add_post_vars(arr, &post_data, 1 TSRMLS_CC);
  307. if (post_data.str.c) {
  308. efree(post_data.str.c);
  309. }
  310. }
  311. }
  312. #undef SAPI_POST_HANDLER_BUFSIZ
  313. SAPI_API SAPI_INPUT_FILTER_FUNC(php_default_input_filter)
  314. {
  315. /* TODO: check .ini setting here and apply user-defined input filter */
  316. if(new_val_len) *new_val_len = val_len;
  317. return 1;
  318. }
  319. SAPI_API SAPI_TREAT_DATA_FUNC(php_default_treat_data)
  320. {
  321. char *res = NULL, *var, *val, *separator = NULL;
  322. const char *c_var;
  323. zval *array_ptr;
  324. int free_buffer = 0;
  325. char *strtok_buf = NULL;
  326. long count = 0;
  327. switch (arg) {
  328. case PARSE_POST:
  329. case PARSE_GET:
  330. case PARSE_COOKIE:
  331. ALLOC_ZVAL(array_ptr);
  332. array_init(array_ptr);
  333. INIT_PZVAL(array_ptr);
  334. switch (arg) {
  335. case PARSE_POST:
  336. if (PG(http_globals)[TRACK_VARS_POST]) {
  337. zval_ptr_dtor(&PG(http_globals)[TRACK_VARS_POST]);
  338. }
  339. PG(http_globals)[TRACK_VARS_POST] = array_ptr;
  340. break;
  341. case PARSE_GET:
  342. if (PG(http_globals)[TRACK_VARS_GET]) {
  343. zval_ptr_dtor(&PG(http_globals)[TRACK_VARS_GET]);
  344. }
  345. PG(http_globals)[TRACK_VARS_GET] = array_ptr;
  346. break;
  347. case PARSE_COOKIE:
  348. if (PG(http_globals)[TRACK_VARS_COOKIE]) {
  349. zval_ptr_dtor(&PG(http_globals)[TRACK_VARS_COOKIE]);
  350. }
  351. PG(http_globals)[TRACK_VARS_COOKIE] = array_ptr;
  352. break;
  353. }
  354. break;
  355. default:
  356. array_ptr = destArray;
  357. break;
  358. }
  359. if (arg == PARSE_POST) {
  360. sapi_handle_post(array_ptr TSRMLS_CC);
  361. return;
  362. }
  363. if (arg == PARSE_GET) { /* GET data */
  364. c_var = SG(request_info).query_string;
  365. if (c_var && *c_var) {
  366. res = (char *) estrdup(c_var);
  367. free_buffer = 1;
  368. } else {
  369. free_buffer = 0;
  370. }
  371. } else if (arg == PARSE_COOKIE) { /* Cookie data */
  372. c_var = SG(request_info).cookie_data;
  373. if (c_var && *c_var) {
  374. res = (char *) estrdup(c_var);
  375. free_buffer = 1;
  376. } else {
  377. free_buffer = 0;
  378. }
  379. } else if (arg == PARSE_STRING) { /* String data */
  380. res = str;
  381. free_buffer = 1;
  382. }
  383. if (!res) {
  384. return;
  385. }
  386. switch (arg) {
  387. case PARSE_GET:
  388. case PARSE_STRING:
  389. separator = (char *) estrdup(PG(arg_separator).input);
  390. break;
  391. case PARSE_COOKIE:
  392. separator = ";\0";
  393. break;
  394. }
  395. var = php_strtok_r(res, separator, &strtok_buf);
  396. while (var) {
  397. val = strchr(var, '=');
  398. if (arg == PARSE_COOKIE) {
  399. /* Remove leading spaces from cookie names, needed for multi-cookie header where ; can be followed by a space */
  400. while (isspace(*var)) {
  401. var++;
  402. }
  403. if (var == val || *var == '\0') {
  404. goto next_cookie;
  405. }
  406. }
  407. if (++count > PG(max_input_vars)) {
  408. php_error_docref(NULL TSRMLS_CC, E_WARNING, "Input variables exceeded %ld. To increase the limit change max_input_vars in php.ini.", PG(max_input_vars));
  409. break;
  410. }
  411. if (val) { /* have a value */
  412. int val_len;
  413. unsigned int new_val_len;
  414. *val++ = '\0';
  415. php_url_decode(var, strlen(var));
  416. val_len = php_url_decode(val, strlen(val));
  417. val = estrndup(val, val_len);
  418. if (sapi_module.input_filter(arg, var, &val, val_len, &new_val_len TSRMLS_CC)) {
  419. php_register_variable_safe(var, val, new_val_len, array_ptr TSRMLS_CC);
  420. }
  421. efree(val);
  422. } else {
  423. int val_len;
  424. unsigned int new_val_len;
  425. php_url_decode(var, strlen(var));
  426. val_len = 0;
  427. val = estrndup("", val_len);
  428. if (sapi_module.input_filter(arg, var, &val, val_len, &new_val_len TSRMLS_CC)) {
  429. php_register_variable_safe(var, val, new_val_len, array_ptr TSRMLS_CC);
  430. }
  431. efree(val);
  432. }
  433. next_cookie:
  434. var = php_strtok_r(NULL, separator, &strtok_buf);
  435. }
  436. if (arg != PARSE_COOKIE) {
  437. efree(separator);
  438. }
  439. if (free_buffer) {
  440. efree(res);
  441. }
  442. }
  443. void _php_import_environment_variables(zval *array_ptr TSRMLS_DC)
  444. {
  445. char buf[128];
  446. char **env, *p, *t = buf;
  447. size_t alloc_size = sizeof(buf);
  448. unsigned long nlen; /* ptrdiff_t is not portable */
  449. for (env = environ; env != NULL && *env != NULL; env++) {
  450. p = strchr(*env, '=');
  451. if (!p) { /* malformed entry? */
  452. continue;
  453. }
  454. nlen = p - *env;
  455. if (nlen >= alloc_size) {
  456. alloc_size = nlen + 64;
  457. t = (t == buf ? emalloc(alloc_size): erealloc(t, alloc_size));
  458. }
  459. memcpy(t, *env, nlen);
  460. t[nlen] = '\0';
  461. php_register_variable(t, p + 1, array_ptr TSRMLS_CC);
  462. }
  463. if (t != buf && t != NULL) {
  464. efree(t);
  465. }
  466. }
  467. zend_bool php_std_auto_global_callback(char *name, uint name_len TSRMLS_DC)
  468. {
  469. zend_printf("%s\n", name);
  470. return 0; /* don't rearm */
  471. }
  472. /* {{{ php_build_argv
  473. */
  474. static void php_build_argv(char *s, zval *track_vars_array TSRMLS_DC)
  475. {
  476. zval *arr, *argc, *tmp;
  477. int count = 0;
  478. char *ss, *space;
  479. if (!(SG(request_info).argc || track_vars_array)) {
  480. return;
  481. }
  482. ALLOC_INIT_ZVAL(arr);
  483. array_init(arr);
  484. /* Prepare argv */
  485. if (SG(request_info).argc) { /* are we in cli sapi? */
  486. int i;
  487. for (i = 0; i < SG(request_info).argc; i++) {
  488. ALLOC_ZVAL(tmp);
  489. Z_TYPE_P(tmp) = IS_STRING;
  490. Z_STRLEN_P(tmp) = strlen(SG(request_info).argv[i]);
  491. Z_STRVAL_P(tmp) = estrndup(SG(request_info).argv[i], Z_STRLEN_P(tmp));
  492. INIT_PZVAL(tmp);
  493. if (zend_hash_next_index_insert(Z_ARRVAL_P(arr), &tmp, sizeof(zval *), NULL) == FAILURE) {
  494. if (Z_TYPE_P(tmp) == IS_STRING) {
  495. efree(Z_STRVAL_P(tmp));
  496. }
  497. }
  498. }
  499. } else if (s && *s) {
  500. ss = s;
  501. while (ss) {
  502. space = strchr(ss, '+');
  503. if (space) {
  504. *space = '\0';
  505. }
  506. /* auto-type */
  507. ALLOC_ZVAL(tmp);
  508. Z_TYPE_P(tmp) = IS_STRING;
  509. Z_STRLEN_P(tmp) = strlen(ss);
  510. Z_STRVAL_P(tmp) = estrndup(ss, Z_STRLEN_P(tmp));
  511. INIT_PZVAL(tmp);
  512. count++;
  513. if (zend_hash_next_index_insert(Z_ARRVAL_P(arr), &tmp, sizeof(zval *), NULL) == FAILURE) {
  514. if (Z_TYPE_P(tmp) == IS_STRING) {
  515. efree(Z_STRVAL_P(tmp));
  516. }
  517. }
  518. if (space) {
  519. *space = '+';
  520. ss = space + 1;
  521. } else {
  522. ss = space;
  523. }
  524. }
  525. }
  526. /* prepare argc */
  527. ALLOC_INIT_ZVAL(argc);
  528. if (SG(request_info).argc) {
  529. Z_LVAL_P(argc) = SG(request_info).argc;
  530. } else {
  531. Z_LVAL_P(argc) = count;
  532. }
  533. Z_TYPE_P(argc) = IS_LONG;
  534. if (SG(request_info).argc) {
  535. Z_ADDREF_P(arr);
  536. Z_ADDREF_P(argc);
  537. zend_hash_update(&EG(symbol_table), "argv", sizeof("argv"), &arr, sizeof(zval *), NULL);
  538. zend_hash_update(&EG(symbol_table), "argc", sizeof("argc"), &argc, sizeof(zval *), NULL);
  539. }
  540. if (track_vars_array) {
  541. Z_ADDREF_P(arr);
  542. Z_ADDREF_P(argc);
  543. zend_hash_update(Z_ARRVAL_P(track_vars_array), "argv", sizeof("argv"), &arr, sizeof(zval *), NULL);
  544. zend_hash_update(Z_ARRVAL_P(track_vars_array), "argc", sizeof("argc"), &argc, sizeof(zval *), NULL);
  545. }
  546. zval_ptr_dtor(&arr);
  547. zval_ptr_dtor(&argc);
  548. }
  549. /* }}} */
  550. /* {{{ php_register_server_variables
  551. */
  552. static inline void php_register_server_variables(TSRMLS_D)
  553. {
  554. zval *array_ptr = NULL;
  555. ALLOC_ZVAL(array_ptr);
  556. array_init(array_ptr);
  557. INIT_PZVAL(array_ptr);
  558. if (PG(http_globals)[TRACK_VARS_SERVER]) {
  559. zval_ptr_dtor(&PG(http_globals)[TRACK_VARS_SERVER]);
  560. }
  561. PG(http_globals)[TRACK_VARS_SERVER] = array_ptr;
  562. /* Server variables */
  563. if (sapi_module.register_server_variables) {
  564. sapi_module.register_server_variables(array_ptr TSRMLS_CC);
  565. }
  566. /* PHP Authentication support */
  567. if (SG(request_info).auth_user) {
  568. php_register_variable("PHP_AUTH_USER", SG(request_info).auth_user, array_ptr TSRMLS_CC);
  569. }
  570. if (SG(request_info).auth_password) {
  571. php_register_variable("PHP_AUTH_PW", SG(request_info).auth_password, array_ptr TSRMLS_CC);
  572. }
  573. if (SG(request_info).auth_digest) {
  574. php_register_variable("PHP_AUTH_DIGEST", SG(request_info).auth_digest, array_ptr TSRMLS_CC);
  575. }
  576. /* store request init time */
  577. {
  578. zval request_time_float, request_time_long;
  579. Z_TYPE(request_time_float) = IS_DOUBLE;
  580. Z_DVAL(request_time_float) = sapi_get_request_time(TSRMLS_C);
  581. php_register_variable_ex("REQUEST_TIME_FLOAT", &request_time_float, array_ptr TSRMLS_CC);
  582. Z_TYPE(request_time_long) = IS_LONG;
  583. Z_LVAL(request_time_long) = zend_dval_to_lval(Z_DVAL(request_time_float));
  584. php_register_variable_ex("REQUEST_TIME", &request_time_long, array_ptr TSRMLS_CC);
  585. }
  586. }
  587. /* }}} */
  588. /* {{{ php_autoglobal_merge
  589. */
  590. static void php_autoglobal_merge(HashTable *dest, HashTable *src TSRMLS_DC)
  591. {
  592. zval **src_entry, **dest_entry;
  593. char *string_key;
  594. uint string_key_len;
  595. ulong num_key;
  596. HashPosition pos;
  597. int key_type;
  598. int globals_check = (dest == (&EG(symbol_table)));
  599. zend_hash_internal_pointer_reset_ex(src, &pos);
  600. while (zend_hash_get_current_data_ex(src, (void **)&src_entry, &pos) == SUCCESS) {
  601. key_type = zend_hash_get_current_key_ex(src, &string_key, &string_key_len, &num_key, 0, &pos);
  602. if (Z_TYPE_PP(src_entry) != IS_ARRAY
  603. || (key_type == HASH_KEY_IS_STRING && zend_hash_find(dest, string_key, string_key_len, (void **) &dest_entry) != SUCCESS)
  604. || (key_type == HASH_KEY_IS_LONG && zend_hash_index_find(dest, num_key, (void **)&dest_entry) != SUCCESS)
  605. || Z_TYPE_PP(dest_entry) != IS_ARRAY
  606. ) {
  607. Z_ADDREF_PP(src_entry);
  608. if (key_type == HASH_KEY_IS_STRING) {
  609. if (!globals_check || string_key_len != sizeof("GLOBALS") || memcmp(string_key, "GLOBALS", sizeof("GLOBALS") - 1)) {
  610. zend_hash_update(dest, string_key, string_key_len, src_entry, sizeof(zval *), NULL);
  611. } else {
  612. Z_DELREF_PP(src_entry);
  613. }
  614. } else {
  615. zend_hash_index_update(dest, num_key, src_entry, sizeof(zval *), NULL);
  616. }
  617. } else {
  618. SEPARATE_ZVAL(dest_entry);
  619. php_autoglobal_merge(Z_ARRVAL_PP(dest_entry), Z_ARRVAL_PP(src_entry) TSRMLS_CC);
  620. }
  621. zend_hash_move_forward_ex(src, &pos);
  622. }
  623. }
  624. /* }}} */
  625. static zend_bool php_auto_globals_create_server(const char *name, uint name_len TSRMLS_DC);
  626. static zend_bool php_auto_globals_create_env(const char *name, uint name_len TSRMLS_DC);
  627. static zend_bool php_auto_globals_create_request(const char *name, uint name_len TSRMLS_DC);
  628. /* {{{ php_hash_environment
  629. */
  630. PHPAPI int php_hash_environment(TSRMLS_D)
  631. {
  632. memset(PG(http_globals), 0, sizeof(PG(http_globals)));
  633. zend_activate_auto_globals(TSRMLS_C);
  634. if (PG(register_argc_argv)) {
  635. php_build_argv(SG(request_info).query_string, PG(http_globals)[TRACK_VARS_SERVER] TSRMLS_CC);
  636. }
  637. return SUCCESS;
  638. }
  639. /* }}} */
  640. static zend_bool php_auto_globals_create_get(const char *name, uint name_len TSRMLS_DC)
  641. {
  642. zval *vars;
  643. if (PG(variables_order) && (strchr(PG(variables_order),'G') || strchr(PG(variables_order),'g'))) {
  644. sapi_module.treat_data(PARSE_GET, NULL, NULL TSRMLS_CC);
  645. vars = PG(http_globals)[TRACK_VARS_GET];
  646. } else {
  647. ALLOC_ZVAL(vars);
  648. array_init(vars);
  649. INIT_PZVAL(vars);
  650. if (PG(http_globals)[TRACK_VARS_GET]) {
  651. zval_ptr_dtor(&PG(http_globals)[TRACK_VARS_GET]);
  652. }
  653. PG(http_globals)[TRACK_VARS_GET] = vars;
  654. }
  655. zend_hash_update(&EG(symbol_table), name, name_len + 1, &vars, sizeof(zval *), NULL);
  656. Z_ADDREF_P(vars);
  657. return 0; /* don't rearm */
  658. }
  659. static zend_bool php_auto_globals_create_post(const char *name, uint name_len TSRMLS_DC)
  660. {
  661. zval *vars;
  662. if (PG(variables_order) &&
  663. (strchr(PG(variables_order),'P') || strchr(PG(variables_order),'p')) &&
  664. SG(request_info).request_method &&
  665. !strcasecmp(SG(request_info).request_method, "POST")) {
  666. sapi_module.treat_data(PARSE_POST, NULL, NULL TSRMLS_CC);
  667. vars = PG(http_globals)[TRACK_VARS_POST];
  668. } else {
  669. ALLOC_ZVAL(vars);
  670. array_init(vars);
  671. INIT_PZVAL(vars);
  672. if (PG(http_globals)[TRACK_VARS_POST]) {
  673. zval_ptr_dtor(&PG(http_globals)[TRACK_VARS_POST]);
  674. }
  675. PG(http_globals)[TRACK_VARS_POST] = vars;
  676. }
  677. zend_hash_update(&EG(symbol_table), name, name_len + 1, &vars, sizeof(zval *), NULL);
  678. Z_ADDREF_P(vars);
  679. return 0; /* don't rearm */
  680. }
  681. static zend_bool php_auto_globals_create_cookie(const char *name, uint name_len TSRMLS_DC)
  682. {
  683. zval *vars;
  684. if (PG(variables_order) && (strchr(PG(variables_order),'C') || strchr(PG(variables_order),'c'))) {
  685. sapi_module.treat_data(PARSE_COOKIE, NULL, NULL TSRMLS_CC);
  686. vars = PG(http_globals)[TRACK_VARS_COOKIE];
  687. } else {
  688. ALLOC_ZVAL(vars);
  689. array_init(vars);
  690. INIT_PZVAL(vars);
  691. if (PG(http_globals)[TRACK_VARS_COOKIE]) {
  692. zval_ptr_dtor(&PG(http_globals)[TRACK_VARS_COOKIE]);
  693. }
  694. PG(http_globals)[TRACK_VARS_COOKIE] = vars;
  695. }
  696. zend_hash_update(&EG(symbol_table), name, name_len + 1, &vars, sizeof(zval *), NULL);
  697. Z_ADDREF_P(vars);
  698. return 0; /* don't rearm */
  699. }
  700. static zend_bool php_auto_globals_create_files(const char *name, uint name_len TSRMLS_DC)
  701. {
  702. zval *vars;
  703. if (PG(http_globals)[TRACK_VARS_FILES]) {
  704. vars = PG(http_globals)[TRACK_VARS_FILES];
  705. } else {
  706. ALLOC_ZVAL(vars);
  707. array_init(vars);
  708. INIT_PZVAL(vars);
  709. PG(http_globals)[TRACK_VARS_FILES] = vars;
  710. }
  711. zend_hash_update(&EG(symbol_table), name, name_len + 1, &vars, sizeof(zval *), NULL);
  712. Z_ADDREF_P(vars);
  713. return 0; /* don't rearm */
  714. }
  715. /* Upgly hack to fix HTTP_PROXY issue, see bug #72573 */
  716. static void check_http_proxy(HashTable *var_table)
  717. {
  718. if (zend_hash_exists(var_table, "HTTP_PROXY", sizeof("HTTP_PROXY"))) {
  719. char *local_proxy = getenv("HTTP_PROXY");
  720. if (!local_proxy) {
  721. zend_hash_del(var_table, "HTTP_PROXY", sizeof("HTTP_PROXY"));
  722. } else {
  723. zval *local_zval;
  724. ALLOC_INIT_ZVAL(local_zval);
  725. ZVAL_STRING(local_zval, local_proxy, 1);
  726. zend_hash_update(var_table, "HTTP_PROXY", sizeof("HTTP_PROXY"), &local_zval, sizeof(zval **), NULL);
  727. }
  728. }
  729. }
  730. static zend_bool php_auto_globals_create_server(const char *name, uint name_len TSRMLS_DC)
  731. {
  732. if (PG(variables_order) && (strchr(PG(variables_order),'S') || strchr(PG(variables_order),'s'))) {
  733. php_register_server_variables(TSRMLS_C);
  734. if (PG(register_argc_argv)) {
  735. if (SG(request_info).argc) {
  736. zval **argc, **argv;
  737. if (zend_hash_find(&EG(symbol_table), "argc", sizeof("argc"), (void**)&argc) == SUCCESS &&
  738. zend_hash_find(&EG(symbol_table), "argv", sizeof("argv"), (void**)&argv) == SUCCESS) {
  739. Z_ADDREF_PP(argc);
  740. Z_ADDREF_PP(argv);
  741. zend_hash_update(Z_ARRVAL_P(PG(http_globals)[TRACK_VARS_SERVER]), "argv", sizeof("argv"), argv, sizeof(zval *), NULL);
  742. zend_hash_update(Z_ARRVAL_P(PG(http_globals)[TRACK_VARS_SERVER]), "argc", sizeof("argc"), argc, sizeof(zval *), NULL);
  743. }
  744. } else {
  745. php_build_argv(SG(request_info).query_string, PG(http_globals)[TRACK_VARS_SERVER] TSRMLS_CC);
  746. }
  747. }
  748. } else {
  749. zval *server_vars=NULL;
  750. ALLOC_ZVAL(server_vars);
  751. array_init(server_vars);
  752. INIT_PZVAL(server_vars);
  753. if (PG(http_globals)[TRACK_VARS_SERVER]) {
  754. zval_ptr_dtor(&PG(http_globals)[TRACK_VARS_SERVER]);
  755. }
  756. PG(http_globals)[TRACK_VARS_SERVER] = server_vars;
  757. }
  758. check_http_proxy(Z_ARRVAL_P(PG(http_globals)[TRACK_VARS_SERVER]));
  759. zend_hash_update(&EG(symbol_table), name, name_len + 1, &PG(http_globals)[TRACK_VARS_SERVER], sizeof(zval *), NULL);
  760. Z_ADDREF_P(PG(http_globals)[TRACK_VARS_SERVER]);
  761. return 0; /* don't rearm */
  762. }
  763. static zend_bool php_auto_globals_create_env(const char *name, uint name_len TSRMLS_DC)
  764. {
  765. zval *env_vars = NULL;
  766. ALLOC_ZVAL(env_vars);
  767. array_init(env_vars);
  768. INIT_PZVAL(env_vars);
  769. if (PG(http_globals)[TRACK_VARS_ENV]) {
  770. zval_ptr_dtor(&PG(http_globals)[TRACK_VARS_ENV]);
  771. }
  772. PG(http_globals)[TRACK_VARS_ENV] = env_vars;
  773. if (PG(variables_order) && (strchr(PG(variables_order),'E') || strchr(PG(variables_order),'e'))) {
  774. php_import_environment_variables(PG(http_globals)[TRACK_VARS_ENV] TSRMLS_CC);
  775. }
  776. check_http_proxy(Z_ARRVAL_P(PG(http_globals)[TRACK_VARS_ENV]));
  777. zend_hash_update(&EG(symbol_table), name, name_len + 1, &PG(http_globals)[TRACK_VARS_ENV], sizeof(zval *), NULL);
  778. Z_ADDREF_P(PG(http_globals)[TRACK_VARS_ENV]);
  779. return 0; /* don't rearm */
  780. }
  781. static zend_bool php_auto_globals_create_request(const char *name, uint name_len TSRMLS_DC)
  782. {
  783. zval *form_variables;
  784. unsigned char _gpc_flags[3] = {0, 0, 0};
  785. char *p;
  786. ALLOC_ZVAL(form_variables);
  787. array_init(form_variables);
  788. INIT_PZVAL(form_variables);
  789. if (PG(request_order) != NULL) {
  790. p = PG(request_order);
  791. } else {
  792. p = PG(variables_order);
  793. }
  794. for (; p && *p; p++) {
  795. switch (*p) {
  796. case 'g':
  797. case 'G':
  798. if (!_gpc_flags[0]) {
  799. php_autoglobal_merge(Z_ARRVAL_P(form_variables), Z_ARRVAL_P(PG(http_globals)[TRACK_VARS_GET]) TSRMLS_CC);
  800. _gpc_flags[0] = 1;
  801. }
  802. break;
  803. case 'p':
  804. case 'P':
  805. if (!_gpc_flags[1]) {
  806. php_autoglobal_merge(Z_ARRVAL_P(form_variables), Z_ARRVAL_P(PG(http_globals)[TRACK_VARS_POST]) TSRMLS_CC);
  807. _gpc_flags[1] = 1;
  808. }
  809. break;
  810. case 'c':
  811. case 'C':
  812. if (!_gpc_flags[2]) {
  813. php_autoglobal_merge(Z_ARRVAL_P(form_variables), Z_ARRVAL_P(PG(http_globals)[TRACK_VARS_COOKIE]) TSRMLS_CC);
  814. _gpc_flags[2] = 1;
  815. }
  816. break;
  817. }
  818. }
  819. zend_hash_update(&EG(symbol_table), name, name_len + 1, &form_variables, sizeof(zval *), NULL);
  820. return 0;
  821. }
  822. void php_startup_auto_globals(TSRMLS_D)
  823. {
  824. zend_register_auto_global(ZEND_STRL("_GET"), 0, php_auto_globals_create_get TSRMLS_CC);
  825. zend_register_auto_global(ZEND_STRL("_POST"), 0, php_auto_globals_create_post TSRMLS_CC);
  826. zend_register_auto_global(ZEND_STRL("_COOKIE"), 0, php_auto_globals_create_cookie TSRMLS_CC);
  827. zend_register_auto_global(ZEND_STRL("_SERVER"), PG(auto_globals_jit), php_auto_globals_create_server TSRMLS_CC);
  828. zend_register_auto_global(ZEND_STRL("_ENV"), PG(auto_globals_jit), php_auto_globals_create_env TSRMLS_CC);
  829. zend_register_auto_global(ZEND_STRL("_REQUEST"), PG(auto_globals_jit), php_auto_globals_create_request TSRMLS_CC);
  830. zend_register_auto_global(ZEND_STRL("_FILES"), 0, php_auto_globals_create_files TSRMLS_CC);
  831. }
  832. /*
  833. * Local variables:
  834. * tab-width: 4
  835. * c-basic-offset: 4
  836. * End:
  837. * vim600: sw=4 ts=4 fdm=marker
  838. * vim<600: sw=4 ts=4
  839. */