Skip to content

Commit c2c01ae

Browse files
committed
Fix heap over-read in cli_get_prompt() for empty cli.prompt
The prompt parser ran as a do-while, so an empty cli.prompt executed the body on the terminator and scanned past it. Use a while loop and smart_str_extract(), which returns the interned empty string when nothing was appended. No regression test: extra unicode warnings from the over-read depend on heap contents, so a .phpt cannot pin the bug red-before. Closes GH-23415
1 parent 4e64a26 commit c2c01ae

2 files changed

Lines changed: 8 additions & 4 deletions

File tree

‎NEWS‎

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -38,6 +38,10 @@ PHP NEWS
3838
. Fixed PDOStatement::getColumnMeta() reading out of bounds for an invalid
3939
column index. (Ilia Alshanetsky)
4040

41+
- Readline:
42+
. Fixed a heap over-read in the interactive shell prompt when cli.prompt is
43+
set to an empty string. (Ilia Alshanetsky)
44+
4145
- Sockets:
4246
. Fixed socket_select() silently truncating sets larger than FD_SETSIZE on
4347
Windows. (David Carlier)

‎ext/readline/readline_cli.c‎

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -130,7 +130,7 @@ static zend_string *cli_get_prompt(char *block, char prompt) /* {{{ */
130130
char *prompt_spec = CLIR_G(prompt) ? CLIR_G(prompt) : DEFAULT_PROMPT;
131131
bool unicode_warned = false;
132132

133-
do {
133+
while (*prompt_spec) {
134134
if (*prompt_spec == '\\') {
135135
switch (prompt_spec[1]) {
136136
case '\\':
@@ -198,9 +198,9 @@ static zend_string *cli_get_prompt(char *block, char prompt) /* {{{ */
198198
smart_str_appendc(&retval, '?');
199199
}
200200
}
201-
} while (++prompt_spec && *prompt_spec);
202-
smart_str_0(&retval);
203-
return retval.s;
201+
++prompt_spec;
202+
}
203+
return smart_str_extract(&retval);
204204
}
205205
/* }}} */
206206

0 commit comments

Comments
 (0)