f3124d
From 3c3ff434329d2f505b00a79bacfdef95ca96f0d2 Mon Sep 17 00:00:00 2001
f3124d
From: krakjoe <joe.watkins@live.co.uk>
f3124d
Date: Wed, 1 Jan 2014 12:58:18 +0000
f3124d
Subject: [PATCH] fix #66375 bad logic in sapi header callback routine
f3124d
f3124d
---
f3124d
 main/SAPI.c | 43 +++++++++++++++++++++++++------------------
f3124d
 1 file changed, 25 insertions(+), 18 deletions(-)
f3124d
f3124d
diff --git a/main/SAPI.c b/main/SAPI.c
f3124d
index dcb2da6..9ffc258 100644
f3124d
--- a/main/SAPI.c
f3124d
+++ b/main/SAPI.c
f3124d
@@ -137,6 +137,7 @@ PHP_FUNCTION(header_register_callback)
f3124d
 		efree(callback_name);
f3124d
 		RETURN_FALSE;
f3124d
 	}
f3124d
+
f3124d
 	efree(callback_name);
f3124d
 
f3124d
 	if (SG(callback_func)) {
f3124d
@@ -144,10 +145,10 @@ PHP_FUNCTION(header_register_callback)
f3124d
 		SG(fci_cache) = empty_fcall_info_cache;
f3124d
 	}
f3124d
 
f3124d
-	Z_ADDREF_P(callback_func);
f3124d
-
f3124d
 	SG(callback_func) = callback_func;
f3124d
-	
f3124d
+
f3124d
+	Z_ADDREF_P(SG(callback_func));
f3124d
+
f3124d
 	RETURN_TRUE;
f3124d
 }
f3124d
 /* }}} */
f3124d
@@ -156,24 +157,30 @@ static void sapi_run_header_callback(TSRMLS_D)
f3124d
 {
f3124d
 	int   error;
f3124d
 	zend_fcall_info fci;
f3124d
+	char *callback_name = NULL;
f3124d
+	char *callback_error = NULL;
f3124d
 	zval *retval_ptr = NULL;
f3124d
-
f3124d
-	fci.size = sizeof(fci);
f3124d
-	fci.function_table = EG(function_table);
f3124d
-	fci.object_ptr = NULL;
f3124d
-	fci.function_name = SG(callback_func);
f3124d
-	fci.retval_ptr_ptr = &retval_ptr;
f3124d
-	fci.param_count = 0;
f3124d
-	fci.params = NULL;
f3124d
-	fci.no_separation = 0;
f3124d
-	fci.symbol_table = NULL;
f3124d
-
f3124d
-	error = zend_call_function(&fci, &SG(fci_cache) TSRMLS_CC);
f3124d
-	if (error == FAILURE) {
f3124d
+	
f3124d
+	if (zend_fcall_info_init(SG(callback_func), 0, &fci, &SG(fci_cache), &callback_name, &callback_error TSRMLS_CC) == SUCCESS) {
f3124d
+		fci.retval_ptr_ptr = &retval_ptr;
f3124d
+		
f3124d
+		error = zend_call_function(&fci, &SG(fci_cache) TSRMLS_CC);
f3124d
+		if (error == FAILURE) {
f3124d
+			goto callback_failed;
f3124d
+		} else if (retval_ptr) {
f3124d
+			zval_ptr_dtor(&retval_ptr);
f3124d
+		}
f3124d
+	} else {
f3124d
+callback_failed:
f3124d
 		php_error_docref(NULL TSRMLS_CC, E_WARNING, "Could not call the sapi_header_callback");
f3124d
-	} else if (retval_ptr) {
f3124d
-		zval_ptr_dtor(&retval_ptr);
f3124d
 	}
f3124d
+	
f3124d
+	if (callback_name) {
f3124d
+		efree(callback_name);
f3124d
+	}
f3124d
+	if (callback_error) {
f3124d
+		efree(callback_error);
f3124d
+	}	
f3124d
 }
f3124d
 
f3124d
 SAPI_API void sapi_handle_post(void *arg TSRMLS_DC)
f3124d
-- 
f3124d
2.1.4
f3124d