Skip to content

Commit e5751dd

Browse files
committed
ext/soap: fix use of uninitialized func in do_request() on OOM bailout.
Follow-up to GH-22592: an OOM while copying the trace request or allocating the __doRequest function name leaves func uninitialized before the cleanup path destroys it. Also backport the GH-22585 test.
1 parent 3f3499f commit e5751dd

2 files changed

Lines changed: 40 additions & 0 deletions

File tree

‎ext/soap/soap.c‎

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -2240,6 +2240,7 @@ static bool do_request(zval *this_ptr, xmlDoc *request, const char *location, co
22402240
return false;
22412241
}
22422242

2243+
ZVAL_UNDEF(&func);
22432244
ZVAL_UNDEF(&params[0]);
22442245
ZVAL_UNDEF(&params[1]);
22452246
ZVAL_UNDEF(&params[2]);

‎ext/soap/tests/gh22585.phpt‎

Lines changed: 39 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,39 @@
1+
--TEST--
2+
GH-22585 (Use of uninitialized params in do_request() on out-of-memory bailout)
3+
--EXTENSIONS--
4+
soap
5+
--INI--
6+
soap.wsdl_cache_enabled=0
7+
memory_limit=64M
8+
--FILE--
9+
<?php
10+
/* Deep recursion that keeps issuing SOAP calls until memory is exhausted while
11+
* do_request() is only part-way through initializing its params array. The
12+
* cleanup path must not touch the uninitialized slots. Depending on the
13+
* environment the run ends either by the recursion limit (reaching "Done") or
14+
* by the memory-exhaustion fatal; both are fine, a crash/UB abort is not. */
15+
try {
16+
class MySoapClient extends SoapClient {
17+
public function __doRequest($request, $location, $action, $version, $one_way = false, ?string $uriParserClass = null): string {
18+
return '';
19+
}
20+
}
21+
22+
function main() {
23+
for (;;) {
24+
$soap = new MySoapClient(
25+
null,
26+
['location' => "http://localhost/soap.php", 'uri' => "http://localhost/"]
27+
);
28+
$soap->call(1.1);
29+
main();
30+
}
31+
}
32+
33+
main();
34+
} catch (\Throwable $e) {
35+
}
36+
echo "Done" . PHP_EOL;
37+
?>
38+
--EXPECTREGEX--
39+
(?s)(Done|.*Allowed memory size of \d+ bytes exhausted.*)

0 commit comments

Comments
 (0)