mirror of
https://github.com/php/php-src.git
synced 2026-04-20 22:41:20 +02:00
This patch adds missing newlines, trims multiple redundant final newlines into a single one, and trims redundant leading newlines in all *.phpt sections. According to POSIX, a line is a sequence of zero or more non-' <newline>' characters plus a terminating '<newline>' character. [1] Files should normally have at least one final newline character. C89 [2] and later standards [3] mention a final newline: "A source file that is not empty shall end in a new-line character, which shall not be immediately preceded by a backslash character." Although it is not mandatory for all files to have a final newline fixed, a more consistent and homogeneous approach brings less of commit differences issues and a better development experience in certain text editors and IDEs. [1] http://pubs.opengroup.org/onlinepubs/9699919799/basedefs/V1_chap03.html#tag_03_206 [2] https://port70.net/~nsz/c/c89/c89-draft.html#2.1.1.2 [3] https://port70.net/~nsz/c/c99/n1256.html#5.1.1.2
27 lines
628 B
PHP
27 lines
628 B
PHP
--TEST--
|
|
Bug #70741 (Session WDDX Packet Deserialization Type Confusion Vulnerability)
|
|
--SKIPIF--
|
|
<?php
|
|
if (!extension_loaded("wddx")) print "skip";
|
|
if (!extension_loaded("session")) print "skip session extension not available";
|
|
?>
|
|
--FILE--
|
|
<?php
|
|
ini_set('session.serialize_handler', 'wddx');
|
|
session_start();
|
|
|
|
$hashtable = str_repeat('A', 66);
|
|
$wddx = "<?xml version='1.0'?>
|
|
<wddxPacket version='1.0'>
|
|
<header/>
|
|
<data>
|
|
<string>$hashtable</string>
|
|
</data>
|
|
</wddxPacket>";
|
|
session_decode($wddx);
|
|
?>
|
|
DONE
|
|
--EXPECTF--
|
|
Warning: session_decode(): Failed to decode session object. Session has been destroyed in %s on line %d
|
|
DONE
|