Coverage Report

Created: 2025-12-14 06:09

next uncovered line (L), next uncovered region (R), next uncovered branch (B)
/src/php-src/Zend/zend_property_hooks.c
Line
Count
Source
1
/*
2
   +----------------------------------------------------------------------+
3
   | Zend Engine                                                          |
4
   +----------------------------------------------------------------------+
5
   | Copyright (c) Zend Technologies Ltd. (http://www.zend.com)           |
6
   +----------------------------------------------------------------------+
7
   | This source file is subject to version 2.00 of the Zend license,     |
8
   | that is bundled with this package in the file LICENSE, and is        |
9
   | available through the world-wide-web at the following url:           |
10
   | http://www.zend.com/license/2_00.txt.                                |
11
   | If you did not receive a copy of the Zend license and are unable to  |
12
   | obtain it through the world-wide-web, please send a note to          |
13
   | license@zend.com so we can mail you a copy immediately.              |
14
   +----------------------------------------------------------------------+
15
   | Authors: Ilija Tovilo <ilutov@php.net>                               |
16
   +----------------------------------------------------------------------+
17
*/
18
19
#include "zend.h"
20
#include "zend_API.h"
21
#include "zend_hash.h"
22
#include "zend_lazy_objects.h"
23
#include "zend_property_hooks.h"
24
25
typedef struct {
26
  zend_object_iterator it;
27
  bool by_ref;
28
  bool declared_props_done;
29
  zval declared_props;
30
  bool dynamic_props_done;
31
  uint32_t dynamic_prop_offset;
32
  uint32_t dynamic_prop_it;
33
  zval current_key;
34
  zval current_data;
35
} zend_hooked_object_iterator;
36
37
static zend_result zho_it_valid(zend_object_iterator *iter);
38
static void zho_it_move_forward(zend_object_iterator *iter);
39
40
static uint32_t zho_find_dynamic_prop_offset(zend_array *properties)
41
142
{
42
142
  uint32_t offset = 0;
43
142
  zval *value;
44
45
1.06k
  ZEND_HASH_MAP_FOREACH_VAL(properties, value) {
46
1.06k
    if (Z_TYPE_P(value) != IS_INDIRECT) {
47
82
      break;
48
82
    }
49
272
    offset++;
50
272
  } ZEND_HASH_FOREACH_END();
51
52
142
  return offset;
53
142
}
54
55
static zend_array *zho_build_properties_ex(zend_object *zobj, bool check_access, bool force_ptr, bool include_dynamic_props)
56
260
{
57
260
  zend_class_entry *ce = zobj->ce;
58
260
  zend_array *properties = zend_new_array(include_dynamic_props && zobj->properties
59
260
    ? zend_hash_num_elements(zobj->properties)
60
260
    : ce->default_properties_count);
61
260
  zend_hash_real_init_mixed(properties);
62
63
  /* Build list of parents */
64
260
  int32_t parent_count = 0;
65
600
  for (zend_class_entry *pce = ce; pce; pce = pce->parent) {
66
340
    parent_count++;
67
340
  }
68
260
  zend_class_entry **parents = emalloc(sizeof(zend_class_entry*) * parent_count);
69
260
  int32_t i = 0;
70
600
  for (zend_class_entry *pce = ce; pce; pce = pce->parent) {
71
340
    parents[i++] = pce;
72
340
  }
73
74
  /* Iterate parents top to bottom */
75
260
  i--;
76
600
  for (; i >= 0; i--) {
77
340
    zend_class_entry *pce = parents[i];
78
79
340
    zend_property_info *prop_info;
80
3.39k
    ZEND_HASH_MAP_FOREACH_PTR(&pce->properties_info, prop_info) {
81
3.39k
      if (prop_info->flags & ZEND_ACC_STATIC) {
82
0
        continue;
83
0
      }
84
1.35k
      zend_string *property_name = prop_info->name;
85
      /* When promoting properties from protected to public, use the unmangled name to preserve order. */
86
1.35k
      if (prop_info->flags & ZEND_ACC_PROTECTED) {
87
6
        const char *tmp = zend_get_unmangled_property_name(property_name);
88
6
        zend_string *unmangled_name = zend_string_init(tmp, strlen(tmp), false);
89
6
        zend_property_info *child_prop_info = zend_hash_find_ptr(&ce->properties_info, unmangled_name);
90
6
        if (child_prop_info && (child_prop_info->flags & ZEND_ACC_PUBLIC)) {
91
2
          property_name = unmangled_name;
92
4
        } else {
93
4
          zend_string_release(unmangled_name);
94
4
        }
95
6
      }
96
1.35k
      if (check_access && zend_check_property_access(zobj, property_name, false) == FAILURE) {
97
130
        goto skip_property;
98
130
      }
99
1.22k
      if (prop_info->hooks || force_ptr) {
100
1.11k
        zend_hash_update_ptr(properties, property_name, prop_info);
101
1.11k
      } else {
102
116
        if (UNEXPECTED(Z_TYPE_P(OBJ_PROP(zobj, prop_info->offset)) == IS_UNDEF)) {
103
66
          HT_FLAGS(properties) |= HASH_FLAG_HAS_EMPTY_IND;
104
66
        }
105
116
        zval *tmp = zend_hash_lookup(properties, property_name);
106
116
        ZVAL_INDIRECT(tmp, OBJ_PROP(zobj, prop_info->offset));
107
116
      }
108
1.35k
skip_property:
109
1.35k
      if (property_name != prop_info->name) {
110
2
        zend_string_release(property_name);
111
2
      }
112
1.35k
    } ZEND_HASH_FOREACH_END();
113
340
  }
114
115
260
  efree(parents);
116
117
260
  if (include_dynamic_props && zobj->properties) {
118
114
    zend_string *prop_name;
119
114
    zval *prop_value;
120
1.01k
    ZEND_HASH_FOREACH_STR_KEY_VAL(zobj->properties, prop_name, prop_value) {
121
1.01k
      if (Z_TYPE_P(prop_value) == IS_INDIRECT) {
122
436
        continue;
123
436
      }
124
12
      zval *tmp = _zend_hash_append(properties, prop_name, prop_value);
125
12
      Z_TRY_ADDREF_P(tmp);
126
12
    } ZEND_HASH_FOREACH_END();
127
114
  }
128
129
260
  return properties;
130
260
}
131
132
ZEND_API zend_array *zend_hooked_object_build_properties(zend_object *zobj)
133
132
{
134
132
  if (UNEXPECTED(zend_lazy_object_must_init(zobj))) {
135
24
    zobj = zend_lazy_object_init(zobj);
136
24
    if (UNEXPECTED(!zobj)) {
137
14
      return (zend_array*) &zend_empty_array;
138
14
    }
139
24
  }
140
141
118
  return zho_build_properties_ex(zobj, false, false, true);
142
132
}
143
144
static void zho_dynamic_it_init(zend_hooked_object_iterator *hooked_iter)
145
142
{
146
142
  zend_object *zobj = Z_OBJ_P(&hooked_iter->it.data);
147
142
  zend_array *properties = zobj->handlers->get_properties(zobj);
148
142
  hooked_iter->dynamic_props_done = false;
149
142
  hooked_iter->dynamic_prop_offset = zho_find_dynamic_prop_offset(properties);
150
142
  hooked_iter->dynamic_prop_it = zend_hash_iterator_add(properties, hooked_iter->dynamic_prop_offset);
151
142
}
152
153
static void zho_it_get_current_key(zend_object_iterator *iter, zval *key);
154
155
static void zho_declared_it_fetch_current(zend_object_iterator *iter)
156
292
{
157
292
  zend_hooked_object_iterator *hooked_iter = (zend_hooked_object_iterator*)iter;
158
292
  zend_object *zobj = Z_OBJ_P(&iter->data);
159
292
  zend_array *properties = Z_ARR(hooked_iter->declared_props);
160
161
292
  zend_property_info *prop_info = Z_PTR_P(zend_hash_get_current_data(properties));
162
292
  if (prop_info->hooks) {
163
158
    zend_function *get = prop_info->hooks[ZEND_PROPERTY_HOOK_GET];
164
158
    if (!get && (prop_info->flags & ZEND_ACC_VIRTUAL)) {
165
10
      return;
166
10
    }
167
148
    if (hooked_iter->by_ref
168
68
     && (get == NULL
169
68
      || !(get->common.fn_flags & ZEND_ACC_RETURN_REFERENCE))) {
170
2
      zend_throw_error(NULL, "Cannot create reference to property %s::$%s",
171
2
        ZSTR_VAL(zobj->ce->name), zend_get_unmangled_property_name(prop_info->name));
172
2
      return;
173
2
    }
174
146
    zend_string *unmangled_name = prop_info->name;
175
146
    if (ZSTR_VAL(unmangled_name)[0] == '\0') {
176
4
      const char *tmp = zend_get_unmangled_property_name(unmangled_name);
177
4
      unmangled_name = zend_string_init(tmp, strlen(tmp), false);
178
4
    }
179
146
    zval *value = zend_read_property_ex(prop_info->ce, zobj, unmangled_name, /* silent */ true, &hooked_iter->current_data);
180
146
    if (unmangled_name != prop_info->name) {
181
4
      zend_string_release(unmangled_name);
182
4
    }
183
146
    if (value == &EG(uninitialized_zval)) {
184
4
      return;
185
142
    } else if (value != &hooked_iter->current_data) {
186
2
      ZVAL_COPY(&hooked_iter->current_data, value);
187
2
    }
188
146
  } else {
189
134
    zval *property = OBJ_PROP(zobj, prop_info->offset);
190
134
    ZVAL_DEINDIRECT(property);
191
134
    if (Z_TYPE_P(property) == IS_UNDEF) {
192
4
      return;
193
4
    }
194
130
    if (!hooked_iter->by_ref) {
195
64
      ZVAL_DEREF(property);
196
66
    } else if (Z_TYPE_P(property) != IS_REFERENCE) {
197
66
      if (UNEXPECTED(prop_info->flags & ZEND_ACC_READONLY)) {
198
2
        zend_throw_error(NULL,
199
2
          "Cannot acquire reference to readonly property %s::$%s",
200
2
          ZSTR_VAL(prop_info->ce->name), zend_get_unmangled_property_name(prop_info->name));
201
2
        return;
202
2
      }
203
64
      ZVAL_MAKE_REF(property);
204
64
      if (ZEND_TYPE_IS_SET(prop_info->type)) {
205
60
        ZEND_REF_ADD_TYPE_SOURCE(Z_REF_P(property), prop_info);
206
60
      }
207
64
    }
208
128
    ZVAL_COPY(&hooked_iter->current_data, property);
209
128
  }
210
211
270
  if (ZSTR_VAL(prop_info->name)[0] == '\0') {
212
6
    const char *tmp = zend_get_unmangled_property_name(prop_info->name);
213
6
    ZVAL_STR(&hooked_iter->current_key, zend_string_init(tmp, strlen(tmp), false));
214
264
  } else {
215
264
    ZVAL_STR_COPY(&hooked_iter->current_key, prop_info->name);
216
264
  }
217
270
}
218
219
static void zho_dynamic_it_fetch_current(zend_object_iterator *iter)
220
302
{
221
302
  zend_hooked_object_iterator *hooked_iter = (zend_hooked_object_iterator*)iter;
222
302
  zend_array *properties = Z_OBJ(iter->data)->properties;
223
302
  HashPosition pos = zend_hash_iterator_pos(hooked_iter->dynamic_prop_it, properties);
224
225
302
  if (pos >= properties->nNumUsed) {
226
136
    hooked_iter->dynamic_props_done = true;
227
136
    return;
228
136
  }
229
230
166
  Bucket *bucket = properties->arData + pos;
231
232
166
  if (UNEXPECTED(Z_TYPE(bucket->val) == IS_UNDEF)) {
233
70
    return;
234
70
  }
235
236
96
  zend_object *zobj = Z_OBJ_P(&hooked_iter->it.data);
237
96
  if (bucket->key && zend_check_property_access(zobj, bucket->key, true) != SUCCESS) {
238
2
    return;
239
2
  }
240
241
94
  if (hooked_iter->by_ref && Z_TYPE(bucket->val) != IS_REFERENCE) {
242
46
    ZVAL_MAKE_REF(&bucket->val);
243
46
  }
244
94
  ZVAL_COPY(&hooked_iter->current_data, &bucket->val);
245
246
94
  if (bucket->key) {
247
94
    ZVAL_STR_COPY(&hooked_iter->current_key, bucket->key);
248
94
  } else {
249
0
    ZVAL_LONG(&hooked_iter->current_key, bucket->h);
250
0
  }
251
94
}
252
253
static void zho_it_fetch_current(zend_object_iterator *iter)
254
1.23k
{
255
1.23k
  zend_hooked_object_iterator *hooked_iter = (zend_hooked_object_iterator*)iter;
256
1.23k
  if (Z_TYPE(hooked_iter->current_data) != IS_UNDEF) {
257
724
    return;
258
724
  }
259
260
730
  while (true) {
261
730
    if (!hooked_iter->declared_props_done) {
262
292
      zho_declared_it_fetch_current(iter);
263
438
    } else if (!hooked_iter->dynamic_props_done) {
264
302
      zho_dynamic_it_fetch_current(iter);
265
302
    } else {
266
136
      break;
267
136
    }
268
594
    if (Z_TYPE(hooked_iter->current_data) != IS_UNDEF || EG(exception)) {
269
370
      break;
270
370
    }
271
224
    zho_it_move_forward(iter);
272
224
  }
273
506
}
274
275
static void zho_it_dtor(zend_object_iterator *iter)
276
142
{
277
142
  zend_hooked_object_iterator *hooked_iter = (zend_hooked_object_iterator*)iter;
278
142
  zval_ptr_dtor(&iter->data);
279
142
  zval_ptr_dtor(&hooked_iter->declared_props);
280
142
  zval_ptr_dtor_nogc(&hooked_iter->current_key);
281
142
  zval_ptr_dtor(&hooked_iter->current_data);
282
142
  zend_hash_iterator_del(hooked_iter->dynamic_prop_it);
283
142
}
284
285
static zend_result zho_it_valid(zend_object_iterator *iter)
286
506
{
287
506
  zend_hooked_object_iterator *hooked_iter = (zend_hooked_object_iterator*)iter;
288
506
  zho_it_fetch_current(iter);
289
506
  return Z_TYPE(hooked_iter->current_data) != IS_UNDEF ? SUCCESS : FAILURE;
290
506
}
291
292
static zval *zho_it_get_current_data(zend_object_iterator *iter)
293
364
{
294
364
  zend_hooked_object_iterator *hooked_iter = (zend_hooked_object_iterator*)iter;
295
364
  zho_it_fetch_current(iter);
296
364
  return &hooked_iter->current_data;
297
364
}
298
299
static void zho_it_get_current_key(zend_object_iterator *iter, zval *key)
300
360
{
301
360
  zend_hooked_object_iterator *hooked_iter = (zend_hooked_object_iterator*)iter;
302
360
  zho_it_fetch_current(iter);
303
360
  ZVAL_COPY(key, &hooked_iter->current_key);
304
360
}
305
306
static void zho_it_move_forward(zend_object_iterator *iter)
307
588
{
308
588
  zend_hooked_object_iterator *hooked_iter = (zend_hooked_object_iterator*)iter;
309
310
588
  zval_ptr_dtor(&hooked_iter->current_data);
311
588
  ZVAL_UNDEF(&hooked_iter->current_data);
312
588
  zval_ptr_dtor_nogc(&hooked_iter->current_key);
313
588
  ZVAL_UNDEF(&hooked_iter->current_key);
314
315
588
  if (!hooked_iter->declared_props_done) {
316
286
    zend_array *properties = Z_ARR(hooked_iter->declared_props);
317
286
    zend_hash_move_forward(properties);
318
286
    if (zend_hash_has_more_elements(properties) != SUCCESS) {
319
136
      hooked_iter->declared_props_done = true;
320
136
    }
321
302
  } else if (!hooked_iter->dynamic_props_done) {
322
166
    zend_array *properties = Z_OBJ(iter->data)->properties;
323
166
    HashPosition pos = zend_hash_iterator_pos(hooked_iter->dynamic_prop_it, properties);
324
166
    pos++;
325
166
    EG(ht_iterators)[hooked_iter->dynamic_prop_it].pos = pos;
326
166
  }
327
588
}
328
329
static void zho_it_rewind(zend_object_iterator *iter)
330
142
{
331
142
  zend_hooked_object_iterator *hooked_iter = (zend_hooked_object_iterator*)iter;
332
333
142
  zval_ptr_dtor(&hooked_iter->current_data);
334
142
  ZVAL_UNDEF(&hooked_iter->current_data);
335
142
  zval_ptr_dtor_nogc(&hooked_iter->current_key);
336
142
  ZVAL_UNDEF(&hooked_iter->current_key);
337
338
142
  zend_array *properties = Z_ARR(hooked_iter->declared_props);
339
142
  zend_hash_internal_pointer_reset(properties);
340
142
  hooked_iter->declared_props_done = !zend_hash_num_elements(properties);
341
142
  hooked_iter->dynamic_props_done = false;
342
142
  EG(ht_iterators)[hooked_iter->dynamic_prop_it].pos = hooked_iter->dynamic_prop_offset;
343
142
}
344
345
static HashTable *zho_it_get_gc(zend_object_iterator *iter, zval **table, int *n)
346
0
{
347
0
  zend_hooked_object_iterator *hooked_iter = (zend_hooked_object_iterator*)iter;
348
0
  zend_get_gc_buffer *gc_buffer = zend_get_gc_buffer_create();
349
0
  zend_get_gc_buffer_add_zval(gc_buffer, &iter->data);
350
0
  zend_get_gc_buffer_add_zval(gc_buffer, &hooked_iter->declared_props);
351
0
  zend_get_gc_buffer_add_zval(gc_buffer, &hooked_iter->current_data);
352
0
  zend_get_gc_buffer_use(gc_buffer, table, n);
353
0
  return NULL;
354
0
}
355
356
static const zend_object_iterator_funcs zend_hooked_object_it_funcs = {
357
  zho_it_dtor,
358
  zho_it_valid,
359
  zho_it_get_current_data,
360
  zho_it_get_current_key,
361
  zho_it_move_forward,
362
  zho_it_rewind,
363
  NULL,
364
  zho_it_get_gc,
365
};
366
367
ZEND_API zend_object_iterator *zend_hooked_object_get_iterator(zend_class_entry *ce, zval *object, int by_ref)
368
144
{
369
144
  zend_object *zobj = Z_OBJ_P(object);
370
144
  if (UNEXPECTED(zend_lazy_object_must_init(zobj))) {
371
94
    zobj = zend_lazy_object_init(zobj);
372
94
    if (UNEXPECTED(!zobj)) {
373
2
      return NULL;
374
2
    }
375
94
  }
376
377
142
  zend_hooked_object_iterator *iterator = emalloc(sizeof(zend_hooked_object_iterator));
378
142
  zend_iterator_init(&iterator->it);
379
380
142
  ZVAL_OBJ_COPY(&iterator->it.data, zobj);
381
142
  iterator->it.funcs = &zend_hooked_object_it_funcs;
382
142
  iterator->by_ref = by_ref;
383
142
  zend_array *properties = zho_build_properties_ex(zobj, true, true, false);
384
142
  ZVAL_ARR(&iterator->declared_props, properties);
385
142
  iterator->declared_props_done = !zend_hash_num_elements(properties);
386
142
  zho_dynamic_it_init(iterator);
387
142
  ZVAL_UNDEF(&iterator->current_key);
388
142
  ZVAL_UNDEF(&iterator->current_data);
389
390
142
  return &iterator->it;
391
144
}