Coverage Report

Created: 2026-06-02 06:37

next uncovered line (L), next uncovered region (R), next uncovered branch (B)
/src/php-src/Zend/zend_string.c
Line
Count
Source
1
/*
2
   +----------------------------------------------------------------------+
3
   | Zend Engine                                                          |
4
   +----------------------------------------------------------------------+
5
   | Copyright © Zend Technologies Ltd., a subsidiary company of          |
6
   |     Perforce Software, Inc., and Contributors.                       |
7
   +----------------------------------------------------------------------+
8
   | This source file is subject to the Modified BSD License that is      |
9
   | bundled with this package in the file LICENSE, and is available      |
10
   | through the World Wide Web at <https://www.php.net/license/>.        |
11
   |                                                                      |
12
   | SPDX-License-Identifier: BSD-3-Clause                                |
13
   +----------------------------------------------------------------------+
14
   | Authors: Dmitry Stogov <dmitry@php.net>                              |
15
   +----------------------------------------------------------------------+
16
*/
17
18
#include "zend.h"
19
#include "zend_globals.h"
20
#include "zend_multiply.h"
21
22
#ifdef HAVE_VALGRIND
23
# include "valgrind/callgrind.h"
24
#endif
25
26
#if __has_feature(memory_sanitizer)
27
# include <sanitizer/msan_interface.h>
28
#endif
29
30
ZEND_API zend_new_interned_string_func_t zend_new_interned_string;
31
ZEND_API zend_string_init_interned_func_t zend_string_init_interned;
32
ZEND_API zend_string_init_existing_interned_func_t zend_string_init_existing_interned;
33
34
static zend_string* ZEND_FASTCALL zend_new_interned_string_permanent(zend_string *str);
35
static zend_string* ZEND_FASTCALL zend_new_interned_string_request(zend_string *str);
36
static zend_string* ZEND_FASTCALL zend_string_init_interned_permanent(const char *str, size_t size, bool permanent);
37
static zend_string* ZEND_FASTCALL zend_string_init_existing_interned_permanent(const char *str, size_t size, bool permanent);
38
static zend_string* ZEND_FASTCALL zend_string_init_interned_request(const char *str, size_t size, bool permanent);
39
static zend_string* ZEND_FASTCALL zend_string_init_existing_interned_request(const char *str, size_t size, bool permanent);
40
41
/* Any strings interned in the startup phase. Common to all the threads,
42
   won't be free'd until process exit. If we want an ability to
43
   add permanent strings even after startup, it would be still
44
   possible on costs of locking in the thread safe builds. */
45
static HashTable interned_strings_permanent;
46
47
static zend_new_interned_string_func_t interned_string_request_handler = zend_new_interned_string_request;
48
static zend_string_init_interned_func_t interned_string_init_request_handler = zend_string_init_interned_request;
49
static zend_string_init_existing_interned_func_t interned_string_init_existing_request_handler = zend_string_init_existing_interned_request;
50
51
ZEND_API zend_string  *zend_empty_string = NULL;
52
ZEND_API zend_string  *zend_one_char_string[256];
53
ZEND_API zend_string **zend_known_strings = NULL;
54
55
ZEND_API zend_ulong ZEND_FASTCALL zend_string_hash_func(zend_string *str)
56
776k
{
57
776k
  return ZSTR_H(str) = zend_hash_func(ZSTR_VAL(str), ZSTR_LEN(str));
58
776k
}
59
60
ZEND_API zend_ulong ZEND_FASTCALL zend_hash_func(const char *str, size_t len)
61
882k
{
62
882k
  return zend_inline_hash_func(str, len);
63
882k
}
64
65
static void _str_dtor(zval *zv)
66
0
{
67
0
  zend_string *str = Z_STR_P(zv);
68
0
  pefree(str, GC_FLAGS(str) & IS_STR_PERSISTENT);
69
0
}
70
71
static const char *known_strings[] = {
72
#define _ZEND_STR_DSC(id, str) str,
73
ZEND_KNOWN_STRINGS(_ZEND_STR_DSC)
74
#undef _ZEND_STR_DSC
75
  NULL
76
};
77
78
static zend_always_inline void zend_init_interned_strings_ht(HashTable *interned_strings, bool permanent)
79
38.8k
{
80
38.8k
  zend_hash_init(interned_strings, 1024, NULL, _str_dtor, permanent);
81
38.8k
  if (permanent) {
82
2
    zend_hash_real_init_mixed(interned_strings);
83
2
  }
84
38.8k
}
85
86
ZEND_API void zend_interned_strings_init(void)
87
2
{
88
2
  char s[2];
89
90
2
  interned_string_request_handler = zend_new_interned_string_request;
91
2
  interned_string_init_request_handler = zend_string_init_interned_request;
92
2
  interned_string_init_existing_request_handler = zend_string_init_existing_interned_request;
93
94
2
  zend_empty_string = NULL;
95
2
  zend_known_strings = NULL;
96
97
2
  zend_init_interned_strings_ht(&interned_strings_permanent, true);
98
99
2
  zend_new_interned_string = zend_new_interned_string_permanent;
100
2
  zend_string_init_interned = zend_string_init_interned_permanent;
101
2
  zend_string_init_existing_interned = zend_string_init_existing_interned_permanent;
102
103
  /* interned empty string */
104
2
  zend_empty_string = zend_string_init_interned_permanent("", 0, true);
105
2
  GC_ADD_FLAGS(zend_empty_string, IS_STR_VALID_UTF8);
106
107
2
  s[1] = 0;
108
514
  for (size_t i = 0; i < 256; i++) {
109
512
    s[0] = i;
110
512
    zend_one_char_string[i] = zend_string_init_interned_permanent(s, 1, true);
111
512
    if (i < 0x80) {
112
256
      GC_ADD_FLAGS(zend_one_char_string[i], IS_STR_VALID_UTF8);
113
256
    }
114
512
  }
115
116
  /* known strings */
117
2
  zend_known_strings = pemalloc(sizeof(zend_string*) * ((sizeof(known_strings) / sizeof(known_strings[0]) - 1)), 1);
118
180
  for (size_t i = 0; i < (sizeof(known_strings) / sizeof(known_strings[0])) - 1; i++) {
119
178
    zend_known_strings[i] = zend_string_init_interned_permanent(known_strings[i], strlen(known_strings[i]), true);
120
178
    GC_ADD_FLAGS(zend_known_strings[i], IS_STR_VALID_UTF8);
121
178
  }
122
2
}
123
124
ZEND_API void zend_interned_strings_dtor(void)
125
0
{
126
0
  zend_hash_destroy(&interned_strings_permanent);
127
128
0
  free(zend_known_strings);
129
0
  zend_known_strings = NULL;
130
0
}
131
132
static zend_always_inline zend_string *zend_interned_string_ht_lookup_ex(zend_ulong h, const char *str, size_t size, HashTable *interned_strings)
133
13.2k
{
134
13.2k
  uint32_t nIndex;
135
13.2k
  uint32_t idx;
136
13.2k
  Bucket *p;
137
138
13.2k
  nIndex = h | interned_strings->nTableMask;
139
13.2k
  idx = HT_HASH(interned_strings, nIndex);
140
16.8k
  while (idx != HT_INVALID_IDX) {
141
10.0k
    p = HT_HASH_TO_BUCKET(interned_strings, idx);
142
10.0k
    if ((p->h == h) && zend_string_equals_cstr(p->key, str, size)) {
143
6.53k
      return p->key;
144
6.53k
    }
145
3.54k
    idx = Z_NEXT(p->val);
146
3.54k
  }
147
148
6.73k
  return NULL;
149
13.2k
}
150
151
static zend_always_inline zend_string *zend_interned_string_ht_lookup(zend_string *str, HashTable *interned_strings)
152
1.69k
{
153
1.69k
  zend_ulong h = ZSTR_H(str);
154
1.69k
  uint32_t nIndex;
155
1.69k
  uint32_t idx;
156
1.69k
  Bucket *p;
157
158
1.69k
  nIndex = h | interned_strings->nTableMask;
159
1.69k
  idx = HT_HASH(interned_strings, nIndex);
160
2.21k
  while (idx != HT_INVALID_IDX) {
161
1.09k
    p = HT_HASH_TO_BUCKET(interned_strings, idx);
162
1.09k
    if ((p->h == h) && zend_string_equal_content(p->key, str)) {
163
584
      return p->key;
164
584
    }
165
514
    idx = Z_NEXT(p->val);
166
514
  }
167
168
1.11k
  return NULL;
169
1.69k
}
170
171
/* This function might be not thread safe at least because it would update the
172
   hash val in the passed string. Be sure it is called in the appropriate context. */
173
static zend_always_inline zend_string *zend_add_interned_string(zend_string *str, HashTable *interned_strings, uint32_t flags)
174
7.84k
{
175
7.84k
  zval val;
176
177
7.84k
  GC_SET_REFCOUNT(str, 1);
178
7.84k
  GC_ADD_FLAGS(str, IS_STR_INTERNED | flags);
179
180
7.84k
  ZVAL_INTERNED_STR(&val, str);
181
182
7.84k
  zend_hash_add_new(interned_strings, str, &val);
183
184
7.84k
  return str;
185
7.84k
}
186
187
ZEND_API zend_string* ZEND_FASTCALL zend_interned_string_find_permanent(zend_string *str)
188
0
{
189
0
  zend_string_hash_val(str);
190
0
  return zend_interned_string_ht_lookup(str, &interned_strings_permanent);
191
0
}
192
193
static zend_string* ZEND_FASTCALL zend_init_string_for_interning(zend_string *str, bool persistent)
194
20
{
195
20
  uint32_t flags = ZSTR_GET_COPYABLE_CONCAT_PROPERTIES(str);
196
20
  zend_ulong h = ZSTR_H(str);
197
20
  zend_string_delref(str);
198
20
  str = zend_string_init(ZSTR_VAL(str), ZSTR_LEN(str), persistent);
199
20
  GC_ADD_FLAGS(str, flags);
200
20
  ZSTR_H(str) = h;
201
20
  return str;
202
20
}
203
204
static zend_string* ZEND_FASTCALL zend_new_interned_string_permanent(zend_string *str)
205
4.11k
{
206
4.11k
  zend_string *ret;
207
208
4.11k
  if (ZSTR_IS_INTERNED(str)) {
209
2.42k
    return str;
210
2.42k
  }
211
212
1.69k
  zend_string_hash_val(str);
213
1.69k
  ret = zend_interned_string_ht_lookup(str, &interned_strings_permanent);
214
1.69k
  if (ret) {
215
584
    zend_string_release(str);
216
584
    return ret;
217
584
  }
218
219
1.11k
  ZEND_ASSERT(GC_FLAGS(str) & GC_PERSISTENT);
220
1.11k
  if (GC_REFCOUNT(str) > 1) {
221
20
    str = zend_init_string_for_interning(str, true);
222
20
  }
223
224
1.11k
  return zend_add_interned_string(str, &interned_strings_permanent, IS_STR_PERMANENT);
225
1.11k
}
226
227
static zend_string* ZEND_FASTCALL zend_new_interned_string_request(zend_string *str)
228
0
{
229
0
  zend_string *ret;
230
231
0
  if (ZSTR_IS_INTERNED(str)) {
232
0
    return str;
233
0
  }
234
235
0
  zend_string_hash_val(str);
236
237
  /* Check for permanent strings, the table is readonly at this point. */
238
0
  ret = zend_interned_string_ht_lookup(str, &interned_strings_permanent);
239
0
  if (ret) {
240
0
    zend_string_release(str);
241
0
    return ret;
242
0
  }
243
244
0
  ret = zend_interned_string_ht_lookup(str, &CG(interned_strings));
245
0
  if (ret) {
246
0
    zend_string_release(str);
247
0
    return ret;
248
0
  }
249
250
  /* Create a short living interned, freed after the request. */
251
#if ZEND_RC_DEBUG
252
  if (zend_rc_debug) {
253
    /* PHP shouldn't create persistent interned string during request,
254
     * but at least dl() may do this */
255
    ZEND_ASSERT(!(GC_FLAGS(str) & GC_PERSISTENT));
256
  }
257
#endif
258
0
  if (GC_REFCOUNT(str) > 1) {
259
0
    str = zend_init_string_for_interning(str, false);
260
0
  }
261
262
0
  ret = zend_add_interned_string(str, &CG(interned_strings), 0);
263
264
0
  return ret;
265
0
}
266
267
static zend_string* ZEND_FASTCALL zend_string_init_interned_permanent(const char *str, size_t size, bool permanent)
268
13.2k
{
269
13.2k
  zend_string *ret;
270
13.2k
  zend_ulong h = zend_inline_hash_func(str, size);
271
272
13.2k
  ret = zend_interned_string_ht_lookup_ex(h, str, size, &interned_strings_permanent);
273
13.2k
  if (ret) {
274
6.53k
    return ret;
275
6.53k
  }
276
277
6.73k
  ZEND_ASSERT(permanent);
278
6.73k
  ret = zend_string_init(str, size, permanent);
279
6.73k
  ZSTR_H(ret) = h;
280
6.73k
  return zend_add_interned_string(ret, &interned_strings_permanent, IS_STR_PERMANENT);
281
6.73k
}
282
283
static zend_string* ZEND_FASTCALL zend_string_init_existing_interned_permanent(const char *str, size_t size, bool permanent)
284
0
{
285
0
  zend_ulong h = zend_inline_hash_func(str, size);
286
0
  zend_string *ret = zend_interned_string_ht_lookup_ex(h, str, size, &interned_strings_permanent);
287
0
  if (ret) {
288
0
    return ret;
289
0
  }
290
291
0
  ZEND_ASSERT(permanent);
292
0
  ret = zend_string_init(str, size, permanent);
293
0
  ZSTR_H(ret) = h;
294
0
  return ret;
295
0
}
296
297
static zend_string* ZEND_FASTCALL zend_string_init_interned_request(const char *str, size_t size, bool permanent)
298
0
{
299
0
  zend_string *ret;
300
0
  zend_ulong h = zend_inline_hash_func(str, size);
301
302
  /* Check for permanent strings, the table is readonly at this point. */
303
0
  ret = zend_interned_string_ht_lookup_ex(h, str, size, &interned_strings_permanent);
304
0
  if (ret) {
305
0
    return ret;
306
0
  }
307
308
0
  ret = zend_interned_string_ht_lookup_ex(h, str, size, &CG(interned_strings));
309
0
  if (ret) {
310
0
    return ret;
311
0
  }
312
313
#if ZEND_RC_DEBUG
314
  if (zend_rc_debug) {
315
    /* PHP shouldn't create persistent interned string during request,
316
     * but at least dl() may do this */
317
    ZEND_ASSERT(!permanent);
318
  }
319
#endif
320
0
  ret = zend_string_init(str, size, permanent);
321
0
  ZSTR_H(ret) = h;
322
323
  /* Create a short living interned, freed after the request. */
324
0
  return zend_add_interned_string(ret, &CG(interned_strings), 0);
325
0
}
326
327
static zend_string* ZEND_FASTCALL zend_string_init_existing_interned_request(const char *str, size_t size, bool permanent)
328
0
{
329
0
  zend_ulong h = zend_inline_hash_func(str, size);
330
0
  zend_string *ret = zend_interned_string_ht_lookup_ex(h, str, size, &interned_strings_permanent);
331
0
  if (ret) {
332
0
    return ret;
333
0
  }
334
335
0
  ret = zend_interned_string_ht_lookup_ex(h, str, size, &CG(interned_strings));
336
0
  if (ret) {
337
0
    return ret;
338
0
  }
339
340
0
  ZEND_ASSERT(!permanent);
341
0
  ret = zend_string_init(str, size, permanent);
342
0
  ZSTR_H(ret) = h;
343
0
  return ret;
344
0
}
345
346
ZEND_API void zend_interned_strings_activate(void)
347
38.8k
{
348
38.8k
  zend_init_interned_strings_ht(&CG(interned_strings), false);
349
38.8k
}
350
351
ZEND_API void zend_interned_strings_deactivate(void)
352
38.8k
{
353
38.8k
  zend_hash_destroy(&CG(interned_strings));
354
38.8k
}
355
356
ZEND_API void zend_interned_strings_set_request_storage_handlers(zend_new_interned_string_func_t handler, zend_string_init_interned_func_t init_handler, zend_string_init_existing_interned_func_t init_existing_handler)
357
2
{
358
2
  interned_string_request_handler = handler;
359
2
  interned_string_init_request_handler = init_handler;
360
2
  interned_string_init_existing_request_handler = init_existing_handler;
361
2
}
362
363
ZEND_API void zend_interned_strings_switch_storage(bool request)
364
2
{
365
2
  if (request) {
366
2
    zend_new_interned_string = interned_string_request_handler;
367
2
    zend_string_init_interned = interned_string_init_request_handler;
368
2
    zend_string_init_existing_interned = interned_string_init_existing_request_handler;
369
2
  } else {
370
0
    zend_new_interned_string = zend_new_interned_string_permanent;
371
0
    zend_string_init_interned = zend_string_init_interned_permanent;
372
0
    zend_string_init_existing_interned = zend_string_init_existing_interned_permanent;
373
0
  }
374
2
}
375
376
#if defined(__GNUC__) && (defined(__i386__) || (defined(__x86_64__) && !defined(__ILP32__)))
377
/* Even if we don't build with valgrind support, include the symbol so that valgrind available
378
 * only at runtime will not result in false positives. */
379
#ifndef I_REPLACE_SONAME_FNNAME_ZU
380
# define I_REPLACE_SONAME_FNNAME_ZU(soname, fnname) _vgr00000ZU_ ## soname ## _ ## fnname
381
#endif
382
383
/* See GH-9068 */
384
#if __has_attribute(noipa)
385
# define NOIPA __attribute__((noipa))
386
#else
387
# define NOIPA
388
#endif
389
390
ZEND_API bool ZEND_FASTCALL I_REPLACE_SONAME_FNNAME_ZU(NONE,zend_string_equal_val)(const zend_string *s1, const zend_string *s2)
391
0
{
392
0
  return !memcmp(ZSTR_VAL(s1), ZSTR_VAL(s2), ZSTR_LEN(s1));
393
0
}
394
#endif
395
396
#if defined(__GNUC__) && defined(__i386__)
397
ZEND_API zend_never_inline NOIPA bool ZEND_FASTCALL zend_string_equal_val(const zend_string *s1, const zend_string *s2)
398
{
399
  const char *ptr = ZSTR_VAL(s1);
400
  uintptr_t delta = (uintptr_t) s2 - (uintptr_t) s1;
401
  size_t len = ZSTR_LEN(s1);
402
  zend_ulong ret;
403
404
  __asm__ (
405
    "0:\n\t"
406
    "movl (%2,%3), %0\n\t"
407
    "xorl (%2), %0\n\t"
408
    "jne 1f\n\t"
409
    "addl $0x4, %2\n\t"
410
    "subl $0x4, %1\n\t"
411
    "ja 0b\n\t"
412
    "movl $0x1, %0\n\t"
413
    "jmp 3f\n\t"
414
    "1:\n\t"
415
    "cmpl $0x4,%1\n\t"
416
    "jb 2f\n\t"
417
    "xorl %0, %0\n\t"
418
    "jmp 3f\n\t"
419
    "2:\n\t"
420
    "negl %1\n\t"
421
    "lea 0x20(,%1,8), %1\n\t"
422
    "shll %b1, %0\n\t"
423
    "sete %b0\n\t"
424
    "movzbl %b0, %0\n\t"
425
    "3:\n"
426
    : "=&a"(ret),
427
      "+c"(len),
428
      "+r"(ptr)
429
    : "r"(delta)
430
    : "cc");
431
  return ret;
432
}
433
434
#elif defined(__GNUC__) && defined(__x86_64__) && !defined(__ILP32__)
435
ZEND_API zend_never_inline NOIPA bool ZEND_FASTCALL zend_string_equal_val(const zend_string *s1, const zend_string *s2)
436
357k
{
437
357k
  const char *ptr = ZSTR_VAL(s1);
438
357k
  uintptr_t delta = (uintptr_t) s2 - (uintptr_t) s1;
439
357k
  size_t len = ZSTR_LEN(s1);
440
357k
  zend_ulong ret;
441
442
357k
  __asm__ (
443
357k
    "0:\n\t"
444
357k
    "movq (%2,%3), %0\n\t"
445
357k
    "xorq (%2), %0\n\t"
446
357k
    "jne 1f\n\t"
447
357k
    "addq $0x8, %2\n\t"
448
357k
    "subq $0x8, %1\n\t"
449
357k
    "ja 0b\n\t"
450
357k
    "movq $0x1, %0\n\t"
451
357k
    "jmp 3f\n\t"
452
357k
    "1:\n\t"
453
357k
    "cmpq $0x8,%1\n\t"
454
357k
    "jb 2f\n\t"
455
357k
    "xorq %0, %0\n\t"
456
357k
    "jmp 3f\n\t"
457
357k
    "2:\n\t"
458
357k
    "negq %1\n\t"
459
357k
    "lea 0x40(,%1,8), %1\n\t"
460
357k
    "shlq %b1, %0\n\t"
461
357k
    "sete %b0\n\t"
462
357k
    "movzbq %b0, %0\n\t"
463
357k
    "3:\n"
464
357k
    : "=&a"(ret),
465
357k
      "+c"(len),
466
357k
      "+r"(ptr)
467
357k
    : "r"(delta)
468
357k
    : "cc");
469
357k
  return ret;
470
357k
}
471
#endif
472
473
ZEND_API zend_string *zend_string_concat2(
474
    const char *str1, size_t str1_len,
475
    const char *str2, size_t str2_len)
476
13
{
477
13
  zend_string *res = zend_string_safe_alloc(1, str1_len, str2_len, 0);
478
479
13
  char *p = ZSTR_VAL(res);
480
13
  p = zend_mempcpy(p, str1, str1_len);
481
13
  p = zend_mempcpy(p, str2, str2_len);
482
13
  *p++ = '\0';
483
484
13
  return res;
485
13
}
486
487
ZEND_API zend_string *zend_string_concat3(
488
    const char *str1, size_t str1_len,
489
    const char *str2, size_t str2_len,
490
    const char *str3, size_t str3_len)
491
0
{
492
0
  size_t tmp_len = zend_safe_address_guarded(1, str1_len, str2_len);
493
0
  size_t len = zend_safe_address_guarded(1, tmp_len, str3_len);
494
0
  zend_string *res = zend_string_alloc(len, 0);
495
496
0
  char *p = ZSTR_VAL(res);
497
0
  p = zend_mempcpy(p, str1, str1_len);
498
0
  p = zend_mempcpy(p, str2, str2_len);
499
0
  p = zend_mempcpy(p, str3, str3_len);
500
0
  *p++ = '\0';
501
502
0
  return res;
503
0
}
504
505
/* strlcpy and strlcat are not always intercepted by msan, so we need to do it
506
 * ourselves. Apply a simple heuristic to determine the platforms that need it.
507
 * See https://github.com/php/php-src/issues/20002. */
508
#if __has_feature(memory_sanitizer) && !defined(__FreeBSD__) && !defined(__NetBSD__) && !defined(__APPLE__)
509
static size_t (*libc_strlcpy)(char *__restrict, const char *__restrict, size_t);
510
size_t strlcpy(char *__restrict dest, const char *__restrict src, size_t n)
511
{
512
  if (!libc_strlcpy) {
513
    libc_strlcpy = dlsym(RTLD_NEXT, "strlcpy");
514
  }
515
  size_t result = libc_strlcpy(dest, src, n);
516
  __msan_unpoison_string(dest);
517
  return result;
518
}
519
static size_t (*libc_strlcat)(char *__restrict, const char *__restrict, size_t);
520
size_t strlcat (char *__restrict dest, const char *restrict src, size_t n)
521
{
522
  if (!libc_strlcat) {
523
    libc_strlcat = dlsym(RTLD_NEXT, "strlcat");
524
  }
525
  size_t result = libc_strlcat(dest, src, n);
526
  __msan_unpoison_string(dest);
527
  return result;
528
}
529
#endif