Coverage Report

Created: 2025-09-27 06:26

next uncovered line (L), next uncovered region (R), next uncovered branch (B)
/src/php-src/Zend/zend_property_hooks.c
Line
Count
Source
1
/*
2
   +----------------------------------------------------------------------+
3
   | Zend Engine                                                          |
4
   +----------------------------------------------------------------------+
5
   | Copyright (c) Zend Technologies Ltd. (http://www.zend.com)           |
6
   +----------------------------------------------------------------------+
7
   | This source file is subject to version 2.00 of the Zend license,     |
8
   | that is bundled with this package in the file LICENSE, and is        |
9
   | available through the world-wide-web at the following url:           |
10
   | http://www.zend.com/license/2_00.txt.                                |
11
   | If you did not receive a copy of the Zend license and are unable to  |
12
   | obtain it through the world-wide-web, please send a note to          |
13
   | license@zend.com so we can mail you a copy immediately.              |
14
   +----------------------------------------------------------------------+
15
   | Authors: Ilija Tovilo <ilutov@php.net>                               |
16
   +----------------------------------------------------------------------+
17
*/
18
19
#include "zend.h"
20
#include "zend_API.h"
21
#include "zend_hash.h"
22
#include "zend_lazy_objects.h"
23
#include "zend_property_hooks.h"
24
25
typedef struct {
26
  zend_object_iterator it;
27
  bool by_ref;
28
  bool declared_props_done;
29
  zval declared_props;
30
  bool dynamic_props_done;
31
  uint32_t dynamic_prop_offset;
32
  uint32_t dynamic_prop_it;
33
  zval current_key;
34
  zval current_data;
35
} zend_hooked_object_iterator;
36
37
static zend_result zho_it_valid(zend_object_iterator *iter);
38
static void zho_it_move_forward(zend_object_iterator *iter);
39
40
static uint32_t zho_find_dynamic_prop_offset(zend_array *properties)
41
263
{
42
263
  uint32_t offset = 0;
43
263
  zval *value;
44
45
2.01k
  ZEND_HASH_MAP_FOREACH_VAL(properties, value) {
46
2.01k
    if (Z_TYPE_P(value) != IS_INDIRECT) {
47
155
      break;
48
155
    }
49
521
    offset++;
50
521
  } ZEND_HASH_FOREACH_END();
51
52
263
  return offset;
53
263
}
54
55
static zend_array *zho_build_properties_ex(zend_object *zobj, bool check_access, bool force_ptr, bool include_dynamic_props)
56
542
{
57
542
  zend_class_entry *ce = zobj->ce;
58
542
  zend_array *properties = zend_new_array(include_dynamic_props && zobj->properties
59
542
    ? zend_hash_num_elements(zobj->properties)
60
542
    : ce->default_properties_count);
61
542
  zend_hash_real_init_mixed(properties);
62
63
  /* Build list of parents */
64
542
  int32_t parent_count = 0;
65
1.29k
  for (zend_class_entry *pce = ce; pce; pce = pce->parent) {
66
757
    parent_count++;
67
757
  }
68
542
  zend_class_entry **parents = emalloc(sizeof(zend_class_entry*) * parent_count);
69
542
  int32_t i = 0;
70
1.29k
  for (zend_class_entry *pce = ce; pce; pce = pce->parent) {
71
757
    parents[i++] = pce;
72
757
  }
73
74
  /* Iterate parents top to bottom */
75
542
  i--;
76
1.29k
  for (; i >= 0; i--) {
77
757
    zend_class_entry *pce = parents[i];
78
79
757
    zend_property_info *prop_info;
80
7.43k
    ZEND_HASH_MAP_FOREACH_PTR(&pce->properties_info, prop_info) {
81
7.43k
      if (prop_info->flags & ZEND_ACC_STATIC) {
82
0
        continue;
83
0
      }
84
2.96k
      zend_string *property_name = prop_info->name;
85
      /* When promoting properties from protected to public, use the unmangled name to preserve order. */
86
2.96k
      if (prop_info->flags & ZEND_ACC_PROTECTED) {
87
33
        const char *tmp = zend_get_unmangled_property_name(property_name);
88
33
        zend_string *unmangled_name = zend_string_init(tmp, strlen(tmp), false);
89
33
        zend_property_info *child_prop_info = zend_hash_find_ptr(&ce->properties_info, unmangled_name);
90
33
        if (child_prop_info && (child_prop_info->flags & ZEND_ACC_PUBLIC)) {
91
11
          property_name = unmangled_name;
92
22
        } else {
93
22
          zend_string_release(unmangled_name);
94
22
        }
95
33
      }
96
2.96k
      if (check_access && zend_check_property_access(zobj, property_name, false) == FAILURE) {
97
252
        goto skip_property;
98
252
      }
99
2.70k
      if (prop_info->hooks || force_ptr) {
100
2.44k
        zend_hash_update_ptr(properties, property_name, prop_info);
101
2.44k
      } else {
102
260
        if (UNEXPECTED(Z_TYPE_P(OBJ_PROP(zobj, prop_info->offset)) == IS_UNDEF)) {
103
159
          HT_FLAGS(properties) |= HASH_FLAG_HAS_EMPTY_IND;
104
159
        }
105
260
        zval *tmp = zend_hash_lookup(properties, property_name);
106
260
        ZVAL_INDIRECT(tmp, OBJ_PROP(zobj, prop_info->offset));
107
260
      }
108
2.96k
skip_property:
109
2.96k
      if (property_name != prop_info->name) {
110
11
        zend_string_release(property_name);
111
11
      }
112
2.96k
    } ZEND_HASH_FOREACH_END();
113
757
  }
114
115
542
  efree(parents);
116
117
542
  if (include_dynamic_props && zobj->properties) {
118
263
    zend_string *prop_name;
119
263
    zval *prop_value;
120
2.19k
    ZEND_HASH_FOREACH_STR_KEY_VAL(zobj->properties, prop_name, prop_value) {
121
2.19k
      if (Z_TYPE_P(prop_value) == IS_INDIRECT) {
122
934
        continue;
123
934
      }
124
29
      zval *tmp = _zend_hash_append(properties, prop_name, prop_value);
125
29
      Z_TRY_ADDREF_P(tmp);
126
29
    } ZEND_HASH_FOREACH_END();
127
263
  }
128
129
542
  return properties;
130
542
}
131
132
ZEND_API zend_array *zend_hooked_object_build_properties(zend_object *zobj)
133
314
{
134
314
  if (UNEXPECTED(zend_lazy_object_must_init(zobj))) {
135
54
    zobj = zend_lazy_object_init(zobj);
136
54
    if (UNEXPECTED(!zobj)) {
137
35
      return (zend_array*) &zend_empty_array;
138
35
    }
139
54
  }
140
141
279
  return zho_build_properties_ex(zobj, false, false, true);
142
314
}
143
144
static void zho_dynamic_it_init(zend_hooked_object_iterator *hooked_iter)
145
263
{
146
263
  zend_object *zobj = Z_OBJ_P(&hooked_iter->it.data);
147
263
  zend_array *properties = zobj->handlers->get_properties(zobj);
148
263
  hooked_iter->dynamic_props_done = false;
149
263
  hooked_iter->dynamic_prop_offset = zho_find_dynamic_prop_offset(properties);
150
263
  hooked_iter->dynamic_prop_it = zend_hash_iterator_add(properties, hooked_iter->dynamic_prop_offset);
151
263
}
152
153
static void zho_it_get_current_key(zend_object_iterator *iter, zval *key);
154
155
static void zho_declared_it_fetch_current(zend_object_iterator *iter)
156
610
{
157
610
  zend_hooked_object_iterator *hooked_iter = (zend_hooked_object_iterator*)iter;
158
610
  zend_object *zobj = Z_OBJ_P(&iter->data);
159
610
  zend_array *properties = Z_ARR(hooked_iter->declared_props);
160
161
610
  zend_property_info *prop_info = Z_PTR_P(zend_hash_get_current_data(properties));
162
610
  if (prop_info->hooks) {
163
366
    zend_function *get = prop_info->hooks[ZEND_PROPERTY_HOOK_GET];
164
366
    if (!get && (prop_info->flags & ZEND_ACC_VIRTUAL)) {
165
52
      return;
166
52
    }
167
314
    if (hooked_iter->by_ref
168
111
     && (get == NULL
169
111
      || !(get->common.fn_flags & ZEND_ACC_RETURN_REFERENCE))) {
170
5
      zend_throw_error(NULL, "Cannot create reference to property %s::$%s",
171
5
        ZSTR_VAL(zobj->ce->name), zend_get_unmangled_property_name(prop_info->name));
172
5
      return;
173
5
    }
174
309
    zend_string *unmangled_name = prop_info->name;
175
309
    if (ZSTR_VAL(unmangled_name)[0] == '\0') {
176
22
      const char *tmp = zend_get_unmangled_property_name(unmangled_name);
177
22
      unmangled_name = zend_string_init(tmp, strlen(tmp), false);
178
22
    }
179
309
    zval *value = zend_read_property_ex(prop_info->ce, zobj, unmangled_name, /* silent */ true, &hooked_iter->current_data);
180
309
    if (unmangled_name != prop_info->name) {
181
22
      zend_string_release(unmangled_name);
182
22
    }
183
309
    if (value == &EG(uninitialized_zval)) {
184
11
      return;
185
298
    } else if (value != &hooked_iter->current_data) {
186
6
      ZVAL_COPY(&hooked_iter->current_data, value);
187
6
    }
188
309
  } else {
189
244
    zval *property = OBJ_PROP(zobj, prop_info->offset);
190
244
    ZVAL_DEINDIRECT(property);
191
244
    if (Z_TYPE_P(property) == IS_UNDEF) {
192
13
      return;
193
13
    }
194
231
    if (!hooked_iter->by_ref) {
195
119
      ZVAL_DEREF(property);
196
119
    } else if (Z_TYPE_P(property) != IS_REFERENCE) {
197
112
      if (UNEXPECTED(prop_info->flags & ZEND_ACC_READONLY)) {
198
8
        zend_throw_error(NULL,
199
8
          "Cannot acquire reference to readonly property %s::$%s",
200
8
          ZSTR_VAL(prop_info->ce->name), zend_get_unmangled_property_name(prop_info->name));
201
8
        return;
202
8
      }
203
104
      ZVAL_MAKE_REF(property);
204
104
      if (ZEND_TYPE_IS_SET(prop_info->type)) {
205
88
        ZEND_REF_ADD_TYPE_SOURCE(Z_REF_P(property), prop_info);
206
88
      }
207
104
    }
208
223
    ZVAL_COPY(&hooked_iter->current_data, property);
209
223
  }
210
211
521
  if (ZSTR_VAL(prop_info->name)[0] == '\0') {
212
33
    const char *tmp = zend_get_unmangled_property_name(prop_info->name);
213
33
    ZVAL_STR(&hooked_iter->current_key, zend_string_init(tmp, strlen(tmp), false));
214
488
  } else {
215
488
    ZVAL_STR_COPY(&hooked_iter->current_key, prop_info->name);
216
488
  }
217
521
}
218
219
static void zho_dynamic_it_fetch_current(zend_object_iterator *iter)
220
548
{
221
548
  zend_hooked_object_iterator *hooked_iter = (zend_hooked_object_iterator*)iter;
222
548
  zend_array *properties = Z_OBJ(iter->data)->properties;
223
548
  HashPosition pos = zend_hash_iterator_pos(hooked_iter->dynamic_prop_it, properties);
224
225
548
  if (pos >= properties->nNumUsed) {
226
242
    hooked_iter->dynamic_props_done = true;
227
242
    return;
228
242
  }
229
230
306
  Bucket *bucket = properties->arData + pos;
231
232
306
  if (UNEXPECTED(Z_TYPE(bucket->val) == IS_UNDEF)) {
233
125
    return;
234
125
  }
235
236
181
  zend_object *zobj = Z_OBJ_P(&hooked_iter->it.data);
237
181
  if (bucket->key && zend_check_property_access(zobj, bucket->key, true) != SUCCESS) {
238
11
    return;
239
11
  }
240
241
170
  if (hooked_iter->by_ref && Z_TYPE(bucket->val) != IS_REFERENCE) {
242
75
    ZVAL_MAKE_REF(&bucket->val);
243
75
  }
244
170
  ZVAL_COPY(&hooked_iter->current_data, &bucket->val);
245
246
170
  if (bucket->key) {
247
170
    ZVAL_STR_COPY(&hooked_iter->current_key, bucket->key);
248
170
  } else {
249
0
    ZVAL_LONG(&hooked_iter->current_key, bucket->h);
250
0
  }
251
170
}
252
253
static void zho_it_fetch_current(zend_object_iterator *iter)
254
2.32k
{
255
2.32k
  zend_hooked_object_iterator *hooked_iter = (zend_hooked_object_iterator*)iter;
256
2.32k
  if (Z_TYPE(hooked_iter->current_data) != IS_UNDEF) {
257
1.36k
    return;
258
1.36k
  }
259
260
1.40k
  while (true) {
261
1.40k
    if (!hooked_iter->declared_props_done) {
262
610
      zho_declared_it_fetch_current(iter);
263
790
    } else if (!hooked_iter->dynamic_props_done) {
264
548
      zho_dynamic_it_fetch_current(iter);
265
548
    } else {
266
242
      break;
267
242
    }
268
1.15k
    if (Z_TYPE(hooked_iter->current_data) != IS_UNDEF || EG(exception)) {
269
709
      break;
270
709
    }
271
449
    zho_it_move_forward(iter);
272
449
  }
273
951
}
274
275
static void zho_it_dtor(zend_object_iterator *iter)
276
263
{
277
263
  zend_hooked_object_iterator *hooked_iter = (zend_hooked_object_iterator*)iter;
278
263
  zval_ptr_dtor(&iter->data);
279
263
  zval_ptr_dtor(&hooked_iter->declared_props);
280
263
  zval_ptr_dtor_nogc(&hooked_iter->current_key);
281
263
  zval_ptr_dtor(&hooked_iter->current_data);
282
263
  zend_hash_iterator_del(hooked_iter->dynamic_prop_it);
283
263
}
284
285
static zend_result zho_it_valid(zend_object_iterator *iter)
286
951
{
287
951
  zend_hooked_object_iterator *hooked_iter = (zend_hooked_object_iterator*)iter;
288
951
  zho_it_fetch_current(iter);
289
951
  return Z_TYPE(hooked_iter->current_data) != IS_UNDEF ? SUCCESS : FAILURE;
290
951
}
291
292
static zval *zho_it_get_current_data(zend_object_iterator *iter)
293
691
{
294
691
  zend_hooked_object_iterator *hooked_iter = (zend_hooked_object_iterator*)iter;
295
691
  zho_it_fetch_current(iter);
296
691
  return &hooked_iter->current_data;
297
691
}
298
299
static void zho_it_get_current_key(zend_object_iterator *iter, zval *key)
300
678
{
301
678
  zend_hooked_object_iterator *hooked_iter = (zend_hooked_object_iterator*)iter;
302
678
  zho_it_fetch_current(iter);
303
678
  ZVAL_COPY(key, &hooked_iter->current_key);
304
678
}
305
306
static void zho_it_move_forward(zend_object_iterator *iter)
307
1.13k
{
308
1.13k
  zend_hooked_object_iterator *hooked_iter = (zend_hooked_object_iterator*)iter;
309
310
1.13k
  zval_ptr_dtor(&hooked_iter->current_data);
311
1.13k
  ZVAL_UNDEF(&hooked_iter->current_data);
312
1.13k
  zval_ptr_dtor_nogc(&hooked_iter->current_key);
313
1.13k
  ZVAL_UNDEF(&hooked_iter->current_key);
314
315
1.13k
  if (!hooked_iter->declared_props_done) {
316
589
    zend_array *properties = Z_ARR(hooked_iter->declared_props);
317
589
    zend_hash_move_forward(properties);
318
589
    if (zend_hash_has_more_elements(properties) != SUCCESS) {
319
242
      hooked_iter->declared_props_done = true;
320
242
    }
321
589
  } else if (!hooked_iter->dynamic_props_done) {
322
306
    zend_array *properties = Z_OBJ(iter->data)->properties;
323
306
    HashPosition pos = zend_hash_iterator_pos(hooked_iter->dynamic_prop_it, properties);
324
306
    pos++;
325
306
    EG(ht_iterators)[hooked_iter->dynamic_prop_it].pos = pos;
326
306
  }
327
1.13k
}
328
329
static void zho_it_rewind(zend_object_iterator *iter)
330
263
{
331
263
  zend_hooked_object_iterator *hooked_iter = (zend_hooked_object_iterator*)iter;
332
333
263
  zval_ptr_dtor(&hooked_iter->current_data);
334
263
  ZVAL_UNDEF(&hooked_iter->current_data);
335
263
  zval_ptr_dtor_nogc(&hooked_iter->current_key);
336
263
  ZVAL_UNDEF(&hooked_iter->current_key);
337
338
263
  zend_array *properties = Z_ARR(hooked_iter->declared_props);
339
263
  zend_hash_internal_pointer_reset(properties);
340
263
  hooked_iter->declared_props_done = !zend_hash_num_elements(properties);
341
263
  hooked_iter->dynamic_props_done = false;
342
263
  EG(ht_iterators)[hooked_iter->dynamic_prop_it].pos = hooked_iter->dynamic_prop_offset;
343
263
}
344
345
static HashTable *zho_it_get_gc(zend_object_iterator *iter, zval **table, int *n)
346
0
{
347
0
  zend_hooked_object_iterator *hooked_iter = (zend_hooked_object_iterator*)iter;
348
0
  zend_get_gc_buffer *gc_buffer = zend_get_gc_buffer_create();
349
0
  zend_get_gc_buffer_add_zval(gc_buffer, &iter->data);
350
0
  zend_get_gc_buffer_add_zval(gc_buffer, &hooked_iter->declared_props);
351
0
  zend_get_gc_buffer_add_zval(gc_buffer, &hooked_iter->current_data);
352
0
  zend_get_gc_buffer_use(gc_buffer, table, n);
353
0
  return NULL;
354
0
}
355
356
static const zend_object_iterator_funcs zend_hooked_object_it_funcs = {
357
  zho_it_dtor,
358
  zho_it_valid,
359
  zho_it_get_current_data,
360
  zho_it_get_current_key,
361
  zho_it_move_forward,
362
  zho_it_rewind,
363
  NULL,
364
  zho_it_get_gc,
365
};
366
367
ZEND_API zend_object_iterator *zend_hooked_object_get_iterator(zend_class_entry *ce, zval *object, int by_ref)
368
270
{
369
270
  zend_object *zobj = Z_OBJ_P(object);
370
270
  if (UNEXPECTED(zend_lazy_object_must_init(zobj))) {
371
138
    zobj = zend_lazy_object_init(zobj);
372
138
    if (UNEXPECTED(!zobj)) {
373
7
      return NULL;
374
7
    }
375
138
  }
376
377
263
  zend_hooked_object_iterator *iterator = emalloc(sizeof(zend_hooked_object_iterator));
378
263
  zend_iterator_init(&iterator->it);
379
380
263
  ZVAL_OBJ_COPY(&iterator->it.data, zobj);
381
263
  iterator->it.funcs = &zend_hooked_object_it_funcs;
382
263
  iterator->by_ref = by_ref;
383
263
  zend_array *properties = zho_build_properties_ex(zobj, true, true, false);
384
263
  ZVAL_ARR(&iterator->declared_props, properties);
385
263
  iterator->declared_props_done = !zend_hash_num_elements(properties);
386
263
  zho_dynamic_it_init(iterator);
387
263
  ZVAL_UNDEF(&iterator->current_key);
388
263
  ZVAL_UNDEF(&iterator->current_data);
389
390
263
  return &iterator->it;
391
270
}