Coverage Report

Created: 2025-12-31 07:28

next uncovered line (L), next uncovered region (R), next uncovered branch (B)
/src/php-src/Zend/zend_property_hooks.c
Line
Count
Source
1
/*
2
   +----------------------------------------------------------------------+
3
   | Zend Engine                                                          |
4
   +----------------------------------------------------------------------+
5
   | Copyright (c) Zend Technologies Ltd. (http://www.zend.com)           |
6
   +----------------------------------------------------------------------+
7
   | This source file is subject to version 2.00 of the Zend license,     |
8
   | that is bundled with this package in the file LICENSE, and is        |
9
   | available through the world-wide-web at the following url:           |
10
   | http://www.zend.com/license/2_00.txt.                                |
11
   | If you did not receive a copy of the Zend license and are unable to  |
12
   | obtain it through the world-wide-web, please send a note to          |
13
   | license@zend.com so we can mail you a copy immediately.              |
14
   +----------------------------------------------------------------------+
15
   | Authors: Ilija Tovilo <ilutov@php.net>                               |
16
   +----------------------------------------------------------------------+
17
*/
18
19
#include "zend.h"
20
#include "zend_API.h"
21
#include "zend_hash.h"
22
#include "zend_lazy_objects.h"
23
#include "zend_property_hooks.h"
24
25
typedef struct {
26
  zend_object_iterator it;
27
  bool by_ref;
28
  bool declared_props_done;
29
  zval declared_props;
30
  bool dynamic_props_done;
31
  uint32_t dynamic_prop_offset;
32
  uint32_t dynamic_prop_it;
33
  zval current_key;
34
  zval current_data;
35
} zend_hooked_object_iterator;
36
37
static zend_result zho_it_valid(zend_object_iterator *iter);
38
static void zho_it_move_forward(zend_object_iterator *iter);
39
40
static uint32_t zho_find_dynamic_prop_offset(zend_array *properties)
41
104
{
42
104
  uint32_t offset = 0;
43
104
  zval *value;
44
45
911
  ZEND_HASH_MAP_FOREACH_VAL(properties, value) {
46
911
    if (Z_TYPE_P(value) != IS_INDIRECT) {
47
78
      break;
48
78
    }
49
239
    offset++;
50
239
  } ZEND_HASH_FOREACH_END();
51
52
104
  return offset;
53
104
}
54
55
static zend_array *zho_build_properties_ex(zend_object *zobj, bool check_access, bool force_ptr, bool include_dynamic_props)
56
223
{
57
223
  zend_class_entry *ce = zobj->ce;
58
223
  zend_array *properties = zend_new_array(include_dynamic_props && zobj->properties
59
223
    ? zend_hash_num_elements(zobj->properties)
60
223
    : ce->default_properties_count);
61
223
  zend_hash_real_init_mixed(properties);
62
63
  /* Build list of parents */
64
223
  int32_t parent_count = 0;
65
540
  for (zend_class_entry *pce = ce; pce; pce = pce->parent) {
66
317
    parent_count++;
67
317
  }
68
223
  zend_class_entry **parents = emalloc(sizeof(zend_class_entry*) * parent_count);
69
223
  int32_t i = 0;
70
540
  for (zend_class_entry *pce = ce; pce; pce = pce->parent) {
71
317
    parents[i++] = pce;
72
317
  }
73
74
  /* Iterate parents top to bottom */
75
223
  i--;
76
540
  for (; i >= 0; i--) {
77
317
    zend_class_entry *pce = parents[i];
78
79
317
    zend_property_info *prop_info;
80
3.81k
    ZEND_HASH_MAP_FOREACH_PTR(&pce->properties_info, prop_info) {
81
3.81k
      if (prop_info->flags & ZEND_ACC_STATIC) {
82
0
        continue;
83
0
      }
84
1.58k
      zend_string *property_name = prop_info->name;
85
      /* When promoting properties from protected to public, use the unmangled name to preserve order. */
86
1.58k
      if (prop_info->flags & ZEND_ACC_PROTECTED) {
87
27
        const char *tmp = zend_get_unmangled_property_name(property_name);
88
27
        zend_string *unmangled_name = zend_string_init(tmp, strlen(tmp), false);
89
27
        zend_property_info *child_prop_info = zend_hash_find_ptr(&ce->properties_info, unmangled_name);
90
27
        if (child_prop_info && (child_prop_info->flags & ZEND_ACC_PUBLIC)) {
91
9
          property_name = unmangled_name;
92
18
        } else {
93
18
          zend_string_release(unmangled_name);
94
18
        }
95
27
      }
96
1.58k
      if (check_access && zend_check_property_access(zobj, property_name, false) == FAILURE) {
97
132
        goto skip_property;
98
132
      }
99
1.45k
      if (prop_info->hooks || force_ptr) {
100
1.33k
        zend_hash_update_ptr(properties, property_name, prop_info);
101
1.33k
      } else {
102
118
        if (UNEXPECTED(Z_TYPE_P(OBJ_PROP(zobj, prop_info->offset)) == IS_UNDEF)) {
103
70
          HT_FLAGS(properties) |= HASH_FLAG_HAS_EMPTY_IND;
104
70
        }
105
118
        zval *tmp = zend_hash_lookup(properties, property_name);
106
118
        ZVAL_INDIRECT(tmp, OBJ_PROP(zobj, prop_info->offset));
107
118
      }
108
1.58k
skip_property:
109
1.58k
      if (property_name != prop_info->name) {
110
9
        zend_string_release(property_name);
111
9
      }
112
1.58k
    } ZEND_HASH_FOREACH_END();
113
317
  }
114
115
223
  efree(parents);
116
117
223
  if (include_dynamic_props && zobj->properties) {
118
119
    zend_string *prop_name;
119
119
    zval *prop_value;
120
1.17k
    ZEND_HASH_FOREACH_STR_KEY_VAL(zobj->properties, prop_name, prop_value) {
121
1.17k
      if (Z_TYPE_P(prop_value) == IS_INDIRECT) {
122
514
        continue;
123
514
      }
124
13
      zval *tmp = _zend_hash_append(properties, prop_name, prop_value);
125
13
      Z_TRY_ADDREF_P(tmp);
126
13
    } ZEND_HASH_FOREACH_END();
127
119
  }
128
129
223
  return properties;
130
223
}
131
132
ZEND_API zend_array *zend_hooked_object_build_properties(zend_object *zobj)
133
140
{
134
140
  if (UNEXPECTED(zend_lazy_object_must_init(zobj))) {
135
30
    zobj = zend_lazy_object_init(zobj);
136
30
    if (UNEXPECTED(!zobj)) {
137
21
      return (zend_array*) &zend_empty_array;
138
21
    }
139
30
  }
140
141
119
  return zho_build_properties_ex(zobj, false, false, true);
142
140
}
143
144
static void zho_dynamic_it_init(zend_hooked_object_iterator *hooked_iter)
145
104
{
146
104
  zend_object *zobj = Z_OBJ_P(&hooked_iter->it.data);
147
104
  zend_array *properties = zobj->handlers->get_properties(zobj);
148
104
  hooked_iter->dynamic_props_done = false;
149
104
  hooked_iter->dynamic_prop_offset = zho_find_dynamic_prop_offset(properties);
150
104
  hooked_iter->dynamic_prop_it = zend_hash_iterator_add(properties, hooked_iter->dynamic_prop_offset);
151
104
}
152
153
static void zho_it_get_current_key(zend_object_iterator *iter, zval *key);
154
155
static void zho_declared_it_fetch_current(zend_object_iterator *iter)
156
296
{
157
296
  zend_hooked_object_iterator *hooked_iter = (zend_hooked_object_iterator*)iter;
158
296
  zend_object *zobj = Z_OBJ_P(&iter->data);
159
296
  zend_array *properties = Z_ARR(hooked_iter->declared_props);
160
161
296
  zend_property_info *prop_info = Z_PTR_P(zend_hash_get_current_data(properties));
162
296
  if (prop_info->hooks) {
163
194
    zend_function *get = prop_info->hooks[ZEND_PROPERTY_HOOK_GET];
164
194
    if (!get && (prop_info->flags & ZEND_ACC_VIRTUAL)) {
165
33
      return;
166
33
    }
167
161
    if (hooked_iter->by_ref
168
39
     && (get == NULL
169
39
      || !(get->common.fn_flags & ZEND_ACC_RETURN_REFERENCE))) {
170
0
      zend_throw_error(NULL, "Cannot create reference to property %s::$%s",
171
0
        ZSTR_VAL(zobj->ce->name), zend_get_unmangled_property_name(prop_info->name));
172
0
      return;
173
0
    }
174
161
    zend_string *unmangled_name = prop_info->name;
175
161
    if (ZSTR_VAL(unmangled_name)[0] == '\0') {
176
18
      const char *tmp = zend_get_unmangled_property_name(unmangled_name);
177
18
      unmangled_name = zend_string_init(tmp, strlen(tmp), false);
178
18
    }
179
161
    zval *value = zend_read_property_ex(prop_info->ce, zobj, unmangled_name, /* silent */ true, &hooked_iter->current_data);
180
161
    if (unmangled_name != prop_info->name) {
181
18
      zend_string_release(unmangled_name);
182
18
    }
183
161
    if (value == &EG(uninitialized_zval)) {
184
4
      return;
185
157
    } else if (value != &hooked_iter->current_data) {
186
1
      ZVAL_COPY(&hooked_iter->current_data, value);
187
1
    }
188
161
  } else {
189
102
    zval *property = OBJ_PROP(zobj, prop_info->offset);
190
102
    ZVAL_DEINDIRECT(property);
191
102
    if (Z_TYPE_P(property) == IS_UNDEF) {
192
0
      return;
193
0
    }
194
102
    if (!hooked_iter->by_ref) {
195
63
      ZVAL_DEREF(property);
196
63
    } else if (Z_TYPE_P(property) != IS_REFERENCE) {
197
39
      if (UNEXPECTED(prop_info->flags & ZEND_ACC_READONLY)) {
198
0
        zend_throw_error(NULL,
199
0
          "Cannot acquire reference to readonly property %s::$%s",
200
0
          ZSTR_VAL(prop_info->ce->name), zend_get_unmangled_property_name(prop_info->name));
201
0
        return;
202
0
      }
203
39
      ZVAL_MAKE_REF(property);
204
39
      if (ZEND_TYPE_IS_SET(prop_info->type)) {
205
30
        ZEND_REF_ADD_TYPE_SOURCE(Z_REF_P(property), prop_info);
206
30
      }
207
39
    }
208
102
    ZVAL_COPY(&hooked_iter->current_data, property);
209
102
  }
210
211
259
  if (ZSTR_VAL(prop_info->name)[0] == '\0') {
212
27
    const char *tmp = zend_get_unmangled_property_name(prop_info->name);
213
27
    ZVAL_STR(&hooked_iter->current_key, zend_string_init(tmp, strlen(tmp), false));
214
232
  } else {
215
232
    ZVAL_STR_COPY(&hooked_iter->current_key, prop_info->name);
216
232
  }
217
259
}
218
219
static void zho_dynamic_it_fetch_current(zend_object_iterator *iter)
220
245
{
221
245
  zend_hooked_object_iterator *hooked_iter = (zend_hooked_object_iterator*)iter;
222
245
  zend_array *properties = Z_OBJ(iter->data)->properties;
223
245
  HashPosition pos = zend_hash_iterator_pos(hooked_iter->dynamic_prop_it, properties);
224
225
245
  if (pos >= properties->nNumUsed) {
226
98
    hooked_iter->dynamic_props_done = true;
227
98
    return;
228
98
  }
229
230
147
  Bucket *bucket = properties->arData + pos;
231
232
147
  if (UNEXPECTED(Z_TYPE(bucket->val) == IS_UNDEF)) {
233
63
    return;
234
63
  }
235
236
84
  zend_object *zobj = Z_OBJ_P(&hooked_iter->it.data);
237
84
  if (bucket->key && zend_check_property_access(zobj, bucket->key, true) != SUCCESS) {
238
9
    return;
239
9
  }
240
241
75
  if (hooked_iter->by_ref && Z_TYPE(bucket->val) != IS_REFERENCE) {
242
27
    ZVAL_MAKE_REF(&bucket->val);
243
27
  }
244
75
  ZVAL_COPY(&hooked_iter->current_data, &bucket->val);
245
246
75
  if (bucket->key) {
247
75
    ZVAL_STR_COPY(&hooked_iter->current_key, bucket->key);
248
75
  } else {
249
0
    ZVAL_LONG(&hooked_iter->current_key, bucket->h);
250
0
  }
251
75
}
252
253
static void zho_it_fetch_current(zend_object_iterator *iter)
254
1.10k
{
255
1.10k
  zend_hooked_object_iterator *hooked_iter = (zend_hooked_object_iterator*)iter;
256
1.10k
  if (Z_TYPE(hooked_iter->current_data) != IS_UNDEF) {
257
668
    return;
258
668
  }
259
260
639
  while (true) {
261
639
    if (!hooked_iter->declared_props_done) {
262
296
      zho_declared_it_fetch_current(iter);
263
343
    } else if (!hooked_iter->dynamic_props_done) {
264
245
      zho_dynamic_it_fetch_current(iter);
265
245
    } else {
266
98
      break;
267
98
    }
268
541
    if (Z_TYPE(hooked_iter->current_data) != IS_UNDEF || EG(exception)) {
269
337
      break;
270
337
    }
271
204
    zho_it_move_forward(iter);
272
204
  }
273
435
}
274
275
static void zho_it_dtor(zend_object_iterator *iter)
276
104
{
277
104
  zend_hooked_object_iterator *hooked_iter = (zend_hooked_object_iterator*)iter;
278
104
  zval_ptr_dtor(&iter->data);
279
104
  zval_ptr_dtor(&hooked_iter->declared_props);
280
104
  zval_ptr_dtor_nogc(&hooked_iter->current_key);
281
104
  zval_ptr_dtor(&hooked_iter->current_data);
282
104
  zend_hash_iterator_del(hooked_iter->dynamic_prop_it);
283
104
}
284
285
static zend_result zho_it_valid(zend_object_iterator *iter)
286
435
{
287
435
  zend_hooked_object_iterator *hooked_iter = (zend_hooked_object_iterator*)iter;
288
435
  zho_it_fetch_current(iter);
289
435
  return Z_TYPE(hooked_iter->current_data) != IS_UNDEF ? SUCCESS : FAILURE;
290
435
}
291
292
static zval *zho_it_get_current_data(zend_object_iterator *iter)
293
334
{
294
334
  zend_hooked_object_iterator *hooked_iter = (zend_hooked_object_iterator*)iter;
295
334
  zho_it_fetch_current(iter);
296
334
  return &hooked_iter->current_data;
297
334
}
298
299
static void zho_it_get_current_key(zend_object_iterator *iter, zval *key)
300
334
{
301
334
  zend_hooked_object_iterator *hooked_iter = (zend_hooked_object_iterator*)iter;
302
334
  zho_it_fetch_current(iter);
303
334
  ZVAL_COPY(key, &hooked_iter->current_key);
304
334
}
305
306
static void zho_it_move_forward(zend_object_iterator *iter)
307
535
{
308
535
  zend_hooked_object_iterator *hooked_iter = (zend_hooked_object_iterator*)iter;
309
310
535
  zval_ptr_dtor(&hooked_iter->current_data);
311
535
  ZVAL_UNDEF(&hooked_iter->current_data);
312
535
  zval_ptr_dtor_nogc(&hooked_iter->current_key);
313
535
  ZVAL_UNDEF(&hooked_iter->current_key);
314
315
535
  if (!hooked_iter->declared_props_done) {
316
290
    zend_array *properties = Z_ARR(hooked_iter->declared_props);
317
290
    zend_hash_move_forward(properties);
318
290
    if (zend_hash_has_more_elements(properties) != SUCCESS) {
319
98
      hooked_iter->declared_props_done = true;
320
98
    }
321
290
  } else if (!hooked_iter->dynamic_props_done) {
322
147
    zend_array *properties = Z_OBJ(iter->data)->properties;
323
147
    HashPosition pos = zend_hash_iterator_pos(hooked_iter->dynamic_prop_it, properties);
324
147
    pos++;
325
147
    EG(ht_iterators)[hooked_iter->dynamic_prop_it].pos = pos;
326
147
  }
327
535
}
328
329
static void zho_it_rewind(zend_object_iterator *iter)
330
104
{
331
104
  zend_hooked_object_iterator *hooked_iter = (zend_hooked_object_iterator*)iter;
332
333
104
  zval_ptr_dtor(&hooked_iter->current_data);
334
104
  ZVAL_UNDEF(&hooked_iter->current_data);
335
104
  zval_ptr_dtor_nogc(&hooked_iter->current_key);
336
104
  ZVAL_UNDEF(&hooked_iter->current_key);
337
338
104
  zend_array *properties = Z_ARR(hooked_iter->declared_props);
339
104
  zend_hash_internal_pointer_reset(properties);
340
104
  hooked_iter->declared_props_done = !zend_hash_num_elements(properties);
341
104
  hooked_iter->dynamic_props_done = false;
342
104
  EG(ht_iterators)[hooked_iter->dynamic_prop_it].pos = hooked_iter->dynamic_prop_offset;
343
104
}
344
345
static HashTable *zho_it_get_gc(zend_object_iterator *iter, zval **table, int *n)
346
0
{
347
0
  zend_hooked_object_iterator *hooked_iter = (zend_hooked_object_iterator*)iter;
348
0
  zend_get_gc_buffer *gc_buffer = zend_get_gc_buffer_create();
349
0
  zend_get_gc_buffer_add_zval(gc_buffer, &iter->data);
350
0
  zend_get_gc_buffer_add_zval(gc_buffer, &hooked_iter->declared_props);
351
0
  zend_get_gc_buffer_add_zval(gc_buffer, &hooked_iter->current_data);
352
0
  zend_get_gc_buffer_use(gc_buffer, table, n);
353
0
  return NULL;
354
0
}
355
356
static const zend_object_iterator_funcs zend_hooked_object_it_funcs = {
357
  zho_it_dtor,
358
  zho_it_valid,
359
  zho_it_get_current_data,
360
  zho_it_get_current_key,
361
  zho_it_move_forward,
362
  zho_it_rewind,
363
  NULL,
364
  zho_it_get_gc,
365
};
366
367
ZEND_API zend_object_iterator *zend_hooked_object_get_iterator(zend_class_entry *ce, zval *object, int by_ref)
368
106
{
369
106
  zend_object *zobj = Z_OBJ_P(object);
370
106
  if (UNEXPECTED(zend_lazy_object_must_init(zobj))) {
371
50
    zobj = zend_lazy_object_init(zobj);
372
50
    if (UNEXPECTED(!zobj)) {
373
2
      return NULL;
374
2
    }
375
50
  }
376
377
104
  zend_hooked_object_iterator *iterator = emalloc(sizeof(zend_hooked_object_iterator));
378
104
  zend_iterator_init(&iterator->it);
379
380
104
  ZVAL_OBJ_COPY(&iterator->it.data, zobj);
381
104
  iterator->it.funcs = &zend_hooked_object_it_funcs;
382
104
  iterator->by_ref = by_ref;
383
104
  zend_array *properties = zho_build_properties_ex(zobj, true, true, false);
384
104
  ZVAL_ARR(&iterator->declared_props, properties);
385
104
  iterator->declared_props_done = !zend_hash_num_elements(properties);
386
104
  zho_dynamic_it_init(iterator);
387
104
  ZVAL_UNDEF(&iterator->current_key);
388
104
  ZVAL_UNDEF(&iterator->current_data);
389
390
104
  return &iterator->it;
391
106
}