Coverage Report

Created: 2025-12-31 07:28

next uncovered line (L), next uncovered region (R), next uncovered branch (B)
/src/php-src/Zend/zend_string.c
Line
Count
Source
1
/*
2
   +----------------------------------------------------------------------+
3
   | Zend Engine                                                          |
4
   +----------------------------------------------------------------------+
5
   | Copyright (c) Zend Technologies Ltd. (http://www.zend.com)           |
6
   +----------------------------------------------------------------------+
7
   | This source file is subject to version 2.00 of the Zend license,     |
8
   | that is bundled with this package in the file LICENSE, and is        |
9
   | available through the world-wide-web at the following url:           |
10
   | http://www.zend.com/license/2_00.txt.                                |
11
   | If you did not receive a copy of the Zend license and are unable to  |
12
   | obtain it through the world-wide-web, please send a note to          |
13
   | license@zend.com so we can mail you a copy immediately.              |
14
   +----------------------------------------------------------------------+
15
   | Authors: Dmitry Stogov <dmitry@php.net>                              |
16
   +----------------------------------------------------------------------+
17
*/
18
19
#include "zend.h"
20
#include "zend_globals.h"
21
22
#ifdef HAVE_VALGRIND
23
# include "valgrind/callgrind.h"
24
#endif
25
26
#if __has_feature(memory_sanitizer)
27
# include <sanitizer/msan_interface.h>
28
#endif
29
30
ZEND_API zend_new_interned_string_func_t zend_new_interned_string;
31
ZEND_API zend_string_init_interned_func_t zend_string_init_interned;
32
ZEND_API zend_string_init_existing_interned_func_t zend_string_init_existing_interned;
33
34
static zend_string* ZEND_FASTCALL zend_new_interned_string_permanent(zend_string *str);
35
static zend_string* ZEND_FASTCALL zend_new_interned_string_request(zend_string *str);
36
static zend_string* ZEND_FASTCALL zend_string_init_interned_permanent(const char *str, size_t size, bool permanent);
37
static zend_string* ZEND_FASTCALL zend_string_init_existing_interned_permanent(const char *str, size_t size, bool permanent);
38
static zend_string* ZEND_FASTCALL zend_string_init_interned_request(const char *str, size_t size, bool permanent);
39
static zend_string* ZEND_FASTCALL zend_string_init_existing_interned_request(const char *str, size_t size, bool permanent);
40
41
/* Any strings interned in the startup phase. Common to all the threads,
42
   won't be free'd until process exit. If we want an ability to
43
   add permanent strings even after startup, it would be still
44
   possible on costs of locking in the thread safe builds. */
45
static HashTable interned_strings_permanent;
46
47
static zend_new_interned_string_func_t interned_string_request_handler = zend_new_interned_string_request;
48
static zend_string_init_interned_func_t interned_string_init_request_handler = zend_string_init_interned_request;
49
static zend_string_init_existing_interned_func_t interned_string_init_existing_request_handler = zend_string_init_existing_interned_request;
50
51
ZEND_API zend_string  *zend_empty_string = NULL;
52
ZEND_API zend_string  *zend_one_char_string[256];
53
ZEND_API zend_string **zend_known_strings = NULL;
54
55
ZEND_API zend_ulong ZEND_FASTCALL zend_string_hash_func(zend_string *str)
56
46.8M
{
57
46.8M
  return ZSTR_H(str) = zend_hash_func(ZSTR_VAL(str), ZSTR_LEN(str));
58
46.8M
}
59
60
ZEND_API zend_ulong ZEND_FASTCALL zend_hash_func(const char *str, size_t len)
61
47.1M
{
62
47.1M
  return zend_inline_hash_func(str, len);
63
47.1M
}
64
65
static void _str_dtor(zval *zv)
66
0
{
67
0
  zend_string *str = Z_STR_P(zv);
68
0
  pefree(str, GC_FLAGS(str) & IS_STR_PERSISTENT);
69
0
}
70
71
static const char *known_strings[] = {
72
#define _ZEND_STR_DSC(id, str) str,
73
ZEND_KNOWN_STRINGS(_ZEND_STR_DSC)
74
#undef _ZEND_STR_DSC
75
  NULL
76
};
77
78
static zend_always_inline void zend_init_interned_strings_ht(HashTable *interned_strings, bool permanent)
79
222k
{
80
222k
  zend_hash_init(interned_strings, 1024, NULL, _str_dtor, permanent);
81
222k
  if (permanent) {
82
14
    zend_hash_real_init_mixed(interned_strings);
83
14
  }
84
222k
}
85
86
ZEND_API void zend_interned_strings_init(void)
87
14
{
88
14
  char s[2];
89
90
14
  interned_string_request_handler = zend_new_interned_string_request;
91
14
  interned_string_init_request_handler = zend_string_init_interned_request;
92
14
  interned_string_init_existing_request_handler = zend_string_init_existing_interned_request;
93
94
14
  zend_empty_string = NULL;
95
14
  zend_known_strings = NULL;
96
97
14
  zend_init_interned_strings_ht(&interned_strings_permanent, true);
98
99
14
  zend_new_interned_string = zend_new_interned_string_permanent;
100
14
  zend_string_init_interned = zend_string_init_interned_permanent;
101
14
  zend_string_init_existing_interned = zend_string_init_existing_interned_permanent;
102
103
  /* interned empty string */
104
14
  zend_empty_string = zend_string_init_interned_permanent("", 0, true);
105
14
  GC_ADD_FLAGS(zend_empty_string, IS_STR_VALID_UTF8);
106
107
14
  s[1] = 0;
108
3.59k
  for (size_t i = 0; i < 256; i++) {
109
3.58k
    s[0] = i;
110
3.58k
    zend_one_char_string[i] = zend_string_init_interned_permanent(s, 1, true);
111
3.58k
    if (i < 0x80) {
112
1.79k
      GC_ADD_FLAGS(zend_one_char_string[i], IS_STR_VALID_UTF8);
113
1.79k
    }
114
3.58k
  }
115
116
  /* known strings */
117
14
  zend_known_strings = pemalloc(sizeof(zend_string*) * ((sizeof(known_strings) / sizeof(known_strings[0]) - 1)), 1);
118
1.24k
  for (size_t i = 0; i < (sizeof(known_strings) / sizeof(known_strings[0])) - 1; i++) {
119
1.23k
    zend_known_strings[i] = zend_string_init_interned_permanent(known_strings[i], strlen(known_strings[i]), true);
120
1.23k
    GC_ADD_FLAGS(zend_known_strings[i], IS_STR_VALID_UTF8);
121
1.23k
  }
122
14
}
123
124
ZEND_API void zend_interned_strings_dtor(void)
125
0
{
126
0
  zend_hash_destroy(&interned_strings_permanent);
127
128
0
  free(zend_known_strings);
129
0
  zend_known_strings = NULL;
130
0
}
131
132
static zend_always_inline zend_string *zend_interned_string_ht_lookup_ex(zend_ulong h, const char *str, size_t size, HashTable *interned_strings)
133
90.7k
{
134
90.7k
  uint32_t nIndex;
135
90.7k
  uint32_t idx;
136
90.7k
  Bucket *p;
137
138
90.7k
  nIndex = h | interned_strings->nTableMask;
139
90.7k
  idx = HT_HASH(interned_strings, nIndex);
140
114k
  while (idx != HT_INVALID_IDX) {
141
69.0k
    p = HT_HASH_TO_BUCKET(interned_strings, idx);
142
69.0k
    if ((p->h == h) && zend_string_equals_cstr(p->key, str, size)) {
143
45.1k
      return p->key;
144
45.1k
    }
145
23.8k
    idx = Z_NEXT(p->val);
146
23.8k
  }
147
148
45.5k
  return NULL;
149
90.7k
}
150
151
static zend_always_inline zend_string *zend_interned_string_ht_lookup(zend_string *str, HashTable *interned_strings)
152
11.5k
{
153
11.5k
  zend_ulong h = ZSTR_H(str);
154
11.5k
  uint32_t nIndex;
155
11.5k
  uint32_t idx;
156
11.5k
  Bucket *p;
157
158
11.5k
  nIndex = h | interned_strings->nTableMask;
159
11.5k
  idx = HT_HASH(interned_strings, nIndex);
160
15.0k
  while (idx != HT_INVALID_IDX) {
161
7.45k
    p = HT_HASH_TO_BUCKET(interned_strings, idx);
162
7.45k
    if ((p->h == h) && zend_string_equal_content(p->key, str)) {
163
3.99k
      return p->key;
164
3.99k
    }
165
3.45k
    idx = Z_NEXT(p->val);
166
3.45k
  }
167
168
7.56k
  return NULL;
169
11.5k
}
170
171
/* This function might be not thread safe at least because it would update the
172
   hash val in the passed string. Be sure it is called in the appropriate context. */
173
static zend_always_inline zend_string *zend_add_interned_string(zend_string *str, HashTable *interned_strings, uint32_t flags)
174
53.1k
{
175
53.1k
  zval val;
176
177
53.1k
  GC_SET_REFCOUNT(str, 1);
178
53.1k
  GC_ADD_FLAGS(str, IS_STR_INTERNED | flags);
179
180
53.1k
  ZVAL_INTERNED_STR(&val, str);
181
182
53.1k
  zend_hash_add_new(interned_strings, str, &val);
183
184
53.1k
  return str;
185
53.1k
}
186
187
ZEND_API zend_string* ZEND_FASTCALL zend_interned_string_find_permanent(zend_string *str)
188
0
{
189
0
  zend_string_hash_val(str);
190
0
  return zend_interned_string_ht_lookup(str, &interned_strings_permanent);
191
0
}
192
193
static zend_string* ZEND_FASTCALL zend_init_string_for_interning(zend_string *str, bool persistent)
194
114
{
195
114
  uint32_t flags = ZSTR_GET_COPYABLE_CONCAT_PROPERTIES(str);
196
114
  zend_ulong h = ZSTR_H(str);
197
114
  zend_string_delref(str);
198
114
  str = zend_string_init(ZSTR_VAL(str), ZSTR_LEN(str), persistent);
199
114
  GC_ADD_FLAGS(str, flags);
200
114
  ZSTR_H(str) = h;
201
114
  return str;
202
114
}
203
204
static zend_string* ZEND_FASTCALL zend_new_interned_string_permanent(zend_string *str)
205
28.0k
{
206
28.0k
  zend_string *ret;
207
208
28.0k
  if (ZSTR_IS_INTERNED(str)) {
209
16.4k
    return str;
210
16.4k
  }
211
212
11.5k
  zend_string_hash_val(str);
213
11.5k
  ret = zend_interned_string_ht_lookup(str, &interned_strings_permanent);
214
11.5k
  if (ret) {
215
3.99k
    zend_string_release(str);
216
3.99k
    return ret;
217
3.99k
  }
218
219
7.56k
  ZEND_ASSERT(GC_FLAGS(str) & GC_PERSISTENT);
220
7.56k
  if (GC_REFCOUNT(str) > 1) {
221
114
    str = zend_init_string_for_interning(str, true);
222
114
  }
223
224
7.56k
  return zend_add_interned_string(str, &interned_strings_permanent, IS_STR_PERMANENT);
225
7.56k
}
226
227
static zend_string* ZEND_FASTCALL zend_new_interned_string_request(zend_string *str)
228
0
{
229
0
  zend_string *ret;
230
231
0
  if (ZSTR_IS_INTERNED(str)) {
232
0
    return str;
233
0
  }
234
235
0
  zend_string_hash_val(str);
236
237
  /* Check for permanent strings, the table is readonly at this point. */
238
0
  ret = zend_interned_string_ht_lookup(str, &interned_strings_permanent);
239
0
  if (ret) {
240
0
    zend_string_release(str);
241
0
    return ret;
242
0
  }
243
244
0
  ret = zend_interned_string_ht_lookup(str, &CG(interned_strings));
245
0
  if (ret) {
246
0
    zend_string_release(str);
247
0
    return ret;
248
0
  }
249
250
  /* Create a short living interned, freed after the request. */
251
#if ZEND_RC_DEBUG
252
  if (zend_rc_debug) {
253
    /* PHP shouldn't create persistent interned string during request,
254
     * but at least dl() may do this */
255
    ZEND_ASSERT(!(GC_FLAGS(str) & GC_PERSISTENT));
256
  }
257
#endif
258
0
  if (GC_REFCOUNT(str) > 1) {
259
0
    str = zend_init_string_for_interning(str, false);
260
0
  }
261
262
0
  ret = zend_add_interned_string(str, &CG(interned_strings), 0);
263
264
0
  return ret;
265
0
}
266
267
static zend_string* ZEND_FASTCALL zend_string_init_interned_permanent(const char *str, size_t size, bool permanent)
268
90.7k
{
269
90.7k
  zend_string *ret;
270
90.7k
  zend_ulong h = zend_inline_hash_func(str, size);
271
272
90.7k
  ret = zend_interned_string_ht_lookup_ex(h, str, size, &interned_strings_permanent);
273
90.7k
  if (ret) {
274
45.1k
    return ret;
275
45.1k
  }
276
277
45.5k
  ZEND_ASSERT(permanent);
278
45.5k
  ret = zend_string_init(str, size, permanent);
279
45.5k
  ZSTR_H(ret) = h;
280
45.5k
  return zend_add_interned_string(ret, &interned_strings_permanent, IS_STR_PERMANENT);
281
45.5k
}
282
283
static zend_string* ZEND_FASTCALL zend_string_init_existing_interned_permanent(const char *str, size_t size, bool permanent)
284
0
{
285
0
  zend_ulong h = zend_inline_hash_func(str, size);
286
0
  zend_string *ret = zend_interned_string_ht_lookup_ex(h, str, size, &interned_strings_permanent);
287
0
  if (ret) {
288
0
    return ret;
289
0
  }
290
291
0
  ZEND_ASSERT(permanent);
292
0
  ret = zend_string_init(str, size, permanent);
293
0
  ZSTR_H(ret) = h;
294
0
  return ret;
295
0
}
296
297
static zend_string* ZEND_FASTCALL zend_string_init_interned_request(const char *str, size_t size, bool permanent)
298
0
{
299
0
  zend_string *ret;
300
0
  zend_ulong h = zend_inline_hash_func(str, size);
301
302
  /* Check for permanent strings, the table is readonly at this point. */
303
0
  ret = zend_interned_string_ht_lookup_ex(h, str, size, &interned_strings_permanent);
304
0
  if (ret) {
305
0
    return ret;
306
0
  }
307
308
0
  ret = zend_interned_string_ht_lookup_ex(h, str, size, &CG(interned_strings));
309
0
  if (ret) {
310
0
    return ret;
311
0
  }
312
313
#if ZEND_RC_DEBUG
314
  if (zend_rc_debug) {
315
    /* PHP shouldn't create persistent interned string during request,
316
     * but at least dl() may do this */
317
    ZEND_ASSERT(!permanent);
318
  }
319
#endif
320
0
  ret = zend_string_init(str, size, permanent);
321
0
  ZSTR_H(ret) = h;
322
323
  /* Create a short living interned, freed after the request. */
324
0
  return zend_add_interned_string(ret, &CG(interned_strings), 0);
325
0
}
326
327
static zend_string* ZEND_FASTCALL zend_string_init_existing_interned_request(const char *str, size_t size, bool permanent)
328
0
{
329
0
  zend_ulong h = zend_inline_hash_func(str, size);
330
0
  zend_string *ret = zend_interned_string_ht_lookup_ex(h, str, size, &interned_strings_permanent);
331
0
  if (ret) {
332
0
    return ret;
333
0
  }
334
335
0
  ret = zend_interned_string_ht_lookup_ex(h, str, size, &CG(interned_strings));
336
0
  if (ret) {
337
0
    return ret;
338
0
  }
339
340
0
  ZEND_ASSERT(!permanent);
341
0
  ret = zend_string_init(str, size, permanent);
342
0
  ZSTR_H(ret) = h;
343
0
  return ret;
344
0
}
345
346
ZEND_API void zend_interned_strings_activate(void)
347
222k
{
348
222k
  zend_init_interned_strings_ht(&CG(interned_strings), false);
349
222k
}
350
351
ZEND_API void zend_interned_strings_deactivate(void)
352
222k
{
353
222k
  zend_hash_destroy(&CG(interned_strings));
354
222k
}
355
356
ZEND_API void zend_interned_strings_set_request_storage_handlers(zend_new_interned_string_func_t handler, zend_string_init_interned_func_t init_handler, zend_string_init_existing_interned_func_t init_existing_handler)
357
14
{
358
14
  interned_string_request_handler = handler;
359
14
  interned_string_init_request_handler = init_handler;
360
14
  interned_string_init_existing_request_handler = init_existing_handler;
361
14
}
362
363
ZEND_API void zend_interned_strings_switch_storage(bool request)
364
14
{
365
14
  if (request) {
366
14
    zend_new_interned_string = interned_string_request_handler;
367
14
    zend_string_init_interned = interned_string_init_request_handler;
368
14
    zend_string_init_existing_interned = interned_string_init_existing_request_handler;
369
14
  } else {
370
0
    zend_new_interned_string = zend_new_interned_string_permanent;
371
0
    zend_string_init_interned = zend_string_init_interned_permanent;
372
0
    zend_string_init_existing_interned = zend_string_init_existing_interned_permanent;
373
0
  }
374
14
}
375
376
#if defined(__GNUC__) && (defined(__i386__) || (defined(__x86_64__) && !defined(__ILP32__)))
377
/* Even if we don't build with valgrind support, include the symbol so that valgrind available
378
 * only at runtime will not result in false positives. */
379
#ifndef I_REPLACE_SONAME_FNNAME_ZU
380
# define I_REPLACE_SONAME_FNNAME_ZU(soname, fnname) _vgr00000ZU_ ## soname ## _ ## fnname
381
#endif
382
383
/* See GH-9068 */
384
#if __has_attribute(noipa)
385
# define NOIPA __attribute__((noipa))
386
#else
387
# define NOIPA
388
#endif
389
390
ZEND_API bool ZEND_FASTCALL I_REPLACE_SONAME_FNNAME_ZU(NONE,zend_string_equal_val)(const zend_string *s1, const zend_string *s2)
391
0
{
392
0
  return !memcmp(ZSTR_VAL(s1), ZSTR_VAL(s2), ZSTR_LEN(s1));
393
0
}
394
#endif
395
396
#if defined(__GNUC__) && defined(__i386__)
397
ZEND_API zend_never_inline NOIPA bool ZEND_FASTCALL zend_string_equal_val(const zend_string *s1, const zend_string *s2)
398
{
399
  const char *ptr = ZSTR_VAL(s1);
400
  uintptr_t delta = (uintptr_t) s2 - (uintptr_t) s1;
401
  size_t len = ZSTR_LEN(s1);
402
  zend_ulong ret;
403
404
  __asm__ (
405
    "0:\n\t"
406
    "movl (%2,%3), %0\n\t"
407
    "xorl (%2), %0\n\t"
408
    "jne 1f\n\t"
409
    "addl $0x4, %2\n\t"
410
    "subl $0x4, %1\n\t"
411
    "ja 0b\n\t"
412
    "movl $0x1, %0\n\t"
413
    "jmp 3f\n\t"
414
    "1:\n\t"
415
    "cmpl $0x4,%1\n\t"
416
    "jb 2f\n\t"
417
    "xorl %0, %0\n\t"
418
    "jmp 3f\n\t"
419
    "2:\n\t"
420
    "negl %1\n\t"
421
    "lea 0x20(,%1,8), %1\n\t"
422
    "shll %b1, %0\n\t"
423
    "sete %b0\n\t"
424
    "movzbl %b0, %0\n\t"
425
    "3:\n"
426
    : "=&a"(ret),
427
      "+c"(len),
428
      "+r"(ptr)
429
    : "r"(delta)
430
    : "cc");
431
  return ret;
432
}
433
434
#elif defined(__GNUC__) && defined(__x86_64__) && !defined(__ILP32__)
435
ZEND_API zend_never_inline NOIPA bool ZEND_FASTCALL zend_string_equal_val(const zend_string *s1, const zend_string *s2)
436
5.35M
{
437
5.35M
  const char *ptr = ZSTR_VAL(s1);
438
5.35M
  uintptr_t delta = (uintptr_t) s2 - (uintptr_t) s1;
439
5.35M
  size_t len = ZSTR_LEN(s1);
440
5.35M
  zend_ulong ret;
441
442
5.35M
  __asm__ (
443
5.35M
    "0:\n\t"
444
5.35M
    "movq (%2,%3), %0\n\t"
445
5.35M
    "xorq (%2), %0\n\t"
446
5.35M
    "jne 1f\n\t"
447
5.35M
    "addq $0x8, %2\n\t"
448
5.35M
    "subq $0x8, %1\n\t"
449
5.35M
    "ja 0b\n\t"
450
5.35M
    "movq $0x1, %0\n\t"
451
5.35M
    "jmp 3f\n\t"
452
5.35M
    "1:\n\t"
453
5.35M
    "cmpq $0x8,%1\n\t"
454
5.35M
    "jb 2f\n\t"
455
5.35M
    "xorq %0, %0\n\t"
456
5.35M
    "jmp 3f\n\t"
457
5.35M
    "2:\n\t"
458
5.35M
    "negq %1\n\t"
459
5.35M
    "lea 0x40(,%1,8), %1\n\t"
460
5.35M
    "shlq %b1, %0\n\t"
461
5.35M
    "sete %b0\n\t"
462
5.35M
    "movzbq %b0, %0\n\t"
463
5.35M
    "3:\n"
464
5.35M
    : "=&a"(ret),
465
5.35M
      "+c"(len),
466
5.35M
      "+r"(ptr)
467
5.35M
    : "r"(delta)
468
5.35M
    : "cc");
469
5.35M
  return ret;
470
5.35M
}
471
#endif
472
473
ZEND_API zend_string *zend_string_concat2(
474
    const char *str1, size_t str1_len,
475
    const char *str2, size_t str2_len)
476
75.3k
{
477
75.3k
  size_t len = str1_len + str2_len;
478
75.3k
  zend_string *res = zend_string_alloc(len, 0);
479
480
75.3k
  memcpy(ZSTR_VAL(res), str1, str1_len);
481
75.3k
  memcpy(ZSTR_VAL(res) + str1_len, str2, str2_len);
482
75.3k
  ZSTR_VAL(res)[len] = '\0';
483
484
75.3k
  return res;
485
75.3k
}
486
487
ZEND_API zend_string *zend_string_concat3(
488
    const char *str1, size_t str1_len,
489
    const char *str2, size_t str2_len,
490
    const char *str3, size_t str3_len)
491
15.3M
{
492
15.3M
  size_t len = str1_len + str2_len + str3_len;
493
15.3M
  zend_string *res = zend_string_alloc(len, 0);
494
495
15.3M
  memcpy(ZSTR_VAL(res), str1, str1_len);
496
15.3M
  memcpy(ZSTR_VAL(res) + str1_len, str2, str2_len);
497
15.3M
  memcpy(ZSTR_VAL(res) + str1_len + str2_len, str3, str3_len);
498
15.3M
  ZSTR_VAL(res)[len] = '\0';
499
500
15.3M
  return res;
501
15.3M
}
502
503
/* strlcpy and strlcat are not always intercepted by msan, so we need to do it
504
 * ourselves. Apply a simple heuristic to determine the platforms that need it.
505
 * See https://github.com/php/php-src/issues/20002. */
506
#if __has_feature(memory_sanitizer) && !defined(__FreeBSD__) && !defined(__NetBSD__) && !defined(__APPLE__)
507
static size_t (*libc_strlcpy)(char *__restrict, const char *__restrict, size_t);
508
size_t strlcpy(char *__restrict dest, const char *__restrict src, size_t n)
509
{
510
  if (!libc_strlcpy) {
511
    libc_strlcpy = dlsym(RTLD_NEXT, "strlcpy");
512
  }
513
  size_t result = libc_strlcpy(dest, src, n);
514
  __msan_unpoison_string(dest);
515
  return result;
516
}
517
static size_t (*libc_strlcat)(char *__restrict, const char *__restrict, size_t);
518
size_t strlcat (char *__restrict dest, const char *restrict src, size_t n)
519
{
520
  if (!libc_strlcat) {
521
    libc_strlcat = dlsym(RTLD_NEXT, "strlcat");
522
  }
523
  size_t result = libc_strlcat(dest, src, n);
524
  __msan_unpoison_string(dest);
525
  return result;
526
}
527
#endif