Coverage Report

Created: 2026-04-01 06:49

next uncovered line (L), next uncovered region (R), next uncovered branch (B)
/src/php-src/Zend/zend_objects.c
Line
Count
Source
1
/*
2
   +----------------------------------------------------------------------+
3
   | Zend Engine                                                          |
4
   +----------------------------------------------------------------------+
5
   | Copyright (c) Zend Technologies Ltd. (http://www.zend.com)           |
6
   +----------------------------------------------------------------------+
7
   | This source file is subject to version 2.00 of the Zend license,     |
8
   | that is bundled with this package in the file LICENSE, and is        |
9
   | available through the world-wide-web at the following url:           |
10
   | http://www.zend.com/license/2_00.txt.                                |
11
   | If you did not receive a copy of the Zend license and are unable to  |
12
   | obtain it through the world-wide-web, please send a note to          |
13
   | license@zend.com so we can mail you a copy immediately.              |
14
   +----------------------------------------------------------------------+
15
   | Authors: Andi Gutmans <andi@php.net>                                 |
16
   |          Zeev Suraski <zeev@php.net>                                 |
17
   |          Dmitry Stogov <dmitry@php.net>                              |
18
   +----------------------------------------------------------------------+
19
*/
20
21
#include "zend.h"
22
#include "zend_globals.h"
23
#include "zend_variables.h"
24
#include "zend_API.h"
25
#include "zend_interfaces.h"
26
#include "zend_exceptions.h"
27
#include "zend_weakrefs.h"
28
#include "zend_lazy_objects.h"
29
30
static zend_always_inline void _zend_object_std_init(zend_object *object, zend_class_entry *ce)
31
3.98M
{
32
3.98M
  GC_SET_REFCOUNT(object, 1);
33
3.98M
  GC_TYPE_INFO(object) = GC_OBJECT;
34
3.98M
  object->ce = ce;
35
3.98M
  object->extra_flags = 0;
36
3.98M
  object->handlers = ce->default_object_handlers;
37
3.98M
  object->properties = NULL;
38
3.98M
  zend_objects_store_put(object);
39
3.98M
  if (UNEXPECTED(ce->ce_flags & ZEND_ACC_USE_GUARDS)) {
40
336k
    zval *guard_value = object->properties_table + object->ce->default_properties_count;
41
336k
    ZVAL_UNDEF(guard_value);
42
336k
    Z_GUARD_P(guard_value) = 0;
43
336k
  }
44
3.98M
}
45
46
ZEND_API void ZEND_FASTCALL zend_object_std_init(zend_object *object, zend_class_entry *ce)
47
1.06M
{
48
1.06M
  _zend_object_std_init(object, ce);
49
1.06M
}
50
51
void zend_object_dtor_dynamic_properties(zend_object *object)
52
3.98M
{
53
3.98M
  if (object->properties) {
54
713k
    if (EXPECTED(!(GC_FLAGS(object->properties) & IS_ARRAY_IMMUTABLE))) {
55
713k
      if (EXPECTED(GC_DELREF(object->properties) == 0)
56
713k
          && EXPECTED(GC_TYPE(object->properties) != IS_NULL)) {
57
713k
        zend_array_destroy(object->properties);
58
713k
      }
59
713k
    }
60
713k
  }
61
3.98M
}
62
63
void zend_object_dtor_property(zend_object *object, zval *p)
64
6.21M
{
65
6.21M
  if (Z_REFCOUNTED_P(p)) {
66
2.59M
    if (UNEXPECTED(Z_ISREF_P(p)) &&
67
26.8k
        (ZEND_DEBUG || ZEND_REF_HAS_TYPE_SOURCES(Z_REF_P(p)))) {
68
26.8k
      zend_property_info *prop_info = zend_get_property_info_for_slot_self(object, p);
69
26.8k
      if (ZEND_TYPE_IS_SET(prop_info->type)) {
70
26.3k
        ZEND_REF_DEL_TYPE_SOURCE(Z_REF_P(p), prop_info);
71
26.3k
      }
72
26.8k
    }
73
2.59M
    i_zval_ptr_dtor(p);
74
2.59M
  }
75
6.21M
}
76
77
ZEND_API void zend_object_std_dtor(zend_object *object)
78
3.98M
{
79
3.98M
  zval *p, *end;
80
81
3.98M
  if (UNEXPECTED(GC_FLAGS(object) & IS_OBJ_WEAKLY_REFERENCED)) {
82
441
    zend_weakrefs_notify(object);
83
441
  }
84
85
3.98M
  if (UNEXPECTED(zend_object_is_lazy(object))) {
86
1.55k
    zend_lazy_object_del_info(object);
87
1.55k
  }
88
89
3.98M
  zend_object_dtor_dynamic_properties(object);
90
91
3.98M
  p = object->properties_table;
92
3.98M
  if (EXPECTED(object->ce->default_properties_count)) {
93
913k
    end = p + object->ce->default_properties_count;
94
6.20M
    do {
95
6.20M
      zend_object_dtor_property(object, p);
96
6.20M
      p++;
97
6.20M
    } while (p != end);
98
913k
  }
99
100
3.98M
  if (UNEXPECTED(object->ce->ce_flags & ZEND_ACC_USE_GUARDS)) {
101
336k
    if (EXPECTED(Z_TYPE_P(p) == IS_STRING)) {
102
1.09k
      zval_ptr_dtor_str(p);
103
335k
    } else if (Z_TYPE_P(p) == IS_ARRAY) {
104
198
      HashTable *guards;
105
106
198
      guards = Z_ARRVAL_P(p);
107
198
      ZEND_ASSERT(guards != NULL);
108
198
      zend_hash_destroy(guards);
109
198
      FREE_HASHTABLE(guards);
110
198
    }
111
336k
  }
112
3.98M
}
113
114
ZEND_API void zend_objects_destroy_object(zend_object *object)
115
55.1k
{
116
55.1k
  zend_function *destructor = object->ce->destructor;
117
118
55.1k
  if (destructor) {
119
55.1k
    if (UNEXPECTED(zend_object_is_lazy(object))) {
120
146
      return;
121
146
    }
122
123
55.0k
    zend_object *old_exception;
124
55.0k
    const zend_op *old_opline_before_exception = NULL;
125
126
55.0k
    if (destructor->common.fn_flags & (ZEND_ACC_PRIVATE|ZEND_ACC_PROTECTED)) {
127
0
      if (EG(current_execute_data)) {
128
0
        zend_class_entry *scope = zend_get_executed_scope();
129
        /* Ensure that if we're calling a protected or private function, we're allowed to do so. */
130
0
        ZEND_ASSERT(!(destructor->common.fn_flags & ZEND_ACC_PUBLIC));
131
0
        if (!zend_check_method_accessible(destructor, scope)) {
132
0
          zend_throw_error(NULL,
133
0
            "Call to %s %s::__destruct() from %s%s",
134
0
            zend_visibility_string(destructor->common.fn_flags), ZSTR_VAL(object->ce->name),
135
0
            scope ? "scope " : "global scope",
136
0
            scope ? ZSTR_VAL(scope->name) : ""
137
0
          );
138
0
          return;
139
0
        }
140
0
      } else {
141
0
        zend_error(E_WARNING,
142
0
          "Call to %s %s::__destruct() from global scope during shutdown ignored",
143
0
          zend_visibility_string(destructor->common.fn_flags), ZSTR_VAL(object->ce->name));
144
0
        return;
145
0
      }
146
0
    }
147
148
55.0k
    GC_ADDREF(object);
149
150
    /* Make sure that destructors are protected from previously thrown exceptions.
151
     * For example, if an exception was thrown in a function and when the function's
152
     * local variable destruction results in a destructor being called.
153
     */
154
55.0k
    old_exception = NULL;
155
55.0k
    if (EG(exception)) {
156
43.1k
      if (EG(exception) == object) {
157
0
        zend_error_noreturn(E_CORE_ERROR, "Attempt to destruct pending exception");
158
43.1k
      } else {
159
43.1k
        if (EG(current_execute_data)) {
160
14.5k
          if (EG(current_execute_data)->func
161
14.5k
           && ZEND_USER_CODE(EG(current_execute_data)->func->common.type)) {
162
14.4k
            zend_rethrow_exception(EG(current_execute_data));
163
14.4k
          }
164
14.5k
          EG(current_execute_data)->opline = EG(opline_before_exception);
165
14.5k
          old_opline_before_exception = EG(opline_before_exception);
166
14.5k
        }
167
43.1k
        old_exception = EG(exception);
168
43.1k
        EG(exception) = NULL;
169
43.1k
      }
170
43.1k
    }
171
172
55.0k
    zend_call_known_instance_method_with_0_params(destructor, object, NULL);
173
174
55.0k
    if (old_exception) {
175
349
      if (EG(current_execute_data)) {
176
344
        EG(current_execute_data)->opline = EG(exception_op);
177
344
        EG(opline_before_exception) = old_opline_before_exception;
178
344
      }
179
349
      if (EG(exception)) {
180
223
        zend_exception_set_previous(EG(exception), old_exception);
181
223
      } else {
182
126
        EG(exception) = old_exception;
183
126
      }
184
349
    }
185
55.0k
    OBJ_RELEASE(object);
186
55.0k
  }
187
55.1k
}
188
189
ZEND_API zend_object* ZEND_FASTCALL zend_objects_new(zend_class_entry *ce)
190
2.91M
{
191
2.91M
  zend_object *object = emalloc(sizeof(zend_object) + zend_object_properties_size(ce));
192
193
2.91M
  _zend_object_std_init(object, ce);
194
2.91M
  return object;
195
2.91M
}
196
197
ZEND_API void ZEND_FASTCALL zend_objects_clone_members(zend_object *new_object, zend_object *old_object)
198
883
{
199
883
  bool has_clone_method = old_object->ce->clone != NULL;
200
201
883
  if (old_object->ce->default_properties_count) {
202
411
    zval *src = old_object->properties_table;
203
411
    zval *dst = new_object->properties_table;
204
411
    zval *end = src + old_object->ce->default_properties_count;
205
206
793
    do {
207
793
      i_zval_ptr_dtor(dst);
208
793
      ZVAL_COPY_VALUE_PROP(dst, src);
209
793
      zval_add_ref(dst);
210
793
      if (has_clone_method) {
211
        /* Unconditionally add the IS_PROP_REINITABLE flag to avoid a potential cache miss of property_info */
212
193
        Z_PROP_FLAG_P(dst) |= IS_PROP_REINITABLE;
213
193
      }
214
215
793
      if (UNEXPECTED(Z_ISREF_P(dst)) &&
216
8
          (ZEND_DEBUG || ZEND_REF_HAS_TYPE_SOURCES(Z_REF_P(dst)))) {
217
8
        zend_property_info *prop_info = zend_get_property_info_for_slot_self(new_object, dst);
218
8
        if (ZEND_TYPE_IS_SET(prop_info->type)) {
219
8
          ZEND_REF_ADD_TYPE_SOURCE(Z_REF_P(dst), prop_info);
220
8
        }
221
8
      }
222
793
      src++;
223
793
      dst++;
224
793
    } while (src != end);
225
472
  } else if (old_object->properties && !has_clone_method) {
226
    /* fast copy */
227
172
    if (EXPECTED(old_object->handlers == &std_object_handlers)) {
228
172
      if (EXPECTED(!(GC_FLAGS(old_object->properties) & IS_ARRAY_IMMUTABLE))) {
229
172
        GC_ADDREF(old_object->properties);
230
172
      }
231
172
      new_object->properties = old_object->properties;
232
172
      return;
233
172
    }
234
172
  }
235
236
711
  if (old_object->properties &&
237
34
      EXPECTED(zend_hash_num_elements(old_object->properties))) {
238
33
    zval *prop, new_prop;
239
33
    zend_ulong num_key;
240
33
    zend_string *key;
241
242
33
    if (!new_object->properties) {
243
33
      new_object->properties = zend_new_array(zend_hash_num_elements(old_object->properties));
244
33
      zend_hash_real_init_mixed(new_object->properties);
245
33
    } else {
246
0
      zend_hash_extend(new_object->properties, new_object->properties->nNumUsed + zend_hash_num_elements(old_object->properties), 0);
247
0
    }
248
249
33
    HT_FLAGS(new_object->properties) |=
250
33
      HT_FLAGS(old_object->properties) & HASH_FLAG_HAS_EMPTY_IND;
251
252
158
    ZEND_HASH_MAP_FOREACH_KEY_VAL(old_object->properties, num_key, key, prop) {
253
158
      if (Z_TYPE_P(prop) == IS_INDIRECT) {
254
32
        ZVAL_INDIRECT(&new_prop, new_object->properties_table + (Z_INDIRECT_P(prop) - old_object->properties_table));
255
32
      } else {
256
14
        ZVAL_COPY_VALUE(&new_prop, prop);
257
14
        zval_add_ref(&new_prop);
258
14
      }
259
158
      if (has_clone_method) {
260
        /* Unconditionally add the IS_PROP_REINITABLE flag to avoid a potential cache miss of property_info */
261
33
        Z_PROP_FLAG_P(&new_prop) |= IS_PROP_REINITABLE;
262
33
      }
263
158
      if (EXPECTED(key)) {
264
46
        _zend_hash_append(new_object->properties, key, &new_prop);
265
46
      } else {
266
0
        zend_hash_index_add_new(new_object->properties, num_key, &new_prop);
267
0
      }
268
158
    } ZEND_HASH_FOREACH_END();
269
33
  }
270
271
711
  if (has_clone_method) {
272
221
    zend_call_known_instance_method_with_0_params(new_object->ce->clone, new_object, NULL);
273
274
221
    if (ZEND_CLASS_HAS_READONLY_PROPS(new_object->ce)) {
275
267
      for (uint32_t i = 0; i < new_object->ce->default_properties_count; i++) {
276
145
        zval* prop = OBJ_PROP_NUM(new_object, i);
277
        /* Unconditionally remove the IS_PROP_REINITABLE flag to avoid a potential cache miss of property_info */
278
145
        Z_PROP_FLAG_P(prop) &= ~IS_PROP_REINITABLE;
279
145
      }
280
122
    }
281
221
  }
282
711
}
283
284
ZEND_API zend_object *zend_objects_clone_obj_with(zend_object *old_object, const zend_class_entry *scope, const HashTable *properties)
285
192
{
286
192
  zend_object *new_object = old_object->handlers->clone_obj(old_object);
287
288
192
  if (EXPECTED(!EG(exception))) {
289
    /* Unlock readonly properties once more. */
290
192
    if (ZEND_CLASS_HAS_READONLY_PROPS(new_object->ce)) {
291
66
      for (uint32_t i = 0; i < new_object->ce->default_properties_count; i++) {
292
44
        zval* prop = OBJ_PROP_NUM(new_object, i);
293
44
        Z_PROP_FLAG_P(prop) |= IS_PROP_REINITABLE;
294
44
      }
295
22
    }
296
297
192
    const zend_class_entry *old_scope = EG(fake_scope);
298
299
192
    EG(fake_scope) = scope;
300
301
874
    ZEND_HASH_FOREACH_KEY_VAL(properties, zend_ulong num_key, zend_string *key, zval *val) {
302
874
      if (UNEXPECTED(Z_ISREF_P(val))) {
303
13
        if (Z_REFCOUNT_P(val) == 1) {
304
6
          val = Z_REFVAL_P(val);
305
7
        } else {
306
7
          zend_throw_error(NULL, "Cannot assign by reference when cloning with updated properties");
307
7
          break;
308
7
        }
309
13
      }
310
311
334
      if (UNEXPECTED(key == NULL)) {
312
16
        key = zend_long_to_str(num_key);
313
16
        new_object->handlers->write_property(new_object, key, val, NULL);
314
16
        zend_string_release_ex(key, false);
315
318
      } else {
316
318
        new_object->handlers->write_property(new_object, key, val, NULL);
317
318
      }
318
319
334
      if (UNEXPECTED(EG(exception))) {
320
74
        break;
321
74
      }
322
334
    } ZEND_HASH_FOREACH_END();
323
324
192
    EG(fake_scope) = old_scope;
325
192
  }
326
327
192
  return new_object;
328
192
}
329
330
ZEND_API zend_object *zend_objects_clone_obj(zend_object *old_object)
331
934
{
332
934
  zend_object *new_object;
333
334
934
  if (UNEXPECTED(zend_object_is_lazy(old_object))) {
335
66
    return zend_lazy_object_clone(old_object);
336
66
  }
337
338
  /* assume that create isn't overwritten, so when clone depends on the
339
   * overwritten one then it must itself be overwritten */
340
868
  new_object = zend_objects_new(old_object->ce);
341
342
  /* zend_objects_clone_members() expect the properties to be initialized. */
343
868
  if (new_object->ce->default_properties_count) {
344
411
    zval *p = new_object->properties_table;
345
411
    zval *end = p + new_object->ce->default_properties_count;
346
793
    do {
347
793
      ZVAL_UNDEF(p);
348
793
      p++;
349
793
    } while (p != end);
350
411
  }
351
352
868
  zend_objects_clone_members(new_object, old_object);
353
354
868
  return new_object;
355
934
}