Coverage Report

Created: 2026-09-14 06:25

next uncovered line (L), next uncovered region (R), next uncovered branch (B)
/src/php-src/Zend/zend_objects_API.c
Line
Count
Source
1
/*
2
   +----------------------------------------------------------------------+
3
   | Zend Engine                                                          |
4
   +----------------------------------------------------------------------+
5
   | Copyright © Zend Technologies Ltd., a subsidiary company of          |
6
   |     Perforce Software, Inc., and Contributors.                       |
7
   +----------------------------------------------------------------------+
8
   | This source file is subject to the Modified BSD License that is      |
9
   | bundled with this package in the file LICENSE, and is available      |
10
   | through the World Wide Web at <https://www.php.net/license/>.        |
11
   |                                                                      |
12
   | SPDX-License-Identifier: BSD-3-Clause                                |
13
   +----------------------------------------------------------------------+
14
   | Authors: Andi Gutmans <andi@php.net>                                 |
15
   |          Zeev Suraski <zeev@php.net>                                 |
16
   |          Dmitry Stogov <dmitry@php.net>                              |
17
   +----------------------------------------------------------------------+
18
*/
19
20
#include "zend.h"
21
#include "zend_globals.h"
22
#include "zend_variables.h"
23
#include "zend_API.h"
24
#include "zend_objects_API.h"
25
#include "zend_fibers.h"
26
27
ZEND_API void ZEND_FASTCALL zend_objects_store_init(zend_objects_store *objects, uint32_t init_size)
28
295k
{
29
295k
  objects->object_buckets = (zend_object **) emalloc(init_size * sizeof(zend_object*));
30
295k
  objects->top = 1; /* Skip 0 so that handles are true */
31
295k
  objects->size = init_size;
32
295k
  objects->free_list_head = -1;
33
295k
  memset(&objects->object_buckets[0], 0, sizeof(zend_object*));
34
295k
}
35
36
ZEND_API void ZEND_FASTCALL zend_objects_store_destroy(zend_objects_store *objects)
37
295k
{
38
295k
  efree(objects->object_buckets);
39
295k
  objects->object_buckets = NULL;
40
295k
}
41
42
ZEND_API void ZEND_FASTCALL zend_objects_store_call_destructors(zend_objects_store *objects)
43
295k
{
44
295k
  EG(flags) |= EG_FLAGS_OBJECT_STORE_NO_REUSE;
45
295k
  if (objects->top > 1) {
46
2.96M
    for (uint32_t i = 1; i < objects->top; i++) {
47
2.77M
      zend_object *obj = objects->object_buckets[i];
48
2.77M
      if (IS_OBJ_VALID(obj)) {
49
42.4k
        if (!(OBJ_FLAGS(obj) & IS_OBJ_DESTRUCTOR_CALLED)) {
50
35.8k
          GC_ADD_FLAGS(obj, IS_OBJ_DESTRUCTOR_CALLED);
51
52
35.8k
          if (obj->handlers->dtor_obj != zend_objects_destroy_object
53
32.8k
              || obj->ce->destructor) {
54
4.23k
            GC_ADDREF(obj);
55
4.23k
            obj->handlers->dtor_obj(obj);
56
4.23k
            GC_DELREF(obj);
57
4.23k
          }
58
35.8k
        }
59
42.4k
      }
60
2.77M
    }
61
188k
  }
62
295k
}
63
64
ZEND_API void ZEND_FASTCALL zend_objects_store_mark_destructed(zend_objects_store *objects)
65
7.84k
{
66
7.84k
  if (objects->object_buckets && objects->top > 1) {
67
1.26k
    zend_object **obj_ptr = objects->object_buckets + 1;
68
1.26k
    zend_object **end = objects->object_buckets + objects->top;
69
70
185k
    do {
71
185k
      zend_object *obj = *obj_ptr;
72
73
185k
      if (IS_OBJ_VALID(obj)) {
74
183k
        GC_ADD_FLAGS(obj, IS_OBJ_DESTRUCTOR_CALLED);
75
183k
      }
76
185k
      obj_ptr++;
77
185k
    } while (obj_ptr != end);
78
1.26k
  }
79
7.84k
}
80
81
ZEND_API void ZEND_FASTCALL zend_objects_store_free_object_storage(zend_objects_store *objects, bool fast_shutdown)
82
295k
{
83
295k
  zend_object **obj_ptr, **end, *obj;
84
85
295k
  if (objects->top <= 1) {
86
107k
    return;
87
107k
  }
88
89
  /* Free object contents, but don't free objects themselves, so they show up as leaks.
90
   * Also add a ref to all objects, so the object can't be freed by something else later. */
91
188k
  end = objects->object_buckets + 1;
92
188k
  obj_ptr = objects->object_buckets + objects->top;
93
94
188k
  if (fast_shutdown) {
95
0
    do {
96
0
      obj_ptr--;
97
0
      obj = *obj_ptr;
98
0
      if (IS_OBJ_VALID(obj)) {
99
0
        if (!(OBJ_FLAGS(obj) & IS_OBJ_FREE_CALLED)) {
100
0
          GC_ADD_FLAGS(obj, IS_OBJ_FREE_CALLED);
101
0
          if (obj->handlers->free_obj != zend_object_std_dtor
102
0
           || (OBJ_FLAGS(obj) & IS_OBJ_WEAKLY_REFERENCED)
103
0
          ) {
104
0
            GC_ADDREF(obj);
105
0
            obj->handlers->free_obj(obj);
106
0
          }
107
0
        }
108
0
      }
109
0
    } while (obj_ptr != end);
110
188k
  } else {
111
2.89M
    do {
112
2.89M
      obj_ptr--;
113
2.89M
      obj = *obj_ptr;
114
2.89M
      if (IS_OBJ_VALID(obj)) {
115
144k
        if (!(OBJ_FLAGS(obj) & IS_OBJ_FREE_CALLED)) {
116
144k
          GC_ADD_FLAGS(obj, IS_OBJ_FREE_CALLED);
117
144k
          GC_ADDREF(obj);
118
144k
          obj->handlers->free_obj(obj);
119
144k
        }
120
144k
      }
121
2.89M
    } while (obj_ptr != end);
122
188k
  }
123
188k
}
124
125
126
/* Store objects API */
127
static ZEND_COLD zend_never_inline void ZEND_FASTCALL zend_objects_store_put_cold(zend_object *object)
128
483
{
129
483
  uint32_t new_size = 2 * EG(objects_store).size;
130
131
483
  EG(objects_store).object_buckets = (zend_object **) erealloc(EG(objects_store).object_buckets, new_size * sizeof(zend_object*));
132
  /* Assign size after realloc, in case it fails */
133
483
  EG(objects_store).size = new_size;
134
483
  uint32_t handle = EG(objects_store).top++;
135
483
  object->handle = handle;
136
483
  EG(objects_store).object_buckets[handle] = object;
137
483
}
138
139
ZEND_API void ZEND_FASTCALL zend_objects_store_put(zend_object *object)
140
3.82M
{
141
3.82M
  uint32_t handle;
142
143
  /* When in shutdown sequence - do not reuse previously freed handles, to make sure
144
   * the dtors for newly created objects are called in zend_objects_store_call_destructors() loop
145
   */
146
3.82M
  if (EG(objects_store).free_list_head != -1 && EXPECTED(!(EG(flags) & EG_FLAGS_OBJECT_STORE_NO_REUSE))) {
147
923k
    handle = EG(objects_store).free_list_head;
148
923k
    EG(objects_store).free_list_head = GET_OBJ_BUCKET_NUMBER(EG(objects_store).object_buckets[handle]);
149
2.89M
  } else if (UNEXPECTED(EG(objects_store).top == EG(objects_store).size)) {
150
483
    zend_objects_store_put_cold(object);
151
483
    return;
152
2.89M
  } else {
153
2.89M
    handle = EG(objects_store).top++;
154
2.89M
  }
155
3.82M
  object->handle = handle;
156
3.82M
  EG(objects_store).object_buckets[handle] = object;
157
3.82M
}
158
159
ZEND_API void ZEND_FASTCALL zend_objects_store_del(zend_object *object) /* {{{ */
160
3.69M
{
161
3.69M
  ZEND_ASSERT(GC_REFCOUNT(object) == 0);
162
163
  /* GC might have released this object already. */
164
3.69M
  if (UNEXPECTED(GC_TYPE(object) == IS_NULL)) {
165
588
    return;
166
588
  }
167
168
  /*  Make sure we hold a reference count during the destructor call
169
    otherwise, when the destructor ends the storage might be freed
170
    when the refcount reaches 0 a second time
171
   */
172
3.69M
  if (!(OBJ_FLAGS(object) & IS_OBJ_DESTRUCTOR_CALLED)) {
173
3.12M
    GC_ADD_FLAGS(object, IS_OBJ_DESTRUCTOR_CALLED);
174
175
3.12M
    if (object->handlers->dtor_obj != zend_objects_destroy_object
176
3.11M
        || object->ce->destructor) {
177
73.7k
      GC_SET_REFCOUNT(object, 1);
178
73.7k
      object->handlers->dtor_obj(object);
179
73.7k
      GC_DELREF(object);
180
73.7k
    }
181
3.12M
  }
182
183
3.69M
  if (GC_REFCOUNT(object) == 0) {
184
3.63M
    uint32_t handle = object->handle;
185
3.63M
    void *ptr;
186
187
3.63M
    ZEND_ASSERT(EG(objects_store).object_buckets != NULL);
188
3.63M
    ZEND_ASSERT(IS_OBJ_VALID(EG(objects_store).object_buckets[handle]));
189
3.63M
    EG(objects_store).object_buckets[handle] = SET_OBJ_INVALID(object);
190
3.63M
    if (!(OBJ_FLAGS(object) & IS_OBJ_FREE_CALLED)) {
191
3.63M
      GC_ADD_FLAGS(object, IS_OBJ_FREE_CALLED);
192
3.63M
      GC_SET_REFCOUNT(object, 1);
193
3.63M
      object->handlers->free_obj(object);
194
3.63M
    }
195
3.63M
    ptr = ((char*)object) - object->handlers->offset;
196
3.63M
    GC_REMOVE_FROM_BUFFER(object);
197
3.63M
    efree(ptr);
198
3.63M
    ZEND_OBJECTS_STORE_ADD_TO_FREE_LIST(handle);
199
3.63M
  }
200
3.69M
}
201
/* }}} */
202
203
ZEND_API ZEND_COLD zend_property_info *zend_get_property_info_for_slot_slow(zend_object *obj, zval *slot)
204
205
{
205
205
  uintptr_t offset = OBJ_PROP_SLOT_TO_OFFSET(obj, slot);
206
205
  zend_property_info *prop_info;
207
820
  ZEND_HASH_MAP_FOREACH_PTR(&obj->ce->properties_info, prop_info) {
208
820
    if (prop_info->offset == offset) {
209
205
      return prop_info;
210
205
    }
211
820
  } ZEND_HASH_FOREACH_END();
212
0
  return NULL;
213
205
}