1/*
2   +----------------------------------------------------------------------+
3   | Zend Engine                                                          |
4   +----------------------------------------------------------------------+
5   | Copyright (c) 1998-2015 Zend Technologies Ltd. (http://www.zend.com) |
6   +----------------------------------------------------------------------+
7   | This source file is subject to version 2.00 of the Zend license,     |
8   | that is bundled with this package in the file LICENSE, and is        |
9   | available through the world-wide-web at the following url:           |
10   | http://www.zend.com/license/2_00.txt.                                |
11   | If you did not receive a copy of the Zend license and are unable to  |
12   | obtain it through the world-wide-web, please send a note to          |
13   | license@zend.com so we can mail you a copy immediately.              |
14   +----------------------------------------------------------------------+
15   | Authors: Andi Gutmans <andi@zend.com>                                |
16   |          Zeev Suraski <zeev@zend.com>                                |
17   +----------------------------------------------------------------------+
18*/
19
20/* $Id$ */
21
22#include <stdio.h>
23
24#include "zend.h"
25#include "zend_alloc.h"
26#include "zend_compile.h"
27#include "zend_extensions.h"
28#include "zend_API.h"
29
30#include "zend_vm.h"
31
32static void zend_extension_op_array_ctor_handler(zend_extension *extension, zend_op_array *op_array)
33{
34    if (extension->op_array_ctor) {
35        extension->op_array_ctor(op_array);
36    }
37}
38
39static void zend_extension_op_array_dtor_handler(zend_extension *extension, zend_op_array *op_array)
40{
41    if (extension->op_array_dtor) {
42        extension->op_array_dtor(op_array);
43    }
44}
45
46static void op_array_alloc_ops(zend_op_array *op_array, uint32_t size)
47{
48    op_array->opcodes = erealloc(op_array->opcodes, size * sizeof(zend_op));
49}
50
51void init_op_array(zend_op_array *op_array, zend_uchar type, int initial_ops_size)
52{
53    op_array->type = type;
54    op_array->arg_flags[0] = 0;
55    op_array->arg_flags[1] = 0;
56    op_array->arg_flags[2] = 0;
57
58    op_array->refcount = (uint32_t *) emalloc(sizeof(uint32_t));
59    *op_array->refcount = 1;
60    op_array->last = 0;
61    op_array->opcodes = NULL;
62    op_array_alloc_ops(op_array, initial_ops_size);
63
64    op_array->last_var = 0;
65    op_array->vars = NULL;
66
67    op_array->T = 0;
68
69    op_array->function_name = NULL;
70    op_array->filename = zend_get_compiled_filename();
71    op_array->doc_comment = NULL;
72
73    op_array->arg_info = NULL;
74    op_array->num_args = 0;
75    op_array->required_num_args = 0;
76
77    op_array->scope = NULL;
78    op_array->prototype = NULL;
79
80    op_array->brk_cont_array = NULL;
81    op_array->try_catch_array = NULL;
82    op_array->last_brk_cont = 0;
83
84    op_array->static_variables = NULL;
85    op_array->last_try_catch = 0;
86
87    op_array->this_var = -1;
88
89    op_array->fn_flags = 0;
90
91    op_array->early_binding = -1;
92
93    op_array->last_literal = 0;
94    op_array->literals = NULL;
95
96    op_array->run_time_cache = NULL;
97    op_array->cache_size = 0;
98
99    memset(op_array->reserved, 0, ZEND_MAX_RESERVED_RESOURCES * sizeof(void*));
100
101    zend_llist_apply_with_argument(&zend_extensions, (llist_apply_with_arg_func_t) zend_extension_op_array_ctor_handler, op_array);
102}
103
104ZEND_API void destroy_zend_function(zend_function *function)
105{
106    if (function->type == ZEND_USER_FUNCTION) {
107        destroy_op_array(&function->op_array);
108    } else {
109        ZEND_ASSERT(function->type == ZEND_INTERNAL_FUNCTION);
110        ZEND_ASSERT(function->common.function_name);
111        zend_string_release(function->common.function_name);
112    }
113}
114
115ZEND_API void zend_function_dtor(zval *zv)
116{
117    zend_function *function = Z_PTR_P(zv);
118
119    if (function->type == ZEND_USER_FUNCTION) {
120        ZEND_ASSERT(function->common.function_name);
121        destroy_op_array(&function->op_array);
122        /* op_arrays are allocated on arena, so we don't have to free them */
123    } else {
124        ZEND_ASSERT(function->type == ZEND_INTERNAL_FUNCTION);
125        ZEND_ASSERT(function->common.function_name);
126        zend_string_release(function->common.function_name);
127        if (!(function->common.fn_flags & ZEND_ACC_ARENA_ALLOCATED)) {
128            pefree(function, 1);
129        }
130    }
131}
132
133ZEND_API void zend_cleanup_op_array_data(zend_op_array *op_array)
134{
135    if (op_array->static_variables &&
136        !(GC_FLAGS(op_array->static_variables) & IS_ARRAY_IMMUTABLE)) {
137        zend_hash_clean(op_array->static_variables);
138    }
139}
140
141ZEND_API void zend_cleanup_user_class_data(zend_class_entry *ce)
142{
143    /* Clean all parts that can contain run-time data */
144    /* Note that only run-time accessed data need to be cleaned up, pre-defined data can
145       not contain objects and thus are not probelmatic */
146    if (ce->ce_flags & ZEND_HAS_STATIC_IN_METHODS) {
147        zend_function *func;
148
149        ZEND_HASH_FOREACH_PTR(&ce->function_table, func) {
150            if (func->type == ZEND_USER_FUNCTION) {
151                zend_cleanup_op_array_data((zend_op_array *) func);
152            }
153        } ZEND_HASH_FOREACH_END();
154    }
155    if (ce->static_members_table) {
156        zval *static_members = ce->static_members_table;
157        zval *p = static_members;
158        zval *end = p + ce->default_static_members_count;
159
160
161        ce->default_static_members_count = 0;
162        ce->default_static_members_table = ce->static_members_table = NULL;
163        while (p != end) {
164            i_zval_ptr_dtor(p ZEND_FILE_LINE_CC);
165            p++;
166        }
167        efree(static_members);
168    }
169}
170
171ZEND_API void zend_cleanup_internal_class_data(zend_class_entry *ce)
172{
173    if (CE_STATIC_MEMBERS(ce)) {
174        zval *static_members = CE_STATIC_MEMBERS(ce);
175        zval *p = static_members;
176        zval *end = p + ce->default_static_members_count;
177
178#ifdef ZTS
179        CG(static_members_table)[(zend_intptr_t)(ce->static_members_table)] = NULL;
180#else
181        ce->static_members_table = NULL;
182#endif
183        ce->ce_flags &= ~ZEND_ACC_CONSTANTS_UPDATED;
184        while (p != end) {
185            i_zval_ptr_dtor(p ZEND_FILE_LINE_CC);
186            p++;
187        }
188        efree(static_members);
189    }
190}
191
192void _destroy_zend_class_traits_info(zend_class_entry *ce)
193{
194    if (ce->num_traits > 0 && ce->traits) {
195        efree(ce->traits);
196    }
197
198    if (ce->trait_aliases) {
199        size_t i = 0;
200        while (ce->trait_aliases[i]) {
201            if (ce->trait_aliases[i]->trait_method) {
202                if (ce->trait_aliases[i]->trait_method->method_name) {
203                    zend_string_release(ce->trait_aliases[i]->trait_method->method_name);
204                }
205                if (ce->trait_aliases[i]->trait_method->class_name) {
206                    zend_string_release(ce->trait_aliases[i]->trait_method->class_name);
207                }
208                efree(ce->trait_aliases[i]->trait_method);
209            }
210
211            if (ce->trait_aliases[i]->alias) {
212                zend_string_release(ce->trait_aliases[i]->alias);
213            }
214
215            efree(ce->trait_aliases[i]);
216            i++;
217        }
218
219        efree(ce->trait_aliases);
220    }
221
222    if (ce->trait_precedences) {
223        size_t i = 0;
224
225        while (ce->trait_precedences[i]) {
226            zend_string_release(ce->trait_precedences[i]->trait_method->method_name);
227            zend_string_release(ce->trait_precedences[i]->trait_method->class_name);
228            efree(ce->trait_precedences[i]->trait_method);
229
230            if (ce->trait_precedences[i]->exclude_from_classes) {
231                size_t j = 0;
232                zend_trait_precedence *cur_precedence = ce->trait_precedences[i];
233                while (cur_precedence->exclude_from_classes[j].class_name) {
234                    zend_string_release(cur_precedence->exclude_from_classes[j].class_name);
235                    j++;
236                }
237                efree(ce->trait_precedences[i]->exclude_from_classes);
238            }
239            efree(ce->trait_precedences[i]);
240            i++;
241        }
242        efree(ce->trait_precedences);
243    }
244}
245
246ZEND_API void destroy_zend_class(zval *zv)
247{
248    zend_property_info *prop_info;
249    zend_class_entry *ce = Z_PTR_P(zv);
250
251    if (--ce->refcount > 0) {
252        return;
253    }
254    switch (ce->type) {
255        case ZEND_USER_CLASS:
256            if (ce->default_properties_table) {
257                zval *p = ce->default_properties_table;
258                zval *end = p + ce->default_properties_count;
259
260                while (p != end) {
261                    i_zval_ptr_dtor(p ZEND_FILE_LINE_CC);
262                    p++;
263                }
264                efree(ce->default_properties_table);
265            }
266            if (ce->default_static_members_table) {
267                zval *p = ce->default_static_members_table;
268                zval *end = p + ce->default_static_members_count;
269
270                while (p != end) {
271                    i_zval_ptr_dtor(p ZEND_FILE_LINE_CC);
272                    p++;
273                }
274                efree(ce->default_static_members_table);
275            }
276            ZEND_HASH_FOREACH_PTR(&ce->properties_info, prop_info) {
277                if (prop_info->ce == ce || (prop_info->flags & ZEND_ACC_SHADOW)) {
278                    zend_string_release(prop_info->name);
279                    if (prop_info->doc_comment) {
280                        zend_string_release(prop_info->doc_comment);
281                    }
282                }
283            } ZEND_HASH_FOREACH_END();
284            zend_hash_destroy(&ce->properties_info);
285            zend_string_release(ce->name);
286            zend_hash_destroy(&ce->function_table);
287            zend_hash_destroy(&ce->constants_table);
288            if (ce->num_interfaces > 0 && ce->interfaces) {
289                efree(ce->interfaces);
290            }
291            if (ce->info.user.doc_comment) {
292                zend_string_release(ce->info.user.doc_comment);
293            }
294
295            _destroy_zend_class_traits_info(ce);
296
297            break;
298        case ZEND_INTERNAL_CLASS:
299            if (ce->default_properties_table) {
300                zval *p = ce->default_properties_table;
301                zval *end = p + ce->default_properties_count;
302
303                while (p != end) {
304                    zval_internal_ptr_dtor(p);
305                    p++;
306                }
307                free(ce->default_properties_table);
308            }
309            if (ce->default_static_members_table) {
310                zval *p = ce->default_static_members_table;
311                zval *end = p + ce->default_static_members_count;
312
313                while (p != end) {
314                    zval_internal_ptr_dtor(p);
315                    p++;
316                }
317                free(ce->default_static_members_table);
318            }
319            zend_hash_destroy(&ce->properties_info);
320            zend_string_release(ce->name);
321            zend_hash_destroy(&ce->function_table);
322            zend_hash_destroy(&ce->constants_table);
323            if (ce->num_interfaces > 0) {
324                free(ce->interfaces);
325            }
326            free(ce);
327            break;
328    }
329}
330
331void zend_class_add_ref(zval *zv)
332{
333    zend_class_entry *ce = Z_PTR_P(zv);
334
335    ce->refcount++;
336}
337
338ZEND_API zend_bool destroy_op_array(zend_op_array *op_array)
339{
340    zval *literal = op_array->literals;
341    zval *end;
342    uint32_t i;
343
344    if (op_array->static_variables &&
345        !(GC_FLAGS(op_array->static_variables) & IS_ARRAY_IMMUTABLE)) {
346        if (--GC_REFCOUNT(op_array->static_variables) == 0) {
347            zend_array_destroy(op_array->static_variables);
348        }
349    }
350
351    if (op_array->run_time_cache && !op_array->function_name) {
352        efree(op_array->run_time_cache);
353        op_array->run_time_cache = NULL;
354    }
355
356    if (!op_array->refcount) {
357        return 1;
358    }
359
360    if (--(*op_array->refcount) > 0) {
361        return 0;
362    }
363
364    efree_size(op_array->refcount, sizeof(*(op_array->refcount)));
365
366    if (op_array->vars) {
367        i = op_array->last_var;
368        while (i > 0) {
369            i--;
370            zend_string_release(op_array->vars[i]);
371        }
372        efree(op_array->vars);
373    }
374
375    if (literal) {
376        end = literal + op_array->last_literal;
377        while (literal < end) {
378            zval_ptr_dtor_nogc(literal);
379            literal++;
380        }
381        efree(op_array->literals);
382    }
383    efree(op_array->opcodes);
384
385    if (op_array->function_name) {
386        zend_string_release(op_array->function_name);
387    }
388    if (op_array->doc_comment) {
389        zend_string_release(op_array->doc_comment);
390    }
391    if (op_array->brk_cont_array) {
392        efree(op_array->brk_cont_array);
393    }
394    if (op_array->try_catch_array) {
395        efree(op_array->try_catch_array);
396    }
397    if (op_array->fn_flags & ZEND_ACC_DONE_PASS_TWO) {
398        zend_llist_apply_with_argument(&zend_extensions, (llist_apply_with_arg_func_t) zend_extension_op_array_dtor_handler, op_array);
399    }
400    if (op_array->arg_info) {
401        int32_t num_args = op_array->num_args;
402        zend_arg_info *arg_info = op_array->arg_info;
403        int32_t i;
404
405        if (op_array->fn_flags & ZEND_ACC_HAS_RETURN_TYPE) {
406            arg_info--;
407            num_args++;
408        }
409        if (op_array->fn_flags & ZEND_ACC_VARIADIC) {
410            num_args++;
411        }
412        for (i = 0 ; i < num_args; i++) {
413            if (arg_info[i].name) {
414                zend_string_release(arg_info[i].name);
415            }
416            if (arg_info[i].class_name) {
417                zend_string_release(arg_info[i].class_name);
418            }
419        }
420        efree(arg_info);
421    }
422
423    return 1;
424}
425
426void init_op(zend_op *op)
427{
428    memset(op, 0, sizeof(zend_op));
429    op->lineno = CG(zend_lineno);
430    SET_UNUSED(op->result);
431}
432
433zend_op *get_next_op(zend_op_array *op_array)
434{
435    uint32_t next_op_num = op_array->last++;
436    zend_op *next_op;
437
438    if (next_op_num >= CG(context).opcodes_size) {
439        CG(context).opcodes_size *= 4;
440        op_array_alloc_ops(op_array, CG(context).opcodes_size);
441    }
442
443    next_op = &(op_array->opcodes[next_op_num]);
444
445    init_op(next_op);
446
447    return next_op;
448}
449
450int get_next_op_number(zend_op_array *op_array)
451{
452    return op_array->last;
453}
454
455zend_brk_cont_element *get_next_brk_cont_element(zend_op_array *op_array)
456{
457    op_array->last_brk_cont++;
458    op_array->brk_cont_array = erealloc(op_array->brk_cont_array, sizeof(zend_brk_cont_element)*op_array->last_brk_cont);
459    return &op_array->brk_cont_array[op_array->last_brk_cont-1];
460}
461
462static void zend_update_extended_info(zend_op_array *op_array)
463{
464    zend_op *opline = op_array->opcodes, *end=opline+op_array->last;
465
466    while (opline<end) {
467        if (opline->opcode == ZEND_EXT_STMT) {
468            if (opline+1<end) {
469                if ((opline+1)->opcode == ZEND_EXT_STMT) {
470                    opline->opcode = ZEND_NOP;
471                    opline++;
472                    continue;
473                }
474                if (opline+1<end) {
475                    opline->lineno = (opline+1)->lineno;
476                }
477            } else {
478                opline->opcode = ZEND_NOP;
479            }
480        }
481        opline++;
482    }
483}
484
485static void zend_extension_op_array_handler(zend_extension *extension, zend_op_array *op_array)
486{
487    if (extension->op_array_handler) {
488        extension->op_array_handler(op_array);
489    }
490}
491
492static void zend_check_finally_breakout(zend_op_array *op_array, uint32_t op_num, uint32_t dst_num)
493{
494    int i;
495
496    for (i = 0; i < op_array->last_try_catch; i++) {
497        if ((op_num < op_array->try_catch_array[i].finally_op ||
498                    op_num >= op_array->try_catch_array[i].finally_end)
499                && (dst_num >= op_array->try_catch_array[i].finally_op &&
500                     dst_num <= op_array->try_catch_array[i].finally_end)) {
501            CG(in_compilation) = 1;
502            CG(active_op_array) = op_array;
503            CG(zend_lineno) = op_array->opcodes[op_num].lineno;
504            zend_error_noreturn(E_COMPILE_ERROR, "jump into a finally block is disallowed");
505        } else if ((op_num >= op_array->try_catch_array[i].finally_op
506                    && op_num <= op_array->try_catch_array[i].finally_end)
507                && (dst_num > op_array->try_catch_array[i].finally_end
508                    || dst_num < op_array->try_catch_array[i].finally_op)) {
509            CG(in_compilation) = 1;
510            CG(active_op_array) = op_array;
511            CG(zend_lineno) = op_array->opcodes[op_num].lineno;
512            zend_error_noreturn(E_COMPILE_ERROR, "jump out of a finally block is disallowed");
513        }
514    }
515}
516
517static void zend_adjust_fast_call(zend_op_array *op_array, uint32_t fast_call, uint32_t start, uint32_t end)
518{
519    int i;
520    uint32_t op_num = 0;
521
522    for (i = 0; i < op_array->last_try_catch; i++) {
523        if (op_array->try_catch_array[i].finally_op > start
524                && op_array->try_catch_array[i].finally_end < end) {
525            op_num = op_array->try_catch_array[i].finally_op;
526            start = op_array->try_catch_array[i].finally_end;
527        }
528    }
529
530    if (op_num) {
531        /* Must be ZEND_FAST_CALL */
532        ZEND_ASSERT(op_array->opcodes[op_num - 2].opcode == ZEND_FAST_CALL);
533        op_array->opcodes[op_num - 2].extended_value = ZEND_FAST_CALL_FROM_FINALLY;
534        op_array->opcodes[op_num - 2].op2.opline_num = fast_call;
535    }
536}
537
538static void zend_resolve_fast_call(zend_op_array *op_array, uint32_t fast_call, uint32_t op_num)
539{
540    int i;
541    uint32_t finally_op_num = 0;
542
543    for (i = 0; i < op_array->last_try_catch; i++) {
544        if (op_num >= op_array->try_catch_array[i].finally_op
545                && op_num < op_array->try_catch_array[i].finally_end) {
546            finally_op_num = op_array->try_catch_array[i].finally_op;
547        }
548    }
549
550    if (finally_op_num) {
551        /* Must be ZEND_FAST_CALL */
552        ZEND_ASSERT(op_array->opcodes[finally_op_num - 2].opcode == ZEND_FAST_CALL);
553        if (op_array->opcodes[fast_call].extended_value == 0) {
554            op_array->opcodes[fast_call].extended_value = ZEND_FAST_CALL_FROM_FINALLY;
555            op_array->opcodes[fast_call].op2.opline_num = finally_op_num - 2;
556        }
557    }
558}
559
560static void zend_resolve_finally_call(zend_op_array *op_array, uint32_t op_num, uint32_t dst_num)
561{
562    uint32_t start_op;
563    zend_op *opline;
564    uint32_t i = op_array->last_try_catch;
565
566    if (dst_num != (uint32_t)-1) {
567        zend_check_finally_breakout(op_array, op_num, dst_num);
568    }
569
570    /* the backward order is mater */
571    while (i > 0) {
572        i--;
573        if (op_array->try_catch_array[i].finally_op &&
574            op_num >= op_array->try_catch_array[i].try_op &&
575            op_num < op_array->try_catch_array[i].finally_op - 1 &&
576            (dst_num < op_array->try_catch_array[i].try_op ||
577             dst_num > op_array->try_catch_array[i].finally_end)) {
578            /* we have a jump out of try block that needs executing finally */
579            uint32_t fast_call_var;
580
581            /* Must be ZEND_FAST_RET */
582            ZEND_ASSERT(op_array->opcodes[op_array->try_catch_array[i].finally_end].opcode == ZEND_FAST_RET);
583            fast_call_var = op_array->opcodes[op_array->try_catch_array[i].finally_end].op1.var;
584
585            /* generate a FAST_CALL to finally block */
586            start_op = get_next_op_number(op_array);
587
588            opline = get_next_op(op_array);
589            opline->opcode = ZEND_FAST_CALL;
590            opline->result_type = IS_TMP_VAR;
591            opline->result.var = fast_call_var;
592            SET_UNUSED(opline->op1);
593            SET_UNUSED(opline->op2);
594            zend_adjust_fast_call(op_array, start_op,
595                    op_array->try_catch_array[i].finally_op,
596                    op_array->try_catch_array[i].finally_end);
597            zend_resolve_fast_call(op_array, start_op, op_array->try_catch_array[i].finally_op - 2);
598            opline->op1.opline_num = op_array->try_catch_array[i].finally_op;
599
600            /* generate a sequence of FAST_CALL to upward finally block */
601            while (i > 0) {
602                i--;
603                if (op_array->try_catch_array[i].finally_op &&
604                    op_num >= op_array->try_catch_array[i].try_op &&
605                    op_num < op_array->try_catch_array[i].finally_op - 1 &&
606                    (dst_num < op_array->try_catch_array[i].try_op ||
607                     dst_num > op_array->try_catch_array[i].finally_end)) {
608
609                    opline = get_next_op(op_array);
610                    opline->opcode = ZEND_FAST_CALL;
611                    opline->result_type = IS_TMP_VAR;
612                    opline->result.var = fast_call_var;
613                    SET_UNUSED(opline->op1);
614                    SET_UNUSED(opline->op2);
615                    opline->op1.opline_num = op_array->try_catch_array[i].finally_op;
616                }
617            }
618
619            /* Finish the sequence with original opcode */
620            opline = get_next_op(op_array);
621            *opline = op_array->opcodes[op_num];
622
623            /* Replace original opcode with jump to this sequence */
624            opline = op_array->opcodes + op_num;
625            opline->opcode = ZEND_JMP;
626            SET_UNUSED(opline->op1);
627            SET_UNUSED(opline->op2);
628            opline->op1.opline_num = start_op;
629
630            break;
631        }
632    }
633}
634
635static void zend_resolve_finally_ret(zend_op_array *op_array, uint32_t op_num)
636{
637    int i;
638    uint32_t catch_op_num = 0, finally_op_num = 0;
639
640    for (i = 0; i < op_array->last_try_catch; i++) {
641        if (op_array->try_catch_array[i].try_op > op_num) {
642            break;
643        }
644        if (op_num < op_array->try_catch_array[i].finally_op) {
645            finally_op_num = op_array->try_catch_array[i].finally_op;
646        }
647        if (op_num < op_array->try_catch_array[i].catch_op) {
648            catch_op_num = op_array->try_catch_array[i].catch_op;
649        }
650    }
651
652    if (finally_op_num && (!catch_op_num || catch_op_num >= finally_op_num)) {
653        /* in case of unhandled exception return to upward finally block */
654        op_array->opcodes[op_num].extended_value = ZEND_FAST_RET_TO_FINALLY;
655        op_array->opcodes[op_num].op2.opline_num = finally_op_num;
656    } else if (catch_op_num) {
657        /* in case of unhandled exception return to upward catch block */
658        op_array->opcodes[op_num].extended_value = ZEND_FAST_RET_TO_CATCH;
659        op_array->opcodes[op_num].op2.opline_num = catch_op_num;
660    }
661}
662
663static uint32_t zend_get_brk_cont_target(const zend_op_array *op_array, const zend_op *opline) {
664    int nest_levels = opline->op2.num;
665    int array_offset = opline->op1.num;
666    zend_brk_cont_element *jmp_to;
667    do {
668        jmp_to = &op_array->brk_cont_array[array_offset];
669        if (nest_levels > 1) {
670            array_offset = jmp_to->parent;
671        }
672    } while (--nest_levels > 0);
673
674    return opline->opcode == ZEND_BRK ? jmp_to->brk : jmp_to->cont;
675}
676
677static void zend_resolve_finally_calls(zend_op_array *op_array)
678{
679    uint32_t i, j;
680    zend_op *opline;
681
682    for (i = 0, j = op_array->last; i < j; i++) {
683        opline = op_array->opcodes + i;
684        switch (opline->opcode) {
685            case ZEND_RETURN:
686            case ZEND_RETURN_BY_REF:
687            case ZEND_GENERATOR_RETURN:
688                zend_resolve_finally_call(op_array, i, (uint32_t)-1);
689                break;
690            case ZEND_BRK:
691            case ZEND_CONT:
692                zend_resolve_finally_call(op_array, i, zend_get_brk_cont_target(op_array, opline));
693                break;
694            case ZEND_GOTO:
695                if (Z_TYPE_P(CT_CONSTANT_EX(op_array, opline->op2.constant)) != IS_LONG) {
696                    zend_resolve_goto_label(op_array, NULL, opline);
697                }
698                /* break omitted intentionally */
699            case ZEND_JMP:
700                zend_resolve_finally_call(op_array, i, opline->op1.opline_num);
701                break;
702            case ZEND_FAST_CALL:
703                zend_resolve_fast_call(op_array, i, i);
704                break;
705            case ZEND_FAST_RET:
706                zend_resolve_finally_ret(op_array, i);
707                break;
708            default:
709                break;
710        }
711    }
712}
713
714ZEND_API int pass_two(zend_op_array *op_array)
715{
716    zend_op *opline, *end;
717
718    if (!ZEND_USER_CODE(op_array->type)) {
719        return 0;
720    }
721    if (op_array->fn_flags & ZEND_ACC_HAS_FINALLY_BLOCK) {
722        zend_resolve_finally_calls(op_array);
723    }
724    if (CG(compiler_options) & ZEND_COMPILE_EXTENDED_INFO) {
725        zend_update_extended_info(op_array);
726    }
727    if (CG(compiler_options) & ZEND_COMPILE_HANDLE_OP_ARRAY) {
728        zend_llist_apply_with_argument(&zend_extensions, (llist_apply_with_arg_func_t) zend_extension_op_array_handler, op_array);
729    }
730
731    if (CG(context).vars_size != op_array->last_var) {
732        op_array->vars = (zend_string**) erealloc(op_array->vars, sizeof(zend_string*)*op_array->last_var);
733        CG(context).vars_size = op_array->last_var;
734    }
735    if (CG(context).opcodes_size != op_array->last) {
736        op_array->opcodes = (zend_op *) erealloc(op_array->opcodes, sizeof(zend_op)*op_array->last);
737        CG(context).opcodes_size = op_array->last;
738    }
739    if (CG(context).literals_size != op_array->last_literal) {
740        op_array->literals = (zval*)erealloc(op_array->literals, sizeof(zval) * op_array->last_literal);
741        CG(context).literals_size = op_array->last_literal;
742    }
743    opline = op_array->opcodes;
744    end = opline + op_array->last;
745    while (opline < end) {
746        switch (opline->opcode) {
747            case ZEND_DECLARE_ANON_INHERITED_CLASS:
748                ZEND_PASS_TWO_UPDATE_JMP_TARGET(op_array, opline, opline->op1);
749                /* break omitted intentionally */
750            case ZEND_DECLARE_INHERITED_CLASS:
751            case ZEND_DECLARE_INHERITED_CLASS_DELAYED:
752                opline->extended_value = (uint32_t)(zend_intptr_t)ZEND_CALL_VAR_NUM(NULL, op_array->last_var + opline->extended_value);
753                break;
754            case ZEND_BRK:
755            case ZEND_CONT:
756                {
757                    uint32_t jmp_target = zend_get_brk_cont_target(op_array, opline);
758                    opline->opcode = ZEND_JMP;
759                    opline->op1.opline_num = jmp_target;
760                    opline->op2.num = 0;
761                    ZEND_PASS_TWO_UPDATE_JMP_TARGET(op_array, opline, opline->op1);
762                }
763                break;
764            case ZEND_GOTO:
765                if (Z_TYPE_P(CT_CONSTANT_EX(op_array, opline->op2.constant)) != IS_LONG) {
766                    zend_resolve_goto_label(op_array, NULL, opline);
767                }
768                /* break omitted intentionally */
769            case ZEND_JMP:
770            case ZEND_FAST_CALL:
771            case ZEND_DECLARE_ANON_CLASS:
772                ZEND_PASS_TWO_UPDATE_JMP_TARGET(op_array, opline, opline->op1);
773                break;
774            case ZEND_JMPZNZ:
775                /* absolute index to relative offset */
776                opline->extended_value = ZEND_OPLINE_NUM_TO_OFFSET(op_array, opline, opline->extended_value);
777                /* break omitted intentionally */
778            case ZEND_JMPZ:
779            case ZEND_JMPNZ:
780            case ZEND_JMPZ_EX:
781            case ZEND_JMPNZ_EX:
782            case ZEND_JMP_SET:
783            case ZEND_COALESCE:
784            case ZEND_NEW:
785            case ZEND_FE_RESET_R:
786            case ZEND_FE_RESET_RW:
787            case ZEND_ASSERT_CHECK:
788                ZEND_PASS_TWO_UPDATE_JMP_TARGET(op_array, opline, opline->op2);
789                break;
790            case ZEND_FE_FETCH_R:
791            case ZEND_FE_FETCH_RW:
792                opline->extended_value = ZEND_OPLINE_NUM_TO_OFFSET(op_array, opline, opline->extended_value);
793                break;
794            case ZEND_VERIFY_RETURN_TYPE:
795                if (op_array->fn_flags & ZEND_ACC_GENERATOR) {
796                    if (opline->op1_type != IS_UNUSED) {
797                        (opline + 1)->op1 = opline->op1;
798                        (opline + 1)->op1_type = opline->op1_type;
799                    }
800                    MAKE_NOP(opline);
801                }
802                break;
803            case ZEND_RETURN:
804            case ZEND_RETURN_BY_REF:
805                if (op_array->fn_flags & ZEND_ACC_GENERATOR) {
806                    opline->opcode = ZEND_GENERATOR_RETURN;
807                }
808                break;
809        }
810        if (opline->op1_type == IS_CONST) {
811            ZEND_PASS_TWO_UPDATE_CONSTANT(op_array, opline->op1);
812        } else if (opline->op1_type & (IS_VAR|IS_TMP_VAR)) {
813            opline->op1.var = (uint32_t)(zend_intptr_t)ZEND_CALL_VAR_NUM(NULL, op_array->last_var + opline->op1.var);
814        }
815        if (opline->op2_type == IS_CONST) {
816            ZEND_PASS_TWO_UPDATE_CONSTANT(op_array, opline->op2);
817        } else if (opline->op2_type & (IS_VAR|IS_TMP_VAR)) {
818            opline->op2.var = (uint32_t)(zend_intptr_t)ZEND_CALL_VAR_NUM(NULL, op_array->last_var + opline->op2.var);
819        }
820        if (opline->result_type & (IS_VAR|IS_TMP_VAR)) {
821            opline->result.var = (uint32_t)(zend_intptr_t)ZEND_CALL_VAR_NUM(NULL, op_array->last_var + opline->result.var);
822        }
823        ZEND_VM_SET_OPCODE_HANDLER(opline);
824        opline++;
825    }
826
827    op_array->fn_flags |= ZEND_ACC_DONE_PASS_TWO;
828    return 0;
829}
830
831int pass_two_wrapper(zval *el)
832{
833    return pass_two((zend_op_array *) Z_PTR_P(el));
834}
835
836int print_class(zend_class_entry *class_entry)
837{
838    printf("Class %s:\n", ZSTR_VAL(class_entry->name));
839    zend_hash_apply(&class_entry->function_table, pass_two_wrapper);
840    printf("End of class %s.\n\n", ZSTR_VAL(class_entry->name));
841    return 0;
842}
843
844ZEND_API unary_op_type get_unary_op(int opcode)
845{
846    switch (opcode) {
847        case ZEND_BW_NOT:
848            return (unary_op_type) bitwise_not_function;
849        case ZEND_BOOL_NOT:
850            return (unary_op_type) boolean_not_function;
851        default:
852            return (unary_op_type) NULL;
853    }
854}
855
856ZEND_API binary_op_type get_binary_op(int opcode)
857{
858    switch (opcode) {
859        case ZEND_ADD:
860        case ZEND_ASSIGN_ADD:
861            return (binary_op_type) add_function;
862        case ZEND_SUB:
863        case ZEND_ASSIGN_SUB:
864            return (binary_op_type) sub_function;
865        case ZEND_MUL:
866        case ZEND_ASSIGN_MUL:
867            return (binary_op_type) mul_function;
868        case ZEND_POW:
869            return (binary_op_type) pow_function;
870        case ZEND_DIV:
871        case ZEND_ASSIGN_DIV:
872            return (binary_op_type) div_function;
873        case ZEND_MOD:
874        case ZEND_ASSIGN_MOD:
875            return (binary_op_type) mod_function;
876        case ZEND_SL:
877        case ZEND_ASSIGN_SL:
878            return (binary_op_type) shift_left_function;
879        case ZEND_SR:
880        case ZEND_ASSIGN_SR:
881            return (binary_op_type) shift_right_function;
882        case ZEND_FAST_CONCAT:
883        case ZEND_CONCAT:
884        case ZEND_ASSIGN_CONCAT:
885            return (binary_op_type) concat_function;
886        case ZEND_IS_IDENTICAL:
887            return (binary_op_type) is_identical_function;
888        case ZEND_IS_NOT_IDENTICAL:
889            return (binary_op_type) is_not_identical_function;
890        case ZEND_IS_EQUAL:
891            return (binary_op_type) is_equal_function;
892        case ZEND_IS_NOT_EQUAL:
893            return (binary_op_type) is_not_equal_function;
894        case ZEND_IS_SMALLER:
895            return (binary_op_type) is_smaller_function;
896        case ZEND_IS_SMALLER_OR_EQUAL:
897            return (binary_op_type) is_smaller_or_equal_function;
898        case ZEND_SPACESHIP:
899            return (binary_op_type) compare_function;
900        case ZEND_BW_OR:
901        case ZEND_ASSIGN_BW_OR:
902            return (binary_op_type) bitwise_or_function;
903        case ZEND_BW_AND:
904        case ZEND_ASSIGN_BW_AND:
905            return (binary_op_type) bitwise_and_function;
906        case ZEND_BW_XOR:
907        case ZEND_ASSIGN_BW_XOR:
908            return (binary_op_type) bitwise_xor_function;
909        case ZEND_BOOL_XOR:
910            return (binary_op_type) boolean_xor_function;
911        default:
912            return (binary_op_type) NULL;
913    }
914}
915
916/*
917 * Local variables:
918 * tab-width: 4
919 * c-basic-offset: 4
920 * indent-tabs-mode: t
921 * End:
922 */
923