1/*
2   +----------------------------------------------------------------------+
3   | Zend Engine                                                          |
4   +----------------------------------------------------------------------+
5   | Copyright (c) 1998-2015 Zend Technologies Ltd. (http://www.zend.com) |
6   +----------------------------------------------------------------------+
7   | This source file is subject to version 2.00 of the Zend license,     |
8   | that is bundled with this package in the file LICENSE, and is        |
9   | available through the world-wide-web at the following url:           |
10   | http://www.zend.com/license/2_00.txt.                                |
11   | If you did not receive a copy of the Zend license and are unable to  |
12   | obtain it through the world-wide-web, please send a note to          |
13   | license@zend.com so we can mail you a copy immediately.              |
14   +----------------------------------------------------------------------+
15   | Authors: Andi Gutmans <andi@zend.com>                                |
16   |          Zeev Suraski <zeev@zend.com>                                |
17   +----------------------------------------------------------------------+
18*/
19
20/* $Id$ */
21
22#include <stdio.h>
23
24#include "zend.h"
25#include "zend_alloc.h"
26#include "zend_compile.h"
27#include "zend_extensions.h"
28#include "zend_API.h"
29
30#include "zend_vm.h"
31
32static void zend_extension_op_array_ctor_handler(zend_extension *extension, zend_op_array *op_array)
33{
34    if (extension->op_array_ctor) {
35        extension->op_array_ctor(op_array);
36    }
37}
38
39static void zend_extension_op_array_dtor_handler(zend_extension *extension, zend_op_array *op_array)
40{
41    if (extension->op_array_dtor) {
42        extension->op_array_dtor(op_array);
43    }
44}
45
46static void op_array_alloc_ops(zend_op_array *op_array, uint32_t size)
47{
48    op_array->opcodes = erealloc(op_array->opcodes, size * sizeof(zend_op));
49}
50
51void init_op_array(zend_op_array *op_array, zend_uchar type, int initial_ops_size)
52{
53    op_array->type = type;
54    op_array->arg_flags[0] = 0;
55    op_array->arg_flags[1] = 0;
56    op_array->arg_flags[2] = 0;
57
58    op_array->refcount = (uint32_t *) emalloc(sizeof(uint32_t));
59    *op_array->refcount = 1;
60    op_array->last = 0;
61    op_array->opcodes = NULL;
62    op_array_alloc_ops(op_array, initial_ops_size);
63
64    op_array->last_var = 0;
65    op_array->vars = NULL;
66
67    op_array->T = 0;
68
69    op_array->function_name = NULL;
70    op_array->filename = zend_get_compiled_filename();
71    op_array->doc_comment = NULL;
72
73    op_array->arg_info = NULL;
74    op_array->num_args = 0;
75    op_array->required_num_args = 0;
76
77    op_array->scope = NULL;
78    op_array->prototype = NULL;
79
80    op_array->brk_cont_array = NULL;
81    op_array->try_catch_array = NULL;
82    op_array->last_brk_cont = 0;
83
84    op_array->static_variables = NULL;
85    op_array->last_try_catch = 0;
86
87    op_array->this_var = -1;
88
89    op_array->fn_flags = 0;
90
91    op_array->early_binding = -1;
92
93    op_array->last_literal = 0;
94    op_array->literals = NULL;
95
96    op_array->run_time_cache = NULL;
97    op_array->cache_size = 0;
98
99    memset(op_array->reserved, 0, ZEND_MAX_RESERVED_RESOURCES * sizeof(void*));
100
101    zend_llist_apply_with_argument(&zend_extensions, (llist_apply_with_arg_func_t) zend_extension_op_array_ctor_handler, op_array);
102}
103
104ZEND_API void destroy_zend_function(zend_function *function)
105{
106    if (function->type == ZEND_USER_FUNCTION) {
107        destroy_op_array(&function->op_array);
108    } else {
109        ZEND_ASSERT(function->type == ZEND_INTERNAL_FUNCTION);
110        ZEND_ASSERT(function->common.function_name);
111        zend_string_release(function->common.function_name);
112    }
113}
114
115ZEND_API void zend_function_dtor(zval *zv)
116{
117    zend_function *function = Z_PTR_P(zv);
118
119    if (function->type == ZEND_USER_FUNCTION) {
120        ZEND_ASSERT(function->common.function_name);
121        destroy_op_array(&function->op_array);
122        /* op_arrays are allocated on arena, so we don't have to free them */
123    } else {
124        ZEND_ASSERT(function->type == ZEND_INTERNAL_FUNCTION);
125        ZEND_ASSERT(function->common.function_name);
126        zend_string_release(function->common.function_name);
127        if (!(function->common.fn_flags & ZEND_ACC_ARENA_ALLOCATED)) {
128            pefree(function, 1);
129        }
130    }
131}
132
133ZEND_API void zend_cleanup_op_array_data(zend_op_array *op_array)
134{
135    if (op_array->static_variables &&
136        !(GC_FLAGS(op_array->static_variables) & IS_ARRAY_IMMUTABLE)) {
137        zend_hash_clean(op_array->static_variables);
138    }
139}
140
141ZEND_API void zend_cleanup_user_class_data(zend_class_entry *ce)
142{
143    /* Clean all parts that can contain run-time data */
144    /* Note that only run-time accessed data need to be cleaned up, pre-defined data can
145       not contain objects and thus are not probelmatic */
146    if (ce->ce_flags & ZEND_HAS_STATIC_IN_METHODS) {
147        zend_function *func;
148
149        ZEND_HASH_FOREACH_PTR(&ce->function_table, func) {
150            if (func->type == ZEND_USER_FUNCTION) {
151                zend_cleanup_op_array_data((zend_op_array *) func);
152            }
153        } ZEND_HASH_FOREACH_END();
154    }
155    if (ce->static_members_table) {
156        zval *static_members = ce->static_members_table;
157        zval *p = static_members;
158        zval *end = p + ce->default_static_members_count;
159
160
161        ce->default_static_members_count = 0;
162        ce->default_static_members_table = ce->static_members_table = NULL;
163        while (p != end) {
164            i_zval_ptr_dtor(p ZEND_FILE_LINE_CC);
165            p++;
166        }
167        efree(static_members);
168    }
169}
170
171ZEND_API void zend_cleanup_internal_class_data(zend_class_entry *ce)
172{
173    if (CE_STATIC_MEMBERS(ce)) {
174        zval *static_members = CE_STATIC_MEMBERS(ce);
175        zval *p = static_members;
176        zval *end = p + ce->default_static_members_count;
177
178#ifdef ZTS
179        CG(static_members_table)[(zend_intptr_t)(ce->static_members_table)] = NULL;
180#else
181        ce->static_members_table = NULL;
182#endif
183        while (p != end) {
184            i_zval_ptr_dtor(p ZEND_FILE_LINE_CC);
185            p++;
186        }
187        efree(static_members);
188    }
189}
190
191void _destroy_zend_class_traits_info(zend_class_entry *ce)
192{
193    if (ce->num_traits > 0 && ce->traits) {
194        efree(ce->traits);
195    }
196
197    if (ce->trait_aliases) {
198        size_t i = 0;
199        while (ce->trait_aliases[i]) {
200            if (ce->trait_aliases[i]->trait_method) {
201                if (ce->trait_aliases[i]->trait_method->method_name) {
202                    zend_string_release(ce->trait_aliases[i]->trait_method->method_name);
203                }
204                if (ce->trait_aliases[i]->trait_method->class_name) {
205                    zend_string_release(ce->trait_aliases[i]->trait_method->class_name);
206                }
207                efree(ce->trait_aliases[i]->trait_method);
208            }
209
210            if (ce->trait_aliases[i]->alias) {
211                zend_string_release(ce->trait_aliases[i]->alias);
212            }
213
214            efree(ce->trait_aliases[i]);
215            i++;
216        }
217
218        efree(ce->trait_aliases);
219    }
220
221    if (ce->trait_precedences) {
222        size_t i = 0;
223
224        while (ce->trait_precedences[i]) {
225            zend_string_release(ce->trait_precedences[i]->trait_method->method_name);
226            zend_string_release(ce->trait_precedences[i]->trait_method->class_name);
227            efree(ce->trait_precedences[i]->trait_method);
228
229            if (ce->trait_precedences[i]->exclude_from_classes) {
230                size_t j = 0;
231                zend_trait_precedence *cur_precedence = ce->trait_precedences[i];
232                while (cur_precedence->exclude_from_classes[j].class_name) {
233                    zend_string_release(cur_precedence->exclude_from_classes[j].class_name);
234                    j++;
235                }
236                efree(ce->trait_precedences[i]->exclude_from_classes);
237            }
238            efree(ce->trait_precedences[i]);
239            i++;
240        }
241        efree(ce->trait_precedences);
242    }
243}
244
245ZEND_API void destroy_zend_class(zval *zv)
246{
247    zend_property_info *prop_info;
248    zend_class_entry *ce = Z_PTR_P(zv);
249
250    if (--ce->refcount > 0) {
251        return;
252    }
253    switch (ce->type) {
254        case ZEND_USER_CLASS:
255            if (ce->default_properties_table) {
256                zval *p = ce->default_properties_table;
257                zval *end = p + ce->default_properties_count;
258
259                while (p != end) {
260                    i_zval_ptr_dtor(p ZEND_FILE_LINE_CC);
261                    p++;
262                }
263                efree(ce->default_properties_table);
264            }
265            if (ce->default_static_members_table) {
266                zval *p = ce->default_static_members_table;
267                zval *end = p + ce->default_static_members_count;
268
269                while (p != end) {
270                    i_zval_ptr_dtor(p ZEND_FILE_LINE_CC);
271                    p++;
272                }
273                efree(ce->default_static_members_table);
274            }
275            ZEND_HASH_FOREACH_PTR(&ce->properties_info, prop_info) {
276                if (prop_info->ce == ce || (prop_info->flags & ZEND_ACC_SHADOW)) {
277                    zend_string_release(prop_info->name);
278                    if (prop_info->doc_comment) {
279                        zend_string_release(prop_info->doc_comment);
280                    }
281                }
282            } ZEND_HASH_FOREACH_END();
283            zend_hash_destroy(&ce->properties_info);
284            zend_string_release(ce->name);
285            zend_hash_destroy(&ce->function_table);
286            zend_hash_destroy(&ce->constants_table);
287            if (ce->num_interfaces > 0 && ce->interfaces) {
288                efree(ce->interfaces);
289            }
290            if (ce->info.user.doc_comment) {
291                zend_string_release(ce->info.user.doc_comment);
292            }
293
294            _destroy_zend_class_traits_info(ce);
295
296            break;
297        case ZEND_INTERNAL_CLASS:
298            if (ce->default_properties_table) {
299                zval *p = ce->default_properties_table;
300                zval *end = p + ce->default_properties_count;
301
302                while (p != end) {
303                    zval_internal_ptr_dtor(p);
304                    p++;
305                }
306                free(ce->default_properties_table);
307            }
308            if (ce->default_static_members_table) {
309                zval *p = ce->default_static_members_table;
310                zval *end = p + ce->default_static_members_count;
311
312                while (p != end) {
313                    zval_internal_ptr_dtor(p);
314                    p++;
315                }
316                free(ce->default_static_members_table);
317            }
318            zend_hash_destroy(&ce->properties_info);
319            zend_string_release(ce->name);
320            zend_hash_destroy(&ce->function_table);
321            zend_hash_destroy(&ce->constants_table);
322            if (ce->num_interfaces > 0) {
323                free(ce->interfaces);
324            }
325            free(ce);
326            break;
327    }
328}
329
330void zend_class_add_ref(zval *zv)
331{
332    zend_class_entry *ce = Z_PTR_P(zv);
333
334    ce->refcount++;
335}
336
337ZEND_API void destroy_op_array(zend_op_array *op_array)
338{
339    zval *literal = op_array->literals;
340    zval *end;
341    uint32_t i;
342
343    if (op_array->static_variables &&
344        !(GC_FLAGS(op_array->static_variables) & IS_ARRAY_IMMUTABLE)) {
345        if (--GC_REFCOUNT(op_array->static_variables) == 0) {
346            zend_array_destroy(op_array->static_variables);
347        }
348    }
349
350    if (op_array->run_time_cache && !op_array->function_name) {
351        efree(op_array->run_time_cache);
352    }
353
354    if (!op_array->refcount || --(*op_array->refcount)>0) {
355        return;
356    }
357
358    efree_size(op_array->refcount, sizeof(*(op_array->refcount)));
359
360    if (op_array->vars) {
361        i = op_array->last_var;
362        while (i > 0) {
363            i--;
364            zend_string_release(op_array->vars[i]);
365        }
366        efree(op_array->vars);
367    }
368
369    if (literal) {
370        end = literal + op_array->last_literal;
371        while (literal < end) {
372            zval_ptr_dtor_nogc(literal);
373            literal++;
374        }
375        efree(op_array->literals);
376    }
377    efree(op_array->opcodes);
378
379    if (op_array->function_name) {
380        zend_string_release(op_array->function_name);
381    }
382    if (op_array->doc_comment) {
383        zend_string_release(op_array->doc_comment);
384    }
385    if (op_array->brk_cont_array) {
386        efree(op_array->brk_cont_array);
387    }
388    if (op_array->try_catch_array) {
389        efree(op_array->try_catch_array);
390    }
391    if (op_array->fn_flags & ZEND_ACC_DONE_PASS_TWO) {
392        zend_llist_apply_with_argument(&zend_extensions, (llist_apply_with_arg_func_t) zend_extension_op_array_dtor_handler, op_array);
393    }
394    if (op_array->arg_info) {
395        int32_t num_args = op_array->num_args;
396        zend_arg_info *arg_info = op_array->arg_info;
397        int32_t i;
398
399        if (op_array->fn_flags & ZEND_ACC_HAS_RETURN_TYPE) {
400            arg_info--;
401            num_args++;
402        }
403        if (op_array->fn_flags & ZEND_ACC_VARIADIC) {
404            num_args++;
405        }
406        for (i = 0 ; i < num_args; i++) {
407            if (arg_info[i].name) {
408                zend_string_release(arg_info[i].name);
409            }
410            if (arg_info[i].class_name) {
411                zend_string_release(arg_info[i].class_name);
412            }
413        }
414        efree(arg_info);
415    }
416}
417
418void init_op(zend_op *op)
419{
420    memset(op, 0, sizeof(zend_op));
421    op->lineno = CG(zend_lineno);
422    SET_UNUSED(op->result);
423}
424
425zend_op *get_next_op(zend_op_array *op_array)
426{
427    uint32_t next_op_num = op_array->last++;
428    zend_op *next_op;
429
430    if (next_op_num >= CG(context).opcodes_size) {
431        CG(context).opcodes_size *= 4;
432        op_array_alloc_ops(op_array, CG(context).opcodes_size);
433    }
434
435    next_op = &(op_array->opcodes[next_op_num]);
436
437    init_op(next_op);
438
439    return next_op;
440}
441
442int get_next_op_number(zend_op_array *op_array)
443{
444    return op_array->last;
445}
446
447zend_brk_cont_element *get_next_brk_cont_element(zend_op_array *op_array)
448{
449    op_array->last_brk_cont++;
450    op_array->brk_cont_array = erealloc(op_array->brk_cont_array, sizeof(zend_brk_cont_element)*op_array->last_brk_cont);
451    return &op_array->brk_cont_array[op_array->last_brk_cont-1];
452}
453
454static void zend_update_extended_info(zend_op_array *op_array)
455{
456    zend_op *opline = op_array->opcodes, *end=opline+op_array->last;
457
458    while (opline<end) {
459        if (opline->opcode == ZEND_EXT_STMT) {
460            if (opline+1<end) {
461                if ((opline+1)->opcode == ZEND_EXT_STMT) {
462                    opline->opcode = ZEND_NOP;
463                    opline++;
464                    continue;
465                }
466                if (opline+1<end) {
467                    opline->lineno = (opline+1)->lineno;
468                }
469            } else {
470                opline->opcode = ZEND_NOP;
471            }
472        }
473        opline++;
474    }
475}
476
477static void zend_extension_op_array_handler(zend_extension *extension, zend_op_array *op_array)
478{
479    if (extension->op_array_handler) {
480        extension->op_array_handler(op_array);
481    }
482}
483
484static void zend_check_finally_breakout(zend_op_array *op_array, uint32_t op_num, uint32_t dst_num)
485{
486    int i;
487
488    for (i = 0; i < op_array->last_try_catch; i++) {
489        if ((op_num < op_array->try_catch_array[i].finally_op ||
490                    op_num >= op_array->try_catch_array[i].finally_end)
491                && (dst_num >= op_array->try_catch_array[i].finally_op &&
492                     dst_num <= op_array->try_catch_array[i].finally_end)) {
493            CG(in_compilation) = 1;
494            CG(active_op_array) = op_array;
495            CG(zend_lineno) = op_array->opcodes[op_num].lineno;
496            zend_error_noreturn(E_COMPILE_ERROR, "jump into a finally block is disallowed");
497        } else if ((op_num >= op_array->try_catch_array[i].finally_op
498                    && op_num <= op_array->try_catch_array[i].finally_end)
499                && (dst_num > op_array->try_catch_array[i].finally_end
500                    || dst_num < op_array->try_catch_array[i].finally_op)) {
501            CG(in_compilation) = 1;
502            CG(active_op_array) = op_array;
503            CG(zend_lineno) = op_array->opcodes[op_num].lineno;
504            zend_error_noreturn(E_COMPILE_ERROR, "jump out of a finally block is disallowed");
505        }
506    }
507}
508
509static void zend_adjust_fast_call(zend_op_array *op_array, uint32_t fast_call, uint32_t start, uint32_t end)
510{
511    int i;
512    uint32_t op_num = 0;
513
514    for (i = 0; i < op_array->last_try_catch; i++) {
515        if (op_array->try_catch_array[i].finally_op > start
516                && op_array->try_catch_array[i].finally_end < end) {
517            op_num = op_array->try_catch_array[i].finally_op;
518            start = op_array->try_catch_array[i].finally_end;
519        }
520    }
521
522    if (op_num) {
523        /* Must be ZEND_FAST_CALL */
524        ZEND_ASSERT(op_array->opcodes[op_num - 2].opcode == ZEND_FAST_CALL);
525        op_array->opcodes[op_num - 2].extended_value = ZEND_FAST_CALL_FROM_FINALLY;
526        op_array->opcodes[op_num - 2].op2.opline_num = fast_call;
527    }
528}
529
530static void zend_resolve_fast_call(zend_op_array *op_array, uint32_t fast_call, uint32_t op_num)
531{
532    int i;
533    uint32_t finally_op_num = 0;
534
535    for (i = 0; i < op_array->last_try_catch; i++) {
536        if (op_num >= op_array->try_catch_array[i].finally_op
537                && op_num < op_array->try_catch_array[i].finally_end) {
538            finally_op_num = op_array->try_catch_array[i].finally_op;
539        }
540    }
541
542    if (finally_op_num) {
543        /* Must be ZEND_FAST_CALL */
544        ZEND_ASSERT(op_array->opcodes[finally_op_num - 2].opcode == ZEND_FAST_CALL);
545        if (op_array->opcodes[fast_call].extended_value == 0) {
546            op_array->opcodes[fast_call].extended_value = ZEND_FAST_CALL_FROM_FINALLY;
547            op_array->opcodes[fast_call].op2.opline_num = finally_op_num - 2;
548        }
549    }
550}
551
552static void zend_resolve_finally_call(zend_op_array *op_array, uint32_t op_num, uint32_t dst_num)
553{
554    uint32_t start_op;
555    zend_op *opline;
556    uint32_t i = op_array->last_try_catch;
557
558    if (dst_num != (uint32_t)-1) {
559        zend_check_finally_breakout(op_array, op_num, dst_num);
560    }
561
562    /* the backward order is mater */
563    while (i > 0) {
564        i--;
565        if (op_array->try_catch_array[i].finally_op &&
566            op_num >= op_array->try_catch_array[i].try_op &&
567            op_num < op_array->try_catch_array[i].finally_op - 1 &&
568            (dst_num < op_array->try_catch_array[i].try_op ||
569             dst_num > op_array->try_catch_array[i].finally_end)) {
570            /* we have a jump out of try block that needs executing finally */
571            uint32_t fast_call_var;
572
573            /* Must be ZEND_FAST_RET */
574            ZEND_ASSERT(op_array->opcodes[op_array->try_catch_array[i].finally_end].opcode == ZEND_FAST_RET);
575            fast_call_var = op_array->opcodes[op_array->try_catch_array[i].finally_end].op1.var;
576
577            /* generate a FAST_CALL to finally block */
578            start_op = get_next_op_number(op_array);
579
580            opline = get_next_op(op_array);
581            opline->opcode = ZEND_FAST_CALL;
582            opline->result_type = IS_TMP_VAR;
583            opline->result.var = fast_call_var;
584            SET_UNUSED(opline->op1);
585            SET_UNUSED(opline->op2);
586            zend_adjust_fast_call(op_array, start_op,
587                    op_array->try_catch_array[i].finally_op,
588                    op_array->try_catch_array[i].finally_end);
589            if (op_array->try_catch_array[i].catch_op) {
590                opline->extended_value = ZEND_FAST_CALL_FROM_CATCH;
591                opline->op2.opline_num = op_array->try_catch_array[i].catch_op;
592                opline->op1.opline_num = get_next_op_number(op_array);
593                /* generate a FAST_CALL to hole CALL_FROM_FINALLY */
594                opline = get_next_op(op_array);
595                opline->opcode = ZEND_FAST_CALL;
596                opline->result_type = IS_TMP_VAR;
597                opline->result.var = fast_call_var;
598                SET_UNUSED(opline->op1);
599                SET_UNUSED(opline->op2);
600                zend_resolve_fast_call(op_array, start_op + 1, op_array->try_catch_array[i].finally_op - 2);
601            } else {
602                zend_resolve_fast_call(op_array, start_op, op_array->try_catch_array[i].finally_op - 2);
603            }
604            opline->op1.opline_num = op_array->try_catch_array[i].finally_op;
605
606            /* generate a sequence of FAST_CALL to upward finally block */
607            while (i > 0) {
608                i--;
609                if (op_array->try_catch_array[i].finally_op &&
610                    op_num >= op_array->try_catch_array[i].try_op &&
611                    op_num < op_array->try_catch_array[i].finally_op - 1 &&
612                    (dst_num < op_array->try_catch_array[i].try_op ||
613                     dst_num > op_array->try_catch_array[i].finally_end)) {
614
615                    opline = get_next_op(op_array);
616                    opline->opcode = ZEND_FAST_CALL;
617                    opline->result_type = IS_TMP_VAR;
618                    opline->result.var = fast_call_var;
619                    SET_UNUSED(opline->op1);
620                    SET_UNUSED(opline->op2);
621                    opline->op1.opline_num = op_array->try_catch_array[i].finally_op;
622                }
623            }
624
625            /* Finish the sequence with original opcode */
626            opline = get_next_op(op_array);
627            *opline = op_array->opcodes[op_num];
628
629            /* Replace original opcode with jump to this sequence */
630            opline = op_array->opcodes + op_num;
631            opline->opcode = ZEND_JMP;
632            SET_UNUSED(opline->op1);
633            SET_UNUSED(opline->op2);
634            opline->op1.opline_num = start_op;
635
636            break;
637        }
638    }
639}
640
641static void zend_resolve_finally_ret(zend_op_array *op_array, uint32_t op_num)
642{
643    int i;
644    uint32_t catch_op_num = 0, finally_op_num = 0;
645
646    for (i = 0; i < op_array->last_try_catch; i++) {
647        if (op_array->try_catch_array[i].try_op > op_num) {
648            break;
649        }
650        if (op_num < op_array->try_catch_array[i].finally_op) {
651            finally_op_num = op_array->try_catch_array[i].finally_op;
652        }
653        if (op_num < op_array->try_catch_array[i].catch_op) {
654            catch_op_num = op_array->try_catch_array[i].catch_op;
655        }
656    }
657
658    if (finally_op_num && (!catch_op_num || catch_op_num >= finally_op_num)) {
659        /* in case of unhandled exception return to upward finally block */
660        op_array->opcodes[op_num].extended_value = ZEND_FAST_RET_TO_FINALLY;
661        op_array->opcodes[op_num].op2.opline_num = finally_op_num;
662    } else if (catch_op_num) {
663        /* in case of unhandled exception return to upward catch block */
664        op_array->opcodes[op_num].extended_value = ZEND_FAST_RET_TO_CATCH;
665        op_array->opcodes[op_num].op2.opline_num = catch_op_num;
666    }
667}
668
669static uint32_t zend_get_brk_cont_target(const zend_op_array *op_array, const zend_op *opline) {
670    int nest_levels = opline->op2.num;
671    int array_offset = opline->op1.num;
672    zend_brk_cont_element *jmp_to;
673    do {
674        jmp_to = &op_array->brk_cont_array[array_offset];
675        if (nest_levels > 1) {
676            array_offset = jmp_to->parent;
677        }
678    } while (--nest_levels > 0);
679
680    return opline->opcode == ZEND_BRK ? jmp_to->brk : jmp_to->cont;
681}
682
683static void zend_resolve_finally_calls(zend_op_array *op_array)
684{
685    uint32_t i, j;
686    zend_op *opline;
687
688    for (i = 0, j = op_array->last; i < j; i++) {
689        opline = op_array->opcodes + i;
690        switch (opline->opcode) {
691            case ZEND_RETURN:
692            case ZEND_RETURN_BY_REF:
693            case ZEND_GENERATOR_RETURN:
694                zend_resolve_finally_call(op_array, i, (uint32_t)-1);
695                break;
696            case ZEND_BRK:
697            case ZEND_CONT:
698                zend_resolve_finally_call(op_array, i, zend_get_brk_cont_target(op_array, opline));
699                break;
700            case ZEND_GOTO:
701                if (Z_TYPE_P(CT_CONSTANT_EX(op_array, opline->op2.constant)) != IS_LONG) {
702                    uint32_t num = opline->op2.constant;
703
704                    ZEND_PASS_TWO_UPDATE_CONSTANT(op_array, opline->op2);
705                    zend_resolve_goto_label(op_array, opline, 1);
706                    opline->op2.constant = num;
707                }
708                /* break omitted intentionally */
709            case ZEND_JMP:
710                zend_resolve_finally_call(op_array, i, opline->op1.opline_num);
711                break;
712            case ZEND_FAST_CALL:
713                zend_resolve_fast_call(op_array, i, i);
714                break;
715            case ZEND_FAST_RET:
716                zend_resolve_finally_ret(op_array, i);
717                break;
718            default:
719                break;
720        }
721    }
722}
723
724ZEND_API int pass_two(zend_op_array *op_array)
725{
726    zend_op *opline, *end;
727
728    if (!ZEND_USER_CODE(op_array->type)) {
729        return 0;
730    }
731    if (op_array->fn_flags & ZEND_ACC_HAS_FINALLY_BLOCK) {
732        zend_resolve_finally_calls(op_array);
733    }
734    if (CG(compiler_options) & ZEND_COMPILE_EXTENDED_INFO) {
735        zend_update_extended_info(op_array);
736    }
737    if (CG(compiler_options) & ZEND_COMPILE_HANDLE_OP_ARRAY) {
738        zend_llist_apply_with_argument(&zend_extensions, (llist_apply_with_arg_func_t) zend_extension_op_array_handler, op_array);
739    }
740
741    if (CG(context).vars_size != op_array->last_var) {
742        op_array->vars = (zend_string**) erealloc(op_array->vars, sizeof(zend_string*)*op_array->last_var);
743        CG(context).vars_size = op_array->last_var;
744    }
745    if (CG(context).opcodes_size != op_array->last) {
746        op_array->opcodes = (zend_op *) erealloc(op_array->opcodes, sizeof(zend_op)*op_array->last);
747        CG(context).opcodes_size = op_array->last;
748    }
749    if (CG(context).literals_size != op_array->last_literal) {
750        op_array->literals = (zval*)erealloc(op_array->literals, sizeof(zval) * op_array->last_literal);
751        CG(context).literals_size = op_array->last_literal;
752    }
753    opline = op_array->opcodes;
754    end = opline + op_array->last;
755    while (opline < end) {
756        if (opline->op1_type == IS_CONST) {
757            ZEND_PASS_TWO_UPDATE_CONSTANT(op_array, opline->op1);
758        } else if (opline->op1_type & (IS_VAR|IS_TMP_VAR)) {
759            opline->op1.var = (uint32_t)(zend_intptr_t)ZEND_CALL_VAR_NUM(NULL, op_array->last_var + opline->op1.var);
760        }
761        if (opline->op2_type == IS_CONST) {
762            ZEND_PASS_TWO_UPDATE_CONSTANT(op_array, opline->op2);
763        } else if (opline->op2_type & (IS_VAR|IS_TMP_VAR)) {
764            opline->op2.var = (uint32_t)(zend_intptr_t)ZEND_CALL_VAR_NUM(NULL, op_array->last_var + opline->op2.var);
765        }
766        if (opline->result_type & (IS_VAR|IS_TMP_VAR)) {
767            opline->result.var = (uint32_t)(zend_intptr_t)ZEND_CALL_VAR_NUM(NULL, op_array->last_var + opline->result.var);
768        }
769        switch (opline->opcode) {
770            case ZEND_DECLARE_ANON_INHERITED_CLASS:
771                ZEND_PASS_TWO_UPDATE_JMP_TARGET(op_array, opline, opline->op1);
772                /* break omitted intentionally */
773            case ZEND_DECLARE_INHERITED_CLASS:
774            case ZEND_DECLARE_INHERITED_CLASS_DELAYED:
775                opline->extended_value = (uint32_t)(zend_intptr_t)ZEND_CALL_VAR_NUM(NULL, op_array->last_var + opline->extended_value);
776                break;
777            case ZEND_BRK:
778            case ZEND_CONT:
779                {
780                    uint32_t jmp_target = zend_get_brk_cont_target(op_array, opline);
781                    opline->opcode = ZEND_JMP;
782                    opline->op1.opline_num = jmp_target;
783                    opline->op2.num = 0;
784                    ZEND_PASS_TWO_UPDATE_JMP_TARGET(op_array, opline, opline->op1);
785                }
786                break;
787            case ZEND_GOTO:
788                if (Z_TYPE_P(RT_CONSTANT(op_array, opline->op2)) != IS_LONG) {
789                    zend_resolve_goto_label(op_array, opline, 1);
790                }
791                /* break omitted intentionally */
792            case ZEND_JMP:
793            case ZEND_FAST_CALL:
794            case ZEND_DECLARE_ANON_CLASS:
795                ZEND_PASS_TWO_UPDATE_JMP_TARGET(op_array, opline, opline->op1);
796                break;
797            case ZEND_JMPZNZ:
798                /* absolute index to relative offset */
799                opline->extended_value = ZEND_OPLINE_NUM_TO_OFFSET(op_array, opline, opline->extended_value);
800                /* break omitted intentionally */
801            case ZEND_JMPZ:
802            case ZEND_JMPNZ:
803            case ZEND_JMPZ_EX:
804            case ZEND_JMPNZ_EX:
805            case ZEND_JMP_SET:
806            case ZEND_COALESCE:
807            case ZEND_NEW:
808            case ZEND_FE_RESET_R:
809            case ZEND_FE_RESET_RW:
810            case ZEND_ASSERT_CHECK:
811                ZEND_PASS_TWO_UPDATE_JMP_TARGET(op_array, opline, opline->op2);
812                break;
813            case ZEND_FE_FETCH_R:
814            case ZEND_FE_FETCH_RW:
815                opline->extended_value = ZEND_OPLINE_NUM_TO_OFFSET(op_array, opline, opline->extended_value);
816                break;
817            case ZEND_VERIFY_RETURN_TYPE:
818                if (op_array->fn_flags & ZEND_ACC_GENERATOR) {
819                    MAKE_NOP(opline);
820                }
821                break;
822            case ZEND_RETURN:
823            case ZEND_RETURN_BY_REF:
824                if (op_array->fn_flags & ZEND_ACC_GENERATOR) {
825                    opline->opcode = ZEND_GENERATOR_RETURN;
826                }
827                break;
828        }
829        ZEND_VM_SET_OPCODE_HANDLER(opline);
830        opline++;
831    }
832
833    op_array->fn_flags |= ZEND_ACC_DONE_PASS_TWO;
834    return 0;
835}
836
837int pass_two_wrapper(zval *el)
838{
839    return pass_two((zend_op_array *) Z_PTR_P(el));
840}
841
842int print_class(zend_class_entry *class_entry)
843{
844    printf("Class %s:\n", class_entry->name->val);
845    zend_hash_apply(&class_entry->function_table, pass_two_wrapper);
846    printf("End of class %s.\n\n", class_entry->name->val);
847    return 0;
848}
849
850ZEND_API unary_op_type get_unary_op(int opcode)
851{
852    switch (opcode) {
853        case ZEND_BW_NOT:
854            return (unary_op_type) bitwise_not_function;
855        case ZEND_BOOL_NOT:
856            return (unary_op_type) boolean_not_function;
857        default:
858            return (unary_op_type) NULL;
859    }
860}
861
862ZEND_API binary_op_type get_binary_op(int opcode)
863{
864    switch (opcode) {
865        case ZEND_ADD:
866        case ZEND_ASSIGN_ADD:
867            return (binary_op_type) add_function;
868        case ZEND_SUB:
869        case ZEND_ASSIGN_SUB:
870            return (binary_op_type) sub_function;
871        case ZEND_MUL:
872        case ZEND_ASSIGN_MUL:
873            return (binary_op_type) mul_function;
874        case ZEND_POW:
875            return (binary_op_type) pow_function;
876        case ZEND_DIV:
877        case ZEND_ASSIGN_DIV:
878            return (binary_op_type) div_function;
879        case ZEND_MOD:
880        case ZEND_ASSIGN_MOD:
881            return (binary_op_type) mod_function;
882        case ZEND_SL:
883        case ZEND_ASSIGN_SL:
884            return (binary_op_type) shift_left_function;
885        case ZEND_SR:
886        case ZEND_ASSIGN_SR:
887            return (binary_op_type) shift_right_function;
888        case ZEND_FAST_CONCAT:
889        case ZEND_CONCAT:
890        case ZEND_ASSIGN_CONCAT:
891            return (binary_op_type) concat_function;
892        case ZEND_IS_IDENTICAL:
893            return (binary_op_type) is_identical_function;
894        case ZEND_IS_NOT_IDENTICAL:
895            return (binary_op_type) is_not_identical_function;
896        case ZEND_IS_EQUAL:
897            return (binary_op_type) is_equal_function;
898        case ZEND_IS_NOT_EQUAL:
899            return (binary_op_type) is_not_equal_function;
900        case ZEND_IS_SMALLER:
901            return (binary_op_type) is_smaller_function;
902        case ZEND_IS_SMALLER_OR_EQUAL:
903            return (binary_op_type) is_smaller_or_equal_function;
904        case ZEND_SPACESHIP:
905            return (binary_op_type) compare_function;
906        case ZEND_BW_OR:
907        case ZEND_ASSIGN_BW_OR:
908            return (binary_op_type) bitwise_or_function;
909        case ZEND_BW_AND:
910        case ZEND_ASSIGN_BW_AND:
911            return (binary_op_type) bitwise_and_function;
912        case ZEND_BW_XOR:
913        case ZEND_ASSIGN_BW_XOR:
914            return (binary_op_type) bitwise_xor_function;
915        case ZEND_BOOL_XOR:
916            return (binary_op_type) boolean_xor_function;
917        default:
918            return (binary_op_type) NULL;
919    }
920}
921
922/*
923 * Local variables:
924 * tab-width: 4
925 * c-basic-offset: 4
926 * indent-tabs-mode: t
927 * End:
928 */
929