php-src/Zend
Arnaud Le Blanc 0406a55c92
Prevent resumption of generator suspended in yield from
Normally we prevent generators from being resumed while they are already
running, but we failed to do so for generators delegating to non-Generators. As
a result such generator can be resumed, terminated, which causes unexpected
results (crashes) later.

In gh19306.phpt in particular, the generator delegate It::getIterator() suspends
while being called by generator g(). We then resume g(), which throws while
trying to resume It::getIterator(). This causes g() and It::getIterator()
to be released. We then UAF when resuming the Fiber in It::getIterator().

Fix this by ensuring that generators are marked as running while they fetch
the next value from the delegate.

Fixes GH-19306
Closes GH-19315
2025-07-31 08:45:19 +02:00
..
asm Merge branch 'PHP-8.2' 2023-02-05 16:47:09 +00:00
Optimizer Fix RCN violations in array functions 2025-06-24 23:29:00 +02:00
tests Prevent resumption of generator suspended in yield from 2025-07-31 08:45:19 +02:00
bench.php
LICENSE
Makefile.frag Remove unneeded zend_language_parser.h patch (#11974) 2023-08-22 11:21:42 +02:00
micro_bench.php
README.md [ci skip] Update README.md on ZE description 2022-02-08 10:38:33 +01:00
zend.c Merge branch 'PHP-8.2' into PHP-8.3 2024-10-31 23:39:40 +01:00
zend.h PHP 8.3 is now for PHP-8.3.25-dev 2025-07-16 14:09:24 +02:00
Zend.m4 Fix GH-13727: macro generating invalid call test prototypes fixes. 2024-03-18 06:53:39 +00:00
zend_alloc.c Merge branch 'PHP-8.2' into PHP-8.3 2025-06-20 14:51:00 +02:00
zend_alloc.h Revert "Zend/zend_types.h: move zend_result to separate header (#10609)" 2023-04-04 22:48:26 +03:00
zend_alloc_sizes.h Fix GH-9361: Segmentation fault on script exit 2022-08-22 12:59:17 +02:00
zend_API.c Destroy temporary module classes in reverse order 2025-03-14 10:45:17 +01:00
zend_API.h Fix GH-17162: zend_array_try_init() with dtor can cause engine UAF 2024-12-15 20:11:40 +01:00
zend_arena.h Revert GH-10279 2023-01-16 12:25:59 +01:00
zend_ast.c Fix failed assertion with throwing __toString in binary const expr 2025-07-30 13:34:01 +02:00
zend_ast.h Use zend_ast_size consistenly (#11955) 2023-08-14 00:51:14 +02:00
zend_atomic.c Fixed undefined macros warnings 2022-09-22 13:17:02 +02:00
zend_atomic.h Fix GH-13215 GCC 14 build 2024-01-22 10:58:04 +01:00
zend_attributes.c Merge branch 'PHP-8.2' into PHP-8.3 2024-05-06 12:48:32 +02:00
zend_attributes.h Merge branch 'PHP-8.2' into PHP-8.3 2024-05-06 12:48:32 +02:00
zend_attributes.stub.php Add support for typed class constants in stubs 2023-07-01 11:50:04 +02:00
zend_attributes_arginfo.h Fix GH-9967 Add support for generating custom function, class const, and property attributes in stubs 2023-08-26 21:35:31 +02:00
zend_bitset.h Add AVX2-accelerated UTF-16 decoding/encoding routines 2023-02-05 20:06:42 +02:00
zend_build.h Revert GH-10279 2023-01-16 12:25:59 +01:00
zend_builtin_functions.c Merge branch 'PHP-8.2' into PHP-8.3 2024-09-27 17:35:55 +02:00
zend_builtin_functions.h Revert "Zend/zend_types.h: move zend_result to separate header (#10609)" 2023-04-04 22:48:26 +03:00
zend_builtin_functions.stub.php Fix gc_status type info 2023-07-17 13:49:23 +02:00
zend_builtin_functions_arginfo.h Fix GH-9967 Add support for generating custom function, class const, and property attributes in stubs 2023-08-26 21:35:31 +02:00
zend_call_stack.c fix memleak due to missing pthread_attr_destroy()-call 2024-06-10 16:09:26 +02:00
zend_call_stack.h zend_call_stack_default_size update BSD values. (#12051) 2023-08-26 16:36:02 +01:00
zend_closures.c Merge branch 'PHP-8.2' into PHP-8.3 2024-10-22 14:48:58 +02:00
zend_closures.h Revert GH-10300 2023-01-16 12:22:54 +01:00
zend_closures.stub.php
zend_closures_arginfo.h
zend_compile.c Fix stack overflow detection for variable compilation 2025-01-29 23:27:27 +01:00
zend_compile.h RFC: Add #[Override] attribute (#9836) 2023-06-29 20:23:53 +02:00
zend_config.w32.h
zend_constants.c Revert "Remove name field from the zend_constant struct (#10954)" 2023-07-17 22:32:41 +02:00
zend_constants.h Revert "Remove name field from the zend_constant struct (#10954)" 2023-07-17 22:32:41 +02:00
zend_constants.stub.php Declare remaining Zend constants in stubs (#9730) 2022-10-12 22:43:36 +02:00
zend_constants_arginfo.h Declare remaining Zend constants in stubs (#9730) 2022-10-12 22:43:36 +02:00
zend_cpuinfo.c Windows arm64 zend and standard extension support 2022-08-09 12:45:14 +02:00
zend_cpuinfo.h Fix build on Apple Clang 17+ (#18629) 2025-05-24 22:26:06 +02:00
zend_default_classes.c
zend_dtrace.c
zend_dtrace.d
zend_dtrace.h
zend_enum.c Merge branch 'PHP-8.2' into PHP-8.3 2024-09-08 23:44:48 +02:00
zend_enum.h Merge branch 'PHP-8.2' into PHP-8.3 2024-08-07 14:55:14 +02:00
zend_enum.stub.php
zend_enum_arginfo.h
zend_errors.h
zend_exceptions.c Fix GH-17408: Assertion failure Zend/zend_exceptions.c 2025-01-21 08:20:38 +01:00
zend_exceptions.h Revert "Zend/zend_types.h: move zend_result to separate header (#10609)" 2023-04-04 22:48:26 +03:00
zend_exceptions.stub.php Require zend_constants.stub.php from zend_exceptions.stubs.php 2022-07-12 10:35:03 +02:00
zend_exceptions_arginfo.h Fix GH-9967 Add support for generating custom function, class const, and property attributes in stubs 2023-08-26 21:35:31 +02:00
zend_execute.c Fix GH-17736: Assertion failure zend_reference_destroy() 2025-03-02 22:33:32 +01:00
zend_execute.h Assert ptr_ptr value of TMP|CONST isn't used (#11865) 2023-08-03 15:28:19 +02:00
zend_execute_API.c Fix GH-17216: Trampoline crash on error 2024-12-21 00:25:06 +01:00
zend_extensions.c Document zend_get_op_array_extension_handle 2023-03-30 17:45:34 -06:00
zend_extensions.h Update API versions and numbers 2023-08-29 17:04:24 +01:00
zend_fibers.c Merge branch 'PHP-8.2' into PHP-8.3 2024-08-28 17:44:41 +02:00
zend_fibers.h Zend/zend_fibers: change return value to zend_result 2023-02-26 15:07:08 +00:00
zend_fibers.stub.php
zend_fibers_arginfo.h
zend_float.c Revert GH-10279 2023-01-16 12:25:59 +01:00
zend_float.h Revert GH-10279 2023-01-16 12:25:59 +01:00
zend_gc.c Fixed bug GH-13193 again 2025-03-21 11:47:52 +01:00
zend_gc.h Remove WeakMap entries whose key is only reachable through the entry value (#10932) 2023-07-16 13:39:08 +02:00
zend_gdb.c Merge branch 'PHP-8.2' 2023-07-13 12:40:59 +01:00
zend_gdb.h
zend_generators.c Prevent resumption of generator suspended in yield from 2025-07-31 08:45:19 +02:00
zend_generators.h Merge branch 'PHP-8.2' into PHP-8.3 2024-10-02 12:31:21 +02:00
zend_generators.stub.php
zend_generators_arginfo.h
zend_globals.h Shrink some commonly used structs by reordering members (#10880) 2023-03-22 19:26:42 +01:00
zend_globals_macros.h Revert GH-10300 2023-01-16 12:22:54 +01:00
zend_hash.c Merge branch 'PHP-8.2' into PHP-8.3 2024-11-04 15:51:03 +01:00
zend_hash.h Merge branch 'PHP-8.2' into PHP-8.3 2024-11-04 16:02:16 +01:00
zend_highlight.c Align highlight_string|file with HTML standard and modern browsers 2023-08-12 15:08:28 +01:00
zend_highlight.h Revert "Zend/zend_types.h: move zend_result to separate header (#10609)" 2023-04-04 22:48:26 +03:00
zend_hrtime.c Use ZEND_API in zend_hrtime (#13288) 2024-03-17 03:09:08 +01:00
zend_hrtime.h Use ZEND_API in zend_hrtime (#13288) 2024-03-17 03:09:08 +01:00
zend_inheritance.c Relax final+private warning for trait methods with inherited final 2025-01-13 16:46:01 +01:00
zend_inheritance.h RFC: Add #[Override] attribute (#9836) 2023-06-29 20:23:53 +02:00
zend_ini.c Add comment 2025-01-09 19:52:13 +01:00
zend_ini.h Fix -Wenum-int-mismatch warnings on gcc 13 2023-04-20 16:04:59 +02:00
zend_ini_parser.y Fix OSS-Fuzz #428983568 and #428760800 2025-07-04 23:58:06 +02:00
zend_ini_scanner.h Zend/zend_ini_scanner: parse const strings 2023-01-04 12:49:48 +00:00
zend_ini_scanner.l Fix -Wuseless-escape warnings emitted by re2c (#19050) 2025-07-07 09:51:25 +02:00
zend_interfaces.c Merge branch 'PHP-8.2' into PHP-8.3 2024-09-26 22:03:01 +02:00
zend_interfaces.h Revert GH-10300 2023-01-16 12:22:54 +01:00
zend_interfaces.stub.php
zend_interfaces_arginfo.h
zend_istdiostream.h
zend_iterators.c Revert GH-10300 2023-01-16 12:22:54 +01:00
zend_iterators.h Revert GH-10300 2023-01-16 12:22:54 +01:00
zend_language_parser.y Correctly handle multiple constants in typed declaration 2023-05-21 14:17:01 +01:00
zend_language_scanner.h Revert GH-10300 2023-01-16 12:22:54 +01:00
zend_language_scanner.l Fix -Wuseless-escape warnings emitted by re2c (#19050) 2025-07-07 09:51:25 +02:00
zend_list.c Merge branch 'PHP-8.1' into PHP-8.2 2023-10-29 21:47:23 +01:00
zend_list.h Fix -Wenum-int-mismatch warnings on gcc 13 2023-04-20 16:04:59 +02:00
zend_llist.c Revert GH-10300 2023-01-16 12:22:54 +01:00
zend_llist.h Revert GH-10300 2023-01-16 12:22:54 +01:00
zend_long.h Revert GH-10279 2023-01-16 12:25:59 +01:00
zend_map_ptr.h Revert GH-10279 2023-01-16 12:25:59 +01:00
zend_max_execution_timer.c zend_max_execution_timer: fix gcc compatibility (#15447) 2024-08-20 16:28:03 +02:00
zend_max_execution_timer.h fix: support for timeouts with ZTS on Linux (#10141) 2023-03-03 11:35:06 +01:00
zend_mmap.h Use PDEATHSIG to kill cli-server workers if parent exists 2022-09-08 10:48:20 +02:00
zend_modules.h Merge branch 'PHP-8.2' into PHP-8.3 2024-02-20 21:25:06 +01:00
zend_multibyte.c Revert GH-10220 2023-01-16 12:27:33 +01:00
zend_multibyte.h Fix -Wenum-int-mismatch warnings on gcc 13 2023-04-20 16:04:59 +02:00
zend_multiply.h Add missing cc clobber 2025-07-22 12:43:08 +02:00
zend_object_handlers.c Prevent operands from being released during comparison 2025-07-30 18:09:24 +02:00
zend_object_handlers.h Introduce Zend guard recursion protection 2023-08-24 13:03:14 +01:00
zend_objects.c Merge branch 'PHP-8.2' into PHP-8.3 2024-03-08 18:27:10 +01:00
zend_objects.h Revert GH-10300 2023-01-16 12:22:54 +01:00
zend_objects_API.c Fix use after free during shutdown destruction 2025-06-18 21:20:03 +02:00
zend_objects_API.h Zend/zend_types.h: deprecate zend_bool, zend_intptr_t, zend_uintptr_t (#10597) 2023-02-18 19:31:28 +00:00
zend_observer.c Fix add/remove observer API with multiple observers installed 2023-06-09 14:00:53 +02:00
zend_observer.h Revert GH-10300 2023-01-16 12:22:54 +01:00
zend_opcode.c Use-after-free for ??= due to incorrect live-range calculation 2025-03-11 22:10:21 +01:00
zend_operators.c Prevent operands from being released during comparison 2025-07-30 18:09:24 +02:00
zend_operators.h Fix fallback paths in fast_long_{add,sub}_function 2025-02-03 22:38:00 +01:00
zend_portability.h Fix GH-19169: ZEND_STATIC_ASSERT for -std=c++17 2025-07-18 18:00:24 +01:00
zend_ptr_stack.c Revert GH-10220 2023-01-16 12:27:33 +01:00
zend_ptr_stack.h Revert GH-10220 2023-01-16 12:27:33 +01:00
zend_range_check.h
zend_signal.c Merge branch 'PHP-8.2' of https://github.com/php/php-src into PHP-8.3 2024-03-18 20:26:00 +01:00
zend_signal.h Revert GH-10220 2023-01-16 12:27:33 +01:00
zend_smart_str.c Revert GH-10220 2023-01-16 12:27:33 +01:00
zend_smart_str.h Revert GH-10220 2023-01-16 12:27:33 +01:00
zend_smart_str_public.h Revert GH-10220 2023-01-16 12:27:33 +01:00
zend_smart_string.h Revert GH-10220 2023-01-16 12:27:33 +01:00
zend_smart_string_public.h Revert GH-10220 2023-01-16 12:27:33 +01:00
zend_sort.c Revert "#include cleanup (#10216)" 2023-01-16 12:29:41 +01:00
zend_sort.h Revert "#include cleanup (#10216)" 2023-01-16 12:29:41 +01:00
zend_stack.c Two enums instead of preprocessor macros (#10617) 2023-02-21 15:34:33 +01:00
zend_stack.h Two enums instead of preprocessor macros (#10617) 2023-02-21 15:34:33 +01:00
zend_stream.c Revert GH-10279 2023-01-16 12:25:59 +01:00
zend_stream.h Revert "Zend/zend_types.h: move zend_result to separate header (#10609)" 2023-04-04 22:48:26 +03:00
zend_string.c Backport GH-16348 2024-12-09 21:00:05 +01:00
zend_string.h Fix zend_string_starts_with_literal_ci (#14137) 2024-05-06 08:49:33 +03:00
zend_strtod.c Merge branch 'PHP-8.2' into PHP-8.3 2024-11-08 12:27:24 +00:00
zend_strtod.h
zend_strtod_int.h build/php.m4: remove test for integer types (#10304) 2023-01-13 11:51:15 +00:00
zend_system_id.c zend_compiler, ...: use uint8_t instead of zend_uchar (#10621) 2023-02-23 14:56:54 +00:00
zend_system_id.h Revert "Zend/zend_types.h: move zend_result to separate header (#10609)" 2023-04-04 22:48:26 +03:00
zend_type_info.h Backport fix for HASH/PACKED array inference through MAY_BE_ARRAY_EMPTY flag (#12591) 2023-11-03 10:54:57 +03:00
zend_types.h Prevent operands from being released during comparison 2025-07-30 18:09:24 +02:00
zend_variables.c Revert "Zend/zend_type_code: remove hard-coded integer values and" 2023-03-03 21:19:58 +00:00
zend_variables.h Revert GH-10220 2023-01-16 12:27:33 +01:00
zend_virtual_cwd.c Remove unnecessary memory clearing in virtual_file_ex() (#10963) 2023-04-12 21:28:53 +02:00
zend_virtual_cwd.h Merge branch 'PHP-8.2' into PHP-8.3 2024-11-29 22:09:40 +01:00
zend_vm.h Add function exposing HAVE_GCC_GLOBAL_REGS (#8359) 2022-06-08 12:32:30 +01:00
zend_vm_def.h Fix GH-19303: Unpacking empty packed array into uninitialized array causes assertion failure 2025-07-30 22:47:11 +02:00
zend_vm_execute.h Fix GH-19303: Unpacking empty packed array into uninitialized array causes assertion failure 2025-07-30 22:47:11 +02:00
zend_vm_execute.skl Zend/zend_types.h: deprecate zend_bool, zend_intptr_t, zend_uintptr_t (#10597) 2023-02-18 19:31:28 +00:00
zend_vm_gen.php Fix GH-17836: zend_vm_gen.php shouldn't break on Windows line endings 2025-03-21 11:50:34 +01:00
zend_vm_handlers.h Add typed specialization for ZEND_COUNT (#11825) 2023-08-03 12:33:32 +02:00
zend_vm_opcodes.c Allow arbitrary expressions in static variable initializer 2023-05-24 20:17:31 +02:00
zend_vm_opcodes.h Allow arbitrary expressions in static variable initializer 2023-05-24 20:17:31 +02:00
zend_vm_trace_handlers.h Use more compact representation for packed arrays. 2021-11-03 15:18:26 +03:00
zend_vm_trace_lines.h
zend_vm_trace_map.h Use more compact representation for packed arrays. 2021-11-03 15:18:26 +03:00
zend_weakrefs.c Merge branch 'PHP-8.2' into PHP-8.3 2024-10-15 12:23:00 +02:00
zend_weakrefs.h Remove WeakMap entries whose key is only reachable through the entry value (#10932) 2023-07-16 13:39:08 +02:00
zend_weakrefs.stub.php
zend_weakrefs_arginfo.h

Zend Engine

Zend memory manager

General

The goal of the new memory manager (available since PHP 5.2) is to reduce memory allocation overhead and speedup memory management.

Debugging

Normal:

sapi/cli/php -r 'leak();'

Zend MM disabled:

USE_ZEND_ALLOC=0 valgrind --leak-check=full sapi/cli/php -r 'leak();'

Shared extensions

Since PHP 5.3.11 it is possible to prevent shared extensions from unloading so that valgrind can correctly track the memory leaks in shared extensions. For this there is the ZEND_DONT_UNLOAD_MODULES environment variable. If set, then DL_UNLOAD() is skipped during the shutdown of shared extensions.

ZEND_VM

ZEND_VM architecture allows specializing opcode handlers according to op_type fields and using different execution methods (call threading, switch threading and direct threading). As a result ZE2 got more than 20% speedup on raw PHP code execution (with specialized executor and direct threading execution method). As in most PHP applications raw execution speed isn't the limiting factor but system calls and database calls are, your mileage with this patch will vary.

Most parts of the old zend_execute.c go into zend_vm_def.h. Here you can find opcode handlers and helpers. The typical opcode handler template looks like this:

ZEND_VM_HANDLER(<OPCODE-NUMBER>, <OPCODE>, <OP1_TYPES>, <OP2_TYPES>)
{
    <HANDLER'S CODE>
}

<OPCODE-NUMBER> is a opcode number (0, 1, ...) <OPCODE> is an opcode name (ZEN_NOP, ZEND_ADD, :) <OP1_TYPES> and <OP2_TYPES> are masks for allowed operand op_types. Specializer will generate code only for defined combination of types. You can use any combination of the following op_types UNUSED, CONST, VAR, TMP and CV also you can use ANY mask to disable specialization according operand's op_type. <HANDLER'S CODE> is a handler's code itself. For most handlers it stills the same as in old zend_execute.c, but now it uses macros to access opcode operands and some internal executor data.

You can see the conformity of new macros to old code in the following list:

EXECUTE_DATA
    execute_data
ZEND_VM_DISPATCH_TO_HANDLER(<OP>)
    return <OP>_helper(ZEND_OPCODE_HANDLER_ARGS_PASSTHRU)
ZEND_VM_DISPATCH_TO_HELPER(<NAME>)
    return <NAME>(ZEND_OPCODE_HANDLER_ARGS_PASSTHRU)
ZEND_VM_DISPATCH_TO_HELPER_EX(<NAME>,<PARAM>,<VAL>)
    return <NAME>(<VAL>, ZEND_OPCODE_HANDLER_ARGS_PASSTHRU)
ZEND_VM_CONTINUE()
    return 0
ZEND_VM_NEXT_OPCODE()
    NEXT_OPCODE()
ZEND_VM_SET_OPCODE(<TARGET>
    SET_OPCODE(<TARGET>
ZEND_VM_INC_OPCODE()
    INC_OPCOD()
ZEND_VM_RETURN_FROM_EXECUTE_LOOP()
    RETURN_FROM_EXECUTE_LOOP()
ZEND_VM_C_LABEL(<LABEL>):
    <LABEL>:
ZEND_VM_C_GOTO(<LABEL>)
    goto <LABEL>
OP<X>_TYPE
    opline->op<X>.op_type
GET_OP<X>_ZVAL_PTR(<TYPE>)
    get_zval_ptr(&opline->op<X>, EX(Ts), &free_op<X>, <TYPE>)
GET_OP<X>_ZVAL_PTR_PTR(<TYPE>)
    get_zval_ptr_ptr(&opline->op<X>, EX(Ts), &free_op<X>, <TYPE>)
GET_OP<X>_OBJ_ZVAL_PTR(<TYPE>)
    get_obj_zval_ptr(&opline->op<X>, EX(Ts), &free_op<X>, <TYPE>)
GET_OP<X>_OBJ_ZVAL_PTR_PTR(<TYPE>)
    get_obj_zval_ptr_ptr(&opline->op<X>, EX(Ts), &free_op<X>, <TYPE>)
IS_OP<X>_TMP_FREE()
    IS_TMP_FREE(free_op<X>)
FREE_OP<X>()
    FREE_OP(free_op<X>)
FREE_OP<X>_IF_VAR()
    FREE_VAR(free_op<X>)
FREE_OP<X>_VAR_PTR()
    FREE_VAR_PTR(free_op<X>)

Executor's helpers can be defined without parameters or with one parameter. This is done with the following constructs:

ZEND_VM_HELPER(<HELPER-NAME>, <OP1_TYPES>, <OP2_TYPES>)
{
    <HELPER'S CODE>
}

ZEND_VM_HELPER_EX(<HELPER-NAME>, <OP1_TYPES>, <OP2_TYPES>, <PARAM_SPEC>)
{
    <HELPER'S CODE>
}

The executors code is generated by the PHP script zend_vm_gen.php. It uses zend_vm_def.h and zend_vm_execute.skl as input and produces zend_vm_opcodes.h and zend_vm_execute.h. The first file is a list of opcode definitions. It is included from zend_compile.h. The second one is an executor code itself. It is included from zend_execute.c.

zend_vm_gen.php can produce different kind of executors. You can select a different opcode threading model using --with-vm-kind=CALL|SWITCH|GOTO|HYBRID. You can disable opcode specialization using --without-specializer. At last you can debug the executor using the original zend_vm_def.h or the generated zend_vm_execute.h file. Debugging with the original file requires the --with-lines option. By default, Zend Engine uses the following command to generate the executor:

# Default VM kind is HYBRID
php zend_vm_gen.php --with-vm-kind=HYBRID