Chris@909: module CodeRay Chris@909: module Scanners Chris@909: Chris@909: load :html Chris@909: Chris@909: # Scanner for PHP. Chris@909: # Chris@909: # Original by Stefan Walk. Chris@909: class PHP < Scanner Chris@909: Chris@909: register_for :php Chris@909: file_extension 'php' Chris@909: encoding 'BINARY' Chris@909: Chris@909: KINDS_NOT_LOC = HTML::KINDS_NOT_LOC Chris@909: Chris@909: protected Chris@909: Chris@909: def setup Chris@909: @html_scanner = CodeRay.scanner :html, :tokens => @tokens, :keep_tokens => true, :keep_state => true Chris@909: end Chris@909: Chris@909: def reset_instance Chris@909: super Chris@909: @html_scanner.reset Chris@909: end Chris@909: Chris@909: module Words # :nodoc: Chris@909: Chris@909: # according to http://www.php.net/manual/en/reserved.keywords.php Chris@909: KEYWORDS = %w[ Chris@909: abstract and array as break case catch class clone const continue declare default do else elseif Chris@909: enddeclare endfor endforeach endif endswitch endwhile extends final for foreach function global Chris@909: goto if implements interface instanceof namespace new or private protected public static switch Chris@909: throw try use var while xor Chris@909: cfunction old_function Chris@909: ] Chris@909: Chris@909: TYPES = %w[ int integer float double bool boolean string array object resource ] Chris@909: Chris@909: LANGUAGE_CONSTRUCTS = %w[ Chris@909: die echo empty exit eval include include_once isset list Chris@909: require require_once return print unset Chris@909: ] Chris@909: Chris@909: CLASSES = %w[ Directory stdClass __PHP_Incomplete_Class exception php_user_filter Closure ] Chris@909: Chris@909: # according to http://php.net/quickref.php on 2009-04-21; Chris@909: # all functions with _ excluded (module functions) and selected additional functions Chris@909: BUILTIN_FUNCTIONS = %w[ Chris@909: abs acos acosh addcslashes addslashes aggregate array arsort ascii2ebcdic asin asinh asort assert atan atan2 Chris@909: atanh basename bcadd bccomp bcdiv bcmod bcmul bcpow bcpowmod bcscale bcsqrt bcsub bin2hex bindec Chris@909: bindtextdomain bzclose bzcompress bzdecompress bzerrno bzerror bzerrstr bzflush bzopen bzread bzwrite Chris@909: calculhmac ceil chdir checkdate checkdnsrr chgrp chmod chop chown chr chroot clearstatcache closedir closelog Chris@909: compact constant copy cos cosh count crc32 crypt current date dcgettext dcngettext deaggregate decbin dechex Chris@909: decoct define defined deg2rad delete dgettext die dirname diskfreespace dl dngettext doubleval each Chris@909: ebcdic2ascii echo empty end ereg eregi escapeshellarg escapeshellcmd eval exec exit exp explode expm1 extract Chris@909: fclose feof fflush fgetc fgetcsv fgets fgetss file fileatime filectime filegroup fileinode filemtime fileowner Chris@909: fileperms filepro filesize filetype floatval flock floor flush fmod fnmatch fopen fpassthru fprintf fputcsv Chris@909: fputs fread frenchtojd fscanf fseek fsockopen fstat ftell ftok ftruncate fwrite getallheaders getcwd getdate Chris@909: getenv gethostbyaddr gethostbyname gethostbynamel getimagesize getlastmod getmxrr getmygid getmyinode getmypid Chris@909: getmyuid getopt getprotobyname getprotobynumber getrandmax getrusage getservbyname getservbyport gettext Chris@909: gettimeofday gettype glob gmdate gmmktime gmstrftime gregoriantojd gzclose gzcompress gzdecode gzdeflate Chris@909: gzencode gzeof gzfile gzgetc gzgets gzgetss gzinflate gzopen gzpassthru gzputs gzread gzrewind gzseek gztell Chris@909: gzuncompress gzwrite hash header hebrev hebrevc hexdec htmlentities htmlspecialchars hypot iconv idate Chris@909: implode include intval ip2long iptcembed iptcparse isset Chris@909: jddayofweek jdmonthname jdtofrench jdtogregorian jdtojewish jdtojulian jdtounix jewishtojd join jpeg2wbmp Chris@909: juliantojd key krsort ksort lcfirst lchgrp lchown levenshtein link linkinfo list localeconv localtime log Chris@909: log10 log1p long2ip lstat ltrim mail main max md5 metaphone mhash microtime min mkdir mktime msql natcasesort Chris@909: natsort next ngettext nl2br nthmac octdec opendir openlog Chris@909: ord overload pack passthru pathinfo pclose pfsockopen phpcredits phpinfo phpversion pi png2wbmp popen pos pow Chris@909: prev print printf putenv quotemeta rad2deg rand range rawurldecode rawurlencode readdir readfile readgzfile Chris@909: readline readlink realpath recode rename require reset rewind rewinddir rmdir round rsort rtrim scandir Chris@909: serialize setcookie setlocale setrawcookie settype sha1 shuffle signeurlpaiement sin sinh sizeof sleep snmpget Chris@909: snmpgetnext snmprealwalk snmpset snmpwalk snmpwalkoid sort soundex split spliti sprintf sqrt srand sscanf stat Chris@909: strcasecmp strchr strcmp strcoll strcspn strftime stripcslashes stripos stripslashes stristr strlen Chris@909: strnatcasecmp strnatcmp strncasecmp strncmp strpbrk strpos strptime strrchr strrev strripos strrpos strspn Chris@909: strstr strtok strtolower strtotime strtoupper strtr strval substr symlink syslog system tan tanh tempnam Chris@909: textdomain time tmpfile touch trim uasort ucfirst ucwords uksort umask uniqid unixtojd unlink unpack Chris@909: unserialize unset urldecode urlencode usleep usort vfprintf virtual vprintf vsprintf wordwrap Chris@909: array_change_key_case array_chunk array_combine array_count_values array_diff array_diff_assoc Chris@909: array_diff_key array_diff_uassoc array_diff_ukey array_fill array_fill_keys array_filter array_flip Chris@909: array_intersect array_intersect_assoc array_intersect_key array_intersect_uassoc array_intersect_ukey Chris@909: array_key_exists array_keys array_map array_merge array_merge_recursive array_multisort array_pad Chris@909: array_pop array_product array_push array_rand array_reduce array_reverse array_search array_shift Chris@909: array_slice array_splice array_sum array_udiff array_udiff_assoc array_udiff_uassoc array_uintersect Chris@909: array_uintersect_assoc array_uintersect_uassoc array_unique array_unshift array_values array_walk Chris@909: array_walk_recursive Chris@909: assert_options base_convert base64_decode base64_encode Chris@909: chunk_split class_exists class_implements class_parents Chris@909: count_chars debug_backtrace debug_print_backtrace debug_zval_dump Chris@909: error_get_last error_log error_reporting extension_loaded Chris@909: file_exists file_get_contents file_put_contents load_file Chris@909: func_get_arg func_get_args func_num_args function_exists Chris@909: get_browser get_called_class get_cfg_var get_class get_class_methods get_class_vars Chris@909: get_current_user get_declared_classes get_declared_interfaces get_defined_constants Chris@909: get_defined_functions get_defined_vars get_extension_funcs get_headers get_html_translation_table Chris@909: get_include_path get_included_files get_loaded_extensions get_magic_quotes_gpc get_magic_quotes_runtime Chris@909: get_meta_tags get_object_vars get_parent_class get_required_filesget_resource_type Chris@909: gc_collect_cycles gc_disable gc_enable gc_enabled Chris@909: halt_compiler headers_list headers_sent highlight_file highlight_string Chris@909: html_entity_decode htmlspecialchars_decode Chris@909: in_array include_once inclued_get_data Chris@909: is_a is_array is_binary is_bool is_buffer is_callable is_dir is_double is_executable is_file is_finite Chris@909: is_float is_infinite is_int is_integer is_link is_long is_nan is_null is_numeric is_object is_readable Chris@909: is_real is_resource is_scalar is_soap_fault is_string is_subclass_of is_unicode is_uploaded_file Chris@909: is_writable is_writeable Chris@909: locale_get_default locale_set_default Chris@909: number_format override_function parse_str parse_url Chris@909: php_check_syntax php_ini_loaded_file php_ini_scanned_files php_logo_guid php_sapi_name Chris@909: php_strip_whitespace php_uname Chris@909: preg_filter preg_grep preg_last_error preg_match preg_match_all preg_quote preg_replace Chris@909: preg_replace_callback preg_split print_r Chris@909: require_once register_shutdown_function register_tick_function Chris@909: set_error_handler set_exception_handler set_file_buffer set_include_path Chris@909: set_magic_quotes_runtime set_time_limit shell_exec Chris@909: str_getcsv str_ireplace str_pad str_repeat str_replace str_rot13 str_shuffle str_split str_word_count Chris@909: strip_tags substr_compare substr_count substr_replace Chris@909: time_nanosleep time_sleep_until Chris@909: token_get_all token_name trigger_error Chris@909: unregister_tick_function use_soap_error_handler user_error Chris@909: utf8_decode utf8_encode var_dump var_export Chris@909: version_compare Chris@909: zend_logo_guid zend_thread_id zend_version Chris@909: create_function call_user_func_array Chris@909: posix_access posix_ctermid posix_get_last_error posix_getcwd posix_getegid Chris@909: posix_geteuid posix_getgid posix_getgrgid posix_getgrnam posix_getgroups Chris@909: posix_getlogin posix_getpgid posix_getpgrp posix_getpid posix_getppid Chris@909: posix_getpwnam posix_getpwuid posix_getrlimit posix_getsid posix_getuid Chris@909: posix_initgroups posix_isatty posix_kill posix_mkfifo posix_mknod Chris@909: posix_setegid posix_seteuid posix_setgid posix_setpgid posix_setsid Chris@909: posix_setuid posix_strerror posix_times posix_ttyname posix_uname Chris@909: pcntl_alarm pcntl_exec pcntl_fork pcntl_getpriority pcntl_setpriority Chris@909: pcntl_signal pcntl_signal_dispatch pcntl_sigprocmask pcntl_sigtimedwait Chris@909: pcntl_sigwaitinfo pcntl_wait pcntl_waitpid pcntl_wexitstatus pcntl_wifexited Chris@909: pcntl_wifsignaled pcntl_wifstopped pcntl_wstopsig pcntl_wtermsig Chris@909: ] Chris@909: # TODO: more built-in PHP functions? Chris@909: Chris@909: EXCEPTIONS = %w[ Chris@909: E_ERROR E_WARNING E_PARSE E_NOTICE E_CORE_ERROR E_CORE_WARNING E_COMPILE_ERROR E_COMPILE_WARNING Chris@909: E_USER_ERROR E_USER_WARNING E_USER_NOTICE E_DEPRECATED E_USER_DEPRECATED E_ALL E_STRICT Chris@909: ] Chris@909: Chris@909: CONSTANTS = %w[ Chris@909: null true false self parent Chris@909: __LINE__ __DIR__ __FILE__ __LINE__ Chris@909: __CLASS__ __NAMESPACE__ __METHOD__ __FUNCTION__ Chris@909: PHP_VERSION PHP_MAJOR_VERSION PHP_MINOR_VERSION PHP_RELEASE_VERSION PHP_VERSION_ID PHP_EXTRA_VERSION PHP_ZTS Chris@909: PHP_DEBUG PHP_MAXPATHLEN PHP_OS PHP_SAPI PHP_EOL PHP_INT_MAX PHP_INT_SIZE DEFAULT_INCLUDE_PATH Chris@909: PEAR_INSTALL_DIR PEAR_EXTENSION_DIR PHP_EXTENSION_DIR PHP_PREFIX PHP_BINDIR PHP_LIBDIR PHP_DATADIR Chris@909: PHP_SYSCONFDIR PHP_LOCALSTATEDIR PHP_CONFIG_FILE_PATH PHP_CONFIG_FILE_SCAN_DIR PHP_SHLIB_SUFFIX Chris@909: PHP_OUTPUT_HANDLER_START PHP_OUTPUT_HANDLER_CONT PHP_OUTPUT_HANDLER_END Chris@909: __COMPILER_HALT_OFFSET__ Chris@909: EXTR_OVERWRITE EXTR_SKIP EXTR_PREFIX_SAME EXTR_PREFIX_ALL EXTR_PREFIX_INVALID EXTR_PREFIX_IF_EXISTS Chris@909: EXTR_IF_EXISTS SORT_ASC SORT_DESC SORT_REGULAR SORT_NUMERIC SORT_STRING CASE_LOWER CASE_UPPER COUNT_NORMAL Chris@909: COUNT_RECURSIVE ASSERT_ACTIVE ASSERT_CALLBACK ASSERT_BAIL ASSERT_WARNING ASSERT_QUIET_EVAL CONNECTION_ABORTED Chris@909: CONNECTION_NORMAL CONNECTION_TIMEOUT INI_USER INI_PERDIR INI_SYSTEM INI_ALL M_E M_LOG2E M_LOG10E M_LN2 M_LN10 Chris@909: M_PI M_PI_2 M_PI_4 M_1_PI M_2_PI M_2_SQRTPI M_SQRT2 M_SQRT1_2 CRYPT_SALT_LENGTH CRYPT_STD_DES CRYPT_EXT_DES Chris@909: CRYPT_MD5 CRYPT_BLOWFISH DIRECTORY_SEPARATOR SEEK_SET SEEK_CUR SEEK_END LOCK_SH LOCK_EX LOCK_UN LOCK_NB Chris@909: HTML_SPECIALCHARS HTML_ENTITIES ENT_COMPAT ENT_QUOTES ENT_NOQUOTES INFO_GENERAL INFO_CREDITS Chris@909: INFO_CONFIGURATION INFO_MODULES INFO_ENVIRONMENT INFO_VARIABLES INFO_LICENSE INFO_ALL CREDITS_GROUP Chris@909: CREDITS_GENERAL CREDITS_SAPI CREDITS_MODULES CREDITS_DOCS CREDITS_FULLPAGE CREDITS_QA CREDITS_ALL STR_PAD_LEFT Chris@909: STR_PAD_RIGHT STR_PAD_BOTH PATHINFO_DIRNAME PATHINFO_BASENAME PATHINFO_EXTENSION PATH_SEPARATOR CHAR_MAX Chris@909: LC_CTYPE LC_NUMERIC LC_TIME LC_COLLATE LC_MONETARY LC_ALL LC_MESSAGES ABDAY_1 ABDAY_2 ABDAY_3 ABDAY_4 ABDAY_5 Chris@909: ABDAY_6 ABDAY_7 DAY_1 DAY_2 DAY_3 DAY_4 DAY_5 DAY_6 DAY_7 ABMON_1 ABMON_2 ABMON_3 ABMON_4 ABMON_5 ABMON_6 Chris@909: ABMON_7 ABMON_8 ABMON_9 ABMON_10 ABMON_11 ABMON_12 MON_1 MON_2 MON_3 MON_4 MON_5 MON_6 MON_7 MON_8 MON_9 Chris@909: MON_10 MON_11 MON_12 AM_STR PM_STR D_T_FMT D_FMT T_FMT T_FMT_AMPM ERA ERA_YEAR ERA_D_T_FMT ERA_D_FMT ERA_T_FMT Chris@909: ALT_DIGITS INT_CURR_SYMBOL CURRENCY_SYMBOL CRNCYSTR MON_DECIMAL_POINT MON_THOUSANDS_SEP MON_GROUPING Chris@909: POSITIVE_SIGN NEGATIVE_SIGN INT_FRAC_DIGITS FRAC_DIGITS P_CS_PRECEDES P_SEP_BY_SPACE N_CS_PRECEDES Chris@909: N_SEP_BY_SPACE P_SIGN_POSN N_SIGN_POSN DECIMAL_POINT RADIXCHAR THOUSANDS_SEP THOUSEP GROUPING YESEXPR NOEXPR Chris@909: YESSTR NOSTR CODESET LOG_EMERG LOG_ALERT LOG_CRIT LOG_ERR LOG_WARNING LOG_NOTICE LOG_INFO LOG_DEBUG LOG_KERN Chris@909: LOG_USER LOG_MAIL LOG_DAEMON LOG_AUTH LOG_SYSLOG LOG_LPR LOG_NEWS LOG_UUCP LOG_CRON LOG_AUTHPRIV LOG_LOCAL0 Chris@909: LOG_LOCAL1 LOG_LOCAL2 LOG_LOCAL3 LOG_LOCAL4 LOG_LOCAL5 LOG_LOCAL6 LOG_LOCAL7 LOG_PID LOG_CONS LOG_ODELAY Chris@909: LOG_NDELAY LOG_NOWAIT LOG_PERROR Chris@909: ] Chris@909: Chris@909: PREDEFINED = %w[ Chris@909: $GLOBALS $_SERVER $_GET $_POST $_FILES $_REQUEST $_SESSION $_ENV Chris@909: $_COOKIE $php_errormsg $HTTP_RAW_POST_DATA $http_response_header Chris@909: $argc $argv Chris@909: ] Chris@909: Chris@909: IDENT_KIND = WordList::CaseIgnoring.new(:ident). Chris@909: add(KEYWORDS, :keyword). Chris@909: add(TYPES, :predefined_type). Chris@909: add(LANGUAGE_CONSTRUCTS, :keyword). Chris@909: add(BUILTIN_FUNCTIONS, :predefined). Chris@909: add(CLASSES, :predefined_constant). Chris@909: add(EXCEPTIONS, :exception). Chris@909: add(CONSTANTS, :predefined_constant) Chris@909: Chris@909: VARIABLE_KIND = WordList.new(:local_variable). Chris@909: add(PREDEFINED, :predefined) Chris@909: end Chris@909: Chris@909: module RE # :nodoc: Chris@909: Chris@909: PHP_START = / Chris@909: ]*?language\s*=\s*"php"[^>]*?> | Chris@909: ]*?language\s*=\s*'php'[^>]*?> | Chris@909: <\?php\d? | Chris@909: <\?(?!xml) Chris@909: /xi Chris@909: Chris@909: PHP_END = %r! Chris@909: | Chris@909: \?> Chris@909: !xi Chris@909: Chris@909: HTML_INDICATOR = / ]/i Chris@909: Chris@909: IDENTIFIER = /[a-z_\x7f-\xFF][a-z0-9_\x7f-\xFF]*/i Chris@909: VARIABLE = /\$#{IDENTIFIER}/ Chris@909: Chris@909: OPERATOR = / Chris@909: \.(?!\d)=? | # dot that is not decimal point, string concatenation Chris@909: && | \|\| | # logic Chris@909: :: | -> | => | # scope, member, dictionary Chris@909: \\(?!\n) | # namespace Chris@909: \+\+ | -- | # increment, decrement Chris@909: [,;?:()\[\]{}] | # simple delimiters Chris@909: [-+*\/%&|^]=? | # ordinary math, binary logic, assignment shortcuts Chris@909: [~$] | # whatever Chris@909: =& | # reference assignment Chris@909: [=!]=?=? | <> | # comparison and assignment Chris@909: <<=? | >>=? | [<>]=? # comparison and shift Chris@909: /x Chris@909: Chris@909: end Chris@909: Chris@909: protected Chris@909: Chris@909: def scan_tokens encoder, options Chris@909: Chris@909: if check(RE::PHP_START) || # starts with #{RE::IDENTIFIER}/o) Chris@909: encoder.begin_group :inline Chris@909: encoder.text_token match, :local_variable Chris@909: encoder.text_token scan(/->/), :operator Chris@909: encoder.text_token scan(/#{RE::IDENTIFIER}/o), :ident Chris@909: encoder.end_group :inline Chris@909: elsif check(/->/) Chris@909: match << scan(/->/) Chris@909: encoder.text_token match, :error Chris@909: else Chris@909: encoder.text_token match, :local_variable Chris@909: end Chris@909: elsif match = scan(/\{/) Chris@909: if check(/\$/) Chris@909: encoder.begin_group :inline Chris@909: states[-1] = [states.last, delimiter] Chris@909: delimiter = nil Chris@909: states.push :php Chris@909: encoder.text_token match, :delimiter Chris@909: else Chris@909: encoder.text_token match, :content Chris@909: end Chris@909: elsif match = scan(/\$\{#{RE::IDENTIFIER}\}/o) Chris@909: encoder.text_token match, :local_variable Chris@909: elsif match = scan(/\$/) Chris@909: encoder.text_token match, :content Chris@909: else Chris@909: states.pop Chris@909: end Chris@909: Chris@909: when :class_expected Chris@909: if match = scan(/\s+/) Chris@909: encoder.text_token match, :space Chris@909: elsif match = scan(/#{RE::IDENTIFIER}/o) Chris@909: encoder.text_token match, :class Chris@909: states.pop Chris@909: else Chris@909: states.pop Chris@909: end Chris@909: Chris@909: when :function_expected Chris@909: if match = scan(/\s+/) Chris@909: encoder.text_token match, :space Chris@909: elsif match = scan(/&/) Chris@909: encoder.text_token match, :operator Chris@909: elsif match = scan(/#{RE::IDENTIFIER}/o) Chris@909: encoder.text_token match, :function Chris@909: states.pop Chris@909: else Chris@909: states.pop Chris@909: end Chris@909: Chris@909: else Chris@909: raise_inspect 'Unknown state!', encoder, states Chris@909: end Chris@909: Chris@909: end Chris@909: Chris@909: encoder Chris@909: end Chris@909: Chris@909: end Chris@909: Chris@909: end Chris@909: end