Coverage Report

Created: 2025-12-14 06:05

next uncovered line (L), next uncovered region (R), next uncovered branch (B)
/src/php-src/Zend/Optimizer/zend_optimizer.c
Line
Count
Source
1
/*
2
   +----------------------------------------------------------------------+
3
   | Zend OPcache                                                         |
4
   +----------------------------------------------------------------------+
5
   | Copyright (c) The PHP Group                                          |
6
   +----------------------------------------------------------------------+
7
   | This source file is subject to version 3.01 of the PHP license,      |
8
   | that is bundled with this package in the file LICENSE, and is        |
9
   | available through the world-wide-web at the following url:           |
10
   | https://www.php.net/license/3_01.txt                                 |
11
   | If you did not receive a copy of the PHP license and are unable to   |
12
   | obtain it through the world-wide-web, please send a note to          |
13
   | license@php.net so we can mail you a copy immediately.               |
14
   +----------------------------------------------------------------------+
15
   | Authors: Andi Gutmans <andi@php.net>                                 |
16
   |          Zeev Suraski <zeev@php.net>                                 |
17
   |          Stanislav Malyshev <stas@zend.com>                          |
18
   |          Dmitry Stogov <dmitry@php.net>                              |
19
   +----------------------------------------------------------------------+
20
*/
21
22
#include "Optimizer/zend_optimizer.h"
23
#include "Optimizer/zend_optimizer_internal.h"
24
#include "zend_API.h"
25
#include "zend_constants.h"
26
#include "zend_execute.h"
27
#include "zend_vm.h"
28
#include "zend_cfg.h"
29
#include "zend_func_info.h"
30
#include "zend_call_graph.h"
31
#include "zend_inference.h"
32
#include "zend_dump.h"
33
#include "php.h"
34
35
#ifndef ZEND_OPTIMIZER_MAX_REGISTERED_PASSES
36
0
# define ZEND_OPTIMIZER_MAX_REGISTERED_PASSES 32
37
#endif
38
39
struct {
40
  zend_optimizer_pass_t pass[ZEND_OPTIMIZER_MAX_REGISTERED_PASSES];
41
  int last;
42
} zend_optimizer_registered_passes = {{NULL}, 0};
43
44
void zend_optimizer_collect_constant(zend_optimizer_ctx *ctx, const zval *name, zval* value)
45
0
{
46
0
  if (!ctx->constants) {
47
0
    ctx->constants = zend_arena_alloc(&ctx->arena, sizeof(HashTable));
48
0
    zend_hash_init(ctx->constants, 16, NULL, zval_ptr_dtor_nogc, 0);
49
0
  }
50
51
0
  if (zend_hash_add(ctx->constants, Z_STR_P(name), value)) {
52
0
    Z_TRY_ADDREF_P(value);
53
0
  }
54
0
}
55
56
zend_result zend_optimizer_eval_binary_op(zval *result, uint8_t opcode, zval *op1, zval *op2) /* {{{ */
57
0
{
58
0
  if (zend_binary_op_produces_error(opcode, op1, op2)) {
59
0
    return FAILURE;
60
0
  }
61
62
0
  binary_op_type binary_op = get_binary_op(opcode);
63
0
  return binary_op(result, op1, op2);
64
0
}
65
/* }}} */
66
67
zend_result zend_optimizer_eval_unary_op(zval *result, uint8_t opcode, zval *op1) /* {{{ */
68
0
{
69
0
  unary_op_type unary_op = get_unary_op(opcode);
70
71
0
  if (unary_op) {
72
0
    if (zend_unary_op_produces_error(opcode, op1)) {
73
0
      return FAILURE;
74
0
    }
75
0
    return unary_op(result, op1);
76
0
  } else { /* ZEND_BOOL */
77
0
    if (Z_TYPE_P(op1) == IS_DOUBLE && zend_isnan(Z_DVAL_P(op1))) {
78
0
      return FAILURE;
79
0
    }
80
0
    ZVAL_BOOL(result, zend_is_true(op1));
81
0
    return SUCCESS;
82
0
  }
83
0
}
84
/* }}} */
85
86
zend_result zend_optimizer_eval_cast(zval *result, uint32_t type, zval *op1) /* {{{ */
87
0
{
88
0
  if (zend_try_ct_eval_cast(result, type, op1)) {
89
0
    return SUCCESS;
90
0
  }
91
0
  return FAILURE;
92
0
}
93
/* }}} */
94
95
zend_result zend_optimizer_eval_strlen(zval *result, const zval *op1) /* {{{ */
96
0
{
97
0
  if (Z_TYPE_P(op1) != IS_STRING) {
98
0
    return FAILURE;
99
0
  }
100
0
  ZVAL_LONG(result, Z_STRLEN_P(op1));
101
0
  return SUCCESS;
102
0
}
103
/* }}} */
104
105
zend_result zend_optimizer_eval_special_func_call(
106
0
    zval *result, const zend_string *name, zend_string *arg) {
107
0
  if (zend_string_equals_literal(name, "function_exists") ||
108
0
      zend_string_equals_literal(name, "is_callable")) {
109
0
    zend_string *lc_name = zend_string_tolower(arg);
110
0
    const zend_internal_function *func = zend_hash_find_ptr(EG(function_table), lc_name);
111
0
    zend_string_release_ex(lc_name, 0);
112
113
0
    if (func && func->type == ZEND_INTERNAL_FUNCTION
114
0
        && func->module->type == MODULE_PERSISTENT
115
#ifdef ZEND_WIN32
116
        && func->module->handle == NULL
117
#endif
118
0
    ) {
119
0
      ZVAL_TRUE(result);
120
0
      return SUCCESS;
121
0
    }
122
0
    return FAILURE;
123
0
  }
124
0
  if (zend_string_equals_literal(name, "extension_loaded")) {
125
0
    zend_string *lc_name = zend_string_tolower(arg);
126
0
    zend_module_entry *m = zend_hash_find_ptr(&module_registry, lc_name);
127
0
    zend_string_release_ex(lc_name, 0);
128
129
0
    if (!m) {
130
0
      if (PG(enable_dl)) {
131
0
        return FAILURE;
132
0
      }
133
0
      ZVAL_FALSE(result);
134
0
      return SUCCESS;
135
0
    }
136
137
0
    if (m->type == MODULE_PERSISTENT
138
#ifdef ZEND_WIN32
139
      && m->handle == NULL
140
#endif
141
0
    ) {
142
0
      ZVAL_TRUE(result);
143
0
      return SUCCESS;
144
0
    }
145
0
    return FAILURE;
146
0
  }
147
0
  if (zend_string_equals_literal(name, "constant")) {
148
0
    return zend_optimizer_get_persistent_constant(arg, result, true) ? SUCCESS : FAILURE;
149
0
  }
150
0
  if (zend_string_equals_literal(name, "dirname")) {
151
0
    if (!IS_ABSOLUTE_PATH(ZSTR_VAL(arg), ZSTR_LEN(arg))) {
152
0
      return FAILURE;
153
0
    }
154
155
0
    zend_string *dirname = zend_string_init(ZSTR_VAL(arg), ZSTR_LEN(arg), 0);
156
0
    ZSTR_LEN(dirname) = zend_dirname(ZSTR_VAL(dirname), ZSTR_LEN(dirname));
157
0
    if (IS_ABSOLUTE_PATH(ZSTR_VAL(dirname), ZSTR_LEN(dirname))) {
158
0
      ZVAL_STR(result, dirname);
159
0
      return SUCCESS;
160
0
    }
161
0
    zend_string_release_ex(dirname, 0);
162
0
    return FAILURE;
163
0
  }
164
0
  if (zend_string_equals_literal(name, "ini_get")) {
165
0
    zend_ini_entry *ini_entry = zend_hash_find_ptr(EG(ini_directives), arg);
166
0
    if (!ini_entry) {
167
0
      if (PG(enable_dl)) {
168
0
        return FAILURE;
169
0
      }
170
0
      ZVAL_FALSE(result);
171
0
    } else if (ini_entry->modifiable != ZEND_INI_SYSTEM) {
172
0
      return FAILURE;
173
0
    } else if (ini_entry->value) {
174
0
      ZVAL_STR_COPY(result, ini_entry->value);
175
0
    } else {
176
0
      ZVAL_EMPTY_STRING(result);
177
0
    }
178
0
    return SUCCESS;
179
0
  }
180
0
  return FAILURE;
181
0
}
182
183
bool zend_optimizer_get_collected_constant(const HashTable *constants, const zval *name, zval* value)
184
0
{
185
0
  zval *val;
186
187
0
  if ((val = zend_hash_find(constants, Z_STR_P(name))) != NULL) {
188
0
    ZVAL_COPY(value, val);
189
0
    return true;
190
0
  }
191
0
  return false;
192
0
}
193
194
void zend_optimizer_convert_to_free_op1(const zend_op_array *op_array, zend_op *opline)
195
0
{
196
0
  if (opline->op1_type == IS_CV) {
197
0
    opline->opcode = ZEND_CHECK_VAR;
198
0
    SET_UNUSED(opline->op2);
199
0
    SET_UNUSED(opline->result);
200
0
    opline->extended_value = 0;
201
0
  } else if (opline->op1_type & (IS_TMP_VAR|IS_VAR)) {
202
0
    opline->opcode = ZEND_FREE;
203
0
    SET_UNUSED(opline->op2);
204
0
    SET_UNUSED(opline->result);
205
0
    opline->extended_value = 0;
206
0
  } else {
207
0
    ZEND_ASSERT(opline->op1_type == IS_CONST);
208
0
    literal_dtor(&ZEND_OP1_LITERAL(opline));
209
0
    MAKE_NOP(opline);
210
0
  }
211
0
}
212
213
uint32_t zend_optimizer_add_literal(zend_op_array *op_array, const zval *zv)
214
0
{
215
0
  uint32_t i = op_array->last_literal;
216
0
  op_array->last_literal++;
217
0
  op_array->literals = (zval*)erealloc(op_array->literals, op_array->last_literal * sizeof(zval));
218
0
  ZVAL_COPY_VALUE(&op_array->literals[i], zv);
219
0
  Z_EXTRA(op_array->literals[i]) = 0;
220
0
  return i;
221
0
}
222
223
0
static inline uint32_t zend_optimizer_add_literal_string(zend_op_array *op_array, zend_string *str) {
224
0
  zval zv;
225
0
  ZVAL_STR(&zv, str);
226
0
  zend_string_hash_val(str);
227
0
  return zend_optimizer_add_literal(op_array, &zv);
228
0
}
229
230
0
static inline void drop_leading_backslash(zval *val) {
231
0
  if (Z_STRVAL_P(val)[0] == '\\') {
232
0
    zend_string *str = zend_string_init(Z_STRVAL_P(val) + 1, Z_STRLEN_P(val) - 1, 0);
233
0
    zval_ptr_dtor_nogc(val);
234
0
    ZVAL_STR(val, str);
235
0
  }
236
0
}
237
238
0
static inline uint32_t alloc_cache_slots(zend_op_array *op_array, uint32_t num) {
239
0
  uint32_t ret = op_array->cache_size;
240
0
  op_array->cache_size += num * sizeof(void *);
241
0
  return ret;
242
0
}
243
244
0
#define REQUIRES_STRING(val) do { \
245
0
  if (Z_TYPE_P(val) != IS_STRING) { \
246
0
    return 0; \
247
0
  } \
248
0
} while (0)
249
250
0
#define TO_STRING_NOWARN(val) do { \
251
0
  if (Z_TYPE_P(val) >= IS_ARRAY) { \
252
0
    return 0; \
253
0
  } \
254
0
  convert_to_string(val); \
255
0
} while (0)
256
257
bool zend_optimizer_update_op1_const(zend_op_array *op_array,
258
                                    zend_op       *opline,
259
                                    zval          *val)
260
0
{
261
0
  switch (opline->opcode) {
262
0
    case ZEND_OP_DATA:
263
0
      switch ((opline-1)->opcode) {
264
0
        case ZEND_ASSIGN_OBJ_REF:
265
0
        case ZEND_ASSIGN_STATIC_PROP_REF:
266
0
          return false;
267
0
      }
268
0
      opline->op1.constant = zend_optimizer_add_literal(op_array, val);
269
0
      break;
270
0
    case ZEND_FREE:
271
0
    case ZEND_CHECK_VAR:
272
0
      MAKE_NOP(opline);
273
0
      zval_ptr_dtor_nogc(val);
274
0
      return true;
275
0
    case ZEND_SEND_VAR_EX:
276
0
    case ZEND_SEND_FUNC_ARG:
277
0
    case ZEND_FETCH_DIM_W:
278
0
    case ZEND_FETCH_DIM_RW:
279
0
    case ZEND_FETCH_DIM_FUNC_ARG:
280
0
    case ZEND_FETCH_DIM_UNSET:
281
0
    case ZEND_FETCH_LIST_W:
282
0
    case ZEND_ASSIGN_DIM:
283
0
    case ZEND_RETURN_BY_REF:
284
0
    case ZEND_INSTANCEOF:
285
0
    case ZEND_MAKE_REF:
286
0
    case ZEND_SEPARATE:
287
0
    case ZEND_SEND_VAR_NO_REF:
288
0
    case ZEND_SEND_VAR_NO_REF_EX:
289
0
      return false;
290
0
    case ZEND_CATCH:
291
0
      REQUIRES_STRING(val);
292
0
      drop_leading_backslash(val);
293
0
      opline->op1.constant = zend_optimizer_add_literal(op_array, val);
294
0
      opline->extended_value = alloc_cache_slots(op_array, 1) | (opline->extended_value & ZEND_LAST_CATCH);
295
0
      zend_optimizer_add_literal_string(op_array, zend_string_tolower(Z_STR_P(val)));
296
0
      break;
297
0
    case ZEND_DEFINED:
298
0
      REQUIRES_STRING(val);
299
0
      drop_leading_backslash(val);
300
0
      opline->op1.constant = zend_optimizer_add_literal(op_array, val);
301
0
      opline->extended_value = alloc_cache_slots(op_array, 1);
302
0
      zend_optimizer_add_literal_string(op_array, zend_string_tolower(Z_STR_P(val)));
303
0
      break;
304
0
    case ZEND_NEW:
305
0
      REQUIRES_STRING(val);
306
0
      drop_leading_backslash(val);
307
0
      opline->op1.constant = zend_optimizer_add_literal(op_array, val);
308
0
      opline->op2.num = alloc_cache_slots(op_array, 1);
309
0
      zend_optimizer_add_literal_string(op_array, zend_string_tolower(Z_STR_P(val)));
310
0
      break;
311
0
    case ZEND_INIT_STATIC_METHOD_CALL:
312
0
      REQUIRES_STRING(val);
313
0
      drop_leading_backslash(val);
314
0
      opline->op1.constant = zend_optimizer_add_literal(op_array, val);
315
0
      if (opline->op2_type != IS_CONST) {
316
0
        opline->result.num = alloc_cache_slots(op_array, 1);
317
0
      }
318
0
      zend_optimizer_add_literal_string(op_array, zend_string_tolower(Z_STR_P(val)));
319
0
      break;
320
0
    case ZEND_FETCH_CLASS_CONSTANT:
321
0
      REQUIRES_STRING(val);
322
0
      drop_leading_backslash(val);
323
0
      opline->op1.constant = zend_optimizer_add_literal(op_array, val);
324
0
      if (opline->op2_type != IS_CONST) {
325
0
        opline->extended_value = alloc_cache_slots(op_array, 1);
326
0
      }
327
0
      zend_optimizer_add_literal_string(op_array, zend_string_tolower(Z_STR_P(val)));
328
0
      break;
329
0
    case ZEND_ASSIGN_OP:
330
0
    case ZEND_ASSIGN_DIM_OP:
331
0
    case ZEND_ASSIGN_OBJ_OP:
332
0
      break;
333
0
    case ZEND_ASSIGN_STATIC_PROP_OP:
334
0
    case ZEND_ASSIGN_STATIC_PROP:
335
0
    case ZEND_ASSIGN_STATIC_PROP_REF:
336
0
    case ZEND_FETCH_STATIC_PROP_R:
337
0
    case ZEND_FETCH_STATIC_PROP_W:
338
0
    case ZEND_FETCH_STATIC_PROP_RW:
339
0
    case ZEND_FETCH_STATIC_PROP_IS:
340
0
    case ZEND_FETCH_STATIC_PROP_UNSET:
341
0
    case ZEND_FETCH_STATIC_PROP_FUNC_ARG:
342
0
    case ZEND_UNSET_STATIC_PROP:
343
0
    case ZEND_ISSET_ISEMPTY_STATIC_PROP:
344
0
    case ZEND_PRE_INC_STATIC_PROP:
345
0
    case ZEND_PRE_DEC_STATIC_PROP:
346
0
    case ZEND_POST_INC_STATIC_PROP:
347
0
    case ZEND_POST_DEC_STATIC_PROP:
348
0
      TO_STRING_NOWARN(val);
349
0
      opline->op1.constant = zend_optimizer_add_literal(op_array, val);
350
0
      if (opline->op2_type == IS_CONST && (opline->extended_value & ~ZEND_FETCH_OBJ_FLAGS) + sizeof(void*) == op_array->cache_size) {
351
0
        op_array->cache_size += sizeof(void *);
352
0
      } else {
353
0
        opline->extended_value = alloc_cache_slots(op_array, 3) | (opline->extended_value & ZEND_FETCH_OBJ_FLAGS);
354
0
      }
355
0
      break;
356
0
    case ZEND_SEND_VAR:
357
0
      opline->opcode = ZEND_SEND_VAL;
358
0
      opline->op1.constant = zend_optimizer_add_literal(op_array, val);
359
0
      break;
360
0
    case ZEND_CASE:
361
0
      opline->opcode = ZEND_IS_EQUAL;
362
0
      opline->op1.constant = zend_optimizer_add_literal(op_array, val);
363
0
      break;
364
0
    case ZEND_CASE_STRICT:
365
0
      opline->opcode = ZEND_IS_IDENTICAL;
366
0
      opline->op1.constant = zend_optimizer_add_literal(op_array, val);
367
0
      break;
368
0
    case ZEND_VERIFY_RETURN_TYPE:
369
      /* This would require a non-local change.
370
       * zend_optimizer_replace_by_const() supports this. */
371
0
      return false;
372
0
    case ZEND_COPY_TMP:
373
0
    case ZEND_FETCH_CLASS_NAME:
374
0
      return false;
375
0
    case ZEND_ECHO:
376
0
    {
377
0
      zval zv;
378
0
      if (Z_TYPE_P(val) != IS_STRING && zend_optimizer_eval_cast(&zv, IS_STRING, val) == SUCCESS) {
379
0
        zval_ptr_dtor_nogc(val);
380
0
        val = &zv;
381
0
      }
382
0
      opline->op1.constant = zend_optimizer_add_literal(op_array, val);
383
0
      if (Z_TYPE_P(val) == IS_STRING && Z_STRLEN_P(val) == 0) {
384
0
        MAKE_NOP(opline);
385
0
        return true;
386
0
      }
387
      /* TODO: In a subsequent pass, *after* this step and compacting nops, combine consecutive ZEND_ECHOs using the block information from ssa->cfg */
388
      /* (e.g. for ext/opcache/tests/opt/sccp_010.phpt) */
389
0
      break;
390
0
    }
391
0
    case ZEND_CONCAT:
392
0
    case ZEND_FAST_CONCAT:
393
0
    case ZEND_FETCH_R:
394
0
    case ZEND_FETCH_W:
395
0
    case ZEND_FETCH_RW:
396
0
    case ZEND_FETCH_IS:
397
0
    case ZEND_FETCH_UNSET:
398
0
    case ZEND_FETCH_FUNC_ARG:
399
0
    case ZEND_ISSET_ISEMPTY_VAR:
400
0
    case ZEND_UNSET_VAR:
401
0
      TO_STRING_NOWARN(val);
402
0
      if (opline->opcode == ZEND_CONCAT && opline->op2_type == IS_CONST) {
403
0
        opline->opcode = ZEND_FAST_CONCAT;
404
0
      }
405
0
      ZEND_FALLTHROUGH;
406
0
    default:
407
0
      opline->op1.constant = zend_optimizer_add_literal(op_array, val);
408
0
      break;
409
0
  }
410
411
0
  opline->op1_type = IS_CONST;
412
0
  if (Z_TYPE(ZEND_OP1_LITERAL(opline)) == IS_STRING) {
413
0
    zend_string_hash_val(Z_STR(ZEND_OP1_LITERAL(opline)));
414
0
  }
415
0
  return true;
416
0
}
417
418
bool zend_optimizer_update_op2_const(zend_op_array *op_array,
419
                                    zend_op       *opline,
420
                                    zval          *val)
421
0
{
422
0
  zval tmp;
423
424
0
  switch (opline->opcode) {
425
0
    case ZEND_ASSIGN_REF:
426
0
    case ZEND_FAST_CALL:
427
0
      return false;
428
0
    case ZEND_FETCH_CLASS:
429
0
    case ZEND_INSTANCEOF:
430
0
      REQUIRES_STRING(val);
431
0
      drop_leading_backslash(val);
432
0
      opline->op2.constant = zend_optimizer_add_literal(op_array, val);
433
0
      zend_optimizer_add_literal_string(op_array, zend_string_tolower(Z_STR_P(val)));
434
0
      opline->extended_value = alloc_cache_slots(op_array, 1);
435
0
      break;
436
0
    case ZEND_INIT_FCALL_BY_NAME:
437
0
      REQUIRES_STRING(val);
438
0
      drop_leading_backslash(val);
439
0
      opline->op2.constant = zend_optimizer_add_literal(op_array, val);
440
0
      zend_optimizer_add_literal_string(op_array, zend_string_tolower(Z_STR_P(val)));
441
0
      opline->result.num = alloc_cache_slots(op_array, 1);
442
0
      break;
443
0
    case ZEND_ASSIGN_STATIC_PROP:
444
0
    case ZEND_ASSIGN_STATIC_PROP_REF:
445
0
    case ZEND_FETCH_STATIC_PROP_R:
446
0
    case ZEND_FETCH_STATIC_PROP_W:
447
0
    case ZEND_FETCH_STATIC_PROP_RW:
448
0
    case ZEND_FETCH_STATIC_PROP_IS:
449
0
    case ZEND_FETCH_STATIC_PROP_UNSET:
450
0
    case ZEND_FETCH_STATIC_PROP_FUNC_ARG:
451
0
    case ZEND_UNSET_STATIC_PROP:
452
0
    case ZEND_ISSET_ISEMPTY_STATIC_PROP:
453
0
    case ZEND_PRE_INC_STATIC_PROP:
454
0
    case ZEND_PRE_DEC_STATIC_PROP:
455
0
    case ZEND_POST_INC_STATIC_PROP:
456
0
    case ZEND_POST_DEC_STATIC_PROP:
457
0
    case ZEND_ASSIGN_STATIC_PROP_OP:
458
0
      REQUIRES_STRING(val);
459
0
      drop_leading_backslash(val);
460
0
      opline->op2.constant = zend_optimizer_add_literal(op_array, val);
461
0
      zend_optimizer_add_literal_string(op_array, zend_string_tolower(Z_STR_P(val)));
462
0
      if (opline->op1_type != IS_CONST) {
463
0
        opline->extended_value = alloc_cache_slots(op_array, 1) | (opline->extended_value & (ZEND_RETURNS_FUNCTION|ZEND_ISEMPTY|ZEND_FETCH_OBJ_FLAGS));
464
0
      }
465
0
      break;
466
0
    case ZEND_INIT_FCALL:
467
0
      REQUIRES_STRING(val);
468
0
      if (Z_REFCOUNT_P(val) == 1) {
469
0
        zend_str_tolower(Z_STRVAL_P(val), Z_STRLEN_P(val));
470
0
      } else {
471
0
        ZVAL_STR(&tmp, zend_string_tolower(Z_STR_P(val)));
472
0
        zval_ptr_dtor_nogc(val);
473
0
        val = &tmp;
474
0
      }
475
0
      opline->op2.constant = zend_optimizer_add_literal(op_array, val);
476
0
      opline->result.num = alloc_cache_slots(op_array, 1);
477
0
      break;
478
0
    case ZEND_INIT_DYNAMIC_CALL:
479
0
      if (Z_TYPE_P(val) == IS_STRING) {
480
0
        if (zend_memrchr(Z_STRVAL_P(val), ':', Z_STRLEN_P(val))) {
481
0
          return false;
482
0
        }
483
484
0
        if (zend_optimizer_classify_function(Z_STR_P(val), opline->extended_value)) {
485
          /* Dynamic call to various special functions must stay dynamic,
486
           * otherwise would drop a warning */
487
0
          return false;
488
0
        }
489
490
0
        opline->opcode = ZEND_INIT_FCALL_BY_NAME;
491
0
        drop_leading_backslash(val);
492
0
        opline->op2.constant = zend_optimizer_add_literal(op_array, val);
493
0
        zend_optimizer_add_literal_string(op_array, zend_string_tolower(Z_STR_P(val)));
494
0
        opline->result.num = alloc_cache_slots(op_array, 1);
495
0
      } else {
496
0
        opline->op2.constant = zend_optimizer_add_literal(op_array, val);
497
0
      }
498
0
      break;
499
0
    case ZEND_INIT_METHOD_CALL:
500
0
      REQUIRES_STRING(val);
501
0
      opline->op2.constant = zend_optimizer_add_literal(op_array, val);
502
0
      zend_optimizer_add_literal_string(op_array, zend_string_tolower(Z_STR_P(val)));
503
0
      opline->result.num = alloc_cache_slots(op_array, 2);
504
0
      break;
505
0
    case ZEND_INIT_STATIC_METHOD_CALL:
506
0
      REQUIRES_STRING(val);
507
0
      opline->op2.constant = zend_optimizer_add_literal(op_array, val);
508
0
      zend_optimizer_add_literal_string(op_array, zend_string_tolower(Z_STR_P(val)));
509
0
      if (opline->op1_type != IS_CONST) {
510
0
        opline->result.num = alloc_cache_slots(op_array, 2);
511
0
      }
512
0
      break;
513
0
    case ZEND_ASSIGN_OBJ:
514
0
    case ZEND_ASSIGN_OBJ_REF:
515
0
    case ZEND_FETCH_OBJ_R:
516
0
    case ZEND_FETCH_OBJ_W:
517
0
    case ZEND_FETCH_OBJ_RW:
518
0
    case ZEND_FETCH_OBJ_IS:
519
0
    case ZEND_FETCH_OBJ_UNSET:
520
0
    case ZEND_FETCH_OBJ_FUNC_ARG:
521
0
    case ZEND_UNSET_OBJ:
522
0
    case ZEND_PRE_INC_OBJ:
523
0
    case ZEND_PRE_DEC_OBJ:
524
0
    case ZEND_POST_INC_OBJ:
525
0
    case ZEND_POST_DEC_OBJ:
526
0
      TO_STRING_NOWARN(val);
527
0
      opline->op2.constant = zend_optimizer_add_literal(op_array, val);
528
0
      opline->extended_value = alloc_cache_slots(op_array, 3);
529
0
      break;
530
0
    case ZEND_ASSIGN_OBJ_OP:
531
0
      TO_STRING_NOWARN(val);
532
0
      opline->op2.constant = zend_optimizer_add_literal(op_array, val);
533
0
      ZEND_ASSERT((opline + 1)->opcode == ZEND_OP_DATA);
534
0
      (opline + 1)->extended_value = alloc_cache_slots(op_array, 3);
535
0
      break;
536
0
    case ZEND_ISSET_ISEMPTY_PROP_OBJ:
537
0
      TO_STRING_NOWARN(val);
538
0
      opline->op2.constant = zend_optimizer_add_literal(op_array, val);
539
0
      opline->extended_value = alloc_cache_slots(op_array, 3) | (opline->extended_value & ZEND_ISEMPTY);
540
0
      break;
541
0
    case ZEND_ASSIGN_DIM_OP:
542
0
    case ZEND_ISSET_ISEMPTY_DIM_OBJ:
543
0
    case ZEND_ASSIGN_DIM:
544
0
    case ZEND_UNSET_DIM:
545
0
    case ZEND_FETCH_DIM_R:
546
0
    case ZEND_FETCH_DIM_W:
547
0
    case ZEND_FETCH_DIM_RW:
548
0
    case ZEND_FETCH_DIM_IS:
549
0
    case ZEND_FETCH_DIM_FUNC_ARG:
550
0
    case ZEND_FETCH_DIM_UNSET:
551
0
    case ZEND_FETCH_LIST_R:
552
0
    case ZEND_FETCH_LIST_W:
553
0
      if (Z_TYPE_P(val) == IS_STRING) {
554
0
        zend_ulong index;
555
556
0
        if (ZEND_HANDLE_NUMERIC(Z_STR_P(val), index)) {
557
0
          ZVAL_LONG(&tmp, index);
558
0
          opline->op2.constant = zend_optimizer_add_literal(op_array, &tmp);
559
0
          zend_string_hash_val(Z_STR_P(val));
560
0
          zend_optimizer_add_literal(op_array, val);
561
0
          Z_EXTRA(op_array->literals[opline->op2.constant]) = ZEND_EXTRA_VALUE;
562
0
          break;
563
0
        }
564
0
      }
565
0
      opline->op2.constant = zend_optimizer_add_literal(op_array, val);
566
0
      break;
567
0
    case ZEND_ADD_ARRAY_ELEMENT:
568
0
    case ZEND_INIT_ARRAY:
569
0
      if (Z_TYPE_P(val) == IS_STRING) {
570
0
        zend_ulong index;
571
0
        if (ZEND_HANDLE_NUMERIC(Z_STR_P(val), index)) {
572
0
          zval_ptr_dtor_nogc(val);
573
0
          ZVAL_LONG(val, index);
574
0
        }
575
0
      }
576
0
      opline->op2.constant = zend_optimizer_add_literal(op_array, val);
577
0
      break;
578
0
    case ZEND_ROPE_INIT:
579
0
    case ZEND_ROPE_ADD:
580
0
    case ZEND_ROPE_END:
581
0
    case ZEND_CONCAT:
582
0
    case ZEND_FAST_CONCAT:
583
0
      TO_STRING_NOWARN(val);
584
0
      if (opline->opcode == ZEND_CONCAT && opline->op1_type == IS_CONST) {
585
0
        opline->opcode = ZEND_FAST_CONCAT;
586
0
      }
587
0
      ZEND_FALLTHROUGH;
588
0
    default:
589
0
      opline->op2.constant = zend_optimizer_add_literal(op_array, val);
590
0
      break;
591
0
  }
592
593
0
  opline->op2_type = IS_CONST;
594
0
  if (Z_TYPE(ZEND_OP2_LITERAL(opline)) == IS_STRING) {
595
0
    zend_string_hash_val(Z_STR(ZEND_OP2_LITERAL(opline)));
596
0
  }
597
0
  return true;
598
0
}
599
600
bool zend_optimizer_replace_by_const(zend_op_array *op_array,
601
                                    zend_op       *opline,
602
                                    uint8_t        type,
603
                                    uint32_t       var,
604
                                    zval          *val)
605
0
{
606
0
  const zend_op *end = op_array->opcodes + op_array->last;
607
608
0
  while (opline < end) {
609
0
    if (opline->op1_type == type &&
610
0
      opline->op1.var == var) {
611
0
      switch (opline->opcode) {
612
        /* In most cases IS_TMP_VAR operand may be used only once.
613
         * The operands are usually destroyed by the opcode handler.
614
         * However, there are some exception which keep the operand alive. In that case
615
         * we want to try to replace all uses of the temporary.
616
         */
617
0
        case ZEND_FETCH_LIST_R:
618
0
        case ZEND_CASE:
619
0
        case ZEND_CASE_STRICT:
620
0
        case ZEND_SWITCH_LONG:
621
0
        case ZEND_SWITCH_STRING:
622
0
        case ZEND_MATCH:
623
0
        case ZEND_MATCH_ERROR:
624
0
        case ZEND_JMP_NULL: {
625
0
          const zend_op *end = op_array->opcodes + op_array->last;
626
0
          while (opline < end) {
627
0
            if (opline->op1_type == type && opline->op1.var == var) {
628
              /* If this opcode doesn't keep the operand alive, we're done. Check
629
               * this early, because op replacement may modify the opline. */
630
0
              bool is_last = opline->opcode != ZEND_FETCH_LIST_R
631
0
                && opline->opcode != ZEND_CASE
632
0
                && opline->opcode != ZEND_CASE_STRICT
633
0
                && opline->opcode != ZEND_SWITCH_LONG
634
0
                && opline->opcode != ZEND_SWITCH_STRING
635
0
                && opline->opcode != ZEND_MATCH
636
0
                && opline->opcode != ZEND_MATCH_ERROR
637
0
                && opline->opcode != ZEND_JMP_NULL
638
0
                && (opline->opcode != ZEND_FREE
639
0
                  || opline->extended_value != ZEND_FREE_ON_RETURN);
640
641
0
              Z_TRY_ADDREF_P(val);
642
0
              if (!zend_optimizer_update_op1_const(op_array, opline, val)) {
643
0
                zval_ptr_dtor(val);
644
0
                return false;
645
0
              }
646
0
              if (is_last) {
647
0
                break;
648
0
              }
649
0
            }
650
0
            opline++;
651
0
          }
652
0
          zval_ptr_dtor_nogc(val);
653
0
          return true;
654
0
        }
655
0
        case ZEND_VERIFY_RETURN_TYPE: {
656
0
          const zend_arg_info *ret_info = op_array->arg_info - 1;
657
0
          if (!ZEND_TYPE_CONTAINS_CODE(ret_info->type, Z_TYPE_P(val))
658
0
            || (op_array->fn_flags & ZEND_ACC_RETURN_REFERENCE)) {
659
0
            return false;
660
0
          }
661
0
          MAKE_NOP(opline);
662
663
          /* zend_handle_loops_and_finally may inserts other oplines */
664
0
          do {
665
0
            ++opline;
666
0
          } while (opline->opcode != ZEND_RETURN && opline->opcode != ZEND_RETURN_BY_REF);
667
0
          ZEND_ASSERT(opline->op1.var == var);
668
669
0
          break;
670
0
        }
671
0
        default:
672
0
          break;
673
0
      }
674
0
      return zend_optimizer_update_op1_const(op_array, opline, val);
675
0
    }
676
677
0
    if (opline->op2_type == type &&
678
0
      opline->op2.var == var) {
679
0
      return zend_optimizer_update_op2_const(op_array, opline, val);
680
0
    }
681
0
    opline++;
682
0
  }
683
684
0
  return true;
685
0
}
686
687
/* Update jump offsets after a jump was migrated to another opline */
688
0
void zend_optimizer_migrate_jump(const zend_op_array *op_array, zend_op *new_opline, zend_op *opline) {
689
0
  switch (new_opline->opcode) {
690
0
    case ZEND_JMP:
691
0
    case ZEND_FAST_CALL:
692
0
      ZEND_SET_OP_JMP_ADDR(new_opline, new_opline->op1, ZEND_OP1_JMP_ADDR(opline));
693
0
      break;
694
0
    case ZEND_JMPZ:
695
0
    case ZEND_JMPNZ:
696
0
    case ZEND_JMPZ_EX:
697
0
    case ZEND_JMPNZ_EX:
698
0
    case ZEND_FE_RESET_R:
699
0
    case ZEND_FE_RESET_RW:
700
0
    case ZEND_JMP_SET:
701
0
    case ZEND_COALESCE:
702
0
    case ZEND_ASSERT_CHECK:
703
0
    case ZEND_JMP_NULL:
704
0
    case ZEND_BIND_INIT_STATIC_OR_JMP:
705
0
    case ZEND_JMP_FRAMELESS:
706
0
      ZEND_SET_OP_JMP_ADDR(new_opline, new_opline->op2, ZEND_OP2_JMP_ADDR(opline));
707
0
      break;
708
0
    case ZEND_FE_FETCH_R:
709
0
    case ZEND_FE_FETCH_RW:
710
0
      new_opline->extended_value = ZEND_OPLINE_NUM_TO_OFFSET(op_array, new_opline, ZEND_OFFSET_TO_OPLINE_NUM(op_array, opline, opline->extended_value));
711
0
      break;
712
0
    case ZEND_CATCH:
713
0
      if (!(opline->extended_value & ZEND_LAST_CATCH)) {
714
0
        ZEND_SET_OP_JMP_ADDR(new_opline, new_opline->op2, ZEND_OP2_JMP_ADDR(opline));
715
0
      }
716
0
      break;
717
0
    case ZEND_SWITCH_LONG:
718
0
    case ZEND_SWITCH_STRING:
719
0
    case ZEND_MATCH:
720
0
    {
721
0
      const HashTable *jumptable = Z_ARRVAL(ZEND_OP2_LITERAL(opline));
722
0
      zval *zv;
723
0
      ZEND_HASH_FOREACH_VAL(jumptable, zv) {
724
0
        Z_LVAL_P(zv) = ZEND_OPLINE_NUM_TO_OFFSET(op_array, new_opline, ZEND_OFFSET_TO_OPLINE_NUM(op_array, opline, Z_LVAL_P(zv)));
725
0
      } ZEND_HASH_FOREACH_END();
726
0
      new_opline->extended_value = ZEND_OPLINE_NUM_TO_OFFSET(op_array, new_opline, ZEND_OFFSET_TO_OPLINE_NUM(op_array, opline, opline->extended_value));
727
0
      break;
728
0
    }
729
0
  }
730
0
}
731
732
/* Shift jump offsets based on shiftlist */
733
0
void zend_optimizer_shift_jump(const zend_op_array *op_array, zend_op *opline, const uint32_t *shiftlist) {
734
0
  switch (opline->opcode) {
735
0
    case ZEND_JMP:
736
0
    case ZEND_FAST_CALL:
737
0
      ZEND_SET_OP_JMP_ADDR(opline, opline->op1, ZEND_OP1_JMP_ADDR(opline) - shiftlist[ZEND_OP1_JMP_ADDR(opline) - op_array->opcodes]);
738
0
      break;
739
0
    case ZEND_JMPZ:
740
0
    case ZEND_JMPNZ:
741
0
    case ZEND_JMPZ_EX:
742
0
    case ZEND_JMPNZ_EX:
743
0
    case ZEND_FE_RESET_R:
744
0
    case ZEND_FE_RESET_RW:
745
0
    case ZEND_JMP_SET:
746
0
    case ZEND_COALESCE:
747
0
    case ZEND_ASSERT_CHECK:
748
0
    case ZEND_JMP_NULL:
749
0
    case ZEND_BIND_INIT_STATIC_OR_JMP:
750
0
    case ZEND_JMP_FRAMELESS:
751
0
      ZEND_SET_OP_JMP_ADDR(opline, opline->op2, ZEND_OP2_JMP_ADDR(opline) - shiftlist[ZEND_OP2_JMP_ADDR(opline) - op_array->opcodes]);
752
0
      break;
753
0
    case ZEND_CATCH:
754
0
      if (!(opline->extended_value & ZEND_LAST_CATCH)) {
755
0
        ZEND_SET_OP_JMP_ADDR(opline, opline->op2, ZEND_OP2_JMP_ADDR(opline) - shiftlist[ZEND_OP2_JMP_ADDR(opline) - op_array->opcodes]);
756
0
      }
757
0
      break;
758
0
    case ZEND_FE_FETCH_R:
759
0
    case ZEND_FE_FETCH_RW:
760
0
      opline->extended_value = ZEND_OPLINE_NUM_TO_OFFSET(op_array, opline, ZEND_OFFSET_TO_OPLINE_NUM(op_array, opline, opline->extended_value) - shiftlist[ZEND_OFFSET_TO_OPLINE_NUM(op_array, opline, opline->extended_value)]);
761
0
      break;
762
0
    case ZEND_SWITCH_LONG:
763
0
    case ZEND_SWITCH_STRING:
764
0
    case ZEND_MATCH:
765
0
    {
766
0
      const HashTable *jumptable = Z_ARRVAL(ZEND_OP2_LITERAL(opline));
767
0
      zval *zv;
768
0
      ZEND_HASH_FOREACH_VAL(jumptable, zv) {
769
0
        Z_LVAL_P(zv) = ZEND_OPLINE_NUM_TO_OFFSET(op_array, opline, ZEND_OFFSET_TO_OPLINE_NUM(op_array, opline, Z_LVAL_P(zv)) - shiftlist[ZEND_OFFSET_TO_OPLINE_NUM(op_array, opline, Z_LVAL_P(zv))]);
770
0
      } ZEND_HASH_FOREACH_END();
771
0
      opline->extended_value = ZEND_OPLINE_NUM_TO_OFFSET(op_array, opline, ZEND_OFFSET_TO_OPLINE_NUM(op_array, opline, opline->extended_value) - shiftlist[ZEND_OFFSET_TO_OPLINE_NUM(op_array, opline, opline->extended_value)]);
772
0
      break;
773
0
    }
774
0
  }
775
0
}
776
777
static bool zend_optimizer_ignore_class(zval *ce_zv, const zend_string *filename)
778
0
{
779
0
  const zend_class_entry *ce = Z_PTR_P(ce_zv);
780
781
0
  if (ce->ce_flags & ZEND_ACC_PRELOADED) {
782
0
    const Bucket *ce_bucket = (const Bucket*)((uintptr_t)ce_zv - XtOffsetOf(Bucket, val));
783
0
    size_t offset = ce_bucket - EG(class_table)->arData;
784
0
    if (offset < EG(persistent_classes_count)) {
785
0
      return false;
786
0
    }
787
0
  }
788
0
  return ce->type == ZEND_USER_CLASS
789
0
    && (!ce->info.user.filename || ce->info.user.filename != filename);
790
0
}
791
792
static bool zend_optimizer_ignore_function(zval *fbc_zv, const zend_string *filename)
793
0
{
794
0
  const zend_function *fbc = Z_PTR_P(fbc_zv);
795
796
0
  if (fbc->type == ZEND_INTERNAL_FUNCTION) {
797
0
    return false;
798
0
  } else if (fbc->type == ZEND_USER_FUNCTION) {
799
0
    if (fbc->op_array.fn_flags & ZEND_ACC_PRELOADED) {
800
0
      const Bucket *fbc_bucket = (const Bucket*)((uintptr_t)fbc_zv - XtOffsetOf(Bucket, val));
801
0
      size_t offset = fbc_bucket - EG(function_table)->arData;
802
0
      if (offset < EG(persistent_functions_count)) {
803
0
        return false;
804
0
      }
805
0
    }
806
0
    return !fbc->op_array.filename || fbc->op_array.filename != filename;
807
0
  } else {
808
0
    ZEND_ASSERT(fbc->type == ZEND_EVAL_CODE);
809
0
    return true;
810
0
  }
811
0
}
812
813
zend_class_entry *zend_optimizer_get_class_entry(
814
0
    const zend_script *script, const zend_op_array *op_array, zend_string *lcname) {
815
0
  zend_class_entry *ce = script ? zend_hash_find_ptr(&script->class_table, lcname) : NULL;
816
0
  if (ce) {
817
0
    return ce;
818
0
  }
819
820
0
  zval *ce_zv = zend_hash_find(CG(class_table), lcname);
821
0
  if (ce_zv && !zend_optimizer_ignore_class(ce_zv, op_array ? op_array->filename : NULL)) {
822
0
    return Z_PTR_P(ce_zv);
823
0
  }
824
825
0
  if (op_array && op_array->scope && zend_string_equals_ci(op_array->scope->name, lcname)) {
826
0
    return op_array->scope;
827
0
  }
828
829
0
  return NULL;
830
0
}
831
832
zend_class_entry *zend_optimizer_get_class_entry_from_op1(
833
0
    const zend_script *script, const zend_op_array *op_array, const zend_op *opline) {
834
0
  if (opline->op1_type == IS_CONST) {
835
0
    const zval *op1 = CRT_CONSTANT(opline->op1);
836
0
    if (Z_TYPE_P(op1) == IS_STRING) {
837
0
      return zend_optimizer_get_class_entry(script, op_array, Z_STR_P(op1 + 1));
838
0
    }
839
0
  } else if (opline->op1_type == IS_UNUSED && op_array->scope
840
0
      && !(op_array->scope->ce_flags & ZEND_ACC_TRAIT)
841
0
      && ((opline->op1.num & ZEND_FETCH_CLASS_MASK) == ZEND_FETCH_CLASS_SELF
842
0
        || ((opline->op1.num & ZEND_FETCH_CLASS_MASK) == ZEND_FETCH_CLASS_STATIC
843
0
          && (op_array->scope->ce_flags & ZEND_ACC_FINAL)))) {
844
0
    return op_array->scope;
845
0
  }
846
0
  return NULL;
847
0
}
848
849
const zend_class_constant *zend_fetch_class_const_info(
850
0
  const zend_script *script, const zend_op_array *op_array, const zend_op *opline, bool *is_prototype) {
851
0
  const zend_class_entry *ce = NULL;
852
0
  bool is_static_reference = false;
853
854
0
  if (!opline || !op_array || opline->op2_type != IS_CONST || Z_TYPE_P(CRT_CONSTANT(opline->op2)) != IS_STRING) {
855
0
    return NULL;
856
0
  }
857
0
  if (opline->op1_type == IS_CONST) {
858
0
    const zval *op1 = CRT_CONSTANT(opline->op1);
859
0
    if (Z_TYPE_P(op1) == IS_STRING) {
860
0
      if (script) {
861
0
        ce = zend_optimizer_get_class_entry(script, op_array, Z_STR_P(op1 + 1));
862
0
      } else {
863
0
        zval *ce_zv = zend_hash_find(EG(class_table), Z_STR_P(op1 + 1));
864
0
        if (ce_zv && !zend_optimizer_ignore_class(ce_zv, op_array->filename)) {
865
0
          ce = Z_PTR_P(ce_zv);
866
0
        }
867
0
      }
868
0
    }
869
0
  } else if (opline->op1_type == IS_UNUSED
870
0
    && op_array->scope && !(op_array->scope->ce_flags & ZEND_ACC_TRAIT)
871
0
    && !(op_array->fn_flags & ZEND_ACC_TRAIT_CLONE)) {
872
0
    uint32_t fetch_type = opline->op1.num & ZEND_FETCH_CLASS_MASK;
873
0
    if (fetch_type == ZEND_FETCH_CLASS_SELF) {
874
0
      ce = op_array->scope;
875
0
    } else if (fetch_type == ZEND_FETCH_CLASS_STATIC) {
876
0
      ce = op_array->scope;
877
0
      is_static_reference = true;
878
0
    } else if (fetch_type == ZEND_FETCH_CLASS_PARENT) {
879
0
      if (op_array->scope->ce_flags & ZEND_ACC_LINKED) {
880
0
        ce = op_array->scope->parent;
881
0
      }
882
0
    }
883
0
  }
884
0
  if (!ce || (ce->ce_flags & ZEND_ACC_TRAIT)) {
885
0
    return NULL;
886
0
  }
887
0
  zend_class_constant *const_info = zend_hash_find_ptr(&ce->constants_table, Z_STR_P(CRT_CONSTANT(opline->op2)));
888
0
  if (!const_info) {
889
0
    return NULL;
890
0
  }
891
0
  if ((ZEND_CLASS_CONST_FLAGS(const_info) & ZEND_ACC_DEPRECATED)
892
0
    || ((ZEND_CLASS_CONST_FLAGS(const_info) & ZEND_ACC_PPP_MASK) != ZEND_ACC_PUBLIC && const_info->ce != op_array->scope)) {
893
0
    return NULL;
894
0
  }
895
0
  *is_prototype = is_static_reference
896
0
    && !(const_info->ce->ce_flags & ZEND_ACC_FINAL) && !(ZEND_CLASS_CONST_FLAGS(const_info) & ZEND_ACC_FINAL);
897
898
0
  return const_info;
899
0
}
900
901
zend_function *zend_optimizer_get_called_func(
902
    const zend_script *script, const zend_op_array *op_array, zend_op *opline, bool *is_prototype)
903
0
{
904
0
  *is_prototype = false;
905
0
  switch (opline->opcode) {
906
0
    case ZEND_INIT_FCALL:
907
0
    {
908
0
      zend_string *function_name = Z_STR_P(CRT_CONSTANT(opline->op2));
909
0
      zend_function *func;
910
0
      zval *func_zv;
911
0
      if (script && (func = zend_hash_find_ptr(&script->function_table, function_name)) != NULL) {
912
0
        return func;
913
0
      } else if ((func_zv = zend_hash_find(EG(function_table), function_name)) != NULL) {
914
0
        if (!zend_optimizer_ignore_function(func_zv, op_array->filename)) {
915
0
          return Z_PTR_P(func_zv);
916
0
        }
917
0
      }
918
0
      break;
919
0
    }
920
0
    case ZEND_INIT_FCALL_BY_NAME:
921
0
    case ZEND_INIT_NS_FCALL_BY_NAME:
922
0
      if (opline->op2_type == IS_CONST && Z_TYPE_P(CRT_CONSTANT(opline->op2)) == IS_STRING) {
923
0
        const zval *function_name = CRT_CONSTANT(opline->op2) + 1;
924
0
        zend_function *func;
925
0
        zval *func_zv;
926
0
        if (script && (func = zend_hash_find_ptr(&script->function_table, Z_STR_P(function_name)))) {
927
0
          return func;
928
0
        } else if ((func_zv = zend_hash_find(EG(function_table), Z_STR_P(function_name))) != NULL) {
929
0
          if (!zend_optimizer_ignore_function(func_zv, op_array->filename)) {
930
0
            return Z_PTR_P(func_zv);
931
0
          }
932
0
        }
933
0
      }
934
0
      break;
935
0
    case ZEND_INIT_STATIC_METHOD_CALL:
936
0
      if (opline->op2_type == IS_CONST && Z_TYPE_P(CRT_CONSTANT(opline->op2)) == IS_STRING) {
937
0
        const zend_class_entry *ce = zend_optimizer_get_class_entry_from_op1(
938
0
          script, op_array, opline);
939
0
        if (ce) {
940
0
          zend_string *func_name = Z_STR_P(CRT_CONSTANT(opline->op2) + 1);
941
0
          zend_function *fbc = zend_hash_find_ptr(&ce->function_table, func_name);
942
0
          if (fbc) {
943
0
            bool is_public = (fbc->common.fn_flags & ZEND_ACC_PUBLIC) != 0;
944
0
            bool same_scope = fbc->common.scope == op_array->scope;
945
0
            if (is_public || same_scope) {
946
0
              return fbc;
947
0
            }
948
0
          }
949
0
        }
950
0
      }
951
0
      break;
952
0
    case ZEND_INIT_METHOD_CALL:
953
0
      if (opline->op1_type == IS_UNUSED
954
0
          && opline->op2_type == IS_CONST && Z_TYPE_P(CRT_CONSTANT(opline->op2)) == IS_STRING
955
0
          && op_array->scope
956
0
          && !(op_array->fn_flags & ZEND_ACC_TRAIT_CLONE)
957
0
          && !(op_array->scope->ce_flags & ZEND_ACC_TRAIT)) {
958
0
        zend_string *method_name = Z_STR_P(CRT_CONSTANT(opline->op2) + 1);
959
0
        zend_function *fbc = zend_hash_find_ptr(
960
0
          &op_array->scope->function_table, method_name);
961
0
        if (fbc) {
962
0
          bool is_private = (fbc->common.fn_flags & ZEND_ACC_PRIVATE) != 0;
963
0
          if (is_private) {
964
            /* Only use private method if in the same scope. We can't even use it
965
             * as a prototype, as it may be overridden with changed signature. */
966
0
            bool same_scope = fbc->common.scope == op_array->scope;
967
0
            return same_scope ? fbc : NULL;
968
0
          }
969
          /* Prototype methods are potentially overridden. fbc still contains useful type information.
970
           * Some optimizations may not be applied, like inlining or inferring the send-mode of superfluous args.
971
           * A method cannot be overridden if the class or method is final. */
972
0
          if ((fbc->common.fn_flags & ZEND_ACC_FINAL) == 0 &&
973
0
            (fbc->common.scope->ce_flags & ZEND_ACC_FINAL) == 0) {
974
0
            *is_prototype = true;
975
0
          }
976
0
          return fbc;
977
0
        }
978
0
      }
979
0
      break;
980
0
    case ZEND_INIT_PARENT_PROPERTY_HOOK_CALL: {
981
0
      const zend_class_entry *scope = op_array->scope;
982
0
      ZEND_ASSERT(scope != NULL);
983
0
      if ((scope->ce_flags & ZEND_ACC_LINKED) && scope->parent) {
984
0
        const zend_class_entry *parent_scope = scope->parent;
985
0
        zend_string *prop_name = Z_STR_P(CRT_CONSTANT(opline->op1));
986
0
        zend_property_hook_kind hook_kind = opline->op2.num;
987
0
        const zend_property_info *prop_info = zend_get_property_info(parent_scope, prop_name, /* silent */ true);
988
989
0
        if (prop_info
990
0
          && prop_info != ZEND_WRONG_PROPERTY_INFO
991
0
          && !(prop_info->flags & ZEND_ACC_PRIVATE)
992
0
          && prop_info->hooks) {
993
0
          zend_function *fbc = prop_info->hooks[hook_kind];
994
0
          if (fbc) {
995
0
            *is_prototype = false;
996
0
            return fbc;
997
0
          }
998
0
        }
999
0
      }
1000
0
      break;
1001
0
    }
1002
0
    case ZEND_NEW:
1003
0
    {
1004
0
      const zend_class_entry *ce = zend_optimizer_get_class_entry_from_op1(
1005
0
        script, op_array, opline);
1006
0
      if (ce && ce->type == ZEND_USER_CLASS) {
1007
0
        return ce->constructor;
1008
0
      }
1009
0
      break;
1010
0
    }
1011
0
  }
1012
0
  return NULL;
1013
0
}
1014
1015
0
uint32_t zend_optimizer_classify_function(const zend_string *name, uint32_t num_args) {
1016
0
  if (zend_string_equals_literal(name, "extract")) {
1017
0
    return ZEND_FUNC_INDIRECT_VAR_ACCESS;
1018
0
  } else if (zend_string_equals_literal(name, "compact")) {
1019
0
    return ZEND_FUNC_INDIRECT_VAR_ACCESS;
1020
0
  } else if (zend_string_equals_literal(name, "get_defined_vars")) {
1021
0
    return ZEND_FUNC_INDIRECT_VAR_ACCESS;
1022
0
  } else if (zend_string_equals_literal(name, "db2_execute")) {
1023
0
    return ZEND_FUNC_INDIRECT_VAR_ACCESS;
1024
0
  } else if (zend_string_equals_literal(name, "func_num_args")) {
1025
0
    return ZEND_FUNC_VARARG;
1026
0
  } else if (zend_string_equals_literal(name, "func_get_arg")) {
1027
0
    return ZEND_FUNC_VARARG;
1028
0
  } else if (zend_string_equals_literal(name, "func_get_args")) {
1029
0
    return ZEND_FUNC_VARARG;
1030
0
  } else {
1031
0
    return 0;
1032
0
  }
1033
0
}
1034
1035
0
zend_op *zend_optimizer_get_loop_var_def(const zend_op_array *op_array, zend_op *free_opline) {
1036
0
  uint32_t var = free_opline->op1.var;
1037
0
  ZEND_ASSERT(zend_optimizer_is_loop_var_free(free_opline));
1038
1039
0
  while (--free_opline >= op_array->opcodes) {
1040
0
    if ((free_opline->result_type & (IS_TMP_VAR|IS_VAR)) && free_opline->result.var == var) {
1041
0
      return free_opline;
1042
0
    }
1043
0
  }
1044
0
  return NULL;
1045
0
}
1046
1047
static void zend_optimize(zend_op_array      *op_array,
1048
                          zend_optimizer_ctx *ctx)
1049
0
{
1050
0
  if (op_array->type == ZEND_EVAL_CODE) {
1051
0
    return;
1052
0
  }
1053
1054
0
  if (ctx->debug_level & ZEND_DUMP_BEFORE_OPTIMIZER) {
1055
0
    zend_dump_op_array(op_array, ZEND_DUMP_LIVE_RANGES, "before optimizer", NULL);
1056
0
  }
1057
1058
  /* pass 1 (Simple local optimizations)
1059
   * - persistent constant substitution (true, false, null, etc)
1060
   * - constant casting (ADD expects numbers, CONCAT strings, etc)
1061
   * - constant expression evaluation
1062
   * - optimize constant conditional JMPs
1063
   * - pre-evaluate constant function calls
1064
   * - eliminate FETCH $GLOBALS followed by FETCH_DIM/UNSET_DIM/ISSET_ISEMPTY_DIM
1065
   */
1066
0
  if (ZEND_OPTIMIZER_PASS_1 & ctx->optimization_level) {
1067
0
    zend_optimizer_pass1(op_array, ctx);
1068
0
    if (ctx->debug_level & ZEND_DUMP_AFTER_PASS_1) {
1069
0
      zend_dump_op_array(op_array, 0, "after pass 1", NULL);
1070
0
    }
1071
0
  }
1072
1073
  /* pass 3: (Jump optimization)
1074
   * - optimize series of JMPs
1075
   */
1076
0
  if (ZEND_OPTIMIZER_PASS_3 & ctx->optimization_level) {
1077
0
    zend_optimizer_pass3(op_array, ctx);
1078
0
    if (ctx->debug_level & ZEND_DUMP_AFTER_PASS_3) {
1079
0
      zend_dump_op_array(op_array, 0, "after pass 3", NULL);
1080
0
    }
1081
0
  }
1082
1083
  /* pass 4:
1084
   * - INIT_FCALL_BY_NAME -> DO_FCALL
1085
   */
1086
0
  if (ZEND_OPTIMIZER_PASS_4 & ctx->optimization_level) {
1087
0
    zend_optimize_func_calls(op_array, ctx);
1088
0
    if (ctx->debug_level & ZEND_DUMP_AFTER_PASS_4) {
1089
0
      zend_dump_op_array(op_array, 0, "after pass 4", NULL);
1090
0
    }
1091
0
  }
1092
1093
  /* pass 5:
1094
   * - CFG optimization
1095
   */
1096
0
  if (ZEND_OPTIMIZER_PASS_5 & ctx->optimization_level) {
1097
0
    zend_optimize_cfg(op_array, ctx);
1098
0
    if (ctx->debug_level & ZEND_DUMP_AFTER_PASS_5) {
1099
0
      zend_dump_op_array(op_array, 0, "after pass 5", NULL);
1100
0
    }
1101
0
  }
1102
1103
  /* pass 6:
1104
   * - DFA optimization
1105
   */
1106
0
  if ((ZEND_OPTIMIZER_PASS_6 & ctx->optimization_level) &&
1107
0
      !(ZEND_OPTIMIZER_PASS_7 & ctx->optimization_level)) {
1108
0
    zend_optimize_dfa(op_array, ctx);
1109
0
    if (ctx->debug_level & ZEND_DUMP_AFTER_PASS_6) {
1110
0
      zend_dump_op_array(op_array, 0, "after pass 6", NULL);
1111
0
    }
1112
0
  }
1113
1114
  /* pass 9:
1115
   * - Optimize temp variables usage
1116
   */
1117
0
  if ((ZEND_OPTIMIZER_PASS_9 & ctx->optimization_level) &&
1118
0
      !(ZEND_OPTIMIZER_PASS_7 & ctx->optimization_level)) {
1119
0
    zend_optimize_temporary_variables(op_array, ctx);
1120
0
    if (ctx->debug_level & ZEND_DUMP_AFTER_PASS_9) {
1121
0
      zend_dump_op_array(op_array, 0, "after pass 9", NULL);
1122
0
    }
1123
0
  }
1124
1125
  /* pass 10:
1126
   * - remove NOPs
1127
   */
1128
0
  if (((ZEND_OPTIMIZER_PASS_10|ZEND_OPTIMIZER_PASS_5) & ctx->optimization_level) == ZEND_OPTIMIZER_PASS_10) {
1129
0
    zend_optimizer_nop_removal(op_array, ctx);
1130
0
    if (ctx->debug_level & ZEND_DUMP_AFTER_PASS_10) {
1131
0
      zend_dump_op_array(op_array, 0, "after pass 10", NULL);
1132
0
    }
1133
0
  }
1134
1135
  /* pass 11:
1136
   * - Compact literals table
1137
   */
1138
0
  if ((ZEND_OPTIMIZER_PASS_11 & ctx->optimization_level) &&
1139
0
      (!(ZEND_OPTIMIZER_PASS_6 & ctx->optimization_level) ||
1140
0
       !(ZEND_OPTIMIZER_PASS_7 & ctx->optimization_level))) {
1141
0
    zend_optimizer_compact_literals(op_array, ctx);
1142
0
    if (ctx->debug_level & ZEND_DUMP_AFTER_PASS_11) {
1143
0
      zend_dump_op_array(op_array, 0, "after pass 11", NULL);
1144
0
    }
1145
0
  }
1146
1147
0
  if ((ZEND_OPTIMIZER_PASS_13 & ctx->optimization_level) &&
1148
0
      (!(ZEND_OPTIMIZER_PASS_6 & ctx->optimization_level) ||
1149
0
       !(ZEND_OPTIMIZER_PASS_7 & ctx->optimization_level))) {
1150
0
    zend_optimizer_compact_vars(op_array);
1151
0
    if (ctx->debug_level & ZEND_DUMP_AFTER_PASS_13) {
1152
0
      zend_dump_op_array(op_array, 0, "after pass 13", NULL);
1153
0
    }
1154
0
  }
1155
1156
0
  if (ZEND_OPTIMIZER_PASS_7 & ctx->optimization_level) {
1157
0
    return;
1158
0
  }
1159
1160
0
  if (ctx->debug_level & ZEND_DUMP_AFTER_OPTIMIZER) {
1161
0
    zend_dump_op_array(op_array, 0, "after optimizer", NULL);
1162
0
  }
1163
0
}
1164
1165
static void zend_revert_pass_two(zend_op_array *op_array)
1166
0
{
1167
0
  zend_op *opline;
1168
1169
0
  ZEND_ASSERT((op_array->fn_flags & ZEND_ACC_DONE_PASS_TWO) != 0);
1170
1171
0
  opline = op_array->opcodes;
1172
0
  const zend_op *end = opline + op_array->last;
1173
0
  while (opline < end) {
1174
0
    if (opline->op1_type == IS_CONST) {
1175
0
      ZEND_PASS_TWO_UNDO_CONSTANT(op_array, opline, opline->op1);
1176
0
    }
1177
0
    if (opline->op2_type == IS_CONST) {
1178
0
      ZEND_PASS_TWO_UNDO_CONSTANT(op_array, opline, opline->op2);
1179
0
    }
1180
    /* reset smart branch flags IS_SMART_BRANCH_JMP[N]Z */
1181
0
    opline->result_type &= (IS_TMP_VAR|IS_VAR|IS_CV|IS_CONST);
1182
0
    opline++;
1183
0
  }
1184
0
#if !ZEND_USE_ABS_CONST_ADDR
1185
0
  if (op_array->literals) {
1186
0
    zval *literals = emalloc(sizeof(zval) * op_array->last_literal);
1187
0
    memcpy(literals, op_array->literals, sizeof(zval) * op_array->last_literal);
1188
0
    op_array->literals = literals;
1189
0
  }
1190
0
#endif
1191
1192
0
  op_array->fn_flags &= ~ZEND_ACC_DONE_PASS_TWO;
1193
0
}
1194
1195
static void zend_redo_pass_two(zend_op_array *op_array)
1196
0
{
1197
0
  zend_op *opline, *end;
1198
#if ZEND_USE_ABS_JMP_ADDR && !ZEND_USE_ABS_CONST_ADDR
1199
  zend_op *old_opcodes = op_array->opcodes;
1200
#endif
1201
1202
0
  ZEND_ASSERT((op_array->fn_flags & ZEND_ACC_DONE_PASS_TWO) == 0);
1203
1204
0
#if !ZEND_USE_ABS_CONST_ADDR
1205
0
  if (op_array->last_literal) {
1206
0
    op_array->opcodes = (zend_op *) erealloc(op_array->opcodes,
1207
0
      ZEND_MM_ALIGNED_SIZE_EX(sizeof(zend_op) * op_array->last, 16) +
1208
0
      sizeof(zval) * op_array->last_literal);
1209
0
    memcpy(((char*)op_array->opcodes) + ZEND_MM_ALIGNED_SIZE_EX(sizeof(zend_op) * op_array->last, 16),
1210
0
      op_array->literals, sizeof(zval) * op_array->last_literal);
1211
0
    efree(op_array->literals);
1212
0
    op_array->literals = (zval*)(((char*)op_array->opcodes) + ZEND_MM_ALIGNED_SIZE_EX(sizeof(zend_op) * op_array->last, 16));
1213
0
  } else {
1214
0
    if (op_array->literals) {
1215
0
      efree(op_array->literals);
1216
0
    }
1217
0
    op_array->literals = NULL;
1218
0
  }
1219
0
#endif
1220
1221
0
  opline = op_array->opcodes;
1222
0
  end = opline + op_array->last;
1223
0
  while (opline < end) {
1224
0
    if (opline->op1_type == IS_CONST) {
1225
0
      ZEND_PASS_TWO_UPDATE_CONSTANT(op_array, opline, opline->op1);
1226
0
    }
1227
0
    if (opline->op2_type == IS_CONST) {
1228
0
      ZEND_PASS_TWO_UPDATE_CONSTANT(op_array, opline, opline->op2);
1229
0
    }
1230
    /* fix jumps to point to new array */
1231
0
    switch (opline->opcode) {
1232
#if ZEND_USE_ABS_JMP_ADDR && !ZEND_USE_ABS_CONST_ADDR
1233
      case ZEND_JMP:
1234
      case ZEND_FAST_CALL:
1235
        opline->op1.jmp_addr = &op_array->opcodes[opline->op1.jmp_addr - old_opcodes];
1236
        break;
1237
      case ZEND_JMPZ:
1238
      case ZEND_JMPNZ:
1239
      case ZEND_JMPZ_EX:
1240
      case ZEND_JMPNZ_EX:
1241
      case ZEND_JMP_SET:
1242
      case ZEND_COALESCE:
1243
      case ZEND_FE_RESET_R:
1244
      case ZEND_FE_RESET_RW:
1245
      case ZEND_ASSERT_CHECK:
1246
      case ZEND_JMP_NULL:
1247
      case ZEND_BIND_INIT_STATIC_OR_JMP:
1248
      case ZEND_JMP_FRAMELESS:
1249
        opline->op2.jmp_addr = &op_array->opcodes[opline->op2.jmp_addr - old_opcodes];
1250
        break;
1251
      case ZEND_CATCH:
1252
        if (!(opline->extended_value & ZEND_LAST_CATCH)) {
1253
          opline->op2.jmp_addr = &op_array->opcodes[opline->op2.jmp_addr - old_opcodes];
1254
        }
1255
        break;
1256
      case ZEND_FE_FETCH_R:
1257
      case ZEND_FE_FETCH_RW:
1258
      case ZEND_SWITCH_LONG:
1259
      case ZEND_SWITCH_STRING:
1260
      case ZEND_MATCH:
1261
        /* relative extended_value don't have to be changed */
1262
        break;
1263
#endif
1264
0
      case ZEND_IS_IDENTICAL:
1265
0
      case ZEND_IS_NOT_IDENTICAL:
1266
0
      case ZEND_IS_EQUAL:
1267
0
      case ZEND_IS_NOT_EQUAL:
1268
0
      case ZEND_IS_SMALLER:
1269
0
      case ZEND_IS_SMALLER_OR_EQUAL:
1270
0
      case ZEND_CASE:
1271
0
      case ZEND_CASE_STRICT:
1272
0
      case ZEND_ISSET_ISEMPTY_CV:
1273
0
      case ZEND_ISSET_ISEMPTY_VAR:
1274
0
      case ZEND_ISSET_ISEMPTY_DIM_OBJ:
1275
0
      case ZEND_ISSET_ISEMPTY_PROP_OBJ:
1276
0
      case ZEND_ISSET_ISEMPTY_STATIC_PROP:
1277
0
      case ZEND_INSTANCEOF:
1278
0
      case ZEND_TYPE_CHECK:
1279
0
      case ZEND_DEFINED:
1280
0
      case ZEND_IN_ARRAY:
1281
0
      case ZEND_ARRAY_KEY_EXISTS:
1282
0
        if (opline->result_type & IS_TMP_VAR) {
1283
          /* reinitialize result_type of smart branch instructions */
1284
0
          if (opline + 1 < end) {
1285
0
            if ((opline+1)->opcode == ZEND_JMPZ
1286
0
             && (opline+1)->op1_type == IS_TMP_VAR
1287
0
             && (opline+1)->op1.var == opline->result.var) {
1288
0
              opline->result_type = IS_SMART_BRANCH_JMPZ | IS_TMP_VAR;
1289
0
            } else if ((opline+1)->opcode == ZEND_JMPNZ
1290
0
             && (opline+1)->op1_type == IS_TMP_VAR
1291
0
             && (opline+1)->op1.var == opline->result.var) {
1292
0
              opline->result_type = IS_SMART_BRANCH_JMPNZ | IS_TMP_VAR;
1293
0
            }
1294
0
          }
1295
0
        }
1296
0
        break;
1297
0
    }
1298
0
    ZEND_VM_SET_OPCODE_HANDLER(opline);
1299
0
    opline++;
1300
0
  }
1301
1302
0
  op_array->fn_flags |= ZEND_ACC_DONE_PASS_TWO;
1303
0
}
1304
1305
static void zend_redo_pass_two_ex(zend_op_array *op_array, const zend_ssa *ssa)
1306
0
{
1307
0
  zend_op *opline, *end;
1308
#if ZEND_USE_ABS_JMP_ADDR && !ZEND_USE_ABS_CONST_ADDR
1309
  zend_op *old_opcodes = op_array->opcodes;
1310
#endif
1311
1312
0
  ZEND_ASSERT((op_array->fn_flags & ZEND_ACC_DONE_PASS_TWO) == 0);
1313
1314
0
#if !ZEND_USE_ABS_CONST_ADDR
1315
0
  if (op_array->last_literal) {
1316
0
    op_array->opcodes = (zend_op *) erealloc(op_array->opcodes,
1317
0
      ZEND_MM_ALIGNED_SIZE_EX(sizeof(zend_op) * op_array->last, 16) +
1318
0
      sizeof(zval) * op_array->last_literal);
1319
0
    memcpy(((char*)op_array->opcodes) + ZEND_MM_ALIGNED_SIZE_EX(sizeof(zend_op) * op_array->last, 16),
1320
0
      op_array->literals, sizeof(zval) * op_array->last_literal);
1321
0
    efree(op_array->literals);
1322
0
    op_array->literals = (zval*)(((char*)op_array->opcodes) + ZEND_MM_ALIGNED_SIZE_EX(sizeof(zend_op) * op_array->last, 16));
1323
0
  } else {
1324
0
    if (op_array->literals) {
1325
0
      efree(op_array->literals);
1326
0
    }
1327
0
    op_array->literals = NULL;
1328
0
  }
1329
0
#endif
1330
1331
0
  opline = op_array->opcodes;
1332
0
  end = opline + op_array->last;
1333
0
  while (opline < end) {
1334
0
    const zend_ssa_op *ssa_op = &ssa->ops[opline - op_array->opcodes];
1335
0
    uint32_t op1_info = opline->op1_type == IS_UNUSED ? 0 : (OP1_INFO() & (MAY_BE_UNDEF|MAY_BE_ANY|MAY_BE_REF|MAY_BE_ARRAY_OF_ANY|MAY_BE_ARRAY_KEY_ANY));
1336
0
    uint32_t op2_info = opline->op1_type == IS_UNUSED ? 0 : (OP2_INFO() & (MAY_BE_UNDEF|MAY_BE_ANY|MAY_BE_REF|MAY_BE_ARRAY_OF_ANY|MAY_BE_ARRAY_KEY_ANY));
1337
0
    uint32_t res_info =
1338
0
      (opline->opcode == ZEND_PRE_INC ||
1339
0
       opline->opcode == ZEND_PRE_DEC ||
1340
0
       opline->opcode == ZEND_POST_INC ||
1341
0
       opline->opcode == ZEND_POST_DEC) ?
1342
0
        ((ssa->ops[opline - op_array->opcodes].op1_def >= 0) ? (OP1_DEF_INFO() & (MAY_BE_UNDEF|MAY_BE_ANY|MAY_BE_REF|MAY_BE_ARRAY_OF_ANY|MAY_BE_ARRAY_KEY_ANY)) : MAY_BE_ANY) :
1343
0
        (opline->result_type == IS_UNUSED ? 0 : (RES_INFO() & (MAY_BE_UNDEF|MAY_BE_ANY|MAY_BE_REF|MAY_BE_ARRAY_OF_ANY|MAY_BE_ARRAY_KEY_ANY)));
1344
1345
0
    if (opline->op1_type == IS_CONST) {
1346
0
      ZEND_PASS_TWO_UPDATE_CONSTANT(op_array, opline, opline->op1);
1347
0
    }
1348
0
    if (opline->op2_type == IS_CONST) {
1349
0
      ZEND_PASS_TWO_UPDATE_CONSTANT(op_array, opline, opline->op2);
1350
0
    }
1351
1352
    /* fix jumps to point to new array */
1353
0
    switch (opline->opcode) {
1354
#if ZEND_USE_ABS_JMP_ADDR && !ZEND_USE_ABS_CONST_ADDR
1355
      case ZEND_JMP:
1356
      case ZEND_FAST_CALL:
1357
        opline->op1.jmp_addr = &op_array->opcodes[opline->op1.jmp_addr - old_opcodes];
1358
        break;
1359
      case ZEND_JMPZ:
1360
      case ZEND_JMPNZ:
1361
      case ZEND_JMPZ_EX:
1362
      case ZEND_JMPNZ_EX:
1363
      case ZEND_JMP_SET:
1364
      case ZEND_COALESCE:
1365
      case ZEND_FE_RESET_R:
1366
      case ZEND_FE_RESET_RW:
1367
      case ZEND_ASSERT_CHECK:
1368
      case ZEND_JMP_NULL:
1369
      case ZEND_BIND_INIT_STATIC_OR_JMP:
1370
      case ZEND_JMP_FRAMELESS:
1371
        opline->op2.jmp_addr = &op_array->opcodes[opline->op2.jmp_addr - old_opcodes];
1372
        break;
1373
      case ZEND_CATCH:
1374
        if (!(opline->extended_value & ZEND_LAST_CATCH)) {
1375
          opline->op2.jmp_addr = &op_array->opcodes[opline->op2.jmp_addr - old_opcodes];
1376
        }
1377
        break;
1378
      case ZEND_FE_FETCH_R:
1379
      case ZEND_FE_FETCH_RW:
1380
      case ZEND_SWITCH_LONG:
1381
      case ZEND_SWITCH_STRING:
1382
      case ZEND_MATCH:
1383
        /* relative extended_value don't have to be changed */
1384
        break;
1385
#endif
1386
0
      case ZEND_IS_IDENTICAL:
1387
0
      case ZEND_IS_NOT_IDENTICAL:
1388
0
      case ZEND_IS_EQUAL:
1389
0
      case ZEND_IS_NOT_EQUAL:
1390
0
      case ZEND_IS_SMALLER:
1391
0
      case ZEND_IS_SMALLER_OR_EQUAL:
1392
0
      case ZEND_CASE:
1393
0
      case ZEND_CASE_STRICT:
1394
0
      case ZEND_ISSET_ISEMPTY_CV:
1395
0
      case ZEND_ISSET_ISEMPTY_VAR:
1396
0
      case ZEND_ISSET_ISEMPTY_DIM_OBJ:
1397
0
      case ZEND_ISSET_ISEMPTY_PROP_OBJ:
1398
0
      case ZEND_ISSET_ISEMPTY_STATIC_PROP:
1399
0
      case ZEND_INSTANCEOF:
1400
0
      case ZEND_TYPE_CHECK:
1401
0
      case ZEND_DEFINED:
1402
0
      case ZEND_IN_ARRAY:
1403
0
      case ZEND_ARRAY_KEY_EXISTS:
1404
0
        if (opline->result_type & IS_TMP_VAR) {
1405
          /* reinitialize result_type of smart branch instructions */
1406
0
          if (opline + 1 < end) {
1407
0
            if ((opline+1)->opcode == ZEND_JMPZ
1408
0
             && (opline+1)->op1_type == IS_TMP_VAR
1409
0
             && (opline+1)->op1.var == opline->result.var) {
1410
0
              opline->result_type = IS_SMART_BRANCH_JMPZ | IS_TMP_VAR;
1411
0
            } else if ((opline+1)->opcode == ZEND_JMPNZ
1412
0
             && (opline+1)->op1_type == IS_TMP_VAR
1413
0
             && (opline+1)->op1.var == opline->result.var) {
1414
0
              opline->result_type = IS_SMART_BRANCH_JMPNZ | IS_TMP_VAR;
1415
0
            }
1416
0
          }
1417
0
        }
1418
0
        break;
1419
0
    }
1420
#ifdef ZEND_VERIFY_TYPE_INFERENCE
1421
    if (ssa_op->op1_use >= 0) {
1422
      opline->op1_use_type = ssa->var_info[ssa_op->op1_use].type;
1423
    }
1424
    if (ssa_op->op2_use >= 0) {
1425
      opline->op2_use_type = ssa->var_info[ssa_op->op2_use].type;
1426
    }
1427
    if (ssa_op->result_use >= 0) {
1428
      opline->result_use_type = ssa->var_info[ssa_op->result_use].type;
1429
    }
1430
    if (ssa_op->op1_def >= 0) {
1431
      opline->op1_def_type = ssa->var_info[ssa_op->op1_def].type;
1432
    }
1433
    if (ssa_op->op2_def >= 0) {
1434
      opline->op2_def_type = ssa->var_info[ssa_op->op2_def].type;
1435
    }
1436
    if (ssa_op->result_def >= 0) {
1437
      opline->result_def_type = ssa->var_info[ssa_op->result_def].type;
1438
    }
1439
#endif
1440
0
    zend_vm_set_opcode_handler_ex(opline, op1_info, op2_info, res_info);
1441
0
    opline++;
1442
0
  }
1443
1444
0
  op_array->fn_flags |= ZEND_ACC_DONE_PASS_TWO;
1445
0
}
1446
1447
static void zend_optimize_op_array(zend_op_array      *op_array,
1448
                                   zend_optimizer_ctx *ctx)
1449
0
{
1450
  /* Revert pass_two() */
1451
0
  zend_revert_pass_two(op_array);
1452
1453
  /* Do actual optimizations */
1454
0
  zend_optimize(op_array, ctx);
1455
1456
  /* Redo pass_two() */
1457
0
  zend_redo_pass_two(op_array);
1458
1459
0
  if (op_array->live_range) {
1460
0
    zend_recalc_live_ranges(op_array, NULL);
1461
0
  }
1462
0
}
1463
1464
static void zend_adjust_fcall_stack_size(const zend_op_array *op_array, const zend_optimizer_ctx *ctx)
1465
0
{
1466
0
  zend_function *func;
1467
0
  zend_op *opline;
1468
1469
0
  opline = op_array->opcodes;
1470
0
  const zend_op* end = opline + op_array->last;
1471
0
  while (opline < end) {
1472
0
    if (opline->opcode == ZEND_INIT_FCALL) {
1473
0
      func = zend_hash_find_ptr(
1474
0
        &ctx->script->function_table,
1475
0
        Z_STR_P(RT_CONSTANT(opline, opline->op2)));
1476
0
      if (func) {
1477
0
        opline->op1.num = zend_vm_calc_used_stack(opline->extended_value, func);
1478
0
      }
1479
0
    }
1480
0
    opline++;
1481
0
  }
1482
0
}
1483
1484
static void zend_adjust_fcall_stack_size_graph(const zend_op_array *op_array)
1485
0
{
1486
0
  const zend_func_info *func_info = ZEND_FUNC_INFO(op_array);
1487
1488
0
  if (func_info) {
1489
0
    const zend_call_info *call_info =func_info->callee_info;
1490
1491
0
    while (call_info) {
1492
0
      zend_op *opline = call_info->caller_init_opline;
1493
1494
0
      if (opline && call_info->callee_func && opline->opcode == ZEND_INIT_FCALL) {
1495
0
        ZEND_ASSERT(!call_info->is_prototype);
1496
0
        opline->op1.num = zend_vm_calc_used_stack(opline->extended_value, call_info->callee_func);
1497
0
      }
1498
0
      call_info = call_info->next_callee;
1499
0
    }
1500
0
  }
1501
0
}
1502
1503
0
static bool needs_live_range(const zend_op_array *op_array, const zend_op *def_opline) {
1504
0
  const zend_func_info *func_info = ZEND_FUNC_INFO(op_array);
1505
0
  const zend_ssa_op *ssa_op = &func_info->ssa.ops[def_opline - op_array->opcodes];
1506
0
  int ssa_var = ssa_op->result_def;
1507
0
  if (ssa_var < 0) {
1508
    /* Be conservative. */
1509
0
    return true;
1510
0
  }
1511
1512
  /* If the variable is used by a PHI, this may be the assignment of the final branch of a
1513
   * ternary/etc structure. While this is where the live range starts, the value from the other
1514
   * branch may also be used. As such, use the type of the PHI node for the following check. */
1515
0
  if (func_info->ssa.vars[ssa_var].phi_use_chain) {
1516
0
    ssa_var = func_info->ssa.vars[ssa_var].phi_use_chain->ssa_var;
1517
0
  }
1518
1519
0
  uint32_t type = func_info->ssa.var_info[ssa_var].type;
1520
0
  return (type & (MAY_BE_STRING|MAY_BE_ARRAY|MAY_BE_OBJECT|MAY_BE_RESOURCE|MAY_BE_REF)) != 0;
1521
0
}
1522
1523
static void zend_foreach_op_array_helper(
1524
0
    zend_op_array *op_array, zend_op_array_func_t func, void *context) {
1525
0
  func(op_array, context);
1526
0
  for (uint32_t i = 0; i < op_array->num_dynamic_func_defs; i++) {
1527
0
    zend_foreach_op_array_helper(op_array->dynamic_func_defs[i], func, context);
1528
0
  }
1529
0
}
1530
1531
void zend_foreach_op_array(zend_script *script, zend_op_array_func_t func, void *context)
1532
0
{
1533
0
  zval *zv;
1534
0
  zend_op_array *op_array;
1535
1536
0
  zend_foreach_op_array_helper(&script->main_op_array, func, context);
1537
1538
0
  ZEND_HASH_MAP_FOREACH_PTR(&script->function_table, op_array) {
1539
0
    zend_foreach_op_array_helper(op_array, func, context);
1540
0
  } ZEND_HASH_FOREACH_END();
1541
1542
0
  ZEND_HASH_MAP_FOREACH_VAL(&script->class_table, zv) {
1543
0
    if (Z_TYPE_P(zv) == IS_ALIAS_PTR) {
1544
0
      continue;
1545
0
    }
1546
0
    const zend_class_entry *ce = Z_CE_P(zv);
1547
0
    ZEND_HASH_MAP_FOREACH_PTR(&ce->function_table, op_array) {
1548
0
      if (op_array->scope == ce
1549
0
          && op_array->type == ZEND_USER_FUNCTION
1550
0
          && !(op_array->fn_flags & ZEND_ACC_ABSTRACT)
1551
0
          && !(op_array->fn_flags & ZEND_ACC_TRAIT_CLONE)) {
1552
0
        zend_foreach_op_array_helper(op_array, func, context);
1553
0
      }
1554
0
    } ZEND_HASH_FOREACH_END();
1555
1556
0
    zend_property_info *property;
1557
0
    ZEND_HASH_MAP_FOREACH_PTR(&ce->properties_info, property) {
1558
0
      zend_function **hooks = property->hooks;
1559
0
      if (property->ce == ce && property->hooks) {
1560
0
        for (uint32_t i = 0; i < ZEND_PROPERTY_HOOK_COUNT; i++) {
1561
0
          const zend_function *hook = hooks[i];
1562
0
          if (hook && hook->common.scope == ce && !(hooks[i]->op_array.fn_flags & ZEND_ACC_TRAIT_CLONE)) {
1563
0
            zend_foreach_op_array_helper(&hooks[i]->op_array, func, context);
1564
0
          }
1565
0
        }
1566
0
      }
1567
0
    } ZEND_HASH_FOREACH_END();
1568
0
  } ZEND_HASH_FOREACH_END();
1569
0
}
1570
1571
0
static void step_optimize_op_array(zend_op_array *op_array, void *context) {
1572
0
  zend_optimize_op_array(op_array, (zend_optimizer_ctx *) context);
1573
0
}
1574
1575
0
static void step_adjust_fcall_stack_size(zend_op_array *op_array, void *context) {
1576
0
  zend_adjust_fcall_stack_size(op_array, (zend_optimizer_ctx *) context);
1577
0
}
1578
1579
0
static void step_dump_after_optimizer(zend_op_array *op_array, void *context) {
1580
0
  zend_dump_op_array(op_array, ZEND_DUMP_LIVE_RANGES, "after optimizer", NULL);
1581
0
}
1582
1583
0
static void zend_optimizer_call_registered_passes(zend_script *script, void *ctx) {
1584
0
  for (int i = 0; i < zend_optimizer_registered_passes.last; i++) {
1585
0
    if (!zend_optimizer_registered_passes.pass[i]) {
1586
0
      continue;
1587
0
    }
1588
1589
0
    zend_optimizer_registered_passes.pass[i](script, ctx);
1590
0
  }
1591
0
}
1592
1593
ZEND_API void zend_optimize_script(zend_script *script, zend_long optimization_level, zend_long debug_level)
1594
0
{
1595
0
  zend_op_array *op_array;
1596
0
  zend_string *name;
1597
0
  zend_optimizer_ctx ctx;
1598
0
  zval *zv;
1599
1600
0
  ctx.arena = zend_arena_create(64 * 1024);
1601
0
  ctx.script = script;
1602
0
  ctx.constants = NULL;
1603
0
  ctx.optimization_level = optimization_level;
1604
0
  ctx.debug_level = debug_level;
1605
1606
0
  if ((ZEND_OPTIMIZER_PASS_6 & optimization_level) &&
1607
0
      (ZEND_OPTIMIZER_PASS_7 & optimization_level)) {
1608
    /* Optimize using call-graph */
1609
0
    zend_call_graph call_graph;
1610
0
    zend_build_call_graph(&ctx.arena, script, &call_graph);
1611
1612
0
    uint32_t i;
1613
0
    zend_func_info *func_info;
1614
1615
0
    for (i = 0; i < call_graph.op_arrays_count; i++) {
1616
0
      zend_revert_pass_two(call_graph.op_arrays[i]);
1617
0
      zend_optimize(call_graph.op_arrays[i], &ctx);
1618
0
    }
1619
1620
0
      zend_analyze_call_graph(&ctx.arena, script, &call_graph);
1621
1622
0
    for (i = 0; i < call_graph.op_arrays_count; i++) {
1623
0
      func_info = ZEND_FUNC_INFO(call_graph.op_arrays[i]);
1624
0
      if (func_info) {
1625
0
        func_info->call_map = zend_build_call_map(&ctx.arena, func_info, call_graph.op_arrays[i]);
1626
0
        if (call_graph.op_arrays[i]->fn_flags & ZEND_ACC_HAS_RETURN_TYPE) {
1627
0
          zend_init_func_return_info(call_graph.op_arrays[i], script, &func_info->return_info);
1628
0
        }
1629
0
      }
1630
0
    }
1631
1632
0
    for (i = 0; i < call_graph.op_arrays_count; i++) {
1633
0
      func_info = ZEND_FUNC_INFO(call_graph.op_arrays[i]);
1634
0
      if (func_info) {
1635
0
        if (zend_dfa_analyze_op_array(call_graph.op_arrays[i], &ctx, &func_info->ssa) == SUCCESS) {
1636
0
          func_info->flags = func_info->ssa.cfg.flags;
1637
0
        } else {
1638
0
          ZEND_SET_FUNC_INFO(call_graph.op_arrays[i], NULL);
1639
0
        }
1640
0
      }
1641
0
    }
1642
1643
    //TODO: perform inner-script inference???
1644
0
    for (i = 0; i < call_graph.op_arrays_count; i++) {
1645
0
      func_info = ZEND_FUNC_INFO(call_graph.op_arrays[i]);
1646
0
      if (func_info) {
1647
0
        zend_dfa_optimize_op_array(call_graph.op_arrays[i], &ctx, &func_info->ssa, func_info->call_map);
1648
0
      }
1649
0
    }
1650
1651
0
    if (debug_level & ZEND_DUMP_AFTER_PASS_7) {
1652
0
      for (i = 0; i < call_graph.op_arrays_count; i++) {
1653
0
        zend_dump_op_array(call_graph.op_arrays[i], 0, "after pass 7", NULL);
1654
0
      }
1655
0
    }
1656
1657
0
    if (ZEND_OPTIMIZER_PASS_9 & optimization_level) {
1658
0
      for (i = 0; i < call_graph.op_arrays_count; i++) {
1659
0
        zend_optimize_temporary_variables(call_graph.op_arrays[i], &ctx);
1660
0
        if (debug_level & ZEND_DUMP_AFTER_PASS_9) {
1661
0
          zend_dump_op_array(call_graph.op_arrays[i], 0, "after pass 9", NULL);
1662
0
        }
1663
0
      }
1664
0
    }
1665
1666
0
    if (ZEND_OPTIMIZER_PASS_11 & optimization_level) {
1667
0
      for (i = 0; i < call_graph.op_arrays_count; i++) {
1668
0
        zend_optimizer_compact_literals(call_graph.op_arrays[i], &ctx);
1669
0
        if (debug_level & ZEND_DUMP_AFTER_PASS_11) {
1670
0
          zend_dump_op_array(call_graph.op_arrays[i], 0, "after pass 11", NULL);
1671
0
        }
1672
0
      }
1673
0
    }
1674
1675
0
    if (ZEND_OPTIMIZER_PASS_13 & optimization_level) {
1676
0
      for (i = 0; i < call_graph.op_arrays_count; i++) {
1677
0
        zend_optimizer_compact_vars(call_graph.op_arrays[i]);
1678
0
        if (debug_level & ZEND_DUMP_AFTER_PASS_13) {
1679
0
          zend_dump_op_array(call_graph.op_arrays[i], 0, "after pass 13", NULL);
1680
0
        }
1681
0
      }
1682
0
    }
1683
1684
0
    if (ZEND_OPTIMIZER_PASS_12 & optimization_level) {
1685
0
      for (i = 0; i < call_graph.op_arrays_count; i++) {
1686
0
        zend_adjust_fcall_stack_size_graph(call_graph.op_arrays[i]);
1687
0
      }
1688
0
    }
1689
1690
0
    for (i = 0; i < call_graph.op_arrays_count; i++) {
1691
0
      op_array = call_graph.op_arrays[i];
1692
0
      func_info = ZEND_FUNC_INFO(op_array);
1693
0
      if (func_info && func_info->ssa.var_info) {
1694
0
        zend_redo_pass_two_ex(op_array, &func_info->ssa);
1695
0
        if (op_array->live_range) {
1696
0
          zend_recalc_live_ranges(op_array, needs_live_range);
1697
0
        }
1698
0
      } else {
1699
0
        zend_redo_pass_two(op_array);
1700
0
        if (op_array->live_range) {
1701
0
          zend_recalc_live_ranges(op_array, NULL);
1702
0
        }
1703
0
      }
1704
0
    }
1705
1706
0
    for (i = 0; i < call_graph.op_arrays_count; i++) {
1707
0
      ZEND_SET_FUNC_INFO(call_graph.op_arrays[i], NULL);
1708
0
    }
1709
0
  } else {
1710
0
    zend_foreach_op_array(script, step_optimize_op_array, &ctx);
1711
1712
0
    if (ZEND_OPTIMIZER_PASS_12 & optimization_level) {
1713
0
      zend_foreach_op_array(script, step_adjust_fcall_stack_size, &ctx);
1714
0
    }
1715
0
  }
1716
1717
0
  ZEND_HASH_MAP_FOREACH_VAL(&script->class_table, zv) {
1718
0
    if (Z_TYPE_P(zv) == IS_ALIAS_PTR) {
1719
0
      continue;
1720
0
    }
1721
0
    const zend_class_entry *ce = Z_CE_P(zv);
1722
0
    ZEND_HASH_MAP_FOREACH_STR_KEY_PTR(&ce->function_table, name, op_array) {
1723
0
      if (op_array->scope != ce && op_array->type == ZEND_USER_FUNCTION) {
1724
0
        const zend_op_array *orig_op_array =
1725
0
          zend_hash_find_ptr(&op_array->scope->function_table, name);
1726
1727
0
        ZEND_ASSERT(orig_op_array != NULL);
1728
0
        if (orig_op_array != op_array) {
1729
0
          uint32_t fn_flags = op_array->fn_flags;
1730
0
          uint32_t fn_flags2 = op_array->fn_flags2;
1731
0
          zend_function *prototype = op_array->prototype;
1732
0
          HashTable *ht = op_array->static_variables;
1733
1734
0
          *op_array = *orig_op_array;
1735
0
          op_array->fn_flags = fn_flags;
1736
0
          op_array->fn_flags2 = fn_flags2;
1737
0
          op_array->prototype = prototype;
1738
0
          op_array->static_variables = ht;
1739
0
        }
1740
0
      }
1741
0
    } ZEND_HASH_FOREACH_END();
1742
0
  } ZEND_HASH_FOREACH_END();
1743
1744
0
  zend_optimizer_call_registered_passes(script, &ctx);
1745
1746
0
  if ((debug_level & ZEND_DUMP_AFTER_OPTIMIZER) &&
1747
0
      (ZEND_OPTIMIZER_PASS_7 & optimization_level)) {
1748
0
    zend_foreach_op_array(script, step_dump_after_optimizer, NULL);
1749
0
  }
1750
1751
0
  if (ctx.constants) {
1752
0
    zend_hash_destroy(ctx.constants);
1753
0
  }
1754
0
  zend_arena_destroy(ctx.arena);
1755
0
}
1756
1757
ZEND_API int zend_optimizer_register_pass(zend_optimizer_pass_t pass)
1758
0
{
1759
0
  if (!pass) {
1760
0
    return -1;
1761
0
  }
1762
1763
0
  if (zend_optimizer_registered_passes.last == ZEND_OPTIMIZER_MAX_REGISTERED_PASSES) {
1764
0
    return -1;
1765
0
  }
1766
1767
0
  zend_optimizer_registered_passes.pass[
1768
0
    zend_optimizer_registered_passes.last++] = pass;
1769
1770
0
  return zend_optimizer_registered_passes.last;
1771
0
}
1772
1773
ZEND_API void zend_optimizer_unregister_pass(int idx)
1774
0
{
1775
0
  zend_optimizer_registered_passes.pass[idx-1] = NULL;
1776
0
}
1777
1778
zend_result zend_optimizer_startup(void)
1779
2
{
1780
2
  return zend_func_info_startup();
1781
2
}
1782
1783
zend_result zend_optimizer_shutdown(void)
1784
0
{
1785
0
  return zend_func_info_shutdown();
1786
0
}