Coverage Report

Created: 2026-06-02 06:36

next uncovered line (L), next uncovered region (R), next uncovered branch (B)
/src/php-src/Zend/Optimizer/zend_optimizer.c
Line
Count
Source
1
/*
2
   +----------------------------------------------------------------------+
3
   | Zend OPcache                                                         |
4
   +----------------------------------------------------------------------+
5
   | Copyright © The PHP Group and Contributors.                          |
6
   +----------------------------------------------------------------------+
7
   | This source file is subject to the Modified BSD License that is      |
8
   | bundled with this package in the file LICENSE, and is available      |
9
   | through the World Wide Web at <https://www.php.net/license/>.        |
10
   |                                                                      |
11
   | SPDX-License-Identifier: BSD-3-Clause                                |
12
   +----------------------------------------------------------------------+
13
   | Authors: Andi Gutmans <andi@php.net>                                 |
14
   |          Zeev Suraski <zeev@php.net>                                 |
15
   |          Stanislav Malyshev <stas@zend.com>                          |
16
   |          Dmitry Stogov <dmitry@php.net>                              |
17
   +----------------------------------------------------------------------+
18
*/
19
20
#include "Optimizer/zend_optimizer.h"
21
#include "Optimizer/zend_optimizer_internal.h"
22
#include "zend_API.h"
23
#include "zend_constants.h"
24
#include "zend_execute.h"
25
#include "zend_vm.h"
26
#include "zend_cfg.h"
27
#include "zend_func_info.h"
28
#include "zend_call_graph.h"
29
#include "zend_inference.h"
30
#include "zend_dump.h"
31
#include "php.h"
32
33
#ifndef ZEND_OPTIMIZER_MAX_REGISTERED_PASSES
34
0
# define ZEND_OPTIMIZER_MAX_REGISTERED_PASSES 32
35
#endif
36
37
struct {
38
  zend_optimizer_pass_t pass[ZEND_OPTIMIZER_MAX_REGISTERED_PASSES];
39
  int last;
40
} zend_optimizer_registered_passes = {{NULL}, 0};
41
42
void zend_optimizer_collect_constant(zend_optimizer_ctx *ctx, const zval *name, zval* value)
43
0
{
44
0
  if (!ctx->constants) {
45
0
    ctx->constants = zend_arena_alloc(&ctx->arena, sizeof(HashTable));
46
0
    zend_hash_init(ctx->constants, 16, NULL, zval_ptr_dtor_nogc, 0);
47
0
  }
48
49
0
  if (zend_hash_add(ctx->constants, Z_STR_P(name), value)) {
50
0
    Z_TRY_ADDREF_P(value);
51
0
  }
52
0
}
53
54
zend_result zend_optimizer_eval_binary_op(zval *result, uint8_t opcode, zval *op1, zval *op2) /* {{{ */
55
0
{
56
0
  if (zend_binary_op_produces_error(opcode, op1, op2)) {
57
0
    return FAILURE;
58
0
  }
59
60
0
  binary_op_type binary_op = get_binary_op(opcode);
61
0
  return binary_op(result, op1, op2);
62
0
}
63
/* }}} */
64
65
zend_result zend_optimizer_eval_unary_op(zval *result, uint8_t opcode, zval *op1) /* {{{ */
66
0
{
67
0
  unary_op_type unary_op = get_unary_op(opcode);
68
69
0
  if (unary_op) {
70
0
    if (zend_unary_op_produces_error(opcode, op1)) {
71
0
      return FAILURE;
72
0
    }
73
0
    return unary_op(result, op1);
74
0
  } else { /* ZEND_BOOL */
75
0
    if (Z_TYPE_P(op1) == IS_DOUBLE && zend_isnan(Z_DVAL_P(op1))) {
76
0
      return FAILURE;
77
0
    }
78
0
    ZVAL_BOOL(result, zend_is_true(op1));
79
0
    return SUCCESS;
80
0
  }
81
0
}
82
/* }}} */
83
84
zend_result zend_optimizer_eval_cast(zval *result, uint32_t type, zval *op1) /* {{{ */
85
0
{
86
0
  if (zend_try_ct_eval_cast(result, type, op1)) {
87
0
    return SUCCESS;
88
0
  }
89
0
  return FAILURE;
90
0
}
91
/* }}} */
92
93
zend_result zend_optimizer_eval_strlen(zval *result, const zval *op1) /* {{{ */
94
0
{
95
0
  if (Z_TYPE_P(op1) != IS_STRING) {
96
0
    return FAILURE;
97
0
  }
98
0
  ZVAL_LONG(result, Z_STRLEN_P(op1));
99
0
  return SUCCESS;
100
0
}
101
/* }}} */
102
103
zend_result zend_optimizer_eval_special_func_call(
104
0
    zval *result, const zend_string *name, zend_string *arg) {
105
0
  if (zend_string_equals_literal(name, "function_exists") ||
106
0
      zend_string_equals_literal(name, "is_callable")) {
107
0
    zend_string *lc_name = zend_string_tolower(arg);
108
0
    const zend_internal_function *func = zend_hash_find_ptr(EG(function_table), lc_name);
109
0
    zend_string_release_ex(lc_name, 0);
110
111
0
    if (func && func->type == ZEND_INTERNAL_FUNCTION
112
0
        && func->module->type == MODULE_PERSISTENT
113
#ifdef ZEND_WIN32
114
        && func->module->handle == NULL
115
#endif
116
0
    ) {
117
0
      ZVAL_TRUE(result);
118
0
      return SUCCESS;
119
0
    }
120
0
    return FAILURE;
121
0
  }
122
0
  if (zend_string_equals_literal(name, "extension_loaded")) {
123
0
    zend_string *lc_name = zend_string_tolower(arg);
124
0
    zend_module_entry *m = zend_hash_find_ptr(&module_registry, lc_name);
125
0
    zend_string_release_ex(lc_name, 0);
126
127
0
    if (!m) {
128
0
      if (PG(enable_dl)) {
129
0
        return FAILURE;
130
0
      }
131
0
      ZVAL_FALSE(result);
132
0
      return SUCCESS;
133
0
    }
134
135
0
    if (m->type == MODULE_PERSISTENT
136
#ifdef ZEND_WIN32
137
      && m->handle == NULL
138
#endif
139
0
    ) {
140
0
      ZVAL_TRUE(result);
141
0
      return SUCCESS;
142
0
    }
143
0
    return FAILURE;
144
0
  }
145
0
  if (zend_string_equals_literal(name, "constant")) {
146
0
    return zend_optimizer_get_persistent_constant(arg, result, true) ? SUCCESS : FAILURE;
147
0
  }
148
0
  if (zend_string_equals_literal(name, "dirname")) {
149
0
    if (!IS_ABSOLUTE_PATH(ZSTR_VAL(arg), ZSTR_LEN(arg))) {
150
0
      return FAILURE;
151
0
    }
152
153
0
    zend_string *dirname = zend_string_init(ZSTR_VAL(arg), ZSTR_LEN(arg), 0);
154
0
    ZSTR_LEN(dirname) = zend_dirname(ZSTR_VAL(dirname), ZSTR_LEN(dirname));
155
0
    if (IS_ABSOLUTE_PATH(ZSTR_VAL(dirname), ZSTR_LEN(dirname))) {
156
0
      ZVAL_STR(result, dirname);
157
0
      return SUCCESS;
158
0
    }
159
0
    zend_string_release_ex(dirname, 0);
160
0
    return FAILURE;
161
0
  }
162
0
  if (zend_string_equals_literal(name, "ini_get")) {
163
0
    zend_ini_entry *ini_entry = zend_hash_find_ptr(EG(ini_directives), arg);
164
0
    if (!ini_entry) {
165
0
      if (PG(enable_dl)) {
166
0
        return FAILURE;
167
0
      }
168
0
      ZVAL_FALSE(result);
169
0
    } else if (ini_entry->modifiable != ZEND_INI_SYSTEM) {
170
0
      return FAILURE;
171
0
    } else if (ini_entry->value) {
172
0
      ZVAL_STR_COPY(result, ini_entry->value);
173
0
    } else {
174
0
      ZVAL_EMPTY_STRING(result);
175
0
    }
176
0
    return SUCCESS;
177
0
  }
178
0
  return FAILURE;
179
0
}
180
181
bool zend_optimizer_get_collected_constant(const HashTable *constants, const zval *name, zval* value)
182
0
{
183
0
  zval *val;
184
185
0
  if ((val = zend_hash_find(constants, Z_STR_P(name))) != NULL) {
186
0
    ZVAL_COPY(value, val);
187
0
    return true;
188
0
  }
189
0
  return false;
190
0
}
191
192
void zend_optimizer_convert_to_free_op1(const zend_op_array *op_array, zend_op *opline)
193
0
{
194
0
  if (opline->op1_type == IS_CV) {
195
0
    opline->opcode = ZEND_CHECK_VAR;
196
0
    SET_UNUSED(opline->op2);
197
0
    SET_UNUSED(opline->result);
198
0
    opline->extended_value = 0;
199
0
  } else if (opline->op1_type & (IS_TMP_VAR|IS_VAR)) {
200
0
    opline->opcode = ZEND_FREE;
201
0
    SET_UNUSED(opline->op2);
202
0
    SET_UNUSED(opline->result);
203
0
    opline->extended_value = 0;
204
0
  } else {
205
0
    ZEND_ASSERT(opline->op1_type == IS_CONST);
206
0
    literal_dtor(&ZEND_OP1_LITERAL(opline));
207
0
    MAKE_NOP(opline);
208
0
  }
209
0
}
210
211
uint32_t zend_optimizer_add_literal(zend_op_array *op_array, const zval *zv)
212
0
{
213
0
  uint32_t i = op_array->last_literal;
214
0
  op_array->last_literal++;
215
0
  op_array->literals = (zval*)erealloc(op_array->literals, op_array->last_literal * sizeof(zval));
216
0
  ZVAL_COPY_VALUE(&op_array->literals[i], zv);
217
0
  Z_EXTRA(op_array->literals[i]) = 0;
218
0
  return i;
219
0
}
220
221
0
static inline uint32_t zend_optimizer_add_literal_string(zend_op_array *op_array, zend_string *str) {
222
0
  zval zv;
223
0
  ZVAL_STR(&zv, str);
224
0
  zend_string_hash_val(str);
225
0
  return zend_optimizer_add_literal(op_array, &zv);
226
0
}
227
228
0
static inline void drop_leading_backslash(zval *val) {
229
0
  if (Z_STRVAL_P(val)[0] == '\\') {
230
0
    zend_string *str = zend_string_init(Z_STRVAL_P(val) + 1, Z_STRLEN_P(val) - 1, 0);
231
0
    zval_ptr_dtor_nogc(val);
232
0
    ZVAL_STR(val, str);
233
0
  }
234
0
}
235
236
0
static inline uint32_t alloc_cache_slots(zend_op_array *op_array, uint32_t num) {
237
0
  uint32_t ret = op_array->cache_size;
238
0
  op_array->cache_size += num * sizeof(void *);
239
0
  return ret;
240
0
}
241
242
0
#define REQUIRES_STRING(val) do { \
243
0
  if (Z_TYPE_P(val) != IS_STRING) { \
244
0
    return 0; \
245
0
  } \
246
0
} while (0)
247
248
0
#define TO_STRING_NOWARN(val) do { \
249
0
  if (Z_TYPE_P(val) >= IS_ARRAY) { \
250
0
    return 0; \
251
0
  } \
252
0
  convert_to_string(val); \
253
0
} while (0)
254
255
bool zend_optimizer_update_op1_const(zend_op_array *op_array,
256
                                    zend_op       *opline,
257
                                    zval          *val)
258
0
{
259
0
  switch (opline->opcode) {
260
0
    case ZEND_OP_DATA:
261
0
      switch ((opline-1)->opcode) {
262
0
        case ZEND_ASSIGN_OBJ_REF:
263
0
        case ZEND_ASSIGN_STATIC_PROP_REF:
264
0
          return false;
265
0
      }
266
0
      opline->op1.constant = zend_optimizer_add_literal(op_array, val);
267
0
      break;
268
0
    case ZEND_FREE:
269
0
    case ZEND_CHECK_VAR:
270
0
      MAKE_NOP(opline);
271
0
      zval_ptr_dtor_nogc(val);
272
0
      return true;
273
0
    case ZEND_SEND_VAR_EX:
274
0
    case ZEND_SEND_FUNC_ARG:
275
0
    case ZEND_FETCH_DIM_W:
276
0
    case ZEND_FETCH_DIM_RW:
277
0
    case ZEND_FETCH_DIM_FUNC_ARG:
278
0
    case ZEND_FETCH_DIM_UNSET:
279
0
    case ZEND_FETCH_LIST_W:
280
0
    case ZEND_ASSIGN_DIM:
281
0
    case ZEND_RETURN_BY_REF:
282
0
    case ZEND_INSTANCEOF:
283
0
    case ZEND_MAKE_REF:
284
0
    case ZEND_SEPARATE:
285
0
    case ZEND_SEND_VAR_NO_REF:
286
0
    case ZEND_SEND_VAR_NO_REF_EX:
287
0
      return false;
288
0
    case ZEND_CATCH:
289
0
      REQUIRES_STRING(val);
290
0
      drop_leading_backslash(val);
291
0
      opline->op1.constant = zend_optimizer_add_literal(op_array, val);
292
0
      opline->extended_value = alloc_cache_slots(op_array, 1) | (opline->extended_value & ZEND_LAST_CATCH);
293
0
      zend_optimizer_add_literal_string(op_array, zend_string_tolower(Z_STR_P(val)));
294
0
      break;
295
0
    case ZEND_DEFINED:
296
0
      REQUIRES_STRING(val);
297
0
      drop_leading_backslash(val);
298
0
      opline->op1.constant = zend_optimizer_add_literal(op_array, val);
299
0
      opline->extended_value = alloc_cache_slots(op_array, 1);
300
0
      zend_optimizer_add_literal_string(op_array, zend_string_tolower(Z_STR_P(val)));
301
0
      break;
302
0
    case ZEND_NEW:
303
0
      REQUIRES_STRING(val);
304
0
      drop_leading_backslash(val);
305
0
      opline->op1.constant = zend_optimizer_add_literal(op_array, val);
306
0
      opline->op2.num = alloc_cache_slots(op_array, 1);
307
0
      zend_optimizer_add_literal_string(op_array, zend_string_tolower(Z_STR_P(val)));
308
0
      break;
309
0
    case ZEND_INIT_STATIC_METHOD_CALL:
310
0
      REQUIRES_STRING(val);
311
0
      drop_leading_backslash(val);
312
0
      opline->op1.constant = zend_optimizer_add_literal(op_array, val);
313
0
      if (opline->op2_type != IS_CONST) {
314
0
        opline->result.num = alloc_cache_slots(op_array, 1);
315
0
      }
316
0
      zend_optimizer_add_literal_string(op_array, zend_string_tolower(Z_STR_P(val)));
317
0
      break;
318
0
    case ZEND_FETCH_CLASS_CONSTANT:
319
0
      REQUIRES_STRING(val);
320
0
      drop_leading_backslash(val);
321
0
      opline->op1.constant = zend_optimizer_add_literal(op_array, val);
322
0
      if (opline->op2_type != IS_CONST) {
323
0
        opline->extended_value = alloc_cache_slots(op_array, 1);
324
0
      }
325
0
      zend_optimizer_add_literal_string(op_array, zend_string_tolower(Z_STR_P(val)));
326
0
      break;
327
0
    case ZEND_ASSIGN_OP:
328
0
    case ZEND_ASSIGN_DIM_OP:
329
0
    case ZEND_ASSIGN_OBJ_OP:
330
0
      break;
331
0
    case ZEND_ASSIGN_STATIC_PROP_OP:
332
0
    case ZEND_ASSIGN_STATIC_PROP:
333
0
    case ZEND_ASSIGN_STATIC_PROP_REF:
334
0
    case ZEND_FETCH_STATIC_PROP_R:
335
0
    case ZEND_FETCH_STATIC_PROP_W:
336
0
    case ZEND_FETCH_STATIC_PROP_RW:
337
0
    case ZEND_FETCH_STATIC_PROP_IS:
338
0
    case ZEND_FETCH_STATIC_PROP_UNSET:
339
0
    case ZEND_FETCH_STATIC_PROP_FUNC_ARG:
340
0
    case ZEND_UNSET_STATIC_PROP:
341
0
    case ZEND_ISSET_ISEMPTY_STATIC_PROP:
342
0
    case ZEND_PRE_INC_STATIC_PROP:
343
0
    case ZEND_PRE_DEC_STATIC_PROP:
344
0
    case ZEND_POST_INC_STATIC_PROP:
345
0
    case ZEND_POST_DEC_STATIC_PROP:
346
0
      TO_STRING_NOWARN(val);
347
0
      opline->op1.constant = zend_optimizer_add_literal(op_array, val);
348
0
      if (opline->op2_type == IS_CONST && (opline->extended_value & ~ZEND_FETCH_OBJ_FLAGS) + sizeof(void*) == op_array->cache_size) {
349
0
        op_array->cache_size += sizeof(void *);
350
0
      } else {
351
0
        opline->extended_value = alloc_cache_slots(op_array, 3) | (opline->extended_value & ZEND_FETCH_OBJ_FLAGS);
352
0
      }
353
0
      break;
354
0
    case ZEND_SEND_VAR:
355
0
      opline->opcode = ZEND_SEND_VAL;
356
0
      opline->op1.constant = zend_optimizer_add_literal(op_array, val);
357
0
      break;
358
0
    case ZEND_CASE:
359
0
      opline->opcode = ZEND_IS_EQUAL;
360
0
      opline->op1.constant = zend_optimizer_add_literal(op_array, val);
361
0
      break;
362
0
    case ZEND_CASE_STRICT:
363
0
      opline->opcode = ZEND_IS_IDENTICAL;
364
0
      opline->op1.constant = zend_optimizer_add_literal(op_array, val);
365
0
      break;
366
0
    case ZEND_VERIFY_RETURN_TYPE:
367
      /* This would require a non-local change.
368
       * zend_optimizer_replace_by_const() supports this. */
369
0
      return false;
370
0
    case ZEND_COPY_TMP:
371
0
    case ZEND_FETCH_CLASS_NAME:
372
0
      return false;
373
0
    case ZEND_ECHO:
374
0
    {
375
0
      zval zv;
376
0
      if (Z_TYPE_P(val) != IS_STRING && zend_optimizer_eval_cast(&zv, IS_STRING, val) == SUCCESS) {
377
0
        zval_ptr_dtor_nogc(val);
378
0
        val = &zv;
379
0
      }
380
0
      opline->op1.constant = zend_optimizer_add_literal(op_array, val);
381
0
      if (Z_TYPE_P(val) == IS_STRING && Z_STRLEN_P(val) == 0) {
382
0
        MAKE_NOP(opline);
383
0
        return true;
384
0
      }
385
      /* TODO: In a subsequent pass, *after* this step and compacting nops, combine consecutive ZEND_ECHOs using the block information from ssa->cfg */
386
      /* (e.g. for ext/opcache/tests/opt/sccp_010.phpt) */
387
0
      break;
388
0
    }
389
0
    case ZEND_CONCAT:
390
0
    case ZEND_FAST_CONCAT:
391
0
    case ZEND_FETCH_R:
392
0
    case ZEND_FETCH_W:
393
0
    case ZEND_FETCH_RW:
394
0
    case ZEND_FETCH_IS:
395
0
    case ZEND_FETCH_UNSET:
396
0
    case ZEND_FETCH_FUNC_ARG:
397
0
    case ZEND_ISSET_ISEMPTY_VAR:
398
0
    case ZEND_UNSET_VAR:
399
0
      TO_STRING_NOWARN(val);
400
0
      if (opline->opcode == ZEND_CONCAT && opline->op2_type == IS_CONST) {
401
0
        opline->opcode = ZEND_FAST_CONCAT;
402
0
      }
403
0
      ZEND_FALLTHROUGH;
404
0
    default:
405
0
      opline->op1.constant = zend_optimizer_add_literal(op_array, val);
406
0
      break;
407
0
  }
408
409
0
  opline->op1_type = IS_CONST;
410
0
  if (Z_TYPE(ZEND_OP1_LITERAL(opline)) == IS_STRING) {
411
0
    zend_string_hash_val(Z_STR(ZEND_OP1_LITERAL(opline)));
412
0
  }
413
0
  return true;
414
0
}
415
416
bool zend_optimizer_update_op2_const(zend_op_array *op_array,
417
                                    zend_op       *opline,
418
                                    zval          *val)
419
0
{
420
0
  zval tmp;
421
422
0
  switch (opline->opcode) {
423
0
    case ZEND_ASSIGN_REF:
424
0
    case ZEND_FAST_CALL:
425
0
      return false;
426
0
    case ZEND_FETCH_CLASS:
427
0
    case ZEND_INSTANCEOF:
428
0
      REQUIRES_STRING(val);
429
0
      drop_leading_backslash(val);
430
0
      opline->op2.constant = zend_optimizer_add_literal(op_array, val);
431
0
      zend_optimizer_add_literal_string(op_array, zend_string_tolower(Z_STR_P(val)));
432
0
      opline->extended_value = alloc_cache_slots(op_array, 1);
433
0
      break;
434
0
    case ZEND_INIT_FCALL_BY_NAME:
435
0
      REQUIRES_STRING(val);
436
0
      drop_leading_backslash(val);
437
0
      opline->op2.constant = zend_optimizer_add_literal(op_array, val);
438
0
      zend_optimizer_add_literal_string(op_array, zend_string_tolower(Z_STR_P(val)));
439
0
      opline->result.num = alloc_cache_slots(op_array, 1);
440
0
      break;
441
0
    case ZEND_ASSIGN_STATIC_PROP:
442
0
    case ZEND_ASSIGN_STATIC_PROP_REF:
443
0
    case ZEND_FETCH_STATIC_PROP_R:
444
0
    case ZEND_FETCH_STATIC_PROP_W:
445
0
    case ZEND_FETCH_STATIC_PROP_RW:
446
0
    case ZEND_FETCH_STATIC_PROP_IS:
447
0
    case ZEND_FETCH_STATIC_PROP_UNSET:
448
0
    case ZEND_FETCH_STATIC_PROP_FUNC_ARG:
449
0
    case ZEND_UNSET_STATIC_PROP:
450
0
    case ZEND_ISSET_ISEMPTY_STATIC_PROP:
451
0
    case ZEND_PRE_INC_STATIC_PROP:
452
0
    case ZEND_PRE_DEC_STATIC_PROP:
453
0
    case ZEND_POST_INC_STATIC_PROP:
454
0
    case ZEND_POST_DEC_STATIC_PROP:
455
0
    case ZEND_ASSIGN_STATIC_PROP_OP:
456
0
      REQUIRES_STRING(val);
457
0
      drop_leading_backslash(val);
458
0
      opline->op2.constant = zend_optimizer_add_literal(op_array, val);
459
0
      zend_optimizer_add_literal_string(op_array, zend_string_tolower(Z_STR_P(val)));
460
0
      if (opline->op1_type != IS_CONST) {
461
0
        opline->extended_value = alloc_cache_slots(op_array, 1) | (opline->extended_value & (ZEND_RETURNS_FUNCTION|ZEND_ISEMPTY|ZEND_FETCH_OBJ_FLAGS));
462
0
      }
463
0
      break;
464
0
    case ZEND_INIT_FCALL:
465
0
      REQUIRES_STRING(val);
466
0
      if (Z_REFCOUNT_P(val) == 1) {
467
0
        zend_str_tolower(Z_STRVAL_P(val), Z_STRLEN_P(val));
468
0
      } else {
469
0
        ZVAL_STR(&tmp, zend_string_tolower(Z_STR_P(val)));
470
0
        zval_ptr_dtor_nogc(val);
471
0
        val = &tmp;
472
0
      }
473
0
      opline->op2.constant = zend_optimizer_add_literal(op_array, val);
474
0
      opline->result.num = alloc_cache_slots(op_array, 1);
475
0
      break;
476
0
    case ZEND_INIT_DYNAMIC_CALL:
477
0
      if (Z_TYPE_P(val) == IS_STRING) {
478
0
        if (zend_memrchr(Z_STRVAL_P(val), ':', Z_STRLEN_P(val))) {
479
0
          return false;
480
0
        }
481
482
0
        if (zend_optimizer_classify_function(Z_STR_P(val), opline->extended_value)) {
483
          /* Dynamic call to various special functions must stay dynamic,
484
           * otherwise would drop a warning */
485
0
          return false;
486
0
        }
487
488
0
        opline->opcode = ZEND_INIT_FCALL_BY_NAME;
489
0
        drop_leading_backslash(val);
490
0
        opline->op2.constant = zend_optimizer_add_literal(op_array, val);
491
0
        zend_optimizer_add_literal_string(op_array, zend_string_tolower(Z_STR_P(val)));
492
0
        opline->result.num = alloc_cache_slots(op_array, 1);
493
0
      } else {
494
0
        opline->op2.constant = zend_optimizer_add_literal(op_array, val);
495
0
      }
496
0
      break;
497
0
    case ZEND_INIT_METHOD_CALL:
498
0
      REQUIRES_STRING(val);
499
0
      opline->op2.constant = zend_optimizer_add_literal(op_array, val);
500
0
      zend_optimizer_add_literal_string(op_array, zend_string_tolower(Z_STR_P(val)));
501
0
      opline->result.num = alloc_cache_slots(op_array, 2);
502
0
      break;
503
0
    case ZEND_INIT_STATIC_METHOD_CALL:
504
0
      REQUIRES_STRING(val);
505
0
      opline->op2.constant = zend_optimizer_add_literal(op_array, val);
506
0
      zend_optimizer_add_literal_string(op_array, zend_string_tolower(Z_STR_P(val)));
507
0
      if (opline->op1_type != IS_CONST) {
508
0
        opline->result.num = alloc_cache_slots(op_array, 2);
509
0
      }
510
0
      break;
511
0
    case ZEND_ASSIGN_OBJ:
512
0
    case ZEND_ASSIGN_OBJ_REF:
513
0
    case ZEND_FETCH_OBJ_R:
514
0
    case ZEND_FETCH_OBJ_W:
515
0
    case ZEND_FETCH_OBJ_RW:
516
0
    case ZEND_FETCH_OBJ_IS:
517
0
    case ZEND_FETCH_OBJ_UNSET:
518
0
    case ZEND_FETCH_OBJ_FUNC_ARG:
519
0
    case ZEND_UNSET_OBJ:
520
0
    case ZEND_PRE_INC_OBJ:
521
0
    case ZEND_PRE_DEC_OBJ:
522
0
    case ZEND_POST_INC_OBJ:
523
0
    case ZEND_POST_DEC_OBJ:
524
0
      TO_STRING_NOWARN(val);
525
0
      opline->op2.constant = zend_optimizer_add_literal(op_array, val);
526
0
      opline->extended_value = alloc_cache_slots(op_array, 3);
527
0
      break;
528
0
    case ZEND_ASSIGN_OBJ_OP:
529
0
      TO_STRING_NOWARN(val);
530
0
      opline->op2.constant = zend_optimizer_add_literal(op_array, val);
531
0
      ZEND_ASSERT((opline + 1)->opcode == ZEND_OP_DATA);
532
0
      (opline + 1)->extended_value = alloc_cache_slots(op_array, 3);
533
0
      break;
534
0
    case ZEND_ISSET_ISEMPTY_PROP_OBJ:
535
0
      TO_STRING_NOWARN(val);
536
0
      opline->op2.constant = zend_optimizer_add_literal(op_array, val);
537
0
      opline->extended_value = alloc_cache_slots(op_array, 3) | (opline->extended_value & ZEND_ISEMPTY);
538
0
      break;
539
0
    case ZEND_ASSIGN_DIM_OP:
540
0
    case ZEND_ISSET_ISEMPTY_DIM_OBJ:
541
0
    case ZEND_ASSIGN_DIM:
542
0
    case ZEND_UNSET_DIM:
543
0
    case ZEND_FETCH_DIM_R:
544
0
    case ZEND_FETCH_DIM_W:
545
0
    case ZEND_FETCH_DIM_RW:
546
0
    case ZEND_FETCH_DIM_IS:
547
0
    case ZEND_FETCH_DIM_FUNC_ARG:
548
0
    case ZEND_FETCH_DIM_UNSET:
549
0
    case ZEND_FETCH_LIST_R:
550
0
    case ZEND_FETCH_LIST_W:
551
0
      if (Z_TYPE_P(val) == IS_STRING) {
552
0
        zend_ulong index;
553
554
0
        if (ZEND_HANDLE_NUMERIC(Z_STR_P(val), index)) {
555
0
          ZVAL_LONG(&tmp, index);
556
0
          opline->op2.constant = zend_optimizer_add_literal(op_array, &tmp);
557
0
          zend_string_hash_val(Z_STR_P(val));
558
0
          zend_optimizer_add_literal(op_array, val);
559
0
          Z_EXTRA(op_array->literals[opline->op2.constant]) = ZEND_EXTRA_VALUE;
560
0
          break;
561
0
        }
562
0
      }
563
0
      opline->op2.constant = zend_optimizer_add_literal(op_array, val);
564
0
      break;
565
0
    case ZEND_ADD_ARRAY_ELEMENT:
566
0
    case ZEND_INIT_ARRAY:
567
0
      if (Z_TYPE_P(val) == IS_STRING) {
568
0
        zend_ulong index;
569
0
        if (ZEND_HANDLE_NUMERIC(Z_STR_P(val), index)) {
570
0
          zval_ptr_dtor_nogc(val);
571
0
          ZVAL_LONG(val, index);
572
0
        }
573
0
      }
574
0
      opline->op2.constant = zend_optimizer_add_literal(op_array, val);
575
0
      break;
576
0
    case ZEND_ROPE_INIT:
577
0
    case ZEND_ROPE_ADD:
578
0
    case ZEND_ROPE_END:
579
0
    case ZEND_CONCAT:
580
0
    case ZEND_FAST_CONCAT:
581
0
      TO_STRING_NOWARN(val);
582
0
      if (opline->opcode == ZEND_CONCAT && opline->op1_type == IS_CONST) {
583
0
        opline->opcode = ZEND_FAST_CONCAT;
584
0
      }
585
0
      ZEND_FALLTHROUGH;
586
0
    default:
587
0
      opline->op2.constant = zend_optimizer_add_literal(op_array, val);
588
0
      break;
589
0
  }
590
591
0
  opline->op2_type = IS_CONST;
592
0
  if (Z_TYPE(ZEND_OP2_LITERAL(opline)) == IS_STRING) {
593
0
    zend_string_hash_val(Z_STR(ZEND_OP2_LITERAL(opline)));
594
0
  }
595
0
  return true;
596
0
}
597
598
bool zend_optimizer_replace_by_const(zend_op_array *op_array,
599
                                    zend_op       *opline,
600
                                    uint8_t        type,
601
                                    uint32_t       var,
602
                                    zval          *val)
603
0
{
604
0
  const zend_op *end = op_array->opcodes + op_array->last;
605
606
0
  while (opline < end) {
607
0
    if (opline->op1_type == type &&
608
0
      opline->op1.var == var) {
609
0
      switch (opline->opcode) {
610
        /* In most cases IS_TMP_VAR operand may be used only once.
611
         * The operands are usually destroyed by the opcode handler.
612
         * However, there are some exception which keep the operand alive. In that case
613
         * we want to try to replace all uses of the temporary.
614
         */
615
0
        case ZEND_FETCH_LIST_R:
616
0
        case ZEND_CASE:
617
0
        case ZEND_CASE_STRICT:
618
0
        case ZEND_SWITCH_LONG:
619
0
        case ZEND_SWITCH_STRING:
620
0
        case ZEND_MATCH:
621
0
        case ZEND_MATCH_ERROR:
622
0
        case ZEND_JMP_NULL: {
623
0
          const zend_op *end = op_array->opcodes + op_array->last;
624
0
          while (opline < end) {
625
0
            if (opline->op1_type == type && opline->op1.var == var) {
626
              /* If this opcode doesn't keep the operand alive, we're done. Check
627
               * this early, because op replacement may modify the opline. */
628
0
              bool is_last = opline->opcode != ZEND_FETCH_LIST_R
629
0
                && opline->opcode != ZEND_CASE
630
0
                && opline->opcode != ZEND_CASE_STRICT
631
0
                && opline->opcode != ZEND_SWITCH_LONG
632
0
                && opline->opcode != ZEND_SWITCH_STRING
633
0
                && opline->opcode != ZEND_MATCH
634
0
                && opline->opcode != ZEND_MATCH_ERROR
635
0
                && opline->opcode != ZEND_JMP_NULL
636
0
                && (opline->opcode != ZEND_FREE
637
0
                  || opline->extended_value != ZEND_FREE_ON_RETURN);
638
639
0
              Z_TRY_ADDREF_P(val);
640
0
              if (!zend_optimizer_update_op1_const(op_array, opline, val)) {
641
0
                zval_ptr_dtor(val);
642
0
                return false;
643
0
              }
644
0
              if (is_last) {
645
0
                break;
646
0
              }
647
0
            }
648
0
            opline++;
649
0
          }
650
0
          zval_ptr_dtor_nogc(val);
651
0
          return true;
652
0
        }
653
0
        case ZEND_VERIFY_RETURN_TYPE: {
654
0
          const zend_arg_info *ret_info = op_array->arg_info - 1;
655
0
          if (!ZEND_TYPE_CONTAINS_CODE(ret_info->type, Z_TYPE_P(val))
656
0
            || (op_array->fn_flags & ZEND_ACC_RETURN_REFERENCE)) {
657
0
            return false;
658
0
          }
659
0
          MAKE_NOP(opline);
660
661
          /* zend_handle_loops_and_finally may inserts other oplines */
662
0
          do {
663
0
            ++opline;
664
0
          } while (opline->opcode != ZEND_RETURN && opline->opcode != ZEND_RETURN_BY_REF);
665
0
          ZEND_ASSERT(opline->op1.var == var);
666
667
0
          break;
668
0
        }
669
0
        default:
670
0
          break;
671
0
      }
672
0
      return zend_optimizer_update_op1_const(op_array, opline, val);
673
0
    }
674
675
0
    if (opline->op2_type == type &&
676
0
      opline->op2.var == var) {
677
0
      return zend_optimizer_update_op2_const(op_array, opline, val);
678
0
    }
679
0
    opline++;
680
0
  }
681
682
0
  return true;
683
0
}
684
685
/* Update jump offsets after a jump was migrated to another opline */
686
0
void zend_optimizer_migrate_jump(const zend_op_array *op_array, zend_op *new_opline, zend_op *opline) {
687
0
  switch (new_opline->opcode) {
688
0
    case ZEND_JMP:
689
0
    case ZEND_FAST_CALL:
690
0
      ZEND_SET_OP_JMP_ADDR(new_opline, new_opline->op1, ZEND_OP1_JMP_ADDR(opline));
691
0
      break;
692
0
    case ZEND_JMPZ:
693
0
    case ZEND_JMPNZ:
694
0
    case ZEND_JMPZ_EX:
695
0
    case ZEND_JMPNZ_EX:
696
0
    case ZEND_FE_RESET_R:
697
0
    case ZEND_FE_RESET_RW:
698
0
    case ZEND_JMP_SET:
699
0
    case ZEND_COALESCE:
700
0
    case ZEND_ASSERT_CHECK:
701
0
    case ZEND_JMP_NULL:
702
0
    case ZEND_BIND_INIT_STATIC_OR_JMP:
703
0
    case ZEND_JMP_FRAMELESS:
704
0
      ZEND_SET_OP_JMP_ADDR(new_opline, new_opline->op2, ZEND_OP2_JMP_ADDR(opline));
705
0
      break;
706
0
    case ZEND_FE_FETCH_R:
707
0
    case ZEND_FE_FETCH_RW:
708
0
      new_opline->extended_value = ZEND_OPLINE_NUM_TO_OFFSET(op_array, new_opline, ZEND_OFFSET_TO_OPLINE_NUM(op_array, opline, opline->extended_value));
709
0
      break;
710
0
    case ZEND_CATCH:
711
0
      if (!(opline->extended_value & ZEND_LAST_CATCH)) {
712
0
        ZEND_SET_OP_JMP_ADDR(new_opline, new_opline->op2, ZEND_OP2_JMP_ADDR(opline));
713
0
      }
714
0
      break;
715
0
    case ZEND_SWITCH_LONG:
716
0
    case ZEND_SWITCH_STRING:
717
0
    case ZEND_MATCH:
718
0
    {
719
0
      const HashTable *jumptable = Z_ARRVAL(ZEND_OP2_LITERAL(opline));
720
0
      zval *zv;
721
0
      ZEND_HASH_FOREACH_VAL(jumptable, zv) {
722
0
        Z_LVAL_P(zv) = ZEND_OPLINE_NUM_TO_OFFSET(op_array, new_opline, ZEND_OFFSET_TO_OPLINE_NUM(op_array, opline, Z_LVAL_P(zv)));
723
0
      } ZEND_HASH_FOREACH_END();
724
0
      new_opline->extended_value = ZEND_OPLINE_NUM_TO_OFFSET(op_array, new_opline, ZEND_OFFSET_TO_OPLINE_NUM(op_array, opline, opline->extended_value));
725
0
      break;
726
0
    }
727
0
  }
728
0
}
729
730
/* Shift jump offsets based on shiftlist */
731
0
void zend_optimizer_shift_jump(const zend_op_array *op_array, zend_op *opline, const uint32_t *shiftlist) {
732
0
  switch (opline->opcode) {
733
0
    case ZEND_JMP:
734
0
    case ZEND_FAST_CALL:
735
0
      ZEND_SET_OP_JMP_ADDR(opline, opline->op1, ZEND_OP1_JMP_ADDR(opline) - shiftlist[ZEND_OP1_JMP_ADDR(opline) - op_array->opcodes]);
736
0
      break;
737
0
    case ZEND_JMPZ:
738
0
    case ZEND_JMPNZ:
739
0
    case ZEND_JMPZ_EX:
740
0
    case ZEND_JMPNZ_EX:
741
0
    case ZEND_FE_RESET_R:
742
0
    case ZEND_FE_RESET_RW:
743
0
    case ZEND_JMP_SET:
744
0
    case ZEND_COALESCE:
745
0
    case ZEND_ASSERT_CHECK:
746
0
    case ZEND_JMP_NULL:
747
0
    case ZEND_BIND_INIT_STATIC_OR_JMP:
748
0
    case ZEND_JMP_FRAMELESS:
749
0
      ZEND_SET_OP_JMP_ADDR(opline, opline->op2, ZEND_OP2_JMP_ADDR(opline) - shiftlist[ZEND_OP2_JMP_ADDR(opline) - op_array->opcodes]);
750
0
      break;
751
0
    case ZEND_CATCH:
752
0
      if (!(opline->extended_value & ZEND_LAST_CATCH)) {
753
0
        ZEND_SET_OP_JMP_ADDR(opline, opline->op2, ZEND_OP2_JMP_ADDR(opline) - shiftlist[ZEND_OP2_JMP_ADDR(opline) - op_array->opcodes]);
754
0
      }
755
0
      break;
756
0
    case ZEND_FE_FETCH_R:
757
0
    case ZEND_FE_FETCH_RW:
758
0
      opline->extended_value = ZEND_OPLINE_NUM_TO_OFFSET(op_array, opline, ZEND_OFFSET_TO_OPLINE_NUM(op_array, opline, opline->extended_value) - shiftlist[ZEND_OFFSET_TO_OPLINE_NUM(op_array, opline, opline->extended_value)]);
759
0
      break;
760
0
    case ZEND_SWITCH_LONG:
761
0
    case ZEND_SWITCH_STRING:
762
0
    case ZEND_MATCH:
763
0
    {
764
0
      const HashTable *jumptable = Z_ARRVAL(ZEND_OP2_LITERAL(opline));
765
0
      zval *zv;
766
0
      ZEND_HASH_FOREACH_VAL(jumptable, zv) {
767
0
        Z_LVAL_P(zv) = ZEND_OPLINE_NUM_TO_OFFSET(op_array, opline, ZEND_OFFSET_TO_OPLINE_NUM(op_array, opline, Z_LVAL_P(zv)) - shiftlist[ZEND_OFFSET_TO_OPLINE_NUM(op_array, opline, Z_LVAL_P(zv))]);
768
0
      } ZEND_HASH_FOREACH_END();
769
0
      opline->extended_value = ZEND_OPLINE_NUM_TO_OFFSET(op_array, opline, ZEND_OFFSET_TO_OPLINE_NUM(op_array, opline, opline->extended_value) - shiftlist[ZEND_OFFSET_TO_OPLINE_NUM(op_array, opline, opline->extended_value)]);
770
0
      break;
771
0
    }
772
0
  }
773
0
}
774
775
static bool zend_optimizer_ignore_class(zval *ce_zv, const zend_string *filename)
776
0
{
777
0
  const zend_class_entry *ce = Z_PTR_P(ce_zv);
778
779
0
  if (ce->ce_flags & ZEND_ACC_PRELOADED) {
780
0
    if (CG(compiler_options) & ZEND_COMPILE_WITH_FILE_CACHE) {
781
0
      return true;
782
0
    }
783
0
    const Bucket *ce_bucket = ZEND_CONTAINER_OF(ce_zv, Bucket, val);
784
0
    size_t offset = ce_bucket - EG(class_table)->arData;
785
0
    if (offset < EG(persistent_classes_count)) {
786
0
      return false;
787
0
    }
788
0
  }
789
0
  return ce->type == ZEND_USER_CLASS
790
0
    && (!ce->info.user.filename || ce->info.user.filename != filename);
791
0
}
792
793
static bool zend_optimizer_ignore_function(zval *fbc_zv, const zend_string *filename)
794
0
{
795
0
  const zend_function *fbc = Z_PTR_P(fbc_zv);
796
797
0
  if (fbc->type == ZEND_INTERNAL_FUNCTION) {
798
0
    return false;
799
0
  } else if (fbc->type == ZEND_USER_FUNCTION) {
800
0
    if (fbc->op_array.fn_flags & ZEND_ACC_PRELOADED) {
801
0
      if (CG(compiler_options) & ZEND_COMPILE_WITH_FILE_CACHE) {
802
0
        return true;
803
0
      }
804
0
      const Bucket *fbc_bucket = ZEND_CONTAINER_OF(fbc_zv, Bucket, val);
805
0
      size_t offset = fbc_bucket - EG(function_table)->arData;
806
0
      if (offset < EG(persistent_functions_count)) {
807
0
        return false;
808
0
      }
809
0
    }
810
0
    return !fbc->op_array.filename || fbc->op_array.filename != filename;
811
0
  } else {
812
0
    ZEND_ASSERT(fbc->type == ZEND_EVAL_CODE);
813
0
    return true;
814
0
  }
815
0
}
816
817
zend_class_entry *zend_optimizer_get_class_entry(
818
0
    const zend_script *script, const zend_op_array *op_array, zend_string *lcname) {
819
0
  zend_class_entry *ce = script ? zend_hash_find_ptr(&script->class_table, lcname) : NULL;
820
0
  if (ce) {
821
0
    return ce;
822
0
  }
823
824
0
  zval *ce_zv = zend_hash_find(CG(class_table), lcname);
825
0
  if (ce_zv && !zend_optimizer_ignore_class(ce_zv, op_array ? op_array->filename : NULL)) {
826
0
    return Z_PTR_P(ce_zv);
827
0
  }
828
829
0
  if (op_array && op_array->scope && zend_string_equals_ci(op_array->scope->name, lcname)) {
830
0
    return op_array->scope;
831
0
  }
832
833
0
  return NULL;
834
0
}
835
836
zend_class_entry *zend_optimizer_get_class_entry_from_op1(
837
0
    const zend_script *script, const zend_op_array *op_array, const zend_op *opline) {
838
0
  if (opline->op1_type == IS_CONST) {
839
0
    const zval *op1 = CRT_CONSTANT(opline->op1);
840
0
    if (Z_TYPE_P(op1) == IS_STRING) {
841
0
      return zend_optimizer_get_class_entry(script, op_array, Z_STR_P(op1 + 1));
842
0
    }
843
0
  } else if (opline->op1_type == IS_UNUSED && op_array->scope
844
0
      && !(op_array->scope->ce_flags & ZEND_ACC_TRAIT)
845
0
      && ((opline->op1.num & ZEND_FETCH_CLASS_MASK) == ZEND_FETCH_CLASS_SELF
846
0
        || ((opline->op1.num & ZEND_FETCH_CLASS_MASK) == ZEND_FETCH_CLASS_STATIC
847
0
          && (op_array->scope->ce_flags & ZEND_ACC_FINAL)))) {
848
0
    return op_array->scope;
849
0
  }
850
0
  return NULL;
851
0
}
852
853
const zend_class_constant *zend_fetch_class_const_info(
854
0
  const zend_script *script, const zend_op_array *op_array, const zend_op *opline, bool *is_prototype) {
855
0
  const zend_class_entry *ce = NULL;
856
0
  bool is_static_reference = false;
857
858
0
  if (!opline || !op_array || opline->op2_type != IS_CONST || Z_TYPE_P(CRT_CONSTANT(opline->op2)) != IS_STRING) {
859
0
    return NULL;
860
0
  }
861
0
  if (opline->op1_type == IS_CONST) {
862
0
    const zval *op1 = CRT_CONSTANT(opline->op1);
863
0
    if (Z_TYPE_P(op1) == IS_STRING) {
864
0
      if (script) {
865
0
        ce = zend_optimizer_get_class_entry(script, op_array, Z_STR_P(op1 + 1));
866
0
      } else {
867
0
        zval *ce_zv = zend_hash_find(EG(class_table), Z_STR_P(op1 + 1));
868
0
        if (ce_zv && !zend_optimizer_ignore_class(ce_zv, op_array->filename)) {
869
0
          ce = Z_PTR_P(ce_zv);
870
0
        }
871
0
      }
872
0
    }
873
0
  } else if (opline->op1_type == IS_UNUSED
874
0
    && op_array->scope && !(op_array->scope->ce_flags & ZEND_ACC_TRAIT)
875
0
    && !(op_array->fn_flags & ZEND_ACC_TRAIT_CLONE)) {
876
0
    uint32_t fetch_type = opline->op1.num & ZEND_FETCH_CLASS_MASK;
877
0
    if (fetch_type == ZEND_FETCH_CLASS_SELF) {
878
0
      ce = op_array->scope;
879
0
    } else if (fetch_type == ZEND_FETCH_CLASS_STATIC) {
880
0
      ce = op_array->scope;
881
0
      is_static_reference = true;
882
0
    } else if (fetch_type == ZEND_FETCH_CLASS_PARENT) {
883
0
      if (op_array->scope->ce_flags & ZEND_ACC_LINKED) {
884
0
        ce = op_array->scope->parent;
885
0
      }
886
0
    }
887
0
  }
888
0
  if (!ce || (ce->ce_flags & ZEND_ACC_TRAIT)) {
889
0
    return NULL;
890
0
  }
891
0
  zend_class_constant *const_info = zend_hash_find_ptr(&ce->constants_table, Z_STR_P(CRT_CONSTANT(opline->op2)));
892
0
  if (!const_info) {
893
0
    return NULL;
894
0
  }
895
0
  if ((ZEND_CLASS_CONST_FLAGS(const_info) & ZEND_ACC_DEPRECATED)
896
0
    || ((ZEND_CLASS_CONST_FLAGS(const_info) & ZEND_ACC_PPP_MASK) != ZEND_ACC_PUBLIC && const_info->ce != op_array->scope)) {
897
0
    return NULL;
898
0
  }
899
0
  *is_prototype = is_static_reference
900
0
    && !(const_info->ce->ce_flags & ZEND_ACC_FINAL) && !(ZEND_CLASS_CONST_FLAGS(const_info) & ZEND_ACC_FINAL);
901
902
0
  return const_info;
903
0
}
904
905
zend_function *zend_optimizer_get_called_func(
906
    const zend_script *script, const zend_op_array *op_array, zend_op *opline, bool *is_prototype)
907
0
{
908
0
  *is_prototype = false;
909
0
  switch (opline->opcode) {
910
0
    case ZEND_INIT_FCALL:
911
0
    {
912
0
      zend_string *function_name = Z_STR_P(CRT_CONSTANT(opline->op2));
913
0
      zend_function *func;
914
0
      zval *func_zv;
915
0
      if (script && (func = zend_hash_find_ptr(&script->function_table, function_name)) != NULL) {
916
0
        return func;
917
0
      } else if ((func_zv = zend_hash_find(EG(function_table), function_name)) != NULL) {
918
0
        if (!zend_optimizer_ignore_function(func_zv, op_array->filename)) {
919
0
          return Z_PTR_P(func_zv);
920
0
        }
921
0
      }
922
0
      break;
923
0
    }
924
0
    case ZEND_INIT_FCALL_BY_NAME:
925
0
    case ZEND_INIT_NS_FCALL_BY_NAME:
926
0
      if (opline->op2_type == IS_CONST && Z_TYPE_P(CRT_CONSTANT(opline->op2)) == IS_STRING) {
927
0
        const zval *function_name = CRT_CONSTANT(opline->op2) + 1;
928
0
        zend_function *func;
929
0
        zval *func_zv;
930
0
        if (script && (func = zend_hash_find_ptr(&script->function_table, Z_STR_P(function_name)))) {
931
0
          return func;
932
0
        } else if ((func_zv = zend_hash_find(EG(function_table), Z_STR_P(function_name))) != NULL) {
933
0
          if (!zend_optimizer_ignore_function(func_zv, op_array->filename)) {
934
0
            return Z_PTR_P(func_zv);
935
0
          }
936
0
        }
937
0
      }
938
0
      break;
939
0
    case ZEND_INIT_STATIC_METHOD_CALL:
940
0
      if (opline->op2_type == IS_CONST && Z_TYPE_P(CRT_CONSTANT(opline->op2)) == IS_STRING) {
941
0
        const zend_class_entry *ce = zend_optimizer_get_class_entry_from_op1(
942
0
          script, op_array, opline);
943
0
        if (ce) {
944
0
          zend_string *func_name = Z_STR_P(CRT_CONSTANT(opline->op2) + 1);
945
0
          zend_function *fbc = zend_hash_find_ptr(&ce->function_table, func_name);
946
0
          if (fbc && !(fbc->common.fn_flags & ZEND_ACC_ABSTRACT)) {
947
0
            bool is_public = (fbc->common.fn_flags & ZEND_ACC_PUBLIC) != 0;
948
0
            bool same_scope = fbc->common.scope == op_array->scope;
949
0
            if (is_public || same_scope) {
950
0
              return fbc;
951
0
            }
952
0
          }
953
0
        }
954
0
      }
955
0
      break;
956
0
    case ZEND_INIT_METHOD_CALL:
957
0
      if (opline->op1_type == IS_UNUSED
958
0
          && opline->op2_type == IS_CONST && Z_TYPE_P(CRT_CONSTANT(opline->op2)) == IS_STRING
959
0
          && op_array->scope
960
0
          && !(op_array->fn_flags & ZEND_ACC_TRAIT_CLONE)
961
0
          && !(op_array->scope->ce_flags & ZEND_ACC_TRAIT)) {
962
0
        zend_string *method_name = Z_STR_P(CRT_CONSTANT(opline->op2) + 1);
963
0
        zend_function *fbc = zend_hash_find_ptr(
964
0
          &op_array->scope->function_table, method_name);
965
0
        if (fbc) {
966
0
          bool is_private = (fbc->common.fn_flags & ZEND_ACC_PRIVATE) != 0;
967
0
          if (is_private) {
968
            /* Only use private method if in the same scope. We can't even use it
969
             * as a prototype, as it may be overridden with changed signature. */
970
0
            bool same_scope = fbc->common.scope == op_array->scope;
971
0
            return same_scope ? fbc : NULL;
972
0
          }
973
          /* Prototype methods are potentially overridden. fbc still contains useful type information.
974
           * Some optimizations may not be applied, like inlining or inferring the send-mode of superfluous args.
975
           * A method cannot be overridden if the class or method is final. */
976
0
          if ((fbc->common.fn_flags & ZEND_ACC_FINAL) == 0 &&
977
0
            (fbc->common.scope->ce_flags & ZEND_ACC_FINAL) == 0) {
978
0
            *is_prototype = true;
979
0
          }
980
0
          return fbc;
981
0
        }
982
0
      }
983
0
      break;
984
0
    case ZEND_INIT_PARENT_PROPERTY_HOOK_CALL: {
985
0
      const zend_class_entry *scope = op_array->scope;
986
0
      ZEND_ASSERT(scope != NULL);
987
0
      if ((scope->ce_flags & ZEND_ACC_LINKED) && scope->parent) {
988
0
        const zend_class_entry *parent_scope = scope->parent;
989
0
        zend_string *prop_name = Z_STR_P(CRT_CONSTANT(opline->op1));
990
0
        zend_property_hook_kind hook_kind = opline->op2.num;
991
0
        const zend_property_info *prop_info = zend_get_property_info(parent_scope, prop_name, /* silent */ true);
992
993
0
        if (prop_info
994
0
          && prop_info != ZEND_WRONG_PROPERTY_INFO
995
0
          && !(prop_info->flags & ZEND_ACC_PRIVATE)
996
0
          && prop_info->hooks) {
997
0
          zend_function *fbc = prop_info->hooks[hook_kind];
998
0
          if (fbc) {
999
0
            *is_prototype = false;
1000
0
            return fbc;
1001
0
          }
1002
0
        }
1003
0
      }
1004
0
      break;
1005
0
    }
1006
0
    case ZEND_NEW:
1007
0
    {
1008
0
      const zend_class_entry *ce = zend_optimizer_get_class_entry_from_op1(
1009
0
        script, op_array, opline);
1010
0
      if (ce && ce->type == ZEND_USER_CLASS) {
1011
0
        return ce->constructor;
1012
0
      }
1013
0
      break;
1014
0
    }
1015
0
  }
1016
0
  return NULL;
1017
0
}
1018
1019
0
uint32_t zend_optimizer_classify_function(const zend_string *name, uint32_t num_args) {
1020
0
  if (zend_string_equals_literal(name, "extract")) {
1021
0
    return ZEND_FUNC_INDIRECT_VAR_ACCESS;
1022
0
  } else if (zend_string_equals_literal(name, "compact")) {
1023
0
    return ZEND_FUNC_INDIRECT_VAR_ACCESS;
1024
0
  } else if (zend_string_equals_literal(name, "get_defined_vars")) {
1025
0
    return ZEND_FUNC_INDIRECT_VAR_ACCESS;
1026
0
  } else if (zend_string_equals_literal(name, "db2_execute")) {
1027
0
    return ZEND_FUNC_INDIRECT_VAR_ACCESS;
1028
0
  } else if (zend_string_equals_literal(name, "func_num_args")) {
1029
0
    return ZEND_FUNC_VARARG;
1030
0
  } else if (zend_string_equals_literal(name, "func_get_arg")) {
1031
0
    return ZEND_FUNC_VARARG;
1032
0
  } else if (zend_string_equals_literal(name, "func_get_args")) {
1033
0
    return ZEND_FUNC_VARARG;
1034
0
  } else {
1035
0
    return 0;
1036
0
  }
1037
0
}
1038
1039
0
zend_op *zend_optimizer_get_loop_var_def(const zend_op_array *op_array, zend_op *free_opline) {
1040
0
  uint32_t var = free_opline->op1.var;
1041
0
  ZEND_ASSERT(zend_optimizer_is_loop_var_free(free_opline));
1042
1043
0
  while (--free_opline >= op_array->opcodes) {
1044
0
    if ((free_opline->result_type & (IS_TMP_VAR|IS_VAR)) && free_opline->result.var == var) {
1045
0
      return free_opline;
1046
0
    }
1047
0
  }
1048
0
  return NULL;
1049
0
}
1050
1051
static void zend_optimize(zend_op_array      *op_array,
1052
                          zend_optimizer_ctx *ctx)
1053
0
{
1054
0
  if (op_array->type == ZEND_EVAL_CODE) {
1055
0
    return;
1056
0
  }
1057
1058
0
  if (ctx->debug_level & ZEND_DUMP_BEFORE_OPTIMIZER) {
1059
0
    zend_dump_op_array(op_array, ZEND_DUMP_LIVE_RANGES, "before optimizer", NULL);
1060
0
  }
1061
1062
  /* pass 1 (Simple local optimizations)
1063
   * - persistent constant substitution (true, false, null, etc)
1064
   * - constant casting (ADD expects numbers, CONCAT strings, etc)
1065
   * - constant expression evaluation
1066
   * - optimize constant conditional JMPs
1067
   * - pre-evaluate constant function calls
1068
   * - eliminate FETCH $GLOBALS followed by FETCH_DIM/UNSET_DIM/ISSET_ISEMPTY_DIM
1069
   */
1070
0
  if (ZEND_OPTIMIZER_PASS_1 & ctx->optimization_level) {
1071
0
    zend_optimizer_pass1(op_array, ctx);
1072
0
    if (ctx->debug_level & ZEND_DUMP_AFTER_PASS_1) {
1073
0
      zend_dump_op_array(op_array, 0, "after pass 1", NULL);
1074
0
    }
1075
0
  }
1076
1077
  /* pass 3: (Jump optimization)
1078
   * - optimize series of JMPs
1079
   */
1080
0
  if (ZEND_OPTIMIZER_PASS_3 & ctx->optimization_level) {
1081
0
    zend_optimizer_pass3(op_array, ctx);
1082
0
    if (ctx->debug_level & ZEND_DUMP_AFTER_PASS_3) {
1083
0
      zend_dump_op_array(op_array, 0, "after pass 3", NULL);
1084
0
    }
1085
0
  }
1086
1087
  /* pass 4:
1088
   * - INIT_FCALL_BY_NAME -> DO_FCALL
1089
   */
1090
0
  if (ZEND_OPTIMIZER_PASS_4 & ctx->optimization_level) {
1091
0
    zend_optimize_func_calls(op_array, ctx);
1092
0
    if (ctx->debug_level & ZEND_DUMP_AFTER_PASS_4) {
1093
0
      zend_dump_op_array(op_array, 0, "after pass 4", NULL);
1094
0
    }
1095
0
  }
1096
1097
  /* pass 5:
1098
   * - CFG optimization
1099
   */
1100
0
  if (ZEND_OPTIMIZER_PASS_5 & ctx->optimization_level) {
1101
0
    zend_optimize_cfg(op_array, ctx);
1102
0
    if (ctx->debug_level & ZEND_DUMP_AFTER_PASS_5) {
1103
0
      zend_dump_op_array(op_array, 0, "after pass 5", NULL);
1104
0
    }
1105
0
  }
1106
1107
  /* pass 6:
1108
   * - DFA optimization
1109
   */
1110
0
  if ((ZEND_OPTIMIZER_PASS_6 & ctx->optimization_level) &&
1111
0
      !(ZEND_OPTIMIZER_PASS_7 & ctx->optimization_level)) {
1112
0
    zend_optimize_dfa(op_array, ctx);
1113
0
    if (ctx->debug_level & ZEND_DUMP_AFTER_PASS_6) {
1114
0
      zend_dump_op_array(op_array, 0, "after pass 6", NULL);
1115
0
    }
1116
0
  }
1117
1118
  /* pass 9:
1119
   * - Optimize temp variables usage
1120
   */
1121
0
  if ((ZEND_OPTIMIZER_PASS_9 & ctx->optimization_level) &&
1122
0
      !(ZEND_OPTIMIZER_PASS_7 & ctx->optimization_level)) {
1123
0
    zend_optimize_temporary_variables(op_array, ctx);
1124
0
    if (ctx->debug_level & ZEND_DUMP_AFTER_PASS_9) {
1125
0
      zend_dump_op_array(op_array, 0, "after pass 9", NULL);
1126
0
    }
1127
0
  }
1128
1129
  /* pass 10:
1130
   * - remove NOPs
1131
   */
1132
0
  if (((ZEND_OPTIMIZER_PASS_10|ZEND_OPTIMIZER_PASS_5) & ctx->optimization_level) == ZEND_OPTIMIZER_PASS_10) {
1133
0
    zend_optimizer_nop_removal(op_array, ctx);
1134
0
    if (ctx->debug_level & ZEND_DUMP_AFTER_PASS_10) {
1135
0
      zend_dump_op_array(op_array, 0, "after pass 10", NULL);
1136
0
    }
1137
0
  }
1138
1139
  /* pass 11:
1140
   * - Compact literals table
1141
   */
1142
0
  if ((ZEND_OPTIMIZER_PASS_11 & ctx->optimization_level) &&
1143
0
      (!(ZEND_OPTIMIZER_PASS_6 & ctx->optimization_level) ||
1144
0
       !(ZEND_OPTIMIZER_PASS_7 & ctx->optimization_level))) {
1145
0
    zend_optimizer_compact_literals(op_array, ctx);
1146
0
    if (ctx->debug_level & ZEND_DUMP_AFTER_PASS_11) {
1147
0
      zend_dump_op_array(op_array, 0, "after pass 11", NULL);
1148
0
    }
1149
0
  }
1150
1151
0
  if ((ZEND_OPTIMIZER_PASS_13 & ctx->optimization_level) &&
1152
0
      (!(ZEND_OPTIMIZER_PASS_6 & ctx->optimization_level) ||
1153
0
       !(ZEND_OPTIMIZER_PASS_7 & ctx->optimization_level))) {
1154
0
    zend_optimizer_compact_vars(op_array);
1155
0
    if (ctx->debug_level & ZEND_DUMP_AFTER_PASS_13) {
1156
0
      zend_dump_op_array(op_array, 0, "after pass 13", NULL);
1157
0
    }
1158
0
  }
1159
1160
0
  if (ZEND_OPTIMIZER_PASS_7 & ctx->optimization_level) {
1161
0
    return;
1162
0
  }
1163
1164
0
  if (ctx->debug_level & ZEND_DUMP_AFTER_OPTIMIZER) {
1165
0
    zend_dump_op_array(op_array, 0, "after optimizer", NULL);
1166
0
  }
1167
0
}
1168
1169
static void zend_revert_pass_two(zend_op_array *op_array)
1170
0
{
1171
0
  zend_op *opline;
1172
1173
0
  ZEND_ASSERT((op_array->fn_flags & ZEND_ACC_DONE_PASS_TWO) != 0);
1174
1175
0
  opline = op_array->opcodes;
1176
0
  const zend_op *end = opline + op_array->last;
1177
0
  while (opline < end) {
1178
0
    if (opline->op1_type == IS_CONST) {
1179
0
      ZEND_PASS_TWO_UNDO_CONSTANT(op_array, opline, opline->op1);
1180
0
    }
1181
0
    if (opline->op2_type == IS_CONST) {
1182
0
      ZEND_PASS_TWO_UNDO_CONSTANT(op_array, opline, opline->op2);
1183
0
    }
1184
    /* reset smart branch flags IS_SMART_BRANCH_JMP[N]Z */
1185
0
    opline->result_type &= (IS_TMP_VAR|IS_VAR|IS_CV|IS_CONST);
1186
0
    opline++;
1187
0
  }
1188
0
#if !ZEND_USE_ABS_CONST_ADDR
1189
0
  if (op_array->literals) {
1190
0
    zval *literals = emalloc(sizeof(zval) * op_array->last_literal);
1191
0
    memcpy(literals, op_array->literals, sizeof(zval) * op_array->last_literal);
1192
0
    op_array->literals = literals;
1193
0
  }
1194
0
#endif
1195
1196
0
  op_array->fn_flags &= ~ZEND_ACC_DONE_PASS_TWO;
1197
0
}
1198
1199
static void zend_redo_pass_two(zend_op_array *op_array)
1200
0
{
1201
0
  zend_op *opline, *end;
1202
#if ZEND_USE_ABS_JMP_ADDR && !ZEND_USE_ABS_CONST_ADDR
1203
  zend_op *old_opcodes = op_array->opcodes;
1204
#endif
1205
1206
0
  ZEND_ASSERT((op_array->fn_flags & ZEND_ACC_DONE_PASS_TWO) == 0);
1207
1208
0
#if !ZEND_USE_ABS_CONST_ADDR
1209
0
  if (op_array->last_literal) {
1210
0
    op_array->opcodes = (zend_op *) erealloc(op_array->opcodes,
1211
0
      ZEND_MM_ALIGNED_SIZE_EX(sizeof(zend_op) * op_array->last, 16) +
1212
0
      sizeof(zval) * op_array->last_literal);
1213
0
    memcpy(((char*)op_array->opcodes) + ZEND_MM_ALIGNED_SIZE_EX(sizeof(zend_op) * op_array->last, 16),
1214
0
      op_array->literals, sizeof(zval) * op_array->last_literal);
1215
0
    efree(op_array->literals);
1216
0
    op_array->literals = (zval*)(((char*)op_array->opcodes) + ZEND_MM_ALIGNED_SIZE_EX(sizeof(zend_op) * op_array->last, 16));
1217
0
  } else {
1218
0
    if (op_array->literals) {
1219
0
      efree(op_array->literals);
1220
0
    }
1221
0
    op_array->literals = NULL;
1222
0
  }
1223
0
#endif
1224
1225
0
  opline = op_array->opcodes;
1226
0
  end = opline + op_array->last;
1227
0
  while (opline < end) {
1228
0
    if (opline->op1_type == IS_CONST) {
1229
0
      ZEND_PASS_TWO_UPDATE_CONSTANT(op_array, opline, opline->op1);
1230
0
    }
1231
0
    if (opline->op2_type == IS_CONST) {
1232
0
      ZEND_PASS_TWO_UPDATE_CONSTANT(op_array, opline, opline->op2);
1233
0
    }
1234
    /* fix jumps to point to new array */
1235
0
    switch (opline->opcode) {
1236
#if ZEND_USE_ABS_JMP_ADDR && !ZEND_USE_ABS_CONST_ADDR
1237
      case ZEND_JMP:
1238
      case ZEND_FAST_CALL:
1239
        opline->op1.jmp_addr = &op_array->opcodes[opline->op1.jmp_addr - old_opcodes];
1240
        break;
1241
      case ZEND_JMPZ:
1242
      case ZEND_JMPNZ:
1243
      case ZEND_JMPZ_EX:
1244
      case ZEND_JMPNZ_EX:
1245
      case ZEND_JMP_SET:
1246
      case ZEND_COALESCE:
1247
      case ZEND_FE_RESET_R:
1248
      case ZEND_FE_RESET_RW:
1249
      case ZEND_ASSERT_CHECK:
1250
      case ZEND_JMP_NULL:
1251
      case ZEND_BIND_INIT_STATIC_OR_JMP:
1252
      case ZEND_JMP_FRAMELESS:
1253
        opline->op2.jmp_addr = &op_array->opcodes[opline->op2.jmp_addr - old_opcodes];
1254
        break;
1255
      case ZEND_CATCH:
1256
        if (!(opline->extended_value & ZEND_LAST_CATCH)) {
1257
          opline->op2.jmp_addr = &op_array->opcodes[opline->op2.jmp_addr - old_opcodes];
1258
        }
1259
        break;
1260
      case ZEND_FE_FETCH_R:
1261
      case ZEND_FE_FETCH_RW:
1262
      case ZEND_SWITCH_LONG:
1263
      case ZEND_SWITCH_STRING:
1264
      case ZEND_MATCH:
1265
        /* relative extended_value don't have to be changed */
1266
        break;
1267
#endif
1268
0
      case ZEND_IS_IDENTICAL:
1269
0
      case ZEND_IS_NOT_IDENTICAL:
1270
0
      case ZEND_IS_EQUAL:
1271
0
      case ZEND_IS_NOT_EQUAL:
1272
0
      case ZEND_IS_SMALLER:
1273
0
      case ZEND_IS_SMALLER_OR_EQUAL:
1274
0
      case ZEND_CASE:
1275
0
      case ZEND_CASE_STRICT:
1276
0
      case ZEND_ISSET_ISEMPTY_CV:
1277
0
      case ZEND_ISSET_ISEMPTY_VAR:
1278
0
      case ZEND_ISSET_ISEMPTY_DIM_OBJ:
1279
0
      case ZEND_ISSET_ISEMPTY_PROP_OBJ:
1280
0
      case ZEND_ISSET_ISEMPTY_STATIC_PROP:
1281
0
      case ZEND_INSTANCEOF:
1282
0
      case ZEND_TYPE_CHECK:
1283
0
      case ZEND_DEFINED:
1284
0
      case ZEND_IN_ARRAY:
1285
0
      case ZEND_ARRAY_KEY_EXISTS:
1286
0
        if (opline->result_type & IS_TMP_VAR) {
1287
          /* reinitialize result_type of smart branch instructions */
1288
0
          if (opline + 1 < end) {
1289
0
            if ((opline+1)->opcode == ZEND_JMPZ
1290
0
             && (opline+1)->op1_type == IS_TMP_VAR
1291
0
             && (opline+1)->op1.var == opline->result.var) {
1292
0
              opline->result_type = IS_SMART_BRANCH_JMPZ | IS_TMP_VAR;
1293
0
            } else if ((opline+1)->opcode == ZEND_JMPNZ
1294
0
             && (opline+1)->op1_type == IS_TMP_VAR
1295
0
             && (opline+1)->op1.var == opline->result.var) {
1296
0
              opline->result_type = IS_SMART_BRANCH_JMPNZ | IS_TMP_VAR;
1297
0
            }
1298
0
          }
1299
0
        }
1300
0
        break;
1301
0
    }
1302
0
    ZEND_VM_SET_OPCODE_HANDLER(opline);
1303
0
    opline++;
1304
0
  }
1305
1306
0
  op_array->fn_flags |= ZEND_ACC_DONE_PASS_TWO;
1307
0
}
1308
1309
static void zend_redo_pass_two_ex(zend_op_array *op_array, const zend_ssa *ssa)
1310
0
{
1311
0
  zend_op *opline, *end;
1312
#if ZEND_USE_ABS_JMP_ADDR && !ZEND_USE_ABS_CONST_ADDR
1313
  zend_op *old_opcodes = op_array->opcodes;
1314
#endif
1315
1316
0
  ZEND_ASSERT((op_array->fn_flags & ZEND_ACC_DONE_PASS_TWO) == 0);
1317
1318
0
#if !ZEND_USE_ABS_CONST_ADDR
1319
0
  if (op_array->last_literal) {
1320
0
    op_array->opcodes = (zend_op *) erealloc(op_array->opcodes,
1321
0
      ZEND_MM_ALIGNED_SIZE_EX(sizeof(zend_op) * op_array->last, 16) +
1322
0
      sizeof(zval) * op_array->last_literal);
1323
0
    memcpy(((char*)op_array->opcodes) + ZEND_MM_ALIGNED_SIZE_EX(sizeof(zend_op) * op_array->last, 16),
1324
0
      op_array->literals, sizeof(zval) * op_array->last_literal);
1325
0
    efree(op_array->literals);
1326
0
    op_array->literals = (zval*)(((char*)op_array->opcodes) + ZEND_MM_ALIGNED_SIZE_EX(sizeof(zend_op) * op_array->last, 16));
1327
0
  } else {
1328
0
    if (op_array->literals) {
1329
0
      efree(op_array->literals);
1330
0
    }
1331
0
    op_array->literals = NULL;
1332
0
  }
1333
0
#endif
1334
1335
0
  opline = op_array->opcodes;
1336
0
  end = opline + op_array->last;
1337
0
  while (opline < end) {
1338
0
    const zend_ssa_op *ssa_op = &ssa->ops[opline - op_array->opcodes];
1339
0
    uint32_t op1_info = opline->op1_type == IS_UNUSED ? 0 : (OP1_INFO() & (MAY_BE_UNDEF|MAY_BE_ANY|MAY_BE_REF|MAY_BE_ARRAY_OF_ANY|MAY_BE_ARRAY_KEY_ANY));
1340
0
    uint32_t op2_info = opline->op1_type == IS_UNUSED ? 0 : (OP2_INFO() & (MAY_BE_UNDEF|MAY_BE_ANY|MAY_BE_REF|MAY_BE_ARRAY_OF_ANY|MAY_BE_ARRAY_KEY_ANY));
1341
0
    uint32_t res_info =
1342
0
      (opline->opcode == ZEND_PRE_INC ||
1343
0
       opline->opcode == ZEND_PRE_DEC ||
1344
0
       opline->opcode == ZEND_POST_INC ||
1345
0
       opline->opcode == ZEND_POST_DEC) ?
1346
0
        ((ssa->ops[opline - op_array->opcodes].op1_def >= 0) ? (OP1_DEF_INFO() & (MAY_BE_UNDEF|MAY_BE_ANY|MAY_BE_REF|MAY_BE_ARRAY_OF_ANY|MAY_BE_ARRAY_KEY_ANY)) : MAY_BE_ANY) :
1347
0
        (opline->result_type == IS_UNUSED ? 0 : (RES_INFO() & (MAY_BE_UNDEF|MAY_BE_ANY|MAY_BE_REF|MAY_BE_ARRAY_OF_ANY|MAY_BE_ARRAY_KEY_ANY)));
1348
1349
0
    if (opline->op1_type == IS_CONST) {
1350
0
      ZEND_PASS_TWO_UPDATE_CONSTANT(op_array, opline, opline->op1);
1351
0
    }
1352
0
    if (opline->op2_type == IS_CONST) {
1353
0
      ZEND_PASS_TWO_UPDATE_CONSTANT(op_array, opline, opline->op2);
1354
0
    }
1355
1356
    /* fix jumps to point to new array */
1357
0
    switch (opline->opcode) {
1358
#if ZEND_USE_ABS_JMP_ADDR && !ZEND_USE_ABS_CONST_ADDR
1359
      case ZEND_JMP:
1360
      case ZEND_FAST_CALL:
1361
        opline->op1.jmp_addr = &op_array->opcodes[opline->op1.jmp_addr - old_opcodes];
1362
        break;
1363
      case ZEND_JMPZ:
1364
      case ZEND_JMPNZ:
1365
      case ZEND_JMPZ_EX:
1366
      case ZEND_JMPNZ_EX:
1367
      case ZEND_JMP_SET:
1368
      case ZEND_COALESCE:
1369
      case ZEND_FE_RESET_R:
1370
      case ZEND_FE_RESET_RW:
1371
      case ZEND_ASSERT_CHECK:
1372
      case ZEND_JMP_NULL:
1373
      case ZEND_BIND_INIT_STATIC_OR_JMP:
1374
      case ZEND_JMP_FRAMELESS:
1375
        opline->op2.jmp_addr = &op_array->opcodes[opline->op2.jmp_addr - old_opcodes];
1376
        break;
1377
      case ZEND_CATCH:
1378
        if (!(opline->extended_value & ZEND_LAST_CATCH)) {
1379
          opline->op2.jmp_addr = &op_array->opcodes[opline->op2.jmp_addr - old_opcodes];
1380
        }
1381
        break;
1382
      case ZEND_FE_FETCH_R:
1383
      case ZEND_FE_FETCH_RW:
1384
      case ZEND_SWITCH_LONG:
1385
      case ZEND_SWITCH_STRING:
1386
      case ZEND_MATCH:
1387
        /* relative extended_value don't have to be changed */
1388
        break;
1389
#endif
1390
0
      case ZEND_IS_IDENTICAL:
1391
0
      case ZEND_IS_NOT_IDENTICAL:
1392
0
      case ZEND_IS_EQUAL:
1393
0
      case ZEND_IS_NOT_EQUAL:
1394
0
      case ZEND_IS_SMALLER:
1395
0
      case ZEND_IS_SMALLER_OR_EQUAL:
1396
0
      case ZEND_CASE:
1397
0
      case ZEND_CASE_STRICT:
1398
0
      case ZEND_ISSET_ISEMPTY_CV:
1399
0
      case ZEND_ISSET_ISEMPTY_VAR:
1400
0
      case ZEND_ISSET_ISEMPTY_DIM_OBJ:
1401
0
      case ZEND_ISSET_ISEMPTY_PROP_OBJ:
1402
0
      case ZEND_ISSET_ISEMPTY_STATIC_PROP:
1403
0
      case ZEND_INSTANCEOF:
1404
0
      case ZEND_TYPE_CHECK:
1405
0
      case ZEND_DEFINED:
1406
0
      case ZEND_IN_ARRAY:
1407
0
      case ZEND_ARRAY_KEY_EXISTS:
1408
0
        if (opline->result_type & IS_TMP_VAR) {
1409
          /* reinitialize result_type of smart branch instructions */
1410
0
          if (opline + 1 < end) {
1411
0
            if ((opline+1)->opcode == ZEND_JMPZ
1412
0
             && (opline+1)->op1_type == IS_TMP_VAR
1413
0
             && (opline+1)->op1.var == opline->result.var) {
1414
0
              opline->result_type = IS_SMART_BRANCH_JMPZ | IS_TMP_VAR;
1415
0
            } else if ((opline+1)->opcode == ZEND_JMPNZ
1416
0
             && (opline+1)->op1_type == IS_TMP_VAR
1417
0
             && (opline+1)->op1.var == opline->result.var) {
1418
0
              opline->result_type = IS_SMART_BRANCH_JMPNZ | IS_TMP_VAR;
1419
0
            }
1420
0
          }
1421
0
        }
1422
0
        break;
1423
0
    }
1424
#ifdef ZEND_VERIFY_TYPE_INFERENCE
1425
    if (ssa_op->op1_use >= 0) {
1426
      opline->op1_use_type = ssa->var_info[ssa_op->op1_use].type;
1427
    }
1428
    if (ssa_op->op2_use >= 0) {
1429
      opline->op2_use_type = ssa->var_info[ssa_op->op2_use].type;
1430
    }
1431
    if (ssa_op->result_use >= 0) {
1432
      opline->result_use_type = ssa->var_info[ssa_op->result_use].type;
1433
    }
1434
    if (ssa_op->op1_def >= 0) {
1435
      opline->op1_def_type = ssa->var_info[ssa_op->op1_def].type;
1436
    }
1437
    if (ssa_op->op2_def >= 0) {
1438
      opline->op2_def_type = ssa->var_info[ssa_op->op2_def].type;
1439
    }
1440
    if (ssa_op->result_def >= 0) {
1441
      opline->result_def_type = ssa->var_info[ssa_op->result_def].type;
1442
    }
1443
#endif
1444
0
    zend_vm_set_opcode_handler_ex(opline, op1_info, op2_info, res_info);
1445
0
    opline++;
1446
0
  }
1447
1448
0
  op_array->fn_flags |= ZEND_ACC_DONE_PASS_TWO;
1449
0
}
1450
1451
static void zend_optimize_op_array(zend_op_array      *op_array,
1452
                                   zend_optimizer_ctx *ctx)
1453
0
{
1454
  /* Revert pass_two() */
1455
0
  zend_revert_pass_two(op_array);
1456
1457
  /* Do actual optimizations */
1458
0
  zend_optimize(op_array, ctx);
1459
1460
  /* Redo pass_two() */
1461
0
  zend_redo_pass_two(op_array);
1462
1463
0
  if (op_array->live_range) {
1464
0
    zend_recalc_live_ranges(op_array, NULL);
1465
0
  }
1466
0
}
1467
1468
static void zend_adjust_fcall_stack_size(const zend_op_array *op_array, const zend_optimizer_ctx *ctx)
1469
0
{
1470
0
  zend_function *func;
1471
0
  zend_op *opline;
1472
1473
0
  opline = op_array->opcodes;
1474
0
  const zend_op* end = opline + op_array->last;
1475
0
  while (opline < end) {
1476
0
    if (opline->opcode == ZEND_INIT_FCALL) {
1477
0
      func = zend_hash_find_ptr(
1478
0
        &ctx->script->function_table,
1479
0
        Z_STR_P(RT_CONSTANT(opline, opline->op2)));
1480
0
      if (func) {
1481
0
        opline->op1.num = zend_vm_calc_used_stack(opline->extended_value, func);
1482
0
      }
1483
0
    }
1484
0
    opline++;
1485
0
  }
1486
0
}
1487
1488
static void zend_adjust_fcall_stack_size_graph(const zend_op_array *op_array)
1489
0
{
1490
0
  const zend_func_info *func_info = ZEND_FUNC_INFO(op_array);
1491
1492
0
  if (func_info) {
1493
0
    const zend_call_info *call_info =func_info->callee_info;
1494
1495
0
    while (call_info) {
1496
0
      zend_op *opline = call_info->caller_init_opline;
1497
1498
0
      if (opline && call_info->callee_func && opline->opcode == ZEND_INIT_FCALL) {
1499
0
        ZEND_ASSERT(!call_info->is_prototype);
1500
0
        opline->op1.num = zend_vm_calc_used_stack(opline->extended_value, call_info->callee_func);
1501
0
      }
1502
0
      call_info = call_info->next_callee;
1503
0
    }
1504
0
  }
1505
0
}
1506
1507
0
static bool needs_live_range(const zend_op_array *op_array, const zend_op *def_opline) {
1508
0
  const zend_func_info *func_info = ZEND_FUNC_INFO(op_array);
1509
0
  const zend_ssa_op *ssa_op = &func_info->ssa.ops[def_opline - op_array->opcodes];
1510
0
  int ssa_var = ssa_op->result_def;
1511
0
  if (ssa_var < 0) {
1512
    /* Be conservative. */
1513
0
    return true;
1514
0
  }
1515
1516
  /* If the variable is used by a PHI, this may be the assignment of the final branch of a
1517
   * ternary/etc structure. While this is where the live range starts, the value from the other
1518
   * branch may also be used. As such, use the type of the PHI node for the following check. */
1519
0
  if (func_info->ssa.vars[ssa_var].phi_use_chain) {
1520
0
    ssa_var = func_info->ssa.vars[ssa_var].phi_use_chain->ssa_var;
1521
0
  }
1522
1523
0
  uint32_t type = func_info->ssa.var_info[ssa_var].type;
1524
0
  return (type & (MAY_BE_STRING|MAY_BE_ARRAY|MAY_BE_OBJECT|MAY_BE_RESOURCE|MAY_BE_REF)) != 0;
1525
0
}
1526
1527
static void zend_foreach_op_array_helper(
1528
0
    zend_op_array *op_array, zend_op_array_func_t func, void *context) {
1529
0
  func(op_array, context);
1530
0
  for (uint32_t i = 0; i < op_array->num_dynamic_func_defs; i++) {
1531
0
    zend_foreach_op_array_helper(op_array->dynamic_func_defs[i], func, context);
1532
0
  }
1533
0
}
1534
1535
void zend_foreach_op_array(zend_script *script, zend_op_array_func_t func, void *context)
1536
0
{
1537
0
  zval *zv;
1538
0
  zend_op_array *op_array;
1539
1540
0
  zend_foreach_op_array_helper(&script->main_op_array, func, context);
1541
1542
0
  ZEND_HASH_MAP_FOREACH_PTR(&script->function_table, op_array) {
1543
0
    zend_foreach_op_array_helper(op_array, func, context);
1544
0
  } ZEND_HASH_FOREACH_END();
1545
1546
0
  ZEND_HASH_MAP_FOREACH_VAL(&script->class_table, zv) {
1547
0
    if (Z_TYPE_P(zv) == IS_ALIAS_PTR) {
1548
0
      continue;
1549
0
    }
1550
0
    const zend_class_entry *ce = Z_CE_P(zv);
1551
0
    ZEND_HASH_MAP_FOREACH_PTR(&ce->function_table, op_array) {
1552
0
      if (op_array->scope == ce
1553
0
          && op_array->type == ZEND_USER_FUNCTION
1554
0
          && !(op_array->fn_flags & ZEND_ACC_ABSTRACT)
1555
0
          && !(op_array->fn_flags & ZEND_ACC_TRAIT_CLONE)) {
1556
0
        zend_foreach_op_array_helper(op_array, func, context);
1557
0
      }
1558
0
    } ZEND_HASH_FOREACH_END();
1559
1560
0
    zend_property_info *property;
1561
0
    ZEND_HASH_MAP_FOREACH_PTR(&ce->properties_info, property) {
1562
0
      zend_function **hooks = property->hooks;
1563
0
      if (property->ce == ce && property->hooks) {
1564
0
        for (uint32_t i = 0; i < ZEND_PROPERTY_HOOK_COUNT; i++) {
1565
0
          const zend_function *hook = hooks[i];
1566
0
          if (hook && hook->common.scope == ce && !(hooks[i]->op_array.fn_flags & ZEND_ACC_TRAIT_CLONE)) {
1567
0
            zend_foreach_op_array_helper(&hooks[i]->op_array, func, context);
1568
0
          }
1569
0
        }
1570
0
      }
1571
0
    } ZEND_HASH_FOREACH_END();
1572
0
  } ZEND_HASH_FOREACH_END();
1573
0
}
1574
1575
0
static void step_optimize_op_array(zend_op_array *op_array, void *context) {
1576
0
  zend_optimize_op_array(op_array, (zend_optimizer_ctx *) context);
1577
0
}
1578
1579
0
static void step_adjust_fcall_stack_size(zend_op_array *op_array, void *context) {
1580
0
  zend_adjust_fcall_stack_size(op_array, (zend_optimizer_ctx *) context);
1581
0
}
1582
1583
0
static void step_dump_after_optimizer(zend_op_array *op_array, void *context) {
1584
0
  zend_dump_op_array(op_array, ZEND_DUMP_LIVE_RANGES, "after optimizer", NULL);
1585
0
}
1586
1587
0
static void zend_optimizer_call_registered_passes(zend_script *script, void *ctx) {
1588
0
  for (int i = 0; i < zend_optimizer_registered_passes.last; i++) {
1589
0
    if (!zend_optimizer_registered_passes.pass[i]) {
1590
0
      continue;
1591
0
    }
1592
1593
0
    zend_optimizer_registered_passes.pass[i](script, ctx);
1594
0
  }
1595
0
}
1596
1597
ZEND_API void zend_optimize_script(zend_script *script, zend_long optimization_level, zend_long debug_level)
1598
0
{
1599
0
  zend_op_array *op_array;
1600
0
  zend_string *name;
1601
0
  zend_optimizer_ctx ctx;
1602
0
  zval *zv;
1603
1604
0
  ctx.arena = zend_arena_create(64 * 1024);
1605
0
  ctx.script = script;
1606
0
  ctx.constants = NULL;
1607
0
  ctx.optimization_level = optimization_level;
1608
0
  ctx.debug_level = debug_level;
1609
1610
0
  if ((ZEND_OPTIMIZER_PASS_6 & optimization_level) &&
1611
0
      (ZEND_OPTIMIZER_PASS_7 & optimization_level)) {
1612
    /* Optimize using call-graph */
1613
0
    zend_call_graph call_graph;
1614
0
    zend_build_call_graph(&ctx.arena, script, &call_graph);
1615
1616
0
    uint32_t i;
1617
0
    zend_func_info *func_info;
1618
1619
0
    for (i = 0; i < call_graph.op_arrays_count; i++) {
1620
0
      zend_revert_pass_two(call_graph.op_arrays[i]);
1621
0
      zend_optimize(call_graph.op_arrays[i], &ctx);
1622
0
    }
1623
1624
0
      zend_analyze_call_graph(&ctx.arena, script, &call_graph);
1625
1626
0
    for (i = 0; i < call_graph.op_arrays_count; i++) {
1627
0
      func_info = ZEND_FUNC_INFO(call_graph.op_arrays[i]);
1628
0
      if (func_info) {
1629
0
        func_info->call_map = zend_build_call_map(&ctx.arena, func_info, call_graph.op_arrays[i]);
1630
0
        if (call_graph.op_arrays[i]->fn_flags & ZEND_ACC_HAS_RETURN_TYPE) {
1631
0
          zend_init_func_return_info(call_graph.op_arrays[i], script, &func_info->return_info);
1632
0
        }
1633
0
      }
1634
0
    }
1635
1636
0
    for (i = 0; i < call_graph.op_arrays_count; i++) {
1637
0
      func_info = ZEND_FUNC_INFO(call_graph.op_arrays[i]);
1638
0
      if (func_info) {
1639
0
        if (zend_dfa_analyze_op_array(call_graph.op_arrays[i], &ctx, &func_info->ssa) == SUCCESS) {
1640
0
          func_info->flags = func_info->ssa.cfg.flags;
1641
0
        } else {
1642
0
          ZEND_SET_FUNC_INFO(call_graph.op_arrays[i], NULL);
1643
0
        }
1644
0
      }
1645
0
    }
1646
1647
    //TODO: perform inner-script inference???
1648
0
    for (i = 0; i < call_graph.op_arrays_count; i++) {
1649
0
      func_info = ZEND_FUNC_INFO(call_graph.op_arrays[i]);
1650
0
      if (func_info) {
1651
0
        zend_dfa_optimize_op_array(call_graph.op_arrays[i], &ctx, &func_info->ssa, func_info->call_map);
1652
0
      }
1653
0
    }
1654
1655
0
    if (debug_level & ZEND_DUMP_AFTER_PASS_7) {
1656
0
      for (i = 0; i < call_graph.op_arrays_count; i++) {
1657
0
        zend_dump_op_array(call_graph.op_arrays[i], 0, "after pass 7", NULL);
1658
0
      }
1659
0
    }
1660
1661
0
    if (ZEND_OPTIMIZER_PASS_9 & optimization_level) {
1662
0
      for (i = 0; i < call_graph.op_arrays_count; i++) {
1663
0
        zend_optimize_temporary_variables(call_graph.op_arrays[i], &ctx);
1664
0
        if (debug_level & ZEND_DUMP_AFTER_PASS_9) {
1665
0
          zend_dump_op_array(call_graph.op_arrays[i], 0, "after pass 9", NULL);
1666
0
        }
1667
0
      }
1668
0
    }
1669
1670
0
    if (ZEND_OPTIMIZER_PASS_11 & optimization_level) {
1671
0
      for (i = 0; i < call_graph.op_arrays_count; i++) {
1672
0
        zend_optimizer_compact_literals(call_graph.op_arrays[i], &ctx);
1673
0
        if (debug_level & ZEND_DUMP_AFTER_PASS_11) {
1674
0
          zend_dump_op_array(call_graph.op_arrays[i], 0, "after pass 11", NULL);
1675
0
        }
1676
0
      }
1677
0
    }
1678
1679
0
    if (ZEND_OPTIMIZER_PASS_13 & optimization_level) {
1680
0
      for (i = 0; i < call_graph.op_arrays_count; i++) {
1681
0
        zend_optimizer_compact_vars(call_graph.op_arrays[i]);
1682
0
        if (debug_level & ZEND_DUMP_AFTER_PASS_13) {
1683
0
          zend_dump_op_array(call_graph.op_arrays[i], 0, "after pass 13", NULL);
1684
0
        }
1685
0
      }
1686
0
    }
1687
1688
0
    if (ZEND_OPTIMIZER_PASS_12 & optimization_level) {
1689
0
      for (i = 0; i < call_graph.op_arrays_count; i++) {
1690
0
        zend_adjust_fcall_stack_size_graph(call_graph.op_arrays[i]);
1691
0
      }
1692
0
    }
1693
1694
0
    for (i = 0; i < call_graph.op_arrays_count; i++) {
1695
0
      op_array = call_graph.op_arrays[i];
1696
0
      func_info = ZEND_FUNC_INFO(op_array);
1697
0
      if (func_info && func_info->ssa.var_info) {
1698
0
        zend_redo_pass_two_ex(op_array, &func_info->ssa);
1699
0
        if (op_array->live_range) {
1700
0
          zend_recalc_live_ranges(op_array, needs_live_range);
1701
0
        }
1702
0
      } else {
1703
0
        zend_redo_pass_two(op_array);
1704
0
        if (op_array->live_range) {
1705
0
          zend_recalc_live_ranges(op_array, NULL);
1706
0
        }
1707
0
      }
1708
0
    }
1709
1710
0
    for (i = 0; i < call_graph.op_arrays_count; i++) {
1711
0
      ZEND_SET_FUNC_INFO(call_graph.op_arrays[i], NULL);
1712
0
    }
1713
0
  } else {
1714
0
    zend_foreach_op_array(script, step_optimize_op_array, &ctx);
1715
1716
0
    if (ZEND_OPTIMIZER_PASS_12 & optimization_level) {
1717
0
      zend_foreach_op_array(script, step_adjust_fcall_stack_size, &ctx);
1718
0
    }
1719
0
  }
1720
1721
0
  ZEND_HASH_MAP_FOREACH_VAL(&script->class_table, zv) {
1722
0
    if (Z_TYPE_P(zv) == IS_ALIAS_PTR) {
1723
0
      continue;
1724
0
    }
1725
0
    const zend_class_entry *ce = Z_CE_P(zv);
1726
0
    ZEND_HASH_MAP_FOREACH_STR_KEY_PTR(&ce->function_table, name, op_array) {
1727
0
      if (op_array->scope != ce && op_array->type == ZEND_USER_FUNCTION) {
1728
0
        const zend_op_array *orig_op_array =
1729
0
          zend_hash_find_ptr(&op_array->scope->function_table, name);
1730
1731
0
        ZEND_ASSERT(orig_op_array != NULL);
1732
0
        if (orig_op_array != op_array) {
1733
0
          uint32_t fn_flags = op_array->fn_flags;
1734
0
          uint32_t fn_flags2 = op_array->fn_flags2;
1735
0
          zend_function *prototype = op_array->prototype;
1736
0
          HashTable *ht = op_array->static_variables;
1737
1738
0
          *op_array = *orig_op_array;
1739
0
          op_array->fn_flags = fn_flags;
1740
0
          op_array->fn_flags2 = fn_flags2;
1741
0
          op_array->prototype = prototype;
1742
0
          op_array->static_variables = ht;
1743
0
        }
1744
0
      }
1745
0
    } ZEND_HASH_FOREACH_END();
1746
0
  } ZEND_HASH_FOREACH_END();
1747
1748
0
  zend_optimizer_call_registered_passes(script, &ctx);
1749
1750
0
  if ((debug_level & ZEND_DUMP_AFTER_OPTIMIZER) &&
1751
0
      (ZEND_OPTIMIZER_PASS_7 & optimization_level)) {
1752
0
    zend_foreach_op_array(script, step_dump_after_optimizer, NULL);
1753
0
  }
1754
1755
0
  if (ctx.constants) {
1756
0
    zend_hash_destroy(ctx.constants);
1757
0
  }
1758
0
  zend_arena_destroy(ctx.arena);
1759
0
}
1760
1761
ZEND_API int zend_optimizer_register_pass(zend_optimizer_pass_t pass)
1762
0
{
1763
0
  if (!pass) {
1764
0
    return -1;
1765
0
  }
1766
1767
0
  if (zend_optimizer_registered_passes.last == ZEND_OPTIMIZER_MAX_REGISTERED_PASSES) {
1768
0
    return -1;
1769
0
  }
1770
1771
0
  zend_optimizer_registered_passes.pass[
1772
0
    zend_optimizer_registered_passes.last++] = pass;
1773
1774
0
  return zend_optimizer_registered_passes.last;
1775
0
}
1776
1777
ZEND_API void zend_optimizer_unregister_pass(int idx)
1778
0
{
1779
0
  zend_optimizer_registered_passes.pass[idx-1] = NULL;
1780
0
}
1781
1782
zend_result zend_optimizer_startup(void)
1783
2
{
1784
2
  return zend_func_info_startup();
1785
2
}
1786
1787
zend_result zend_optimizer_shutdown(void)
1788
0
{
1789
0
  return zend_func_info_shutdown();
1790
0
}