Coverage Report

Created: 2025-12-31 07:28

next uncovered line (L), next uncovered region (R), next uncovered branch (B)
/src/php-src/Zend/Optimizer/escape_analysis.c
Line
Count
Source
1
/*
2
   +----------------------------------------------------------------------+
3
   | Zend OPcache, Escape Analysis                                        |
4
   +----------------------------------------------------------------------+
5
   | Copyright (c) The PHP Group                                          |
6
   +----------------------------------------------------------------------+
7
   | This source file is subject to version 3.01 of the PHP license,      |
8
   | that is bundled with this package in the file LICENSE, and is        |
9
   | available through the world-wide-web at the following url:           |
10
   | https://www.php.net/license/3_01.txt                                 |
11
   | If you did not receive a copy of the PHP license and are unable to   |
12
   | obtain it through the world-wide-web, please send a note to          |
13
   | license@php.net so we can mail you a copy immediately.               |
14
   +----------------------------------------------------------------------+
15
   | Authors: Dmitry Stogov <dmitry@php.net>                              |
16
   +----------------------------------------------------------------------+
17
*/
18
19
#include "Optimizer/zend_optimizer.h"
20
#include "Optimizer/zend_optimizer_internal.h"
21
#include "zend_bitset.h"
22
#include "zend_cfg.h"
23
#include "zend_ssa.h"
24
#include "zend_inference.h"
25
#include "zend_dump.h"
26
27
/*
28
 * T. Kotzmann and H. Mossenbock. Escape analysis  in the context of dynamic
29
 * compilation and deoptimization. In Proceedings of the International
30
 * Conference on Virtual Execution Environments, pages 111-120, Chicago,
31
 * June 2005
32
 */
33
34
static zend_always_inline void union_find_init(int *parent, int *size, int count) /* {{{ */
35
999
{
36
999
  int i;
37
38
223k
  for (i = 0; i < count; i++) {
39
222k
    parent[i] = i;
40
222k
    size[i] = 1;
41
222k
  }
42
999
}
43
/* }}} */
44
45
static zend_always_inline int union_find_root(int *parent, int i) /* {{{ */
46
421k
{
47
421k
  int p = parent[i];
48
49
582k
  while (i != p) {
50
160k
    p = parent[p];
51
160k
    parent[i] = p;
52
160k
    i = p;
53
160k
    p = parent[i];
54
160k
  }
55
421k
  return i;
56
421k
}
57
/* }}} */
58
59
static zend_always_inline void union_find_unite(int *parent, int *size, int i, int j) /* {{{ */
60
99.7k
{
61
99.7k
  int r1 = union_find_root(parent, i);
62
99.7k
  int r2 = union_find_root(parent, j);
63
64
99.7k
  if (r1 != r2) {
65
77.4k
    if (size[r1] < size[r2]) {
66
42.4k
      parent[r1] = r2;
67
42.4k
      size[r2] += size[r1];
68
42.4k
    } else {
69
35.0k
      parent[r2] = r1;
70
35.0k
      size[r1] += size[r2];
71
35.0k
    }
72
77.4k
  }
73
99.7k
}
74
/* }}} */
75
76
static zend_result zend_build_equi_escape_sets(int *parent, zend_op_array *op_array, zend_ssa *ssa) /* {{{ */
77
999
{
78
999
  zend_ssa_var *ssa_vars = ssa->vars;
79
999
  int ssa_vars_count = ssa->vars_count;
80
999
  zend_ssa_phi *p;
81
999
  int i, j;
82
999
  int *size;
83
999
  ALLOCA_FLAG(use_heap)
84
85
999
  size = do_alloca(sizeof(int) * ssa_vars_count, use_heap);
86
999
  if (!size) {
87
0
    return FAILURE;
88
0
  }
89
999
  union_find_init(parent, size, ssa_vars_count);
90
91
223k
  for (i = 0; i < ssa_vars_count; i++) {
92
222k
    if (ssa_vars[i].definition_phi) {
93
41.0k
      p = ssa_vars[i].definition_phi;
94
41.0k
      if (p->pi >= 0) {
95
12.8k
        union_find_unite(parent, size, i, p->sources[0]);
96
28.2k
      } else {
97
85.4k
        for (j = 0; j < ssa->cfg.blocks[p->block].predecessors_count; j++) {
98
57.2k
          union_find_unite(parent, size, i, p->sources[j]);
99
57.2k
        }
100
28.2k
      }
101
181k
    } else if (ssa_vars[i].definition >= 0) {
102
174k
      int def = ssa_vars[i].definition;
103
174k
      zend_ssa_op *op = ssa->ops + def;
104
174k
      zend_op *opline =  op_array->opcodes + def;
105
106
174k
      if (op->op1_def >= 0) {
107
14.7k
        if (op->op1_use >= 0) {
108
14.7k
          if (opline->opcode != ZEND_ASSIGN) {
109
7.76k
            union_find_unite(parent, size, op->op1_def, op->op1_use);
110
7.76k
          }
111
14.7k
        }
112
14.7k
        if (opline->opcode == ZEND_ASSIGN && op->op2_use >= 0) {
113
5.05k
          union_find_unite(parent, size, op->op1_def, op->op2_use);
114
5.05k
        }
115
14.7k
      }
116
174k
      if (op->op2_def >= 0) {
117
773
        if (op->op2_use >= 0) {
118
753
          union_find_unite(parent, size, op->op2_def, op->op2_use);
119
753
        }
120
773
      }
121
174k
      if (op->result_def >= 0) {
122
166k
        if (op->result_use >= 0) {
123
10.3k
          if (opline->opcode != ZEND_QM_ASSIGN) {
124
10.3k
            union_find_unite(parent, size, op->result_def, op->result_use);
125
10.3k
          }
126
10.3k
        }
127
166k
        if (opline->opcode == ZEND_QM_ASSIGN && op->op1_use >= 0) {
128
215
          union_find_unite(parent, size, op->result_def, op->op1_use);
129
215
        }
130
166k
        if (opline->opcode == ZEND_ASSIGN && op->op2_use >= 0) {
131
2.48k
          union_find_unite(parent, size, op->result_def, op->op2_use);
132
2.48k
        }
133
166k
        if (opline->opcode == ZEND_ASSIGN && op->op1_def >= 0) {
134
3.08k
          union_find_unite(parent, size, op->result_def, op->op1_def);
135
3.08k
        }
136
166k
      }
137
174k
    }
138
222k
  }
139
140
223k
  for (i = 0; i < ssa_vars_count; i++) {
141
222k
    parent[i] = union_find_root(parent, i);
142
222k
  }
143
144
999
  free_alloca(size, use_heap);
145
146
999
  return SUCCESS;
147
999
}
148
/* }}} */
149
150
static bool is_allocation_def(zend_op_array *op_array, zend_ssa *ssa, int def, int var, const zend_script *script) /* {{{ */
151
93.6k
{
152
93.6k
  zend_ssa_op *ssa_op = ssa->ops + def;
153
93.6k
  zend_op *opline = op_array->opcodes + def;
154
155
93.6k
  if (ssa_op->result_def == var) {
156
86.1k
    switch (opline->opcode) {
157
1.05k
      case ZEND_INIT_ARRAY:
158
1.05k
        return true;
159
2.36k
      case ZEND_NEW: {
160
          /* objects with destructors should escape */
161
2.36k
        zend_class_entry *ce = zend_optimizer_get_class_entry_from_op1(
162
2.36k
          script, op_array, opline);
163
2.36k
        uint32_t forbidden_flags =
164
          /* These flags will always cause an exception */
165
2.36k
          ZEND_ACC_IMPLICIT_ABSTRACT_CLASS | ZEND_ACC_EXPLICIT_ABSTRACT_CLASS
166
2.36k
          | ZEND_ACC_INTERFACE | ZEND_ACC_TRAIT;
167
2.36k
        if (ce
168
2.00k
         && !ce->parent
169
1.83k
         && !ce->create_object
170
1.53k
         && ce->default_object_handlers->get_constructor == zend_std_get_constructor
171
1.53k
         && ce->default_object_handlers->dtor_obj == zend_objects_destroy_object
172
1.53k
         && !ce->constructor
173
1.43k
         && !ce->destructor
174
916
         && !ce->__get
175
908
         && !ce->__set
176
906
         && !(ce->ce_flags & forbidden_flags)
177
906
         && (ce->ce_flags & ZEND_ACC_CONSTANTS_UPDATED)) {
178
906
          return true;
179
906
        }
180
1.46k
        break;
181
2.36k
      }
182
1.46k
      case ZEND_QM_ASSIGN:
183
334
        if (opline->op1_type == IS_CONST
184
0
         && Z_TYPE_P(CRT_CONSTANT(opline->op1)) == IS_ARRAY) {
185
0
          return true;
186
0
        }
187
334
        if (opline->op1_type == IS_CV && (OP1_INFO() & MAY_BE_ARRAY)) {
188
0
          return true;
189
0
        }
190
334
        break;
191
334
      case ZEND_ASSIGN:
192
126
        if (opline->op1_type == IS_CV && (OP1_INFO() & MAY_BE_ARRAY)) {
193
54
          return true;
194
54
        }
195
72
        break;
196
86.1k
    }
197
86.1k
  } else if (ssa_op->op1_def == var) {
198
7.46k
    switch (opline->opcode) {
199
3.59k
      case ZEND_ASSIGN:
200
3.59k
        if (opline->op2_type == IS_CONST
201
1.70k
         && Z_TYPE_P(CRT_CONSTANT(opline->op2)) == IS_ARRAY) {
202
494
          return true;
203
494
        }
204
3.09k
        if (opline->op2_type == IS_CV && (OP2_INFO() & MAY_BE_ARRAY)) {
205
44
          return true;
206
44
        }
207
3.05k
        break;
208
3.05k
      case ZEND_ASSIGN_DIM:
209
426
        if (OP1_INFO() & (MAY_BE_UNDEF | MAY_BE_NULL | MAY_BE_FALSE)) {
210
          /* implicit object/array allocation */
211
412
          return true;
212
412
        }
213
14
        break;
214
7.46k
    }
215
7.46k
  }
216
217
90.6k
  return false;
218
93.6k
}
219
/* }}} */
220
221
static bool is_local_def(zend_op_array *op_array, zend_ssa *ssa, int def, int var, const zend_script *script) /* {{{ */
222
46.7k
{
223
46.7k
  zend_ssa_op *op = ssa->ops + def;
224
46.7k
  zend_op *opline = op_array->opcodes + def;
225
226
46.7k
  if (op->result_def == var) {
227
42.3k
    switch (opline->opcode) {
228
766
      case ZEND_INIT_ARRAY:
229
11.1k
      case ZEND_ADD_ARRAY_ELEMENT:
230
11.1k
      case ZEND_QM_ASSIGN:
231
11.2k
      case ZEND_ASSIGN:
232
11.2k
        return true;
233
1.01k
      case ZEND_NEW: {
234
        /* objects with destructors should escape */
235
1.01k
        zend_class_entry *ce = zend_optimizer_get_class_entry_from_op1(
236
1.01k
          script, op_array, opline);
237
1.01k
        if (ce
238
919
         && !ce->create_object
239
751
         && ce->default_object_handlers->get_constructor == zend_std_get_constructor
240
751
         && ce->default_object_handlers->dtor_obj == zend_objects_destroy_object
241
751
         && !ce->constructor
242
702
         && !ce->destructor
243
700
         && !ce->__get
244
700
         && !ce->__set
245
700
         && !ce->parent) {
246
660
          return true;
247
660
        }
248
354
        break;
249
1.01k
      }
250
42.3k
    }
251
42.3k
  } else if (op->op1_def == var) {
252
4.16k
    switch (opline->opcode) {
253
1.77k
      case ZEND_ASSIGN:
254
2.68k
      case ZEND_ASSIGN_DIM:
255
2.99k
      case ZEND_ASSIGN_OBJ:
256
2.99k
      case ZEND_ASSIGN_OBJ_REF:
257
3.01k
      case ZEND_ASSIGN_DIM_OP:
258
3.09k
      case ZEND_ASSIGN_OBJ_OP:
259
3.09k
      case ZEND_PRE_INC_OBJ:
260
3.09k
      case ZEND_PRE_DEC_OBJ:
261
3.09k
      case ZEND_POST_INC_OBJ:
262
3.10k
      case ZEND_POST_DEC_OBJ:
263
3.10k
        return true;
264
4.16k
    }
265
4.16k
  }
266
267
31.7k
  return false;
268
46.7k
}
269
/* }}} */
270
271
static bool is_escape_use(zend_op_array *op_array, zend_ssa *ssa, int use, int var) /* {{{ */
272
4.50k
{
273
4.50k
  zend_ssa_op *ssa_op = ssa->ops + use;
274
4.50k
  zend_op *opline = op_array->opcodes + use;
275
276
4.50k
  if (ssa_op->op1_use == var) {
277
2.99k
    switch (opline->opcode) {
278
242
      case ZEND_ASSIGN:
279
        /* no_val */
280
242
        break;
281
0
      case ZEND_QM_ASSIGN:
282
0
        if (opline->op1_type == IS_CV) {
283
0
          if (OP1_INFO() & MAY_BE_OBJECT) {
284
            /* object aliasing */
285
0
            return true;
286
0
          }
287
0
        }
288
0
        break;
289
0
      case ZEND_ISSET_ISEMPTY_DIM_OBJ:
290
0
      case ZEND_ISSET_ISEMPTY_PROP_OBJ:
291
460
      case ZEND_FETCH_DIM_R:
292
562
      case ZEND_FETCH_OBJ_R:
293
642
      case ZEND_FETCH_DIM_IS:
294
646
      case ZEND_FETCH_OBJ_IS:
295
646
        break;
296
0
      case ZEND_ASSIGN_OP:
297
0
        return true;
298
2
      case ZEND_ASSIGN_DIM_OP:
299
104
      case ZEND_ASSIGN_OBJ_OP:
300
104
      case ZEND_ASSIGN_STATIC_PROP_OP:
301
996
      case ZEND_ASSIGN_DIM:
302
1.24k
      case ZEND_ASSIGN_OBJ:
303
1.25k
      case ZEND_ASSIGN_OBJ_REF:
304
1.25k
        break;
305
0
      case ZEND_PRE_INC_OBJ:
306
0
      case ZEND_PRE_DEC_OBJ:
307
0
      case ZEND_POST_INC_OBJ:
308
0
      case ZEND_POST_DEC_OBJ:
309
0
        break;
310
86
      case ZEND_INIT_ARRAY:
311
213
      case ZEND_ADD_ARRAY_ELEMENT:
312
213
        if (opline->extended_value & ZEND_ARRAY_ELEMENT_REF) {
313
0
          return true;
314
0
        }
315
213
        if (OP1_INFO() & MAY_BE_OBJECT) {
316
          /* object aliasing */
317
77
          return true;
318
77
        }
319
        /* reference dependencies processed separately */
320
136
        break;
321
136
      case ZEND_OP_DATA:
322
34
        if ((opline-1)->opcode != ZEND_ASSIGN_DIM
323
9
         && (opline-1)->opcode != ZEND_ASSIGN_OBJ) {
324
2
          return true;
325
2
        }
326
32
        if (OP1_INFO() & MAY_BE_OBJECT) {
327
          /* object aliasing */
328
8
          return true;
329
8
        }
330
24
        opline--;
331
24
        ssa_op--;
332
24
        if (opline->op1_type != IS_CV
333
20
         || (OP1_INFO() & MAY_BE_REF)
334
20
         || (ssa_op->op1_def >= 0 && ssa->vars[ssa_op->op1_def].alias)) {
335
          /* assignment into escaping structure */
336
4
          return true;
337
4
        }
338
        /* reference dependencies processed separately */
339
20
        break;
340
607
      default:
341
607
        return true;
342
2.99k
    }
343
2.99k
  }
344
345
3.81k
  if (ssa_op->op2_use == var) {
346
514
    switch (opline->opcode) {
347
448
      case ZEND_ASSIGN:
348
448
        if (opline->op1_type != IS_CV
349
436
         || (OP1_INFO() & MAY_BE_REF)
350
262
         || (ssa_op->op1_def >= 0 && ssa->vars[ssa_op->op1_def].alias)) {
351
          /* assignment into escaping variable */
352
186
          return true;
353
186
        }
354
262
        if (opline->op2_type == IS_CV || opline->result_type != IS_UNUSED) {
355
18
          if (OP2_INFO() & MAY_BE_OBJECT) {
356
            /* object aliasing */
357
14
            return true;
358
14
          }
359
18
        }
360
248
        break;
361
248
      default:
362
66
        return true;
363
514
    }
364
514
  }
365
366
3.54k
  if (ssa_op->result_use == var) {
367
997
    switch (opline->opcode) {
368
0
      case ZEND_ASSIGN:
369
0
      case ZEND_QM_ASSIGN:
370
0
      case ZEND_INIT_ARRAY:
371
997
      case ZEND_ADD_ARRAY_ELEMENT:
372
997
        break;
373
0
      default:
374
0
        return true;
375
997
    }
376
997
  }
377
378
3.54k
  return false;
379
3.54k
}
380
/* }}} */
381
382
zend_result zend_ssa_escape_analysis(const zend_script *script, zend_op_array *op_array, zend_ssa *ssa) /* {{{ */
383
6.78k
{
384
6.78k
  zend_ssa_var *ssa_vars = ssa->vars;
385
6.78k
  int ssa_vars_count = ssa->vars_count;
386
6.78k
  int i, root, use;
387
6.78k
  int *ees;
388
6.78k
  bool has_allocations;
389
6.78k
  int num_non_escaped;
390
6.78k
  ALLOCA_FLAG(use_heap)
391
392
6.78k
  if (!ssa_vars) {
393
0
    return SUCCESS;
394
0
  }
395
396
6.78k
  has_allocations = false;
397
389k
  for (i = op_array->last_var; i < ssa_vars_count; i++) {
398
383k
    if (ssa_vars[i].definition >= 0
399
308k
      && (ssa->var_info[i].type & (MAY_BE_ARRAY|MAY_BE_OBJECT))
400
90.9k
      && is_allocation_def(op_array, ssa, ssa_vars[i].definition, i, script)) {
401
999
      has_allocations = true;
402
999
      break;
403
999
    }
404
383k
  }
405
6.78k
  if (!has_allocations) {
406
5.78k
    return SUCCESS;
407
5.78k
  }
408
409
410
  /* 1. Build EES (Equi-Escape Sets) */
411
999
  ees = do_alloca(sizeof(int) * ssa_vars_count, use_heap);
412
999
  if (!ees) {
413
0
    return FAILURE;
414
0
  }
415
416
999
  if (zend_build_equi_escape_sets(ees, op_array, ssa) == FAILURE) {
417
0
    free_alloca(ees, use_heap);
418
0
    return FAILURE;
419
0
  }
420
421
  /* 2. Identify Allocations */
422
999
  num_non_escaped = 0;
423
216k
  for (i = op_array->last_var; i < ssa_vars_count; i++) {
424
215k
    root = ees[i];
425
215k
    if (ssa_vars[root].escape_state > ESCAPE_STATE_NO_ESCAPE) {
426
      /* already escape. skip */
427
197k
    } else if (ssa_vars[i].alias && (ssa->var_info[i].type & MAY_BE_REF)) {
428
0
      if (ssa_vars[root].escape_state == ESCAPE_STATE_NO_ESCAPE) {
429
0
        num_non_escaped--;
430
0
      }
431
0
      ssa_vars[root].escape_state = ESCAPE_STATE_GLOBAL_ESCAPE;
432
197k
    } else if (ssa_vars[i].definition >= 0
433
169k
       && (ssa->var_info[i].type & (MAY_BE_ARRAY|MAY_BE_OBJECT))) {
434
46.7k
      if (!is_local_def(op_array, ssa, ssa_vars[i].definition, i, script)) {
435
31.7k
        if (ssa_vars[root].escape_state == ESCAPE_STATE_NO_ESCAPE) {
436
457
          num_non_escaped--;
437
457
        }
438
31.7k
        ssa_vars[root].escape_state = ESCAPE_STATE_GLOBAL_ESCAPE;
439
31.7k
      } else if (ssa_vars[root].escape_state == ESCAPE_STATE_UNKNOWN
440
2.71k
       && is_allocation_def(op_array, ssa, ssa_vars[i].definition, i, script)) {
441
1.96k
        ssa_vars[root].escape_state = ESCAPE_STATE_NO_ESCAPE;
442
1.96k
        num_non_escaped++;
443
1.96k
      }
444
46.7k
    }
445
215k
  }
446
447
  /* 3. Mark escaped EES */
448
999
  if (num_non_escaped) {
449
135k
    for (i = 0; i < ssa_vars_count; i++) {
450
134k
      if (ssa_vars[i].use_chain >= 0) {
451
108k
        root = ees[i];
452
108k
        if (ssa_vars[root].escape_state == ESCAPE_STATE_NO_ESCAPE) {
453
8.39k
          FOREACH_USE(ssa_vars + i, use) {
454
8.39k
            if (is_escape_use(op_array, ssa, use, i)) {
455
964
              ssa_vars[root].escape_state = ESCAPE_STATE_GLOBAL_ESCAPE;
456
964
              num_non_escaped--;
457
964
              if (num_non_escaped == 0) {
458
424
                i = ssa_vars_count;
459
424
              }
460
964
              break;
461
964
            }
462
8.39k
          } FOREACH_USE_END();
463
3.88k
        }
464
108k
      }
465
134k
    }
466
638
  }
467
468
  /* 4. Process referential dependencies */
469
999
  if (num_non_escaped) {
470
214
    bool changed;
471
472
222
    do {
473
222
      changed = false;
474
20.8k
      for (i = 0; i < ssa_vars_count; i++) {
475
20.5k
        if (ssa_vars[i].use_chain >= 0) {
476
16.6k
          root = ees[i];
477
16.6k
          if (ssa_vars[root].escape_state == ESCAPE_STATE_NO_ESCAPE) {
478
5.32k
            FOREACH_USE(ssa_vars + i, use) {
479
5.32k
              zend_ssa_op *op = ssa->ops + use;
480
5.32k
              zend_op *opline = op_array->opcodes + use;
481
5.32k
              int enclosing_root;
482
483
5.32k
              if (opline->opcode == ZEND_OP_DATA &&
484
20
                  ((opline-1)->opcode == ZEND_ASSIGN_DIM ||
485
0
                   (opline-1)->opcode == ZEND_ASSIGN_OBJ ||
486
0
                   (opline-1)->opcode == ZEND_ASSIGN_OBJ_REF) &&
487
20
                  op->op1_use == i &&
488
20
                  (op-1)->op1_use >= 0) {
489
20
                enclosing_root = ees[(op-1)->op1_use];
490
2.88k
              } else if ((opline->opcode == ZEND_INIT_ARRAY ||
491
2.84k
                   opline->opcode == ZEND_ADD_ARRAY_ELEMENT) &&
492
868
                  op->op1_use == i &&
493
302
                  op->result_def >= 0) {
494
302
                enclosing_root = ees[op->result_def];
495
2.58k
              } else {
496
2.58k
                continue;
497
2.58k
              }
498
499
322
              if (ssa_vars[enclosing_root].escape_state == ESCAPE_STATE_UNKNOWN ||
500
322
                  ssa_vars[enclosing_root].escape_state > ssa_vars[root].escape_state) {
501
128
                  if (ssa_vars[enclosing_root].escape_state == ESCAPE_STATE_UNKNOWN) {
502
0
                  ssa_vars[root].escape_state = ESCAPE_STATE_GLOBAL_ESCAPE;
503
128
                  } else {
504
128
                  ssa_vars[root].escape_state = ssa_vars[enclosing_root].escape_state;
505
128
                }
506
128
                if (ssa_vars[root].escape_state == ESCAPE_STATE_GLOBAL_ESCAPE) {
507
128
                  num_non_escaped--;
508
128
                  if (num_non_escaped == 0) {
509
8
                    changed = false;
510
120
                  } else {
511
120
                    changed = true;
512
120
                  }
513
128
                  break;
514
128
                } else {
515
0
                  changed = true;
516
0
                }
517
128
              }
518
322
            } FOREACH_USE_END();
519
2.41k
          }
520
16.6k
        }
521
20.5k
      }
522
222
    } while (changed);
523
214
  }
524
525
  /* 5. Propagate values of escape sets to variables */
526
223k
  for (i = 0; i < ssa_vars_count; i++) {
527
222k
    root = ees[i];
528
222k
    if (i != root) {
529
77.4k
      ssa_vars[i].escape_state = ssa_vars[root].escape_state;
530
77.4k
    }
531
222k
  }
532
533
999
  free_alloca(ees, use_heap);
534
535
999
  return SUCCESS;
536
999
}
537
/* }}} */