Coverage Report

Created: 2025-12-31 07:28

next uncovered line (L), next uncovered region (R), next uncovered branch (B)
/src/php-src/Zend/Optimizer/zend_call_graph.c
Line
Count
Source
1
/*
2
   +----------------------------------------------------------------------+
3
   | Zend Engine, Call Graph                                              |
4
   +----------------------------------------------------------------------+
5
   | Copyright (c) The PHP Group                                          |
6
   +----------------------------------------------------------------------+
7
   | This source file is subject to version 3.01 of the PHP license,      |
8
   | that is bundled with this package in the file LICENSE, and is        |
9
   | available through the world-wide-web at the following url:           |
10
   | https://www.php.net/license/3_01.txt                                 |
11
   | If you did not receive a copy of the PHP license and are unable to   |
12
   | obtain it through the world-wide-web, please send a note to          |
13
   | license@php.net so we can mail you a copy immediately.               |
14
   +----------------------------------------------------------------------+
15
   | Authors: Dmitry Stogov <dmitry@php.net>                              |
16
   +----------------------------------------------------------------------+
17
*/
18
19
#include "zend_compile.h"
20
#include "zend_extensions.h"
21
#include "Optimizer/zend_optimizer.h"
22
#include "zend_optimizer_internal.h"
23
#include "zend_inference.h"
24
#include "zend_call_graph.h"
25
#include "zend_func_info.h"
26
#include "zend_inference.h"
27
#include "zend_call_graph.h"
28
29
static void zend_op_array_calc(zend_op_array *op_array, void *context)
30
17.0k
{
31
17.0k
  zend_call_graph *call_graph = context;
32
17.0k
  call_graph->op_arrays_count++;
33
17.0k
}
34
35
static void zend_op_array_collect(zend_op_array *op_array, void *context)
36
17.0k
{
37
17.0k
  zend_call_graph *call_graph = context;
38
17.0k
  zend_func_info *func_info = call_graph->func_infos + call_graph->op_arrays_count;
39
40
17.0k
  ZEND_SET_FUNC_INFO(op_array, func_info);
41
17.0k
  call_graph->op_arrays[call_graph->op_arrays_count] = op_array;
42
17.0k
  func_info->num = call_graph->op_arrays_count;
43
17.0k
  call_graph->op_arrays_count++;
44
17.0k
}
45
46
ZEND_API void zend_analyze_calls(zend_arena **arena, zend_script *script, uint32_t build_flags, zend_op_array *op_array, zend_func_info *func_info)
47
17.0k
{
48
17.0k
  zend_op *opline = op_array->opcodes;
49
17.0k
  zend_op *end = opline + op_array->last;
50
17.0k
  zend_function *func;
51
17.0k
  zend_call_info *call_info;
52
17.0k
  int call = 0;
53
17.0k
  zend_call_info **call_stack;
54
17.0k
  ALLOCA_FLAG(use_heap);
55
17.0k
  bool is_prototype;
56
57
17.0k
  call_stack = do_alloca((op_array->last / 2) * sizeof(zend_call_info*), use_heap);
58
17.0k
  call_info = NULL;
59
987k
  while (opline != end) {
60
970k
    switch (opline->opcode) {
61
19.8k
      case ZEND_INIT_FCALL:
62
33.7k
      case ZEND_INIT_METHOD_CALL:
63
34.7k
      case ZEND_INIT_STATIC_METHOD_CALL:
64
34.7k
      case ZEND_INIT_PARENT_PROPERTY_HOOK_CALL:
65
34.7k
        call_stack[call] = call_info;
66
34.7k
        func = zend_optimizer_get_called_func(
67
34.7k
          script, op_array, opline, &is_prototype);
68
34.7k
        if (func) {
69
20.6k
          call_info = zend_arena_calloc(arena, 1, sizeof(zend_call_info) + (sizeof(zend_send_arg_info) * ((int)opline->extended_value - 1)));
70
20.6k
          call_info->caller_op_array = op_array;
71
20.6k
          call_info->caller_init_opline = opline;
72
20.6k
          call_info->caller_call_opline = NULL;
73
20.6k
          call_info->callee_func = func;
74
20.6k
          call_info->num_args = opline->extended_value;
75
20.6k
          call_info->next_callee = func_info->callee_info;
76
20.6k
          call_info->is_prototype = is_prototype;
77
20.6k
          call_info->is_frameless = false;
78
20.6k
          func_info->callee_info = call_info;
79
80
20.6k
          if (build_flags & ZEND_CALL_TREE) {
81
0
            call_info->next_caller = NULL;
82
20.6k
          } else if (func->type == ZEND_INTERNAL_FUNCTION
83
17.1k
           || func->op_array.filename != script->filename) {
84
17.1k
            call_info->next_caller = NULL;
85
17.1k
          } else {
86
3.52k
            zend_func_info *callee_func_info = ZEND_FUNC_INFO(&func->op_array);
87
3.52k
            if (callee_func_info) {
88
3.52k
              call_info->next_caller = callee_func_info->caller_info;
89
3.52k
              callee_func_info->caller_info = call_info;
90
3.52k
            } else {
91
0
              call_info->next_caller = NULL;
92
0
            }
93
3.52k
          }
94
20.6k
        } else {
95
14.0k
          call_info = NULL;
96
14.0k
        }
97
34.7k
        call++;
98
34.7k
        break;
99
1.38k
      case ZEND_INIT_FCALL_BY_NAME:
100
1.72k
      case ZEND_INIT_NS_FCALL_BY_NAME:
101
2.28k
      case ZEND_INIT_DYNAMIC_CALL:
102
20.4k
      case ZEND_NEW:
103
20.5k
      case ZEND_INIT_USER_CALL:
104
20.5k
        call_stack[call] = call_info;
105
20.5k
        call_info = NULL;
106
20.5k
        call++;
107
20.5k
        break;
108
0
      case ZEND_FRAMELESS_ICALL_0:
109
0
      case ZEND_FRAMELESS_ICALL_1:
110
0
      case ZEND_FRAMELESS_ICALL_2:
111
0
      case ZEND_FRAMELESS_ICALL_3: {
112
0
        func = ZEND_FLF_FUNC(opline);
113
0
        zend_call_info *call_info = zend_arena_calloc(arena, 1, sizeof(zend_call_info));
114
0
        call_info->caller_op_array = op_array;
115
0
        call_info->caller_init_opline = opline;
116
0
        call_info->caller_call_opline = NULL;
117
0
        call_info->callee_func = func;
118
0
        call_info->num_args = ZEND_FLF_NUM_ARGS(opline->opcode);
119
0
        call_info->next_callee = func_info->callee_info;
120
0
        call_info->is_prototype = false;
121
0
        call_info->is_frameless = true;
122
0
        call_info->next_caller = NULL;
123
0
        func_info->callee_info = call_info;
124
0
        break;
125
0
      }
126
53.6k
      case ZEND_DO_FCALL:
127
53.6k
      case ZEND_DO_ICALL:
128
55.3k
      case ZEND_DO_UCALL:
129
55.3k
      case ZEND_DO_FCALL_BY_NAME:
130
55.3k
      case ZEND_CALLABLE_CONVERT:
131
55.3k
        func_info->flags |= ZEND_FUNC_HAS_CALLS;
132
55.3k
        if (call_info) {
133
20.6k
          call_info->caller_call_opline = opline;
134
20.6k
        }
135
55.3k
        call--;
136
55.3k
        call_info = call_stack[call];
137
55.3k
        break;
138
13.8k
      case ZEND_SEND_VAL:
139
48.3k
      case ZEND_SEND_VAR:
140
51.3k
      case ZEND_SEND_VAL_EX:
141
55.3k
      case ZEND_SEND_VAR_EX:
142
56.0k
      case ZEND_SEND_FUNC_ARG:
143
56.5k
      case ZEND_SEND_REF:
144
56.8k
      case ZEND_SEND_VAR_NO_REF:
145
57.3k
      case ZEND_SEND_VAR_NO_REF_EX:
146
57.4k
      case ZEND_SEND_USER:
147
57.4k
        if (call_info) {
148
22.4k
          if (opline->op2_type == IS_CONST) {
149
774
            call_info->named_args = true;
150
774
            break;
151
774
          }
152
153
21.6k
          uint32_t num = opline->op2.num;
154
21.6k
          if (num > 0) {
155
21.6k
            num--;
156
21.6k
          }
157
21.6k
          call_info->arg_info[num].opline = opline;
158
21.6k
        }
159
56.6k
        break;
160
56.6k
      case ZEND_SEND_ARRAY:
161
78
      case ZEND_SEND_UNPACK:
162
78
        if (call_info) {
163
2
          call_info->send_unpack = true;
164
2
        }
165
78
        break;
166
970k
    }
167
970k
    opline++;
168
970k
  }
169
17.0k
  free_alloca(call_stack, use_heap);
170
17.0k
}
171
172
static bool zend_is_indirectly_recursive(const zend_op_array *root, const zend_op_array *op_array, zend_bitset visited)
173
4.01k
{
174
4.01k
  const zend_func_info *func_info;
175
4.01k
  zend_call_info *call_info;
176
4.01k
  bool ret = false;
177
178
4.01k
  if (op_array == root) {
179
0
    return true;
180
0
  }
181
182
4.01k
  func_info = ZEND_FUNC_INFO(op_array);
183
4.01k
  if (zend_bitset_in(visited, func_info->num)) {
184
486
    return false;
185
486
  }
186
3.53k
  zend_bitset_incl(visited, func_info->num);
187
3.53k
  call_info = func_info->caller_info;
188
4.12k
  while (call_info) {
189
592
    if (zend_is_indirectly_recursive(root, call_info->caller_op_array, visited)) {
190
0
      call_info->recursive = true;
191
0
      ret = true;
192
0
    }
193
592
    call_info = call_info->next_caller;
194
592
  }
195
3.53k
  return ret;
196
4.01k
}
197
198
static void zend_analyze_recursion(zend_call_graph *call_graph)
199
12.1k
{
200
12.1k
  const zend_op_array *op_array;
201
12.1k
  zend_func_info *func_info;
202
12.1k
  zend_call_info *call_info;
203
12.1k
  uint32_t set_len = zend_bitset_len(call_graph->op_arrays_count);
204
12.1k
  zend_bitset visited;
205
12.1k
  ALLOCA_FLAG(use_heap);
206
207
12.1k
  visited = ZEND_BITSET_ALLOCA(set_len, use_heap);
208
29.2k
  for (uint32_t i = 0; i < call_graph->op_arrays_count; i++) {
209
17.0k
    op_array = call_graph->op_arrays[i];
210
17.0k
    func_info = call_graph->func_infos + i;
211
17.0k
    call_info = func_info->caller_info;
212
20.5k
    for (; call_info; call_info = call_info->next_caller) {
213
3.52k
      if (call_info->is_prototype) {
214
        /* Might be calling an overridden child method and not actually recursive. */
215
100
        continue;
216
100
      }
217
3.42k
      if (call_info->caller_op_array == op_array) {
218
0
        call_info->recursive = true;
219
0
        func_info->flags |= ZEND_FUNC_RECURSIVE | ZEND_FUNC_RECURSIVE_DIRECTLY;
220
3.42k
      } else {
221
3.42k
        memset(visited, 0, sizeof(zend_ulong) * set_len);
222
3.42k
        if (zend_is_indirectly_recursive(op_array, call_info->caller_op_array, visited)) {
223
0
          call_info->recursive = true;
224
0
          func_info->flags |= ZEND_FUNC_RECURSIVE | ZEND_FUNC_RECURSIVE_INDIRECTLY;
225
0
        }
226
3.42k
      }
227
3.42k
    }
228
17.0k
  }
229
230
12.1k
  free_alloca(visited, use_heap);
231
12.1k
}
232
233
static void zend_sort_op_arrays(zend_call_graph *call_graph)
234
12.1k
{
235
12.1k
  (void) call_graph;
236
237
  // TODO: perform topological sort of cyclic call graph
238
12.1k
}
239
240
ZEND_API void zend_build_call_graph(zend_arena **arena, zend_script *script, zend_call_graph *call_graph) /* {{{ */
241
12.1k
{
242
12.1k
  call_graph->op_arrays_count = 0;
243
12.1k
  zend_foreach_op_array(script, zend_op_array_calc, call_graph);
244
245
12.1k
  call_graph->op_arrays = (zend_op_array**)zend_arena_calloc(arena, call_graph->op_arrays_count, sizeof(zend_op_array*));
246
12.1k
  call_graph->func_infos = (zend_func_info*)zend_arena_calloc(arena, call_graph->op_arrays_count, sizeof(zend_func_info));
247
12.1k
  call_graph->op_arrays_count = 0;
248
12.1k
  zend_foreach_op_array(script, zend_op_array_collect, call_graph);
249
12.1k
}
250
/* }}} */
251
252
ZEND_API void zend_analyze_call_graph(zend_arena **arena, zend_script *script, zend_call_graph *call_graph) /* {{{ */
253
12.1k
{
254
29.2k
  for (uint32_t i = 0; i < call_graph->op_arrays_count; i++) {
255
17.0k
    zend_analyze_calls(arena, script, 0, call_graph->op_arrays[i], call_graph->func_infos + i);
256
17.0k
  }
257
12.1k
  zend_analyze_recursion(call_graph);
258
12.1k
  zend_sort_op_arrays(call_graph);
259
12.1k
}
260
/* }}} */
261
262
ZEND_API zend_call_info **zend_build_call_map(zend_arena **arena, const zend_func_info *info, const zend_op_array *op_array) /* {{{ */
263
17.0k
{
264
17.0k
  zend_call_info **map, *call;
265
17.0k
  if (!info->callee_info) {
266
    /* Don't build call map if function contains no calls */
267
11.3k
    return NULL;
268
11.3k
  }
269
270
5.73k
  map = zend_arena_calloc(arena, sizeof(zend_call_info *), op_array->last);
271
26.4k
  for (call = info->callee_info; call; call = call->next_callee) {
272
20.6k
    map[call->caller_init_opline - op_array->opcodes] = call;
273
20.6k
    if (call->caller_call_opline) {
274
20.6k
      map[call->caller_call_opline - op_array->opcodes] = call;
275
20.6k
    }
276
20.6k
    if (!call->is_frameless) {
277
42.3k
      for (uint32_t i = 0; i < call->num_args; i++) {
278
21.6k
        if (call->arg_info[i].opline) {
279
21.6k
          map[call->arg_info[i].opline - op_array->opcodes] = call;
280
21.6k
        }
281
21.6k
      }
282
20.6k
    }
283
20.6k
  }
284
5.73k
  return map;
285
17.0k
}
286
/* }}} */