Coverage Report

Created: 2025-12-31 07:28

next uncovered line (L), next uncovered region (R), next uncovered branch (B)
/src/php-src/Zend/Optimizer/zend_optimizer.c
Line
Count
Source
1
/*
2
   +----------------------------------------------------------------------+
3
   | Zend OPcache                                                         |
4
   +----------------------------------------------------------------------+
5
   | Copyright (c) The PHP Group                                          |
6
   +----------------------------------------------------------------------+
7
   | This source file is subject to version 3.01 of the PHP license,      |
8
   | that is bundled with this package in the file LICENSE, and is        |
9
   | available through the world-wide-web at the following url:           |
10
   | https://www.php.net/license/3_01.txt                                 |
11
   | If you did not receive a copy of the PHP license and are unable to   |
12
   | obtain it through the world-wide-web, please send a note to          |
13
   | license@php.net so we can mail you a copy immediately.               |
14
   +----------------------------------------------------------------------+
15
   | Authors: Andi Gutmans <andi@php.net>                                 |
16
   |          Zeev Suraski <zeev@php.net>                                 |
17
   |          Stanislav Malyshev <stas@zend.com>                          |
18
   |          Dmitry Stogov <dmitry@php.net>                              |
19
   +----------------------------------------------------------------------+
20
*/
21
22
#include "Optimizer/zend_optimizer.h"
23
#include "Optimizer/zend_optimizer_internal.h"
24
#include "zend_API.h"
25
#include "zend_constants.h"
26
#include "zend_execute.h"
27
#include "zend_vm.h"
28
#include "zend_cfg.h"
29
#include "zend_func_info.h"
30
#include "zend_call_graph.h"
31
#include "zend_inference.h"
32
#include "zend_dump.h"
33
#include "php.h"
34
35
#ifndef ZEND_OPTIMIZER_MAX_REGISTERED_PASSES
36
0
# define ZEND_OPTIMIZER_MAX_REGISTERED_PASSES 32
37
#endif
38
39
struct {
40
  zend_optimizer_pass_t pass[ZEND_OPTIMIZER_MAX_REGISTERED_PASSES];
41
  int last;
42
} zend_optimizer_registered_passes = {{NULL}, 0};
43
44
void zend_optimizer_collect_constant(zend_optimizer_ctx *ctx, const zval *name, zval* value)
45
0
{
46
0
  if (!ctx->constants) {
47
0
    ctx->constants = zend_arena_alloc(&ctx->arena, sizeof(HashTable));
48
0
    zend_hash_init(ctx->constants, 16, NULL, zval_ptr_dtor_nogc, 0);
49
0
  }
50
51
0
  if (zend_hash_add(ctx->constants, Z_STR_P(name), value)) {
52
0
    Z_TRY_ADDREF_P(value);
53
0
  }
54
0
}
55
56
zend_result zend_optimizer_eval_binary_op(zval *result, uint8_t opcode, zval *op1, zval *op2) /* {{{ */
57
14.2k
{
58
14.2k
  if (zend_binary_op_produces_error(opcode, op1, op2)) {
59
13.6k
    return FAILURE;
60
13.6k
  }
61
62
675
  binary_op_type binary_op = get_binary_op(opcode);
63
675
  return binary_op(result, op1, op2);
64
14.2k
}
65
/* }}} */
66
67
zend_result zend_optimizer_eval_unary_op(zval *result, uint8_t opcode, zval *op1) /* {{{ */
68
1.68k
{
69
1.68k
  unary_op_type unary_op = get_unary_op(opcode);
70
71
1.68k
  if (unary_op) {
72
156
    if (zend_unary_op_produces_error(opcode, op1)) {
73
144
      return FAILURE;
74
144
    }
75
12
    return unary_op(result, op1);
76
1.53k
  } else { /* ZEND_BOOL */
77
1.53k
    if (Z_TYPE_P(op1) == IS_DOUBLE && zend_isnan(Z_DVAL_P(op1))) {
78
0
      return FAILURE;
79
0
    }
80
1.53k
    ZVAL_BOOL(result, zend_is_true(op1));
81
1.53k
    return SUCCESS;
82
1.53k
  }
83
1.68k
}
84
/* }}} */
85
86
zend_result zend_optimizer_eval_cast(zval *result, uint32_t type, zval *op1) /* {{{ */
87
6.03k
{
88
6.03k
  if (zend_try_ct_eval_cast(result, type, op1)) {
89
5.98k
    return SUCCESS;
90
5.98k
  }
91
50
  return FAILURE;
92
6.03k
}
93
/* }}} */
94
95
zend_result zend_optimizer_eval_strlen(zval *result, const zval *op1) /* {{{ */
96
10
{
97
10
  if (Z_TYPE_P(op1) != IS_STRING) {
98
0
    return FAILURE;
99
0
  }
100
10
  ZVAL_LONG(result, Z_STRLEN_P(op1));
101
10
  return SUCCESS;
102
10
}
103
/* }}} */
104
105
zend_result zend_optimizer_eval_special_func_call(
106
0
    zval *result, const zend_string *name, zend_string *arg) {
107
0
  if (zend_string_equals_literal(name, "function_exists") ||
108
0
      zend_string_equals_literal(name, "is_callable")) {
109
0
    zend_string *lc_name = zend_string_tolower(arg);
110
0
    const zend_internal_function *func = zend_hash_find_ptr(EG(function_table), lc_name);
111
0
    zend_string_release_ex(lc_name, 0);
112
113
0
    if (func && func->type == ZEND_INTERNAL_FUNCTION
114
0
        && func->module->type == MODULE_PERSISTENT
115
#ifdef ZEND_WIN32
116
        && func->module->handle == NULL
117
#endif
118
0
    ) {
119
0
      ZVAL_TRUE(result);
120
0
      return SUCCESS;
121
0
    }
122
0
    return FAILURE;
123
0
  }
124
0
  if (zend_string_equals_literal(name, "extension_loaded")) {
125
0
    zend_string *lc_name = zend_string_tolower(arg);
126
0
    zend_module_entry *m = zend_hash_find_ptr(&module_registry, lc_name);
127
0
    zend_string_release_ex(lc_name, 0);
128
129
0
    if (!m) {
130
0
      if (PG(enable_dl)) {
131
0
        return FAILURE;
132
0
      }
133
0
      ZVAL_FALSE(result);
134
0
      return SUCCESS;
135
0
    }
136
137
0
    if (m->type == MODULE_PERSISTENT
138
#ifdef ZEND_WIN32
139
      && m->handle == NULL
140
#endif
141
0
    ) {
142
0
      ZVAL_TRUE(result);
143
0
      return SUCCESS;
144
0
    }
145
0
    return FAILURE;
146
0
  }
147
0
  if (zend_string_equals_literal(name, "constant")) {
148
0
    return zend_optimizer_get_persistent_constant(arg, result, true) ? SUCCESS : FAILURE;
149
0
  }
150
0
  if (zend_string_equals_literal(name, "dirname")) {
151
0
    if (!IS_ABSOLUTE_PATH(ZSTR_VAL(arg), ZSTR_LEN(arg))) {
152
0
      return FAILURE;
153
0
    }
154
155
0
    zend_string *dirname = zend_string_init(ZSTR_VAL(arg), ZSTR_LEN(arg), 0);
156
0
    ZSTR_LEN(dirname) = zend_dirname(ZSTR_VAL(dirname), ZSTR_LEN(dirname));
157
0
    if (IS_ABSOLUTE_PATH(ZSTR_VAL(dirname), ZSTR_LEN(dirname))) {
158
0
      ZVAL_STR(result, dirname);
159
0
      return SUCCESS;
160
0
    }
161
0
    zend_string_release_ex(dirname, 0);
162
0
    return FAILURE;
163
0
  }
164
0
  if (zend_string_equals_literal(name, "ini_get")) {
165
0
    zend_ini_entry *ini_entry = zend_hash_find_ptr(EG(ini_directives), arg);
166
0
    if (!ini_entry) {
167
0
      if (PG(enable_dl)) {
168
0
        return FAILURE;
169
0
      }
170
0
      ZVAL_FALSE(result);
171
0
    } else if (ini_entry->modifiable != ZEND_INI_SYSTEM) {
172
0
      return FAILURE;
173
0
    } else if (ini_entry->value) {
174
0
      ZVAL_STR_COPY(result, ini_entry->value);
175
0
    } else {
176
0
      ZVAL_EMPTY_STRING(result);
177
0
    }
178
0
    return SUCCESS;
179
0
  }
180
0
  return FAILURE;
181
0
}
182
183
bool zend_optimizer_get_collected_constant(const HashTable *constants, const zval *name, zval* value)
184
0
{
185
0
  zval *val;
186
187
0
  if ((val = zend_hash_find(constants, Z_STR_P(name))) != NULL) {
188
0
    ZVAL_COPY(value, val);
189
0
    return true;
190
0
  }
191
0
  return false;
192
0
}
193
194
void zend_optimizer_convert_to_free_op1(const zend_op_array *op_array, zend_op *opline)
195
2.50k
{
196
2.50k
  if (opline->op1_type == IS_CV) {
197
0
    opline->opcode = ZEND_CHECK_VAR;
198
0
    SET_UNUSED(opline->op2);
199
0
    SET_UNUSED(opline->result);
200
0
    opline->extended_value = 0;
201
2.50k
  } else if (opline->op1_type & (IS_TMP_VAR|IS_VAR)) {
202
1.57k
    opline->opcode = ZEND_FREE;
203
1.57k
    SET_UNUSED(opline->op2);
204
1.57k
    SET_UNUSED(opline->result);
205
1.57k
    opline->extended_value = 0;
206
1.57k
  } else {
207
926
    ZEND_ASSERT(opline->op1_type == IS_CONST);
208
926
    literal_dtor(&ZEND_OP1_LITERAL(opline));
209
926
    MAKE_NOP(opline);
210
926
  }
211
2.50k
}
212
213
uint32_t zend_optimizer_add_literal(zend_op_array *op_array, const zval *zv)
214
8.13k
{
215
8.13k
  uint32_t i = op_array->last_literal;
216
8.13k
  op_array->last_literal++;
217
8.13k
  op_array->literals = (zval*)erealloc(op_array->literals, op_array->last_literal * sizeof(zval));
218
8.13k
  ZVAL_COPY_VALUE(&op_array->literals[i], zv);
219
8.13k
  Z_EXTRA(op_array->literals[i]) = 0;
220
8.13k
  return i;
221
8.13k
}
222
223
0
static inline uint32_t zend_optimizer_add_literal_string(zend_op_array *op_array, zend_string *str) {
224
0
  zval zv;
225
0
  ZVAL_STR(&zv, str);
226
0
  zend_string_hash_val(str);
227
0
  return zend_optimizer_add_literal(op_array, &zv);
228
0
}
229
230
0
static inline void drop_leading_backslash(zval *val) {
231
0
  if (Z_STRVAL_P(val)[0] == '\\') {
232
0
    zend_string *str = zend_string_init(Z_STRVAL_P(val) + 1, Z_STRLEN_P(val) - 1, 0);
233
0
    zval_ptr_dtor_nogc(val);
234
0
    ZVAL_STR(val, str);
235
0
  }
236
0
}
237
238
50
static inline uint32_t alloc_cache_slots(zend_op_array *op_array, uint32_t num) {
239
50
  uint32_t ret = op_array->cache_size;
240
50
  op_array->cache_size += num * sizeof(void *);
241
50
  return ret;
242
50
}
243
244
0
#define REQUIRES_STRING(val) do { \
245
0
  if (Z_TYPE_P(val) != IS_STRING) { \
246
0
    return 0; \
247
0
  } \
248
0
} while (0)
249
250
282
#define TO_STRING_NOWARN(val) do { \
251
282
  if (Z_TYPE_P(val) >= IS_ARRAY) { \
252
0
    return 0; \
253
0
  } \
254
282
  convert_to_string(val); \
255
282
} while (0)
256
257
bool zend_optimizer_update_op1_const(zend_op_array *op_array,
258
                                    zend_op       *opline,
259
                                    zval          *val)
260
4.94k
{
261
4.94k
  switch (opline->opcode) {
262
193
    case ZEND_OP_DATA:
263
193
      switch ((opline-1)->opcode) {
264
0
        case ZEND_ASSIGN_OBJ_REF:
265
0
        case ZEND_ASSIGN_STATIC_PROP_REF:
266
0
          return false;
267
193
      }
268
193
      opline->op1.constant = zend_optimizer_add_literal(op_array, val);
269
193
      break;
270
138
    case ZEND_FREE:
271
138
    case ZEND_CHECK_VAR:
272
138
      MAKE_NOP(opline);
273
138
      zval_ptr_dtor_nogc(val);
274
138
      return true;
275
0
    case ZEND_SEND_VAR_EX:
276
0
    case ZEND_SEND_FUNC_ARG:
277
0
    case ZEND_FETCH_DIM_W:
278
0
    case ZEND_FETCH_DIM_RW:
279
0
    case ZEND_FETCH_DIM_FUNC_ARG:
280
0
    case ZEND_FETCH_DIM_UNSET:
281
0
    case ZEND_FETCH_LIST_W:
282
0
    case ZEND_ASSIGN_DIM:
283
8
    case ZEND_RETURN_BY_REF:
284
8
    case ZEND_INSTANCEOF:
285
8
    case ZEND_MAKE_REF:
286
8
    case ZEND_SEPARATE:
287
8
    case ZEND_SEND_VAR_NO_REF:
288
8
    case ZEND_SEND_VAR_NO_REF_EX:
289
8
      return false;
290
0
    case ZEND_CATCH:
291
0
      REQUIRES_STRING(val);
292
0
      drop_leading_backslash(val);
293
0
      opline->op1.constant = zend_optimizer_add_literal(op_array, val);
294
0
      opline->extended_value = alloc_cache_slots(op_array, 1) | (opline->extended_value & ZEND_LAST_CATCH);
295
0
      zend_optimizer_add_literal_string(op_array, zend_string_tolower(Z_STR_P(val)));
296
0
      break;
297
0
    case ZEND_DEFINED:
298
0
      REQUIRES_STRING(val);
299
0
      drop_leading_backslash(val);
300
0
      opline->op1.constant = zend_optimizer_add_literal(op_array, val);
301
0
      opline->extended_value = alloc_cache_slots(op_array, 1);
302
0
      zend_optimizer_add_literal_string(op_array, zend_string_tolower(Z_STR_P(val)));
303
0
      break;
304
0
    case ZEND_NEW:
305
0
      REQUIRES_STRING(val);
306
0
      drop_leading_backslash(val);
307
0
      opline->op1.constant = zend_optimizer_add_literal(op_array, val);
308
0
      opline->op2.num = alloc_cache_slots(op_array, 1);
309
0
      zend_optimizer_add_literal_string(op_array, zend_string_tolower(Z_STR_P(val)));
310
0
      break;
311
0
    case ZEND_INIT_STATIC_METHOD_CALL:
312
0
      REQUIRES_STRING(val);
313
0
      drop_leading_backslash(val);
314
0
      opline->op1.constant = zend_optimizer_add_literal(op_array, val);
315
0
      if (opline->op2_type != IS_CONST) {
316
0
        opline->result.num = alloc_cache_slots(op_array, 1);
317
0
      }
318
0
      zend_optimizer_add_literal_string(op_array, zend_string_tolower(Z_STR_P(val)));
319
0
      break;
320
0
    case ZEND_FETCH_CLASS_CONSTANT:
321
0
      REQUIRES_STRING(val);
322
0
      drop_leading_backslash(val);
323
0
      opline->op1.constant = zend_optimizer_add_literal(op_array, val);
324
0
      if (opline->op2_type != IS_CONST) {
325
0
        opline->extended_value = alloc_cache_slots(op_array, 1);
326
0
      }
327
0
      zend_optimizer_add_literal_string(op_array, zend_string_tolower(Z_STR_P(val)));
328
0
      break;
329
0
    case ZEND_ASSIGN_OP:
330
0
    case ZEND_ASSIGN_DIM_OP:
331
0
    case ZEND_ASSIGN_OBJ_OP:
332
0
      break;
333
0
    case ZEND_ASSIGN_STATIC_PROP_OP:
334
0
    case ZEND_ASSIGN_STATIC_PROP:
335
0
    case ZEND_ASSIGN_STATIC_PROP_REF:
336
0
    case ZEND_FETCH_STATIC_PROP_R:
337
0
    case ZEND_FETCH_STATIC_PROP_W:
338
0
    case ZEND_FETCH_STATIC_PROP_RW:
339
0
    case ZEND_FETCH_STATIC_PROP_IS:
340
0
    case ZEND_FETCH_STATIC_PROP_UNSET:
341
0
    case ZEND_FETCH_STATIC_PROP_FUNC_ARG:
342
0
    case ZEND_UNSET_STATIC_PROP:
343
0
    case ZEND_ISSET_ISEMPTY_STATIC_PROP:
344
0
    case ZEND_PRE_INC_STATIC_PROP:
345
0
    case ZEND_PRE_DEC_STATIC_PROP:
346
0
    case ZEND_POST_INC_STATIC_PROP:
347
0
    case ZEND_POST_DEC_STATIC_PROP:
348
0
      TO_STRING_NOWARN(val);
349
0
      opline->op1.constant = zend_optimizer_add_literal(op_array, val);
350
0
      if (opline->op2_type == IS_CONST && (opline->extended_value & ~ZEND_FETCH_OBJ_FLAGS) + sizeof(void*) == op_array->cache_size) {
351
0
        op_array->cache_size += sizeof(void *);
352
0
      } else {
353
0
        opline->extended_value = alloc_cache_slots(op_array, 3) | (opline->extended_value & ZEND_FETCH_OBJ_FLAGS);
354
0
      }
355
0
      break;
356
34
    case ZEND_SEND_VAR:
357
34
      opline->opcode = ZEND_SEND_VAL;
358
34
      opline->op1.constant = zend_optimizer_add_literal(op_array, val);
359
34
      break;
360
0
    case ZEND_CASE:
361
0
      opline->opcode = ZEND_IS_EQUAL;
362
0
      opline->op1.constant = zend_optimizer_add_literal(op_array, val);
363
0
      break;
364
0
    case ZEND_CASE_STRICT:
365
0
      opline->opcode = ZEND_IS_IDENTICAL;
366
0
      opline->op1.constant = zend_optimizer_add_literal(op_array, val);
367
0
      break;
368
0
    case ZEND_VERIFY_RETURN_TYPE:
369
      /* This would require a non-local change.
370
       * zend_optimizer_replace_by_const() supports this. */
371
0
      return false;
372
12
    case ZEND_COPY_TMP:
373
12
    case ZEND_FETCH_CLASS_NAME:
374
12
      return false;
375
478
    case ZEND_ECHO:
376
478
    {
377
478
      zval zv;
378
478
      if (Z_TYPE_P(val) != IS_STRING && zend_optimizer_eval_cast(&zv, IS_STRING, val) == SUCCESS) {
379
0
        zval_ptr_dtor_nogc(val);
380
0
        val = &zv;
381
0
      }
382
478
      opline->op1.constant = zend_optimizer_add_literal(op_array, val);
383
478
      if (Z_TYPE_P(val) == IS_STRING && Z_STRLEN_P(val) == 0) {
384
0
        MAKE_NOP(opline);
385
0
        return true;
386
0
      }
387
      /* TODO: In a subsequent pass, *after* this step and compacting nops, combine consecutive ZEND_ECHOs using the block information from ssa->cfg */
388
      /* (e.g. for ext/opcache/tests/opt/sccp_010.phpt) */
389
478
      break;
390
478
    }
391
478
    case ZEND_CONCAT:
392
8
    case ZEND_FAST_CONCAT:
393
8
    case ZEND_FETCH_R:
394
8
    case ZEND_FETCH_W:
395
8
    case ZEND_FETCH_RW:
396
8
    case ZEND_FETCH_IS:
397
8
    case ZEND_FETCH_UNSET:
398
8
    case ZEND_FETCH_FUNC_ARG:
399
8
    case ZEND_ISSET_ISEMPTY_VAR:
400
8
    case ZEND_UNSET_VAR:
401
8
      TO_STRING_NOWARN(val);
402
8
      if (opline->opcode == ZEND_CONCAT && opline->op2_type == IS_CONST) {
403
8
        opline->opcode = ZEND_FAST_CONCAT;
404
8
      }
405
8
      ZEND_FALLTHROUGH;
406
4.07k
    default:
407
4.07k
      opline->op1.constant = zend_optimizer_add_literal(op_array, val);
408
4.07k
      break;
409
4.94k
  }
410
411
4.78k
  opline->op1_type = IS_CONST;
412
4.78k
  if (Z_TYPE(ZEND_OP1_LITERAL(opline)) == IS_STRING) {
413
783
    zend_string_hash_val(Z_STR(ZEND_OP1_LITERAL(opline)));
414
783
  }
415
4.78k
  return true;
416
4.94k
}
417
418
bool zend_optimizer_update_op2_const(zend_op_array *op_array,
419
                                    zend_op       *opline,
420
                                    zval          *val)
421
1.24k
{
422
1.24k
  zval tmp;
423
424
1.24k
  switch (opline->opcode) {
425
12
    case ZEND_ASSIGN_REF:
426
12
    case ZEND_FAST_CALL:
427
12
      return false;
428
0
    case ZEND_FETCH_CLASS:
429
0
    case ZEND_INSTANCEOF:
430
0
      REQUIRES_STRING(val);
431
0
      drop_leading_backslash(val);
432
0
      opline->op2.constant = zend_optimizer_add_literal(op_array, val);
433
0
      zend_optimizer_add_literal_string(op_array, zend_string_tolower(Z_STR_P(val)));
434
0
      opline->extended_value = alloc_cache_slots(op_array, 1);
435
0
      break;
436
0
    case ZEND_INIT_FCALL_BY_NAME:
437
0
      REQUIRES_STRING(val);
438
0
      drop_leading_backslash(val);
439
0
      opline->op2.constant = zend_optimizer_add_literal(op_array, val);
440
0
      zend_optimizer_add_literal_string(op_array, zend_string_tolower(Z_STR_P(val)));
441
0
      opline->result.num = alloc_cache_slots(op_array, 1);
442
0
      break;
443
0
    case ZEND_ASSIGN_STATIC_PROP:
444
0
    case ZEND_ASSIGN_STATIC_PROP_REF:
445
0
    case ZEND_FETCH_STATIC_PROP_R:
446
0
    case ZEND_FETCH_STATIC_PROP_W:
447
0
    case ZEND_FETCH_STATIC_PROP_RW:
448
0
    case ZEND_FETCH_STATIC_PROP_IS:
449
0
    case ZEND_FETCH_STATIC_PROP_UNSET:
450
0
    case ZEND_FETCH_STATIC_PROP_FUNC_ARG:
451
0
    case ZEND_UNSET_STATIC_PROP:
452
0
    case ZEND_ISSET_ISEMPTY_STATIC_PROP:
453
0
    case ZEND_PRE_INC_STATIC_PROP:
454
0
    case ZEND_PRE_DEC_STATIC_PROP:
455
0
    case ZEND_POST_INC_STATIC_PROP:
456
0
    case ZEND_POST_DEC_STATIC_PROP:
457
0
    case ZEND_ASSIGN_STATIC_PROP_OP:
458
0
      REQUIRES_STRING(val);
459
0
      drop_leading_backslash(val);
460
0
      opline->op2.constant = zend_optimizer_add_literal(op_array, val);
461
0
      zend_optimizer_add_literal_string(op_array, zend_string_tolower(Z_STR_P(val)));
462
0
      if (opline->op1_type != IS_CONST) {
463
0
        opline->extended_value = alloc_cache_slots(op_array, 1) | (opline->extended_value & (ZEND_RETURNS_FUNCTION|ZEND_ISEMPTY|ZEND_FETCH_OBJ_FLAGS));
464
0
      }
465
0
      break;
466
0
    case ZEND_INIT_FCALL:
467
0
      REQUIRES_STRING(val);
468
0
      if (Z_REFCOUNT_P(val) == 1) {
469
0
        zend_str_tolower(Z_STRVAL_P(val), Z_STRLEN_P(val));
470
0
      } else {
471
0
        ZVAL_STR(&tmp, zend_string_tolower(Z_STR_P(val)));
472
0
        zval_ptr_dtor_nogc(val);
473
0
        val = &tmp;
474
0
      }
475
0
      opline->op2.constant = zend_optimizer_add_literal(op_array, val);
476
0
      opline->result.num = alloc_cache_slots(op_array, 1);
477
0
      break;
478
4
    case ZEND_INIT_DYNAMIC_CALL:
479
4
      if (Z_TYPE_P(val) == IS_STRING) {
480
0
        if (zend_memrchr(Z_STRVAL_P(val), ':', Z_STRLEN_P(val))) {
481
0
          return false;
482
0
        }
483
484
0
        if (zend_optimizer_classify_function(Z_STR_P(val), opline->extended_value)) {
485
          /* Dynamic call to various special functions must stay dynamic,
486
           * otherwise would drop a warning */
487
0
          return false;
488
0
        }
489
490
0
        opline->opcode = ZEND_INIT_FCALL_BY_NAME;
491
0
        drop_leading_backslash(val);
492
0
        opline->op2.constant = zend_optimizer_add_literal(op_array, val);
493
0
        zend_optimizer_add_literal_string(op_array, zend_string_tolower(Z_STR_P(val)));
494
0
        opline->result.num = alloc_cache_slots(op_array, 1);
495
4
      } else {
496
4
        opline->op2.constant = zend_optimizer_add_literal(op_array, val);
497
4
      }
498
4
      break;
499
4
    case ZEND_INIT_METHOD_CALL:
500
0
      REQUIRES_STRING(val);
501
0
      opline->op2.constant = zend_optimizer_add_literal(op_array, val);
502
0
      zend_optimizer_add_literal_string(op_array, zend_string_tolower(Z_STR_P(val)));
503
0
      opline->result.num = alloc_cache_slots(op_array, 2);
504
0
      break;
505
0
    case ZEND_INIT_STATIC_METHOD_CALL:
506
0
      REQUIRES_STRING(val);
507
0
      opline->op2.constant = zend_optimizer_add_literal(op_array, val);
508
0
      zend_optimizer_add_literal_string(op_array, zend_string_tolower(Z_STR_P(val)));
509
0
      if (opline->op1_type != IS_CONST) {
510
0
        opline->result.num = alloc_cache_slots(op_array, 2);
511
0
      }
512
0
      break;
513
0
    case ZEND_ASSIGN_OBJ:
514
0
    case ZEND_ASSIGN_OBJ_REF:
515
0
    case ZEND_FETCH_OBJ_R:
516
2
    case ZEND_FETCH_OBJ_W:
517
2
    case ZEND_FETCH_OBJ_RW:
518
2
    case ZEND_FETCH_OBJ_IS:
519
2
    case ZEND_FETCH_OBJ_UNSET:
520
2
    case ZEND_FETCH_OBJ_FUNC_ARG:
521
2
    case ZEND_UNSET_OBJ:
522
2
    case ZEND_PRE_INC_OBJ:
523
2
    case ZEND_PRE_DEC_OBJ:
524
2
    case ZEND_POST_INC_OBJ:
525
2
    case ZEND_POST_DEC_OBJ:
526
2
      TO_STRING_NOWARN(val);
527
2
      opline->op2.constant = zend_optimizer_add_literal(op_array, val);
528
2
      opline->extended_value = alloc_cache_slots(op_array, 3);
529
2
      break;
530
48
    case ZEND_ASSIGN_OBJ_OP:
531
48
      TO_STRING_NOWARN(val);
532
48
      opline->op2.constant = zend_optimizer_add_literal(op_array, val);
533
48
      ZEND_ASSERT((opline + 1)->opcode == ZEND_OP_DATA);
534
48
      (opline + 1)->extended_value = alloc_cache_slots(op_array, 3);
535
48
      break;
536
0
    case ZEND_ISSET_ISEMPTY_PROP_OBJ:
537
0
      TO_STRING_NOWARN(val);
538
0
      opline->op2.constant = zend_optimizer_add_literal(op_array, val);
539
0
      opline->extended_value = alloc_cache_slots(op_array, 3) | (opline->extended_value & ZEND_ISEMPTY);
540
0
      break;
541
0
    case ZEND_ASSIGN_DIM_OP:
542
16
    case ZEND_ISSET_ISEMPTY_DIM_OBJ:
543
92
    case ZEND_ASSIGN_DIM:
544
154
    case ZEND_UNSET_DIM:
545
194
    case ZEND_FETCH_DIM_R:
546
218
    case ZEND_FETCH_DIM_W:
547
218
    case ZEND_FETCH_DIM_RW:
548
218
    case ZEND_FETCH_DIM_IS:
549
218
    case ZEND_FETCH_DIM_FUNC_ARG:
550
218
    case ZEND_FETCH_DIM_UNSET:
551
218
    case ZEND_FETCH_LIST_R:
552
218
    case ZEND_FETCH_LIST_W:
553
218
      if (Z_TYPE_P(val) == IS_STRING) {
554
114
        zend_ulong index;
555
556
114
        if (ZEND_HANDLE_NUMERIC(Z_STR_P(val), index)) {
557
90
          ZVAL_LONG(&tmp, index);
558
90
          opline->op2.constant = zend_optimizer_add_literal(op_array, &tmp);
559
90
          zend_string_hash_val(Z_STR_P(val));
560
90
          zend_optimizer_add_literal(op_array, val);
561
90
          Z_EXTRA(op_array->literals[opline->op2.constant]) = ZEND_EXTRA_VALUE;
562
90
          break;
563
90
        }
564
114
      }
565
128
      opline->op2.constant = zend_optimizer_add_literal(op_array, val);
566
128
      break;
567
0
    case ZEND_ADD_ARRAY_ELEMENT:
568
0
    case ZEND_INIT_ARRAY:
569
0
      if (Z_TYPE_P(val) == IS_STRING) {
570
0
        zend_ulong index;
571
0
        if (ZEND_HANDLE_NUMERIC(Z_STR_P(val), index)) {
572
0
          zval_ptr_dtor_nogc(val);
573
0
          ZVAL_LONG(val, index);
574
0
        }
575
0
      }
576
0
      opline->op2.constant = zend_optimizer_add_literal(op_array, val);
577
0
      break;
578
0
    case ZEND_ROPE_INIT:
579
210
    case ZEND_ROPE_ADD:
580
210
    case ZEND_ROPE_END:
581
224
    case ZEND_CONCAT:
582
224
    case ZEND_FAST_CONCAT:
583
224
      TO_STRING_NOWARN(val);
584
224
      if (opline->opcode == ZEND_CONCAT && opline->op1_type == IS_CONST) {
585
0
        opline->opcode = ZEND_FAST_CONCAT;
586
0
      }
587
224
      ZEND_FALLTHROUGH;
588
963
    default:
589
963
      opline->op2.constant = zend_optimizer_add_literal(op_array, val);
590
963
      break;
591
1.24k
  }
592
593
1.23k
  opline->op2_type = IS_CONST;
594
1.23k
  if (Z_TYPE(ZEND_OP2_LITERAL(opline)) == IS_STRING) {
595
403
    zend_string_hash_val(Z_STR(ZEND_OP2_LITERAL(opline)));
596
403
  }
597
1.23k
  return true;
598
1.24k
}
599
600
bool zend_optimizer_replace_by_const(zend_op_array *op_array,
601
                                    zend_op       *opline,
602
                                    uint8_t        type,
603
                                    uint32_t       var,
604
                                    zval          *val)
605
700
{
606
700
  const zend_op *end = op_array->opcodes + op_array->last;
607
608
700
  while (opline < end) {
609
700
    if (opline->op1_type == type &&
610
628
      opline->op1.var == var) {
611
626
      switch (opline->opcode) {
612
        /* In most cases IS_TMP_VAR operand may be used only once.
613
         * The operands are usually destroyed by the opcode handler.
614
         * However, there are some exception which keep the operand alive. In that case
615
         * we want to try to replace all uses of the temporary.
616
         */
617
0
        case ZEND_FETCH_LIST_R:
618
0
        case ZEND_CASE:
619
0
        case ZEND_CASE_STRICT:
620
0
        case ZEND_SWITCH_LONG:
621
0
        case ZEND_SWITCH_STRING:
622
0
        case ZEND_MATCH:
623
0
        case ZEND_MATCH_ERROR:
624
0
        case ZEND_JMP_NULL: {
625
0
          const zend_op *end = op_array->opcodes + op_array->last;
626
0
          while (opline < end) {
627
0
            if (opline->op1_type == type && opline->op1.var == var) {
628
              /* If this opcode doesn't keep the operand alive, we're done. Check
629
               * this early, because op replacement may modify the opline. */
630
0
              bool is_last = opline->opcode != ZEND_FETCH_LIST_R
631
0
                && opline->opcode != ZEND_CASE
632
0
                && opline->opcode != ZEND_CASE_STRICT
633
0
                && opline->opcode != ZEND_SWITCH_LONG
634
0
                && opline->opcode != ZEND_SWITCH_STRING
635
0
                && opline->opcode != ZEND_MATCH
636
0
                && opline->opcode != ZEND_MATCH_ERROR
637
0
                && opline->opcode != ZEND_JMP_NULL
638
0
                && (opline->opcode != ZEND_FREE
639
0
                  || opline->extended_value != ZEND_FREE_ON_RETURN);
640
641
0
              Z_TRY_ADDREF_P(val);
642
0
              if (!zend_optimizer_update_op1_const(op_array, opline, val)) {
643
0
                zval_ptr_dtor(val);
644
0
                return false;
645
0
              }
646
0
              if (is_last) {
647
0
                break;
648
0
              }
649
0
            }
650
0
            opline++;
651
0
          }
652
0
          zval_ptr_dtor_nogc(val);
653
0
          return true;
654
0
        }
655
0
        case ZEND_VERIFY_RETURN_TYPE: {
656
0
          const zend_arg_info *ret_info = op_array->arg_info - 1;
657
0
          if (!ZEND_TYPE_CONTAINS_CODE(ret_info->type, Z_TYPE_P(val))
658
0
            || (op_array->fn_flags & ZEND_ACC_RETURN_REFERENCE)) {
659
0
            return false;
660
0
          }
661
0
          MAKE_NOP(opline);
662
663
          /* zend_handle_loops_and_finally may inserts other oplines */
664
0
          do {
665
0
            ++opline;
666
0
          } while (opline->opcode != ZEND_RETURN && opline->opcode != ZEND_RETURN_BY_REF);
667
0
          ZEND_ASSERT(opline->op1.var == var);
668
669
0
          break;
670
0
        }
671
626
        default:
672
626
          break;
673
626
      }
674
626
      return zend_optimizer_update_op1_const(op_array, opline, val);
675
626
    }
676
677
74
    if (opline->op2_type == type &&
678
74
      opline->op2.var == var) {
679
74
      return zend_optimizer_update_op2_const(op_array, opline, val);
680
74
    }
681
0
    opline++;
682
0
  }
683
684
0
  return true;
685
700
}
686
687
/* Update jump offsets after a jump was migrated to another opline */
688
13.1k
void zend_optimizer_migrate_jump(const zend_op_array *op_array, zend_op *new_opline, zend_op *opline) {
689
13.1k
  switch (new_opline->opcode) {
690
1.42k
    case ZEND_JMP:
691
1.42k
    case ZEND_FAST_CALL:
692
1.42k
      ZEND_SET_OP_JMP_ADDR(new_opline, new_opline->op1, ZEND_OP1_JMP_ADDR(opline));
693
1.42k
      break;
694
1.29k
    case ZEND_JMPZ:
695
2.62k
    case ZEND_JMPNZ:
696
2.71k
    case ZEND_JMPZ_EX:
697
2.88k
    case ZEND_JMPNZ_EX:
698
3.01k
    case ZEND_FE_RESET_R:
699
3.02k
    case ZEND_FE_RESET_RW:
700
3.02k
    case ZEND_JMP_SET:
701
3.34k
    case ZEND_COALESCE:
702
3.34k
    case ZEND_ASSERT_CHECK:
703
5.57k
    case ZEND_JMP_NULL:
704
5.57k
    case ZEND_BIND_INIT_STATIC_OR_JMP:
705
5.57k
    case ZEND_JMP_FRAMELESS:
706
5.57k
      ZEND_SET_OP_JMP_ADDR(new_opline, new_opline->op2, ZEND_OP2_JMP_ADDR(opline));
707
5.57k
      break;
708
132
    case ZEND_FE_FETCH_R:
709
136
    case ZEND_FE_FETCH_RW:
710
136
      new_opline->extended_value = ZEND_OPLINE_NUM_TO_OFFSET(op_array, new_opline, ZEND_OFFSET_TO_OPLINE_NUM(op_array, opline, opline->extended_value));
711
136
      break;
712
0
    case ZEND_CATCH:
713
0
      if (!(opline->extended_value & ZEND_LAST_CATCH)) {
714
0
        ZEND_SET_OP_JMP_ADDR(new_opline, new_opline->op2, ZEND_OP2_JMP_ADDR(opline));
715
0
      }
716
0
      break;
717
0
    case ZEND_SWITCH_LONG:
718
0
    case ZEND_SWITCH_STRING:
719
0
    case ZEND_MATCH:
720
0
    {
721
0
      const HashTable *jumptable = Z_ARRVAL(ZEND_OP2_LITERAL(opline));
722
0
      zval *zv;
723
0
      ZEND_HASH_FOREACH_VAL(jumptable, zv) {
724
0
        Z_LVAL_P(zv) = ZEND_OPLINE_NUM_TO_OFFSET(op_array, new_opline, ZEND_OFFSET_TO_OPLINE_NUM(op_array, opline, Z_LVAL_P(zv)));
725
0
      } ZEND_HASH_FOREACH_END();
726
0
      new_opline->extended_value = ZEND_OPLINE_NUM_TO_OFFSET(op_array, new_opline, ZEND_OFFSET_TO_OPLINE_NUM(op_array, opline, opline->extended_value));
727
0
      break;
728
0
    }
729
13.1k
  }
730
13.1k
}
731
732
/* Shift jump offsets based on shiftlist */
733
29.8k
void zend_optimizer_shift_jump(const zend_op_array *op_array, zend_op *opline, const uint32_t *shiftlist) {
734
29.8k
  switch (opline->opcode) {
735
1.69k
    case ZEND_JMP:
736
1.69k
    case ZEND_FAST_CALL:
737
1.69k
      ZEND_SET_OP_JMP_ADDR(opline, opline->op1, ZEND_OP1_JMP_ADDR(opline) - shiftlist[ZEND_OP1_JMP_ADDR(opline) - op_array->opcodes]);
738
1.69k
      break;
739
1.66k
    case ZEND_JMPZ:
740
3.09k
    case ZEND_JMPNZ:
741
3.21k
    case ZEND_JMPZ_EX:
742
3.40k
    case ZEND_JMPNZ_EX:
743
3.60k
    case ZEND_FE_RESET_R:
744
3.60k
    case ZEND_FE_RESET_RW:
745
3.61k
    case ZEND_JMP_SET:
746
4.07k
    case ZEND_COALESCE:
747
4.07k
    case ZEND_ASSERT_CHECK:
748
13.8k
    case ZEND_JMP_NULL:
749
13.8k
    case ZEND_BIND_INIT_STATIC_OR_JMP:
750
13.8k
    case ZEND_JMP_FRAMELESS:
751
13.8k
      ZEND_SET_OP_JMP_ADDR(opline, opline->op2, ZEND_OP2_JMP_ADDR(opline) - shiftlist[ZEND_OP2_JMP_ADDR(opline) - op_array->opcodes]);
752
13.8k
      break;
753
0
    case ZEND_CATCH:
754
0
      if (!(opline->extended_value & ZEND_LAST_CATCH)) {
755
0
        ZEND_SET_OP_JMP_ADDR(opline, opline->op2, ZEND_OP2_JMP_ADDR(opline) - shiftlist[ZEND_OP2_JMP_ADDR(opline) - op_array->opcodes]);
756
0
      }
757
0
      break;
758
201
    case ZEND_FE_FETCH_R:
759
205
    case ZEND_FE_FETCH_RW:
760
205
      opline->extended_value = ZEND_OPLINE_NUM_TO_OFFSET(op_array, opline, ZEND_OFFSET_TO_OPLINE_NUM(op_array, opline, opline->extended_value) - shiftlist[ZEND_OFFSET_TO_OPLINE_NUM(op_array, opline, opline->extended_value)]);
761
205
      break;
762
0
    case ZEND_SWITCH_LONG:
763
0
    case ZEND_SWITCH_STRING:
764
0
    case ZEND_MATCH:
765
0
    {
766
0
      const HashTable *jumptable = Z_ARRVAL(ZEND_OP2_LITERAL(opline));
767
0
      zval *zv;
768
0
      ZEND_HASH_FOREACH_VAL(jumptable, zv) {
769
0
        Z_LVAL_P(zv) = ZEND_OPLINE_NUM_TO_OFFSET(op_array, opline, ZEND_OFFSET_TO_OPLINE_NUM(op_array, opline, Z_LVAL_P(zv)) - shiftlist[ZEND_OFFSET_TO_OPLINE_NUM(op_array, opline, Z_LVAL_P(zv))]);
770
0
      } ZEND_HASH_FOREACH_END();
771
0
      opline->extended_value = ZEND_OPLINE_NUM_TO_OFFSET(op_array, opline, ZEND_OFFSET_TO_OPLINE_NUM(op_array, opline, opline->extended_value) - shiftlist[ZEND_OFFSET_TO_OPLINE_NUM(op_array, opline, opline->extended_value)]);
772
0
      break;
773
0
    }
774
29.8k
  }
775
29.8k
}
776
777
static bool zend_optimizer_ignore_class(zval *ce_zv, const zend_string *filename)
778
19.2k
{
779
19.2k
  const zend_class_entry *ce = Z_PTR_P(ce_zv);
780
781
19.2k
  if (ce->ce_flags & ZEND_ACC_PRELOADED) {
782
0
    const Bucket *ce_bucket = (const Bucket*)((uintptr_t)ce_zv - XtOffsetOf(Bucket, val));
783
0
    size_t offset = ce_bucket - EG(class_table)->arData;
784
0
    if (offset < EG(persistent_classes_count)) {
785
0
      return false;
786
0
    }
787
0
  }
788
19.2k
  return ce->type == ZEND_USER_CLASS
789
0
    && (!ce->info.user.filename || ce->info.user.filename != filename);
790
19.2k
}
791
792
static bool zend_optimizer_ignore_function(zval *fbc_zv, const zend_string *filename)
793
33.4k
{
794
33.4k
  const zend_function *fbc = Z_PTR_P(fbc_zv);
795
796
33.4k
  if (fbc->type == ZEND_INTERNAL_FUNCTION) {
797
33.4k
    return false;
798
33.4k
  } else if (fbc->type == ZEND_USER_FUNCTION) {
799
0
    if (fbc->op_array.fn_flags & ZEND_ACC_PRELOADED) {
800
0
      const Bucket *fbc_bucket = (const Bucket*)((uintptr_t)fbc_zv - XtOffsetOf(Bucket, val));
801
0
      size_t offset = fbc_bucket - EG(function_table)->arData;
802
0
      if (offset < EG(persistent_functions_count)) {
803
0
        return false;
804
0
      }
805
0
    }
806
0
    return !fbc->op_array.filename || fbc->op_array.filename != filename;
807
0
  } else {
808
0
    ZEND_ASSERT(fbc->type == ZEND_EVAL_CODE);
809
0
    return true;
810
0
  }
811
33.4k
}
812
813
zend_class_entry *zend_optimizer_get_class_entry(
814
27.3k
    const zend_script *script, const zend_op_array *op_array, zend_string *lcname) {
815
27.3k
  zend_class_entry *ce = script ? zend_hash_find_ptr(&script->class_table, lcname) : NULL;
816
27.3k
  if (ce) {
817
6.42k
    return ce;
818
6.42k
  }
819
820
20.9k
  zval *ce_zv = zend_hash_find(CG(class_table), lcname);
821
20.9k
  if (ce_zv && !zend_optimizer_ignore_class(ce_zv, op_array ? op_array->filename : NULL)) {
822
19.2k
    return Z_PTR_P(ce_zv);
823
19.2k
  }
824
825
1.62k
  if (op_array && op_array->scope && zend_string_equals_ci(op_array->scope->name, lcname)) {
826
20
    return op_array->scope;
827
20
  }
828
829
1.60k
  return NULL;
830
1.62k
}
831
832
zend_class_entry *zend_optimizer_get_class_entry_from_op1(
833
25.7k
    const zend_script *script, const zend_op_array *op_array, const zend_op *opline) {
834
25.7k
  if (opline->op1_type == IS_CONST) {
835
25.0k
    const zval *op1 = CRT_CONSTANT(opline->op1);
836
25.0k
    if (Z_TYPE_P(op1) == IS_STRING) {
837
25.0k
      return zend_optimizer_get_class_entry(script, op_array, Z_STR_P(op1 + 1));
838
25.0k
    }
839
25.0k
  } else if (opline->op1_type == IS_UNUSED && op_array->scope
840
83
      && !(op_array->scope->ce_flags & ZEND_ACC_TRAIT)
841
83
      && ((opline->op1.num & ZEND_FETCH_CLASS_MASK) == ZEND_FETCH_CLASS_SELF
842
52
        || ((opline->op1.num & ZEND_FETCH_CLASS_MASK) == ZEND_FETCH_CLASS_STATIC
843
36
          && (op_array->scope->ce_flags & ZEND_ACC_FINAL)))) {
844
31
    return op_array->scope;
845
31
  }
846
686
  return NULL;
847
25.7k
}
848
849
const zend_class_constant *zend_fetch_class_const_info(
850
1.20k
  const zend_script *script, const zend_op_array *op_array, const zend_op *opline, bool *is_prototype) {
851
1.20k
  const zend_class_entry *ce = NULL;
852
1.20k
  bool is_static_reference = false;
853
854
1.20k
  if (!opline || !op_array || opline->op2_type != IS_CONST || Z_TYPE_P(CRT_CONSTANT(opline->op2)) != IS_STRING) {
855
0
    return NULL;
856
0
  }
857
1.20k
  if (opline->op1_type == IS_CONST) {
858
1.09k
    const zval *op1 = CRT_CONSTANT(opline->op1);
859
1.09k
    if (Z_TYPE_P(op1) == IS_STRING) {
860
1.09k
      if (script) {
861
1.09k
        ce = zend_optimizer_get_class_entry(script, op_array, Z_STR_P(op1 + 1));
862
1.09k
      } else {
863
0
        zval *ce_zv = zend_hash_find(EG(class_table), Z_STR_P(op1 + 1));
864
0
        if (ce_zv && !zend_optimizer_ignore_class(ce_zv, op_array->filename)) {
865
0
          ce = Z_PTR_P(ce_zv);
866
0
        }
867
0
      }
868
1.09k
    }
869
1.09k
  } else if (opline->op1_type == IS_UNUSED
870
2
    && op_array->scope && !(op_array->scope->ce_flags & ZEND_ACC_TRAIT)
871
2
    && !(op_array->fn_flags & ZEND_ACC_TRAIT_CLONE)) {
872
2
    uint32_t fetch_type = opline->op1.num & ZEND_FETCH_CLASS_MASK;
873
2
    if (fetch_type == ZEND_FETCH_CLASS_SELF) {
874
2
      ce = op_array->scope;
875
2
    } else if (fetch_type == ZEND_FETCH_CLASS_STATIC) {
876
0
      ce = op_array->scope;
877
0
      is_static_reference = true;
878
0
    } else if (fetch_type == ZEND_FETCH_CLASS_PARENT) {
879
0
      if (op_array->scope->ce_flags & ZEND_ACC_LINKED) {
880
0
        ce = op_array->scope->parent;
881
0
      }
882
0
    }
883
2
  }
884
1.20k
  if (!ce || (ce->ce_flags & ZEND_ACC_TRAIT)) {
885
162
    return NULL;
886
162
  }
887
1.04k
  zend_class_constant *const_info = zend_hash_find_ptr(&ce->constants_table, Z_STR_P(CRT_CONSTANT(opline->op2)));
888
1.04k
  if (!const_info) {
889
404
    return NULL;
890
404
  }
891
636
  if ((ZEND_CLASS_CONST_FLAGS(const_info) & ZEND_ACC_DEPRECATED)
892
632
    || ((ZEND_CLASS_CONST_FLAGS(const_info) & ZEND_ACC_PPP_MASK) != ZEND_ACC_PUBLIC && const_info->ce != op_array->scope)) {
893
4
    return NULL;
894
4
  }
895
632
  *is_prototype = is_static_reference
896
0
    && !(const_info->ce->ce_flags & ZEND_ACC_FINAL) && !(ZEND_CLASS_CONST_FLAGS(const_info) & ZEND_ACC_FINAL);
897
898
632
  return const_info;
899
636
}
900
901
zend_function *zend_optimizer_get_called_func(
902
    const zend_script *script, const zend_op_array *op_array, zend_op *opline, bool *is_prototype)
903
89.4k
{
904
89.4k
  *is_prototype = false;
905
89.4k
  switch (opline->opcode) {
906
39.5k
    case ZEND_INIT_FCALL:
907
39.5k
    {
908
39.5k
      zend_string *function_name = Z_STR_P(CRT_CONSTANT(opline->op2));
909
39.5k
      zend_function *func;
910
39.5k
      zval *func_zv;
911
39.5k
      if (script && (func = zend_hash_find_ptr(&script->function_table, function_name)) != NULL) {
912
6.13k
        return func;
913
33.4k
      } else if ((func_zv = zend_hash_find(EG(function_table), function_name)) != NULL) {
914
33.4k
        if (!zend_optimizer_ignore_function(func_zv, op_array->filename)) {
915
33.4k
          return Z_PTR_P(func_zv);
916
33.4k
        }
917
33.4k
      }
918
0
      break;
919
39.5k
    }
920
1.65k
    case ZEND_INIT_FCALL_BY_NAME:
921
2.00k
    case ZEND_INIT_NS_FCALL_BY_NAME:
922
2.00k
      if (opline->op2_type == IS_CONST && Z_TYPE_P(CRT_CONSTANT(opline->op2)) == IS_STRING) {
923
2.00k
        const zval *function_name = CRT_CONSTANT(opline->op2) + 1;
924
2.00k
        zend_function *func;
925
2.00k
        zval *func_zv;
926
2.00k
        if (script && (func = zend_hash_find_ptr(&script->function_table, Z_STR_P(function_name)))) {
927
243
          return func;
928
1.76k
        } else if ((func_zv = zend_hash_find(EG(function_table), Z_STR_P(function_name))) != NULL) {
929
0
          if (!zend_optimizer_ignore_function(func_zv, op_array->filename)) {
930
0
            return Z_PTR_P(func_zv);
931
0
          }
932
0
        }
933
2.00k
      }
934
1.76k
      break;
935
1.95k
    case ZEND_INIT_STATIC_METHOD_CALL:
936
1.95k
      if (opline->op2_type == IS_CONST && Z_TYPE_P(CRT_CONSTANT(opline->op2)) == IS_STRING) {
937
1.76k
        const zend_class_entry *ce = zend_optimizer_get_class_entry_from_op1(
938
1.76k
          script, op_array, opline);
939
1.76k
        if (ce) {
940
1.39k
          zend_string *func_name = Z_STR_P(CRT_CONSTANT(opline->op2) + 1);
941
1.39k
          zend_function *fbc = zend_hash_find_ptr(&ce->function_table, func_name);
942
1.39k
          if (fbc) {
943
1.36k
            bool is_public = (fbc->common.fn_flags & ZEND_ACC_PUBLIC) != 0;
944
1.36k
            bool same_scope = fbc->common.scope == op_array->scope;
945
1.36k
            if (is_public || same_scope) {
946
1.33k
              return fbc;
947
1.33k
            }
948
1.36k
          }
949
1.39k
        }
950
1.76k
      }
951
616
      break;
952
27.7k
    case ZEND_INIT_METHOD_CALL:
953
27.7k
      if (opline->op1_type == IS_UNUSED
954
264
          && opline->op2_type == IS_CONST && Z_TYPE_P(CRT_CONSTANT(opline->op2)) == IS_STRING
955
264
          && op_array->scope
956
252
          && !(op_array->fn_flags & ZEND_ACC_TRAIT_CLONE)
957
252
          && !(op_array->scope->ce_flags & ZEND_ACC_TRAIT)) {
958
252
        zend_string *method_name = Z_STR_P(CRT_CONSTANT(opline->op2) + 1);
959
252
        zend_function *fbc = zend_hash_find_ptr(
960
252
          &op_array->scope->function_table, method_name);
961
252
        if (fbc) {
962
224
          bool is_private = (fbc->common.fn_flags & ZEND_ACC_PRIVATE) != 0;
963
224
          if (is_private) {
964
            /* Only use private method if in the same scope. We can't even use it
965
             * as a prototype, as it may be overridden with changed signature. */
966
24
            bool same_scope = fbc->common.scope == op_array->scope;
967
24
            return same_scope ? fbc : NULL;
968
24
          }
969
          /* Prototype methods are potentially overridden. fbc still contains useful type information.
970
           * Some optimizations may not be applied, like inlining or inferring the send-mode of superfluous args.
971
           * A method cannot be overridden if the class or method is final. */
972
200
          if ((fbc->common.fn_flags & ZEND_ACC_FINAL) == 0 &&
973
200
            (fbc->common.scope->ce_flags & ZEND_ACC_FINAL) == 0) {
974
200
            *is_prototype = true;
975
200
          }
976
200
          return fbc;
977
224
        }
978
252
      }
979
27.4k
      break;
980
27.4k
    case ZEND_INIT_PARENT_PROPERTY_HOOK_CALL: {
981
12
      const zend_class_entry *scope = op_array->scope;
982
12
      ZEND_ASSERT(scope != NULL);
983
12
      if ((scope->ce_flags & ZEND_ACC_LINKED) && scope->parent) {
984
12
        const zend_class_entry *parent_scope = scope->parent;
985
12
        zend_string *prop_name = Z_STR_P(CRT_CONSTANT(opline->op1));
986
12
        zend_property_hook_kind hook_kind = opline->op2.num;
987
12
        const zend_property_info *prop_info = zend_get_property_info(parent_scope, prop_name, /* silent */ true);
988
989
12
        if (prop_info
990
12
          && prop_info != ZEND_WRONG_PROPERTY_INFO
991
12
          && !(prop_info->flags & ZEND_ACC_PRIVATE)
992
12
          && prop_info->hooks) {
993
0
          zend_function *fbc = prop_info->hooks[hook_kind];
994
0
          if (fbc) {
995
0
            *is_prototype = false;
996
0
            return fbc;
997
0
          }
998
0
        }
999
12
      }
1000
12
      break;
1001
12
    }
1002
18.2k
    case ZEND_NEW:
1003
18.2k
    {
1004
18.2k
      const zend_class_entry *ce = zend_optimizer_get_class_entry_from_op1(
1005
18.2k
        script, op_array, opline);
1006
18.2k
      if (ce && ce->type == ZEND_USER_CLASS) {
1007
1.54k
        return ce->constructor;
1008
1.54k
      }
1009
16.6k
      break;
1010
18.2k
    }
1011
89.4k
  }
1012
46.5k
  return NULL;
1013
89.4k
}
1014
1015
24.8k
uint32_t zend_optimizer_classify_function(const zend_string *name, uint32_t num_args) {
1016
24.8k
  if (zend_string_equals_literal(name, "extract")) {
1017
0
    return ZEND_FUNC_INDIRECT_VAR_ACCESS;
1018
24.8k
  } else if (zend_string_equals_literal(name, "compact")) {
1019
0
    return ZEND_FUNC_INDIRECT_VAR_ACCESS;
1020
24.8k
  } else if (zend_string_equals_literal(name, "get_defined_vars")) {
1021
20
    return ZEND_FUNC_INDIRECT_VAR_ACCESS;
1022
24.8k
  } else if (zend_string_equals_literal(name, "db2_execute")) {
1023
0
    return ZEND_FUNC_INDIRECT_VAR_ACCESS;
1024
24.8k
  } else if (zend_string_equals_literal(name, "func_num_args")) {
1025
4
    return ZEND_FUNC_VARARG;
1026
24.8k
  } else if (zend_string_equals_literal(name, "func_get_arg")) {
1027
86
    return ZEND_FUNC_VARARG;
1028
24.7k
  } else if (zend_string_equals_literal(name, "func_get_args")) {
1029
12
    return ZEND_FUNC_VARARG;
1030
24.7k
  } else {
1031
24.7k
    return 0;
1032
24.7k
  }
1033
24.8k
}
1034
1035
0
zend_op *zend_optimizer_get_loop_var_def(const zend_op_array *op_array, zend_op *free_opline) {
1036
0
  uint32_t var = free_opline->op1.var;
1037
0
  ZEND_ASSERT(zend_optimizer_is_loop_var_free(free_opline));
1038
1039
0
  while (--free_opline >= op_array->opcodes) {
1040
0
    if ((free_opline->result_type & (IS_TMP_VAR|IS_VAR)) && free_opline->result.var == var) {
1041
0
      return free_opline;
1042
0
    }
1043
0
  }
1044
0
  return NULL;
1045
0
}
1046
1047
static void zend_optimize(zend_op_array      *op_array,
1048
                          zend_optimizer_ctx *ctx)
1049
17.0k
{
1050
17.0k
  if (op_array->type == ZEND_EVAL_CODE) {
1051
0
    return;
1052
0
  }
1053
1054
17.0k
  if (ctx->debug_level & ZEND_DUMP_BEFORE_OPTIMIZER) {
1055
0
    zend_dump_op_array(op_array, ZEND_DUMP_LIVE_RANGES, "before optimizer", NULL);
1056
0
  }
1057
1058
  /* pass 1 (Simple local optimizations)
1059
   * - persistent constant substitution (true, false, null, etc)
1060
   * - constant casting (ADD expects numbers, CONCAT strings, etc)
1061
   * - constant expression evaluation
1062
   * - optimize constant conditional JMPs
1063
   * - pre-evaluate constant function calls
1064
   * - eliminate FETCH $GLOBALS followed by FETCH_DIM/UNSET_DIM/ISSET_ISEMPTY_DIM
1065
   */
1066
17.0k
  if (ZEND_OPTIMIZER_PASS_1 & ctx->optimization_level) {
1067
17.0k
    zend_optimizer_pass1(op_array, ctx);
1068
17.0k
    if (ctx->debug_level & ZEND_DUMP_AFTER_PASS_1) {
1069
0
      zend_dump_op_array(op_array, 0, "after pass 1", NULL);
1070
0
    }
1071
17.0k
  }
1072
1073
  /* pass 3: (Jump optimization)
1074
   * - optimize series of JMPs
1075
   */
1076
17.0k
  if (ZEND_OPTIMIZER_PASS_3 & ctx->optimization_level) {
1077
17.0k
    zend_optimizer_pass3(op_array, ctx);
1078
17.0k
    if (ctx->debug_level & ZEND_DUMP_AFTER_PASS_3) {
1079
0
      zend_dump_op_array(op_array, 0, "after pass 3", NULL);
1080
0
    }
1081
17.0k
  }
1082
1083
  /* pass 4:
1084
   * - INIT_FCALL_BY_NAME -> DO_FCALL
1085
   */
1086
17.0k
  if (ZEND_OPTIMIZER_PASS_4 & ctx->optimization_level) {
1087
17.0k
    zend_optimize_func_calls(op_array, ctx);
1088
17.0k
    if (ctx->debug_level & ZEND_DUMP_AFTER_PASS_4) {
1089
0
      zend_dump_op_array(op_array, 0, "after pass 4", NULL);
1090
0
    }
1091
17.0k
  }
1092
1093
  /* pass 5:
1094
   * - CFG optimization
1095
   */
1096
17.0k
  if (ZEND_OPTIMIZER_PASS_5 & ctx->optimization_level) {
1097
17.0k
    zend_optimize_cfg(op_array, ctx);
1098
17.0k
    if (ctx->debug_level & ZEND_DUMP_AFTER_PASS_5) {
1099
0
      zend_dump_op_array(op_array, 0, "after pass 5", NULL);
1100
0
    }
1101
17.0k
  }
1102
1103
  /* pass 6:
1104
   * - DFA optimization
1105
   */
1106
17.0k
  if ((ZEND_OPTIMIZER_PASS_6 & ctx->optimization_level) &&
1107
17.0k
      !(ZEND_OPTIMIZER_PASS_7 & ctx->optimization_level)) {
1108
0
    zend_optimize_dfa(op_array, ctx);
1109
0
    if (ctx->debug_level & ZEND_DUMP_AFTER_PASS_6) {
1110
0
      zend_dump_op_array(op_array, 0, "after pass 6", NULL);
1111
0
    }
1112
0
  }
1113
1114
  /* pass 9:
1115
   * - Optimize temp variables usage
1116
   */
1117
17.0k
  if ((ZEND_OPTIMIZER_PASS_9 & ctx->optimization_level) &&
1118
17.0k
      !(ZEND_OPTIMIZER_PASS_7 & ctx->optimization_level)) {
1119
0
    zend_optimize_temporary_variables(op_array, ctx);
1120
0
    if (ctx->debug_level & ZEND_DUMP_AFTER_PASS_9) {
1121
0
      zend_dump_op_array(op_array, 0, "after pass 9", NULL);
1122
0
    }
1123
0
  }
1124
1125
  /* pass 10:
1126
   * - remove NOPs
1127
   */
1128
17.0k
  if (((ZEND_OPTIMIZER_PASS_10|ZEND_OPTIMIZER_PASS_5) & ctx->optimization_level) == ZEND_OPTIMIZER_PASS_10) {
1129
0
    zend_optimizer_nop_removal(op_array, ctx);
1130
0
    if (ctx->debug_level & ZEND_DUMP_AFTER_PASS_10) {
1131
0
      zend_dump_op_array(op_array, 0, "after pass 10", NULL);
1132
0
    }
1133
0
  }
1134
1135
  /* pass 11:
1136
   * - Compact literals table
1137
   */
1138
17.0k
  if ((ZEND_OPTIMIZER_PASS_11 & ctx->optimization_level) &&
1139
17.0k
      (!(ZEND_OPTIMIZER_PASS_6 & ctx->optimization_level) ||
1140
17.0k
       !(ZEND_OPTIMIZER_PASS_7 & ctx->optimization_level))) {
1141
0
    zend_optimizer_compact_literals(op_array, ctx);
1142
0
    if (ctx->debug_level & ZEND_DUMP_AFTER_PASS_11) {
1143
0
      zend_dump_op_array(op_array, 0, "after pass 11", NULL);
1144
0
    }
1145
0
  }
1146
1147
17.0k
  if ((ZEND_OPTIMIZER_PASS_13 & ctx->optimization_level) &&
1148
17.0k
      (!(ZEND_OPTIMIZER_PASS_6 & ctx->optimization_level) ||
1149
17.0k
       !(ZEND_OPTIMIZER_PASS_7 & ctx->optimization_level))) {
1150
0
    zend_optimizer_compact_vars(op_array);
1151
0
    if (ctx->debug_level & ZEND_DUMP_AFTER_PASS_13) {
1152
0
      zend_dump_op_array(op_array, 0, "after pass 13", NULL);
1153
0
    }
1154
0
  }
1155
1156
17.0k
  if (ZEND_OPTIMIZER_PASS_7 & ctx->optimization_level) {
1157
17.0k
    return;
1158
17.0k
  }
1159
1160
0
  if (ctx->debug_level & ZEND_DUMP_AFTER_OPTIMIZER) {
1161
0
    zend_dump_op_array(op_array, 0, "after optimizer", NULL);
1162
0
  }
1163
0
}
1164
1165
static void zend_revert_pass_two(zend_op_array *op_array)
1166
17.0k
{
1167
17.0k
  zend_op *opline;
1168
1169
17.0k
  ZEND_ASSERT((op_array->fn_flags & ZEND_ACC_DONE_PASS_TWO) != 0);
1170
1171
17.0k
  opline = op_array->opcodes;
1172
17.0k
  const zend_op *end = opline + op_array->last;
1173
1.00M
  while (opline < end) {
1174
987k
    if (opline->op1_type == IS_CONST) {
1175
127k
      ZEND_PASS_TWO_UNDO_CONSTANT(op_array, opline, opline->op1);
1176
127k
    }
1177
987k
    if (opline->op2_type == IS_CONST) {
1178
264k
      ZEND_PASS_TWO_UNDO_CONSTANT(op_array, opline, opline->op2);
1179
264k
    }
1180
    /* reset smart branch flags IS_SMART_BRANCH_JMP[N]Z */
1181
987k
    opline->result_type &= (IS_TMP_VAR|IS_VAR|IS_CV|IS_CONST);
1182
987k
    opline++;
1183
987k
  }
1184
17.0k
#if !ZEND_USE_ABS_CONST_ADDR
1185
17.0k
  if (op_array->literals) {
1186
17.0k
    zval *literals = emalloc(sizeof(zval) * op_array->last_literal);
1187
17.0k
    memcpy(literals, op_array->literals, sizeof(zval) * op_array->last_literal);
1188
17.0k
    op_array->literals = literals;
1189
17.0k
  }
1190
17.0k
#endif
1191
1192
17.0k
  op_array->fn_flags &= ~ZEND_ACC_DONE_PASS_TWO;
1193
17.0k
}
1194
1195
static void zend_redo_pass_two(zend_op_array *op_array)
1196
10.2k
{
1197
10.2k
  zend_op *opline, *end;
1198
#if ZEND_USE_ABS_JMP_ADDR && !ZEND_USE_ABS_CONST_ADDR
1199
  zend_op *old_opcodes = op_array->opcodes;
1200
#endif
1201
1202
10.2k
  ZEND_ASSERT((op_array->fn_flags & ZEND_ACC_DONE_PASS_TWO) == 0);
1203
1204
10.2k
#if !ZEND_USE_ABS_CONST_ADDR
1205
10.2k
  if (op_array->last_literal) {
1206
10.2k
    op_array->opcodes = (zend_op *) erealloc(op_array->opcodes,
1207
10.2k
      ZEND_MM_ALIGNED_SIZE_EX(sizeof(zend_op) * op_array->last, 16) +
1208
10.2k
      sizeof(zval) * op_array->last_literal);
1209
10.2k
    memcpy(((char*)op_array->opcodes) + ZEND_MM_ALIGNED_SIZE_EX(sizeof(zend_op) * op_array->last, 16),
1210
10.2k
      op_array->literals, sizeof(zval) * op_array->last_literal);
1211
10.2k
    efree(op_array->literals);
1212
10.2k
    op_array->literals = (zval*)(((char*)op_array->opcodes) + ZEND_MM_ALIGNED_SIZE_EX(sizeof(zend_op) * op_array->last, 16));
1213
10.2k
  } else {
1214
0
    if (op_array->literals) {
1215
0
      efree(op_array->literals);
1216
0
    }
1217
0
    op_array->literals = NULL;
1218
0
  }
1219
10.2k
#endif
1220
1221
10.2k
  opline = op_array->opcodes;
1222
10.2k
  end = opline + op_array->last;
1223
422k
  while (opline < end) {
1224
412k
    if (opline->op1_type == IS_CONST) {
1225
84.4k
      ZEND_PASS_TWO_UPDATE_CONSTANT(op_array, opline, opline->op1);
1226
84.4k
    }
1227
412k
    if (opline->op2_type == IS_CONST) {
1228
77.5k
      ZEND_PASS_TWO_UPDATE_CONSTANT(op_array, opline, opline->op2);
1229
77.5k
    }
1230
    /* fix jumps to point to new array */
1231
412k
    switch (opline->opcode) {
1232
#if ZEND_USE_ABS_JMP_ADDR && !ZEND_USE_ABS_CONST_ADDR
1233
      case ZEND_JMP:
1234
      case ZEND_FAST_CALL:
1235
        opline->op1.jmp_addr = &op_array->opcodes[opline->op1.jmp_addr - old_opcodes];
1236
        break;
1237
      case ZEND_JMPZ:
1238
      case ZEND_JMPNZ:
1239
      case ZEND_JMPZ_EX:
1240
      case ZEND_JMPNZ_EX:
1241
      case ZEND_JMP_SET:
1242
      case ZEND_COALESCE:
1243
      case ZEND_FE_RESET_R:
1244
      case ZEND_FE_RESET_RW:
1245
      case ZEND_ASSERT_CHECK:
1246
      case ZEND_JMP_NULL:
1247
      case ZEND_BIND_INIT_STATIC_OR_JMP:
1248
      case ZEND_JMP_FRAMELESS:
1249
        opline->op2.jmp_addr = &op_array->opcodes[opline->op2.jmp_addr - old_opcodes];
1250
        break;
1251
      case ZEND_CATCH:
1252
        if (!(opline->extended_value & ZEND_LAST_CATCH)) {
1253
          opline->op2.jmp_addr = &op_array->opcodes[opline->op2.jmp_addr - old_opcodes];
1254
        }
1255
        break;
1256
      case ZEND_FE_FETCH_R:
1257
      case ZEND_FE_FETCH_RW:
1258
      case ZEND_SWITCH_LONG:
1259
      case ZEND_SWITCH_STRING:
1260
      case ZEND_MATCH:
1261
        /* relative extended_value don't have to be changed */
1262
        break;
1263
#endif
1264
34
      case ZEND_IS_IDENTICAL:
1265
50
      case ZEND_IS_NOT_IDENTICAL:
1266
5.70k
      case ZEND_IS_EQUAL:
1267
6.08k
      case ZEND_IS_NOT_EQUAL:
1268
6.61k
      case ZEND_IS_SMALLER:
1269
6.89k
      case ZEND_IS_SMALLER_OR_EQUAL:
1270
6.89k
      case ZEND_CASE:
1271
6.89k
      case ZEND_CASE_STRICT:
1272
6.89k
      case ZEND_ISSET_ISEMPTY_CV:
1273
6.89k
      case ZEND_ISSET_ISEMPTY_VAR:
1274
7.02k
      case ZEND_ISSET_ISEMPTY_DIM_OBJ:
1275
7.02k
      case ZEND_ISSET_ISEMPTY_PROP_OBJ:
1276
7.02k
      case ZEND_ISSET_ISEMPTY_STATIC_PROP:
1277
7.03k
      case ZEND_INSTANCEOF:
1278
7.12k
      case ZEND_TYPE_CHECK:
1279
7.12k
      case ZEND_DEFINED:
1280
7.12k
      case ZEND_IN_ARRAY:
1281
7.12k
      case ZEND_ARRAY_KEY_EXISTS:
1282
7.12k
        if (opline->result_type & IS_TMP_VAR) {
1283
          /* reinitialize result_type of smart branch instructions */
1284
7.12k
          if (opline + 1 < end) {
1285
7.12k
            if ((opline+1)->opcode == ZEND_JMPZ
1286
5.53k
             && (opline+1)->op1_type == IS_TMP_VAR
1287
5.53k
             && (opline+1)->op1.var == opline->result.var) {
1288
5.53k
              opline->result_type = IS_SMART_BRANCH_JMPZ | IS_TMP_VAR;
1289
5.53k
            } else if ((opline+1)->opcode == ZEND_JMPNZ
1290
398
             && (opline+1)->op1_type == IS_TMP_VAR
1291
398
             && (opline+1)->op1.var == opline->result.var) {
1292
398
              opline->result_type = IS_SMART_BRANCH_JMPNZ | IS_TMP_VAR;
1293
398
            }
1294
7.12k
          }
1295
7.12k
        }
1296
7.12k
        break;
1297
412k
    }
1298
412k
    ZEND_VM_SET_OPCODE_HANDLER(opline);
1299
412k
    opline++;
1300
412k
  }
1301
1302
10.2k
  op_array->fn_flags |= ZEND_ACC_DONE_PASS_TWO;
1303
10.2k
}
1304
1305
static void zend_redo_pass_two_ex(zend_op_array *op_array, const zend_ssa *ssa)
1306
6.78k
{
1307
6.78k
  zend_op *opline, *end;
1308
#if ZEND_USE_ABS_JMP_ADDR && !ZEND_USE_ABS_CONST_ADDR
1309
  zend_op *old_opcodes = op_array->opcodes;
1310
#endif
1311
1312
6.78k
  ZEND_ASSERT((op_array->fn_flags & ZEND_ACC_DONE_PASS_TWO) == 0);
1313
1314
6.78k
#if !ZEND_USE_ABS_CONST_ADDR
1315
6.78k
  if (op_array->last_literal) {
1316
6.67k
    op_array->opcodes = (zend_op *) erealloc(op_array->opcodes,
1317
6.67k
      ZEND_MM_ALIGNED_SIZE_EX(sizeof(zend_op) * op_array->last, 16) +
1318
6.67k
      sizeof(zval) * op_array->last_literal);
1319
6.67k
    memcpy(((char*)op_array->opcodes) + ZEND_MM_ALIGNED_SIZE_EX(sizeof(zend_op) * op_array->last, 16),
1320
6.67k
      op_array->literals, sizeof(zval) * op_array->last_literal);
1321
6.67k
    efree(op_array->literals);
1322
6.67k
    op_array->literals = (zval*)(((char*)op_array->opcodes) + ZEND_MM_ALIGNED_SIZE_EX(sizeof(zend_op) * op_array->last, 16));
1323
6.67k
  } else {
1324
105
    if (op_array->literals) {
1325
105
      efree(op_array->literals);
1326
105
    }
1327
105
    op_array->literals = NULL;
1328
105
  }
1329
6.78k
#endif
1330
1331
6.78k
  opline = op_array->opcodes;
1332
6.78k
  end = opline + op_array->last;
1333
551k
  while (opline < end) {
1334
544k
    const zend_ssa_op *ssa_op = &ssa->ops[opline - op_array->opcodes];
1335
544k
    uint32_t op1_info = opline->op1_type == IS_UNUSED ? 0 : (OP1_INFO() & (MAY_BE_UNDEF|MAY_BE_ANY|MAY_BE_REF|MAY_BE_ARRAY_OF_ANY|MAY_BE_ARRAY_KEY_ANY));
1336
544k
    uint32_t op2_info = opline->op1_type == IS_UNUSED ? 0 : (OP2_INFO() & (MAY_BE_UNDEF|MAY_BE_ANY|MAY_BE_REF|MAY_BE_ARRAY_OF_ANY|MAY_BE_ARRAY_KEY_ANY));
1337
544k
    uint32_t res_info =
1338
544k
      (opline->opcode == ZEND_PRE_INC ||
1339
543k
       opline->opcode == ZEND_PRE_DEC ||
1340
543k
       opline->opcode == ZEND_POST_INC ||
1341
543k
       opline->opcode == ZEND_POST_DEC) ?
1342
1.15k
        ((ssa->ops[opline - op_array->opcodes].op1_def >= 0) ? (OP1_DEF_INFO() & (MAY_BE_UNDEF|MAY_BE_ANY|MAY_BE_REF|MAY_BE_ARRAY_OF_ANY|MAY_BE_ARRAY_KEY_ANY)) : MAY_BE_ANY) :
1343
544k
        (opline->result_type == IS_UNUSED ? 0 : (RES_INFO() & (MAY_BE_UNDEF|MAY_BE_ANY|MAY_BE_REF|MAY_BE_ARRAY_OF_ANY|MAY_BE_ARRAY_KEY_ANY)));
1344
1345
544k
    if (opline->op1_type == IS_CONST) {
1346
37.8k
      ZEND_PASS_TWO_UPDATE_CONSTANT(op_array, opline, opline->op1);
1347
37.8k
    }
1348
544k
    if (opline->op2_type == IS_CONST) {
1349
182k
      ZEND_PASS_TWO_UPDATE_CONSTANT(op_array, opline, opline->op2);
1350
182k
    }
1351
1352
    /* fix jumps to point to new array */
1353
544k
    switch (opline->opcode) {
1354
#if ZEND_USE_ABS_JMP_ADDR && !ZEND_USE_ABS_CONST_ADDR
1355
      case ZEND_JMP:
1356
      case ZEND_FAST_CALL:
1357
        opline->op1.jmp_addr = &op_array->opcodes[opline->op1.jmp_addr - old_opcodes];
1358
        break;
1359
      case ZEND_JMPZ:
1360
      case ZEND_JMPNZ:
1361
      case ZEND_JMPZ_EX:
1362
      case ZEND_JMPNZ_EX:
1363
      case ZEND_JMP_SET:
1364
      case ZEND_COALESCE:
1365
      case ZEND_FE_RESET_R:
1366
      case ZEND_FE_RESET_RW:
1367
      case ZEND_ASSERT_CHECK:
1368
      case ZEND_JMP_NULL:
1369
      case ZEND_BIND_INIT_STATIC_OR_JMP:
1370
      case ZEND_JMP_FRAMELESS:
1371
        opline->op2.jmp_addr = &op_array->opcodes[opline->op2.jmp_addr - old_opcodes];
1372
        break;
1373
      case ZEND_CATCH:
1374
        if (!(opline->extended_value & ZEND_LAST_CATCH)) {
1375
          opline->op2.jmp_addr = &op_array->opcodes[opline->op2.jmp_addr - old_opcodes];
1376
        }
1377
        break;
1378
      case ZEND_FE_FETCH_R:
1379
      case ZEND_FE_FETCH_RW:
1380
      case ZEND_SWITCH_LONG:
1381
      case ZEND_SWITCH_STRING:
1382
      case ZEND_MATCH:
1383
        /* relative extended_value don't have to be changed */
1384
        break;
1385
#endif
1386
312
      case ZEND_IS_IDENTICAL:
1387
516
      case ZEND_IS_NOT_IDENTICAL:
1388
1.01k
      case ZEND_IS_EQUAL:
1389
1.66k
      case ZEND_IS_NOT_EQUAL:
1390
3.79k
      case ZEND_IS_SMALLER:
1391
4.23k
      case ZEND_IS_SMALLER_OR_EQUAL:
1392
4.23k
      case ZEND_CASE:
1393
4.23k
      case ZEND_CASE_STRICT:
1394
4.23k
      case ZEND_ISSET_ISEMPTY_CV:
1395
4.23k
      case ZEND_ISSET_ISEMPTY_VAR:
1396
4.88k
      case ZEND_ISSET_ISEMPTY_DIM_OBJ:
1397
4.89k
      case ZEND_ISSET_ISEMPTY_PROP_OBJ:
1398
4.92k
      case ZEND_ISSET_ISEMPTY_STATIC_PROP:
1399
4.93k
      case ZEND_INSTANCEOF:
1400
5.04k
      case ZEND_TYPE_CHECK:
1401
5.05k
      case ZEND_DEFINED:
1402
5.05k
      case ZEND_IN_ARRAY:
1403
5.05k
      case ZEND_ARRAY_KEY_EXISTS:
1404
5.05k
        if (opline->result_type & IS_TMP_VAR) {
1405
          /* reinitialize result_type of smart branch instructions */
1406
5.00k
          if (opline + 1 < end) {
1407
5.00k
            if ((opline+1)->opcode == ZEND_JMPZ
1408
1.23k
             && (opline+1)->op1_type == IS_TMP_VAR
1409
1.23k
             && (opline+1)->op1.var == opline->result.var) {
1410
1.23k
              opline->result_type = IS_SMART_BRANCH_JMPZ | IS_TMP_VAR;
1411
3.76k
            } else if ((opline+1)->opcode == ZEND_JMPNZ
1412
1.07k
             && (opline+1)->op1_type == IS_TMP_VAR
1413
1.07k
             && (opline+1)->op1.var == opline->result.var) {
1414
1.07k
              opline->result_type = IS_SMART_BRANCH_JMPNZ | IS_TMP_VAR;
1415
1.07k
            }
1416
5.00k
          }
1417
5.00k
        }
1418
5.05k
        break;
1419
544k
    }
1420
#ifdef ZEND_VERIFY_TYPE_INFERENCE
1421
    if (ssa_op->op1_use >= 0) {
1422
      opline->op1_use_type = ssa->var_info[ssa_op->op1_use].type;
1423
    }
1424
    if (ssa_op->op2_use >= 0) {
1425
      opline->op2_use_type = ssa->var_info[ssa_op->op2_use].type;
1426
    }
1427
    if (ssa_op->result_use >= 0) {
1428
      opline->result_use_type = ssa->var_info[ssa_op->result_use].type;
1429
    }
1430
    if (ssa_op->op1_def >= 0) {
1431
      opline->op1_def_type = ssa->var_info[ssa_op->op1_def].type;
1432
    }
1433
    if (ssa_op->op2_def >= 0) {
1434
      opline->op2_def_type = ssa->var_info[ssa_op->op2_def].type;
1435
    }
1436
    if (ssa_op->result_def >= 0) {
1437
      opline->result_def_type = ssa->var_info[ssa_op->result_def].type;
1438
    }
1439
#endif
1440
544k
    zend_vm_set_opcode_handler_ex(opline, op1_info, op2_info, res_info);
1441
544k
    opline++;
1442
544k
  }
1443
1444
6.78k
  op_array->fn_flags |= ZEND_ACC_DONE_PASS_TWO;
1445
6.78k
}
1446
1447
static void zend_optimize_op_array(zend_op_array      *op_array,
1448
                                   zend_optimizer_ctx *ctx)
1449
0
{
1450
  /* Revert pass_two() */
1451
0
  zend_revert_pass_two(op_array);
1452
1453
  /* Do actual optimizations */
1454
0
  zend_optimize(op_array, ctx);
1455
1456
  /* Redo pass_two() */
1457
0
  zend_redo_pass_two(op_array);
1458
1459
0
  if (op_array->live_range) {
1460
0
    zend_recalc_live_ranges(op_array, NULL);
1461
0
  }
1462
0
}
1463
1464
static void zend_adjust_fcall_stack_size(const zend_op_array *op_array, const zend_optimizer_ctx *ctx)
1465
0
{
1466
0
  zend_function *func;
1467
0
  zend_op *opline;
1468
1469
0
  opline = op_array->opcodes;
1470
0
  const zend_op* end = opline + op_array->last;
1471
0
  while (opline < end) {
1472
0
    if (opline->opcode == ZEND_INIT_FCALL) {
1473
0
      func = zend_hash_find_ptr(
1474
0
        &ctx->script->function_table,
1475
0
        Z_STR_P(RT_CONSTANT(opline, opline->op2)));
1476
0
      if (func) {
1477
0
        opline->op1.num = zend_vm_calc_used_stack(opline->extended_value, func);
1478
0
      }
1479
0
    }
1480
0
    opline++;
1481
0
  }
1482
0
}
1483
1484
static void zend_adjust_fcall_stack_size_graph(const zend_op_array *op_array)
1485
17.0k
{
1486
17.0k
  const zend_func_info *func_info = ZEND_FUNC_INFO(op_array);
1487
1488
17.0k
  if (func_info) {
1489
6.78k
    const zend_call_info *call_info =func_info->callee_info;
1490
1491
17.1k
    while (call_info) {
1492
10.4k
      zend_op *opline = call_info->caller_init_opline;
1493
1494
10.4k
      if (opline && call_info->callee_func && opline->opcode == ZEND_INIT_FCALL) {
1495
9.75k
        ZEND_ASSERT(!call_info->is_prototype);
1496
9.75k
        opline->op1.num = zend_vm_calc_used_stack(opline->extended_value, call_info->callee_func);
1497
9.75k
      }
1498
10.4k
      call_info = call_info->next_callee;
1499
10.4k
    }
1500
6.78k
  }
1501
17.0k
}
1502
1503
16.9k
static bool needs_live_range(const zend_op_array *op_array, const zend_op *def_opline) {
1504
16.9k
  const zend_func_info *func_info = ZEND_FUNC_INFO(op_array);
1505
16.9k
  const zend_ssa_op *ssa_op = &func_info->ssa.ops[def_opline - op_array->opcodes];
1506
16.9k
  int ssa_var = ssa_op->result_def;
1507
16.9k
  if (ssa_var < 0) {
1508
    /* Be conservative. */
1509
8
    return true;
1510
8
  }
1511
1512
  /* If the variable is used by a PHI, this may be the assignment of the final branch of a
1513
   * ternary/etc structure. While this is where the live range starts, the value from the other
1514
   * branch may also be used. As such, use the type of the PHI node for the following check. */
1515
16.8k
  if (func_info->ssa.vars[ssa_var].phi_use_chain) {
1516
456
    ssa_var = func_info->ssa.vars[ssa_var].phi_use_chain->ssa_var;
1517
456
  }
1518
1519
16.8k
  uint32_t type = func_info->ssa.var_info[ssa_var].type;
1520
16.8k
  return (type & (MAY_BE_STRING|MAY_BE_ARRAY|MAY_BE_OBJECT|MAY_BE_RESOURCE|MAY_BE_REF)) != 0;
1521
16.9k
}
1522
1523
static void zend_foreach_op_array_helper(
1524
34.1k
    zend_op_array *op_array, zend_op_array_func_t func, void *context) {
1525
34.1k
  func(op_array, context);
1526
36.1k
  for (uint32_t i = 0; i < op_array->num_dynamic_func_defs; i++) {
1527
2.08k
    zend_foreach_op_array_helper(op_array->dynamic_func_defs[i], func, context);
1528
2.08k
  }
1529
34.1k
}
1530
1531
void zend_foreach_op_array(zend_script *script, zend_op_array_func_t func, void *context)
1532
24.3k
{
1533
24.3k
  zval *zv;
1534
24.3k
  zend_op_array *op_array;
1535
1536
24.3k
  zend_foreach_op_array_helper(&script->main_op_array, func, context);
1537
1538
54.9k
  ZEND_HASH_MAP_FOREACH_PTR(&script->function_table, op_array) {
1539
54.9k
    zend_foreach_op_array_helper(op_array, func, context);
1540
54.9k
  } ZEND_HASH_FOREACH_END();
1541
1542
57.0k
  ZEND_HASH_MAP_FOREACH_VAL(&script->class_table, zv) {
1543
57.0k
    if (Z_TYPE_P(zv) == IS_ALIAS_PTR) {
1544
0
      continue;
1545
0
    }
1546
4.14k
    const zend_class_entry *ce = Z_CE_P(zv);
1547
22.1k
    ZEND_HASH_MAP_FOREACH_PTR(&ce->function_table, op_array) {
1548
22.1k
      if (op_array->scope == ce
1549
4.05k
          && op_array->type == ZEND_USER_FUNCTION
1550
4.05k
          && !(op_array->fn_flags & ZEND_ACC_ABSTRACT)
1551
3.93k
          && !(op_array->fn_flags & ZEND_ACC_TRAIT_CLONE)) {
1552
3.93k
        zend_foreach_op_array_helper(op_array, func, context);
1553
3.93k
      }
1554
22.1k
    } ZEND_HASH_FOREACH_END();
1555
1556
4.14k
    zend_property_info *property;
1557
16.2k
    ZEND_HASH_MAP_FOREACH_PTR(&ce->properties_info, property) {
1558
16.2k
      zend_function **hooks = property->hooks;
1559
16.2k
      if (property->ce == ce && property->hooks) {
1560
1.30k
        for (uint32_t i = 0; i < ZEND_PROPERTY_HOOK_COUNT; i++) {
1561
872
          const zend_function *hook = hooks[i];
1562
872
          if (hook && hook->common.scope == ce && !(hooks[i]->op_array.fn_flags & ZEND_ACC_TRAIT_CLONE)) {
1563
604
            zend_foreach_op_array_helper(&hooks[i]->op_array, func, context);
1564
604
          }
1565
872
        }
1566
436
      }
1567
16.2k
    } ZEND_HASH_FOREACH_END();
1568
4.14k
  } ZEND_HASH_FOREACH_END();
1569
24.3k
}
1570
1571
0
static void step_optimize_op_array(zend_op_array *op_array, void *context) {
1572
0
  zend_optimize_op_array(op_array, (zend_optimizer_ctx *) context);
1573
0
}
1574
1575
0
static void step_adjust_fcall_stack_size(zend_op_array *op_array, void *context) {
1576
0
  zend_adjust_fcall_stack_size(op_array, (zend_optimizer_ctx *) context);
1577
0
}
1578
1579
0
static void step_dump_after_optimizer(zend_op_array *op_array, void *context) {
1580
0
  zend_dump_op_array(op_array, ZEND_DUMP_LIVE_RANGES, "after optimizer", NULL);
1581
0
}
1582
1583
12.1k
static void zend_optimizer_call_registered_passes(zend_script *script, void *ctx) {
1584
12.1k
  for (int i = 0; i < zend_optimizer_registered_passes.last; i++) {
1585
0
    if (!zend_optimizer_registered_passes.pass[i]) {
1586
0
      continue;
1587
0
    }
1588
1589
0
    zend_optimizer_registered_passes.pass[i](script, ctx);
1590
0
  }
1591
12.1k
}
1592
1593
ZEND_API void zend_optimize_script(zend_script *script, zend_long optimization_level, zend_long debug_level)
1594
12.1k
{
1595
12.1k
  zend_op_array *op_array;
1596
12.1k
  zend_string *name;
1597
12.1k
  zend_optimizer_ctx ctx;
1598
12.1k
  zval *zv;
1599
1600
12.1k
  ctx.arena = zend_arena_create(64 * 1024);
1601
12.1k
  ctx.script = script;
1602
12.1k
  ctx.constants = NULL;
1603
12.1k
  ctx.optimization_level = optimization_level;
1604
12.1k
  ctx.debug_level = debug_level;
1605
1606
12.1k
  if ((ZEND_OPTIMIZER_PASS_6 & optimization_level) &&
1607
12.1k
      (ZEND_OPTIMIZER_PASS_7 & optimization_level)) {
1608
    /* Optimize using call-graph */
1609
12.1k
    zend_call_graph call_graph;
1610
12.1k
    zend_build_call_graph(&ctx.arena, script, &call_graph);
1611
1612
12.1k
    uint32_t i;
1613
12.1k
    zend_func_info *func_info;
1614
1615
29.2k
    for (i = 0; i < call_graph.op_arrays_count; i++) {
1616
17.0k
      zend_revert_pass_two(call_graph.op_arrays[i]);
1617
17.0k
      zend_optimize(call_graph.op_arrays[i], &ctx);
1618
17.0k
    }
1619
1620
12.1k
      zend_analyze_call_graph(&ctx.arena, script, &call_graph);
1621
1622
29.2k
    for (i = 0; i < call_graph.op_arrays_count; i++) {
1623
17.0k
      func_info = ZEND_FUNC_INFO(call_graph.op_arrays[i]);
1624
17.0k
      if (func_info) {
1625
17.0k
        func_info->call_map = zend_build_call_map(&ctx.arena, func_info, call_graph.op_arrays[i]);
1626
17.0k
        if (call_graph.op_arrays[i]->fn_flags & ZEND_ACC_HAS_RETURN_TYPE) {
1627
736
          zend_init_func_return_info(call_graph.op_arrays[i], script, &func_info->return_info);
1628
736
        }
1629
17.0k
      }
1630
17.0k
    }
1631
1632
29.2k
    for (i = 0; i < call_graph.op_arrays_count; i++) {
1633
17.0k
      func_info = ZEND_FUNC_INFO(call_graph.op_arrays[i]);
1634
17.0k
      if (func_info) {
1635
17.0k
        if (zend_dfa_analyze_op_array(call_graph.op_arrays[i], &ctx, &func_info->ssa) == SUCCESS) {
1636
6.78k
          func_info->flags = func_info->ssa.cfg.flags;
1637
10.2k
        } else {
1638
10.2k
          ZEND_SET_FUNC_INFO(call_graph.op_arrays[i], NULL);
1639
10.2k
        }
1640
17.0k
      }
1641
17.0k
    }
1642
1643
    //TODO: perform inner-script inference???
1644
29.2k
    for (i = 0; i < call_graph.op_arrays_count; i++) {
1645
17.0k
      func_info = ZEND_FUNC_INFO(call_graph.op_arrays[i]);
1646
17.0k
      if (func_info) {
1647
6.78k
        zend_dfa_optimize_op_array(call_graph.op_arrays[i], &ctx, &func_info->ssa, func_info->call_map);
1648
6.78k
      }
1649
17.0k
    }
1650
1651
12.1k
    if (debug_level & ZEND_DUMP_AFTER_PASS_7) {
1652
0
      for (i = 0; i < call_graph.op_arrays_count; i++) {
1653
0
        zend_dump_op_array(call_graph.op_arrays[i], 0, "after pass 7", NULL);
1654
0
      }
1655
0
    }
1656
1657
12.1k
    if (ZEND_OPTIMIZER_PASS_9 & optimization_level) {
1658
29.2k
      for (i = 0; i < call_graph.op_arrays_count; i++) {
1659
17.0k
        zend_optimize_temporary_variables(call_graph.op_arrays[i], &ctx);
1660
17.0k
        if (debug_level & ZEND_DUMP_AFTER_PASS_9) {
1661
0
          zend_dump_op_array(call_graph.op_arrays[i], 0, "after pass 9", NULL);
1662
0
        }
1663
17.0k
      }
1664
12.1k
    }
1665
1666
12.1k
    if (ZEND_OPTIMIZER_PASS_11 & optimization_level) {
1667
29.2k
      for (i = 0; i < call_graph.op_arrays_count; i++) {
1668
17.0k
        zend_optimizer_compact_literals(call_graph.op_arrays[i], &ctx);
1669
17.0k
        if (debug_level & ZEND_DUMP_AFTER_PASS_11) {
1670
0
          zend_dump_op_array(call_graph.op_arrays[i], 0, "after pass 11", NULL);
1671
0
        }
1672
17.0k
      }
1673
12.1k
    }
1674
1675
12.1k
    if (ZEND_OPTIMIZER_PASS_13 & optimization_level) {
1676
29.2k
      for (i = 0; i < call_graph.op_arrays_count; i++) {
1677
17.0k
        zend_optimizer_compact_vars(call_graph.op_arrays[i]);
1678
17.0k
        if (debug_level & ZEND_DUMP_AFTER_PASS_13) {
1679
0
          zend_dump_op_array(call_graph.op_arrays[i], 0, "after pass 13", NULL);
1680
0
        }
1681
17.0k
      }
1682
12.1k
    }
1683
1684
12.1k
    if (ZEND_OPTIMIZER_PASS_12 & optimization_level) {
1685
29.2k
      for (i = 0; i < call_graph.op_arrays_count; i++) {
1686
17.0k
        zend_adjust_fcall_stack_size_graph(call_graph.op_arrays[i]);
1687
17.0k
      }
1688
12.1k
    }
1689
1690
29.2k
    for (i = 0; i < call_graph.op_arrays_count; i++) {
1691
17.0k
      op_array = call_graph.op_arrays[i];
1692
17.0k
      func_info = ZEND_FUNC_INFO(op_array);
1693
17.0k
      if (func_info && func_info->ssa.var_info) {
1694
6.78k
        zend_redo_pass_two_ex(op_array, &func_info->ssa);
1695
6.78k
        if (op_array->live_range) {
1696
2.85k
          zend_recalc_live_ranges(op_array, needs_live_range);
1697
2.85k
        }
1698
10.2k
      } else {
1699
10.2k
        zend_redo_pass_two(op_array);
1700
10.2k
        if (op_array->live_range) {
1701
10.0k
          zend_recalc_live_ranges(op_array, NULL);
1702
10.0k
        }
1703
10.2k
      }
1704
17.0k
    }
1705
1706
29.2k
    for (i = 0; i < call_graph.op_arrays_count; i++) {
1707
17.0k
      ZEND_SET_FUNC_INFO(call_graph.op_arrays[i], NULL);
1708
17.0k
    }
1709
12.1k
  } else {
1710
0
    zend_foreach_op_array(script, step_optimize_op_array, &ctx);
1711
1712
0
    if (ZEND_OPTIMIZER_PASS_12 & optimization_level) {
1713
0
      zend_foreach_op_array(script, step_adjust_fcall_stack_size, &ctx);
1714
0
    }
1715
0
  }
1716
1717
28.5k
  ZEND_HASH_MAP_FOREACH_VAL(&script->class_table, zv) {
1718
28.5k
    if (Z_TYPE_P(zv) == IS_ALIAS_PTR) {
1719
0
      continue;
1720
0
    }
1721
2.07k
    const zend_class_entry *ce = Z_CE_P(zv);
1722
11.0k
    ZEND_HASH_MAP_FOREACH_STR_KEY_PTR(&ce->function_table, name, op_array) {
1723
11.0k
      if (op_array->scope != ce && op_array->type == ZEND_USER_FUNCTION) {
1724
134
        const zend_op_array *orig_op_array =
1725
134
          zend_hash_find_ptr(&op_array->scope->function_table, name);
1726
1727
134
        ZEND_ASSERT(orig_op_array != NULL);
1728
134
        if (orig_op_array != op_array) {
1729
0
          uint32_t fn_flags = op_array->fn_flags;
1730
0
          uint32_t fn_flags2 = op_array->fn_flags2;
1731
0
          zend_function *prototype = op_array->prototype;
1732
0
          HashTable *ht = op_array->static_variables;
1733
1734
0
          *op_array = *orig_op_array;
1735
0
          op_array->fn_flags = fn_flags;
1736
0
          op_array->fn_flags2 = fn_flags2;
1737
0
          op_array->prototype = prototype;
1738
0
          op_array->static_variables = ht;
1739
0
        }
1740
134
      }
1741
11.0k
    } ZEND_HASH_FOREACH_END();
1742
2.07k
  } ZEND_HASH_FOREACH_END();
1743
1744
12.1k
  zend_optimizer_call_registered_passes(script, &ctx);
1745
1746
12.1k
  if ((debug_level & ZEND_DUMP_AFTER_OPTIMIZER) &&
1747
0
      (ZEND_OPTIMIZER_PASS_7 & optimization_level)) {
1748
0
    zend_foreach_op_array(script, step_dump_after_optimizer, NULL);
1749
0
  }
1750
1751
12.1k
  if (ctx.constants) {
1752
0
    zend_hash_destroy(ctx.constants);
1753
0
  }
1754
12.1k
  zend_arena_destroy(ctx.arena);
1755
12.1k
}
1756
1757
ZEND_API int zend_optimizer_register_pass(zend_optimizer_pass_t pass)
1758
0
{
1759
0
  if (!pass) {
1760
0
    return -1;
1761
0
  }
1762
1763
0
  if (zend_optimizer_registered_passes.last == ZEND_OPTIMIZER_MAX_REGISTERED_PASSES) {
1764
0
    return -1;
1765
0
  }
1766
1767
0
  zend_optimizer_registered_passes.pass[
1768
0
    zend_optimizer_registered_passes.last++] = pass;
1769
1770
0
  return zend_optimizer_registered_passes.last;
1771
0
}
1772
1773
ZEND_API void zend_optimizer_unregister_pass(int idx)
1774
0
{
1775
0
  zend_optimizer_registered_passes.pass[idx-1] = NULL;
1776
0
}
1777
1778
zend_result zend_optimizer_startup(void)
1779
14
{
1780
14
  return zend_func_info_startup();
1781
14
}
1782
1783
zend_result zend_optimizer_shutdown(void)
1784
0
{
1785
0
  return zend_func_info_shutdown();
1786
0
}